CVE-2018-4266
published 2019-04-03CVE-2018-4266: A race condition was addressed with additional validation. This issue affected versions prior toiVersions prior to: OS 11.4.1, tvOS 11.4.1, watchOS 4.3.2…
PriorityP429medium5.9CVSS 3.0
AVNACHPRNUINSUCNINAH
EPSS
1.78%
75.8th percentile
A race condition was addressed with additional validation. This issue affected versions prior toiVersions prior to: OS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | icloud | < 7.6 | 7.6 |
| apple | icloud_for_windows | — | — |
| apple | ios | — | — |
| apple | iphone_os | < 11.4.1 | 11.4.1 |
| apple | itunes | < 12.8 | 12.8 |
| apple | itunes_12.8_for_windows | — | — |
| apple | safari | < 11.1.2 | 11.1.2 |
| apple | safari | — | — |
| apple | tvos | < 11.4.1 | 11.4.1 |
| apple | tvos | — | — |
| apple | watchos | < 4.3.2 | 4.3.2 |
| apple | watchos | — | — |
| debian | webkit2gtk | < webkit2gtk 2.20.4-1 (bookworm) | webkit2gtk 2.20.4-1 (bookworm) |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.9MEDIUM
vendor_debian5.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fvcx-grrr-x536: A race condition was addressed with additional validation
ghsa_unreviewed·2022-05-14
CVE-2018-4266 [MEDIUM] CWE-362 GHSA-fvcx-grrr-x536: A race condition was addressed with additional validation
A race condition was addressed with additional validation. This issue affected versions prior toiVersions prior to: OS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
OSV
CVE-2018-4266: A race condition was addressed with additional validation
osv·2019-04-03·CVSS 5.9
CVE-2018-4266 [MEDIUM] CVE-2018-4266: A race condition was addressed with additional validation
A race condition was addressed with additional validation. This issue affected versions prior toiVersions prior to: OS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
Ubuntu
WebKitGTK+ vulnerabilities
vendor_ubuntu·2018-08-16
CVE-2018-12911 WebKitGTK+ vulnerabilities
Title: WebKitGTK+ vulnerabilities
Summary: Several security issues were fixed in WebKitGTK+.
A large number of security issues were discovered in the WebKitGTK+ Web and
JavaScript engines. If a user were tricked into viewing a malicious
website, a remote attacker could exploit a variety of issues related to web
browser security, including cross-site scripting attacks, denial of service
attacks, and arbitrary code execution.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use WebKitGTK+, such as Epiphany, to make all the necessary changes.
Apple
CVE-2018-4266: iCloud for Windows 7.6
vendor_apple·2018-07-09·CVSS 5.9
CVE-2018-4266 [MEDIUM] CVE-2018-4266: iCloud for Windows 7.6
Apple Security Update: About the security content of iCloud for Windows 7.6
Product: iCloud for Windows
Version: 7.6
CVE: CVE-2018-4266
Component: WebKit
Impact: A malicious website may be able to cause a denial of service
Description: A race condition was addressed with additional validation.
Apple
CVE-2018-4266: tvOS 11.4.1
vendor_apple·2018-07-09·CVSS 5.9
CVE-2018-4266 [MEDIUM] CVE-2018-4266: tvOS 11.4.1
Apple Security Update: About the security content of tvOS 11.4.1
Product: tvOS
Version: 11.4.1
CVE: CVE-2018-4266
Component: WebKit
Impact: A malicious website may be able to cause a denial of service
Description: A race condition was addressed with additional validation.
Apple
CVE-2018-4266: iOS 11.4.1
vendor_apple·2018-07-09·CVSS 5.9
CVE-2018-4266 [MEDIUM] CVE-2018-4266: iOS 11.4.1
Apple Security Update: About the security content of iOS 11.4.1
Product: iOS
Version: 11.4.1
CVE: CVE-2018-4266
Component: WebKit
Impact: A malicious website may be able to cause a denial of service
Description: A race condition was addressed with additional validation.
Apple
CVE-2018-4266: iTunes 12.8 for Windows
vendor_apple·2018-07-09·CVSS 5.9
CVE-2018-4266 [MEDIUM] CVE-2018-4266: iTunes 12.8 for Windows
Apple Security Update: About the security content of iTunes 12.8 for Windows
Product: iTunes 12.8 for Windows
CVE: CVE-2018-4266
Component: WebKit
Impact: A malicious website may be able to cause a denial of service
Description: A race condition was addressed with additional validation.
Apple
CVE-2018-4266: watchOS 4.3.2
vendor_apple·2018-07-09·CVSS 5.9
CVE-2018-4266 [MEDIUM] CVE-2018-4266: watchOS 4.3.2
Apple Security Update: About the security content of watchOS 4.3.2
Product: watchOS
Version: 4.3.2
CVE: CVE-2018-4266
Component: WebKit
Impact: A malicious website may be able to cause a denial of service
Description: A race condition was addressed with additional validation.
Apple
CVE-2018-4266: Safari 11.1.2
vendor_apple·2018-07-09·CVSS 5.9
CVE-2018-4266 [MEDIUM] CVE-2018-4266: Safari 11.1.2
Apple Security Update: About the security content of Safari 11.1.2
Product: Safari
Version: 11.1.2
CVE: CVE-2018-4266
Component: WebKit
Impact: A malicious website may be able to cause a denial of service
Description: A race condition was addressed with additional validation.
Debian
CVE-2018-4266: webkit2gtk - A race condition was addressed with additional validation. This issue affected v...
vendor_debian·2018·CVSS 5.9
CVE-2018-4266 [MEDIUM] CVE-2018-4266: webkit2gtk - A race condition was addressed with additional validation. This issue affected v...
A race condition was addressed with additional validation. This issue affected versions prior toiVersions prior to: OS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
Scope: local
bookworm: resolved (fixed in 2.20.4-1)
bullseye: resolved (fixed in 2.20.4-1)
forky: resolved (fixed in 2.20.4-1)
sid: resolved (fixed in 2.20.4-1)
trixie: resolved (fixed in 2.20.4-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://support.apple.com/kb/HT208932https://support.apple.com/kb/HT208933https://support.apple.com/kb/HT208934https://support.apple.com/kb/HT208935https://support.apple.com/kb/HT208936https://support.apple.com/kb/HT208938https://support.apple.com/kb/HT208932https://support.apple.com/kb/HT208933https://support.apple.com/kb/HT208934https://support.apple.com/kb/HT208935https://support.apple.com/kb/HT208936https://support.apple.com/kb/HT208938
2019-04-03
Published