CVE-2018-4147Improper Restriction of Operations within the Bounds of a Memory Buffer in Apple Icloud

Severity
9.8CRITICALNVD
EPSS
0.6%
top 30.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 11
Latest updateMay 14

Description

In iCloud for Windows before 7.3, Safari before 11.0.3, iTunes before 12.7.3 for Windows, and iOS before 11.2.5, multiple memory corruption issues exist and were addressed with improved memory handling.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

NVDapple/icloud< 7.3
NVDapple/itunes< 12.7.3
NVDapple/safari< 11.0.3
NVDapple/iphone_os< 11.2.5

🔴Vulnerability Details

2
GHSA
GHSA-fp29-rv58-c49v: In iCloud for Windows before 72022-05-14
CVEList
CVE-2018-4147: In iCloud for Windows before 72019-01-11

📋Vendor Advisories

7
Apple
CVE-2018-4147: iCloud for Windows 7.32018-01-23
Apple
CVE-2018-4147: Safari 11.0.32018-01-23
Apple
CVE-2018-4147: iTunes 12.7.3 for Windows2018-01-23
Apple
CVE-2018-4147: watchOS 4.2.22018-01-23
Apple
CVE-2018-4147: tvOS 11.2.52018-01-23
CVE-2018-4147 — Apple Icloud vulnerability | cvebase