CVE-2018-4302
published 2021-12-23CVE-2018-4302: A null pointer dereference was addressed with improved validation. This issue is fixed in macOS High Sierra 10.13, iCloud for Windows 7.0, watchOS 4, iOS 11…
PriorityP339high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.92%
56.5th percentile
A null pointer dereference was addressed with improved validation. This issue is fixed in macOS High Sierra 10.13, iCloud for Windows 7.0, watchOS 4, iOS 11, iTunes 12.7 for Windows. Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | icloud | <= 7.0 | — |
| apple | icloud_for_windows | — | — |
| apple | icloud_for_windows | >= unspecified < 7.0 | 7.0 |
| apple | ios | — | — |
| apple | ios | >= unspecified < 11 | 11 |
| apple | iphone_os | < 11 | 11 |
| apple | itunes | < 12.7 | 12.7 |
| apple | itunes_12.7_for_windows | — | — |
| apple | itunes_for_windows | >= unspecified < 12.7 | 12.7 |
| apple | mac_os_x | < 10.13 | 10.13 |
| apple | macos | >= unspecified < 10.13 | 10.13 |
| apple | macos_high_sierra | — | — |
| apple | watchos | < 4 | 4 |
| apple | watchos | >= unspecified < 4 | 4 |
| apple | watchos_4 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2018-4302: macOS High Sierra 10.13
vendor_apple·2017-09-25·CVSS 7.5
CVE-2018-4302 [HIGH] CVE-2018-4302: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2018-4302
Component: CVE-2017-9233
Impact: Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution
Description: A null pointer dereference was addressed with improved validation.
Apple
CVE-2018-4302: iCloud for Windows 7.0
vendor_apple·2017-09-25·CVSS 7.8
CVE-2018-4302 [HIGH] CVE-2018-4302: iCloud for Windows 7.0
Apple Security Update: About the security content of iCloud for Windows 7.0
Product: iCloud for Windows
Version: 7.0
CVE: CVE-2018-4302
Component: ImageIO
Impact: Processing a maliciously crafted image may lead to a denial of service
Description: An information disclosure issue existed in the processing of disk images. This issue was addressed through improved memory management.
Apple
CVE-2018-4302: watchOS 4
vendor_apple·2017-09-19·CVSS 7.5
CVE-2018-4302 [HIGH] CVE-2018-4302: watchOS 4
Apple Security Update: About the security content of watchOS 4
Product: watchOS 4
CVE: CVE-2018-4302
Component: CVE-2017-9233
Impact: Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution
Description: A use after free issue was addressed with improved memory management.
Apple
CVE-2018-4302: iOS 11
vendor_apple·2017-09-19·CVSS 7.5
CVE-2018-4302 [HIGH] CVE-2018-4302: iOS 11
Apple Security Update: About the security content of iOS 11
Product: iOS
Version: 11
CVE: CVE-2018-4302
Component: CVE-2017-9233
Impact: Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution
Description: A buffer overflow issue was addressed with improved memory handling.
Apple
CVE-2018-4302: iTunes 12.7 for Windows
vendor_apple·2017-09-12·CVSS 7.8
CVE-2018-4302 [HIGH] CVE-2018-4302: iTunes 12.7 for Windows
Apple Security Update: About the security content of iTunes 12.7 for Windows
Product: iTunes 12.7 for Windows
CVE: CVE-2018-4302
Component: ImageIO
Impact: Processing a maliciously crafted image may lead to a denial of service
Description: An information disclosure issue existed in the processing of disk images. This issue was addressed through improved memory management.
GHSA
GHSA-2573-rpmq-pq99: A null pointer dereference was addressed with improved validation
ghsa_unreviewed·2021-12-24
CVE-2018-4302 [HIGH] CWE-476 GHSA-2573-rpmq-pq99: A null pointer dereference was addressed with improved validation
A null pointer dereference was addressed with improved validation. This issue is fixed in macOS High Sierra 10.13, iCloud for Windows 7.0, watchOS 4, iOS 11, iTunes 12.7 for Windows. Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://support.apple.com/en-us/HT208112https://support.apple.com/en-us/HT208115https://support.apple.com/en-us/HT208141https://support.apple.com/en-us/HT208142https://support.apple.com/en-us/HT208144https://support.apple.com/en-us/HT208112https://support.apple.com/en-us/HT208115https://support.apple.com/en-us/HT208141https://support.apple.com/en-us/HT208142https://support.apple.com/en-us/HT208144
2021-12-23
Published