CVE-2013-1000Improper Restriction of Operations within the Bounds of a Memory Buffer in Apple Iphone OS

Severity
9.3CRITICALNVD
EPSS
1.3%
top 20.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 20
Latest updateMay 14

Description

WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

NVDapple/itunes11.0.2+78
NVDapple/iphone_os6.1.4+47

🔴Vulnerability Details

2
GHSA
GHSA-h2ww-qm2g-98qf: WebKit, as used in Apple iTunes before 112022-05-14
OSV
CVE-2013-1000: WebKit, as used in Apple iTunes before 112013-05-20

💥Exploits & PoCs

4
Exploit-DB
EMC AlphaStor Library Manager < 4.0 build 910 - Opcode 0x4f Buffer Overflow (Metasploit)2017-09-14
Exploit-DB
Microsoft Internet Explorer 9 - CDoc::Execute­Script­Uri Use-After-Free (MS13-009)2016-12-06
Exploit-DB
D-Link DIR-865L - Cross-Site Request Forgery2013-04-19
Exploit-DB
Verizon Fios Router MI424WR-GEN3I - Cross-Site Request Forgery2013-03-19

📋Vendor Advisories

18
Cisco
Multiple Vulnerabilities in Cisco NX-OS-Based Products2014-05-21
Cisco
Multiple Vulnerabilities in Cisco IOS XE Software for 1000 Series Aggregation Services Routers2013-10-30
Cisco
Multiple Vulnerabilities in Cisco NX-OS-Based Products2013-04-24
Cisco
Multiple Vulnerabilities in Cisco IOS XE Software for 1000 Series Aggregation Services Routers2013-04-15
Cisco
Multiple Vulnerabilities in Cisco NX-OS-Based Products