CVE-2017-2534Apple MAC OS X vulnerability

14 documents4 sources
Severity
8.6HIGHNVD
EPSS
0.2%
top 55.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 22
Latest updateMay 13

Description

An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Speech Framework" component. It allows attackers to conduct sandbox-escape attacks via a crafted app.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HExploitability: 1.8 | Impact: 6.0

🔴Vulnerability Details

1
GHSA
GHSA-fxm5-m8r8-2rqj: An issue was discovered in certain Apple products2022-05-13

📋Vendor Advisories

1
Apple
CVE-2017-2534: macOS Sierra 10.12.5, Security Update 2017-002 El Capitan, and Security Update 2017-002 Yosemite2017-05-15

💬Community

11
Bugzilla
CVE-2017-7809 Mozilla: Use-after-free while deleting attached editor DOM node (MFSA 2017-19)2017-08-09
Bugzilla
CVE-2017-7792 Mozilla: Buffer overflow viewing certificates with long OID (MFSA 2017-19)2017-08-08
Bugzilla
CVE-2017-7801 Mozilla: Use-after-free with marquee during window resizing2017-08-08
Bugzilla
CVE-2017-7800 Mozilla: Use-after-free in WebSockets during disconnection (MFSA 2017-19)2017-08-08
Bugzilla
CVE-2017-7784 Mozilla: Use-after-free with image observers (MFSA 2017-19)2017-08-08