CVE-2016-9642Out-of-bounds Read in Apple IOS

CWE-125Out-of-bounds Read7 documents5 sources
Severity
5.5MEDIUMNVD
EPSS
0.2%
top 59.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 3
Latest updateMay 17

Description

JavaScriptCore in WebKit allows attackers to cause a denial of service (out-of-bounds heap read) via a crafted Javascript file.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

Appleapple/ios10.3
Appleapple/tvos10.2
Appleapple/safari10.1

🔴Vulnerability Details

2
GHSA
GHSA-v9jj-hfg8-mx43: JavaScriptCore in WebKit allows attackers to cause a denial of service (out-of-bounds heap read) via a crafted Javascript file2022-05-17
OSV
CVE-2016-9642: JavaScriptCore in WebKit allows attackers to cause a denial of service (out-of-bounds heap read) via a crafted Javascript file2017-02-03

📋Vendor Advisories

4
Ubuntu
WebKitGTK+ vulnerabilities2017-04-10
Apple
CVE-2016-9642: iOS 10.32017-03-27
Apple
CVE-2016-9642: tvOS 10.22017-03-27
Apple
CVE-2016-9642: Safari 10.12017-03-27