CVE-2018-4305
published 2019-04-03CVE-2018-4305: An input validation issue was addressed with improved input validation. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5.
PriorityP424medium6.5CVSS 3.0
AVAACLPRNUINSUCNIHAN
EPSS
0.08%
24.2th percentile
An input validation issue was addressed with improved input validation. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | < 12.0 | 12.0 |
| apple | tvos | < 12 | 12 |
| apple | tvos | — | — |
| apple | watchos | < 5.0 | 5.0 |
| apple | watchos_5 | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:N/I:P/A:N
Apple
CVE-2018-4305: tvOS 12
vendor_apple·2018-09-17·CVSS 6.5
CVE-2018-4305 [MEDIUM] CVE-2018-4305: tvOS 12
Apple Security Update: About the security content of tvOS 12
Product: tvOS
Version: 12
CVE: CVE-2018-4305
Component: IOUserEthernet
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed with improved memory handling.
Apple
CVE-2018-4305: iOS 12
vendor_apple·2018-09-17·CVSS 6.5
CVE-2018-4305 [MEDIUM] CVE-2018-4305: iOS 12
Apple Security Update: About the security content of iOS 12
Product: iOS
Version: 12
CVE: CVE-2018-4305
Component: IOUserEthernet
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed with improved memory handling.
Apple
CVE-2018-4305: watchOS 5
vendor_apple·2018-09-17·CVSS 6.5
CVE-2018-4305 [MEDIUM] CVE-2018-4305: watchOS 5
Apple Security Update: About the security content of watchOS 5
Product: watchOS 5
CVE: CVE-2018-4305
Component: IOUserEthernet
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed with improved memory handling.
GHSA
GHSA-65hx-hqm8-r3mr: An input validation issue was addressed with improved input validation
ghsa_unreviewed·2022-05-14
CVE-2018-4305 [MEDIUM] CWE-20 GHSA-65hx-hqm8-r3mr: An input validation issue was addressed with improved input validation
An input validation issue was addressed with improved input validation. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5.
No detection rules found.
No public exploits indexed.
2019-04-03
Published