CVE-2018-4474

Severity
7.5HIGH
EPSS
0.9%
top 24.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 27
Latest updateMay 24

Description

A memory consumption issue was addressed with improved memory handling. This issue is fixed in iCloud for Windows 7.7, watchOS 5, Safari 12, iOS 12, iTunes 12.9 for Windows, tvOS 12. Unexpected interaction causes an ASSERT failure.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages12 packages

CVEListV5apple/icloud_for_windowsunspecified7.7
CVEListV5apple/itunes_for_windowsunspecified12.9
CVEListV5apple/tvosunspecified12
NVDapple/tvos< 12
CVEListV5apple/safariunspecified12

🔴Vulnerability Details

2
GHSA
GHSA-jr79-gh2g-m9rv: A memory consumption issue was addressed with improved memory handling2022-05-24
CVEList
CVE-2018-4474: A memory consumption issue was addressed with improved memory handling2020-10-27

📋Vendor Advisories

6
Apple
CVE-2018-4474: iCloud for Windows 7.72018-10-08
Apple
CVE-2018-4474: watchOS 52018-09-17
Apple
CVE-2018-4474: iOS 122018-09-17
Apple
CVE-2018-4474: tvOS 122018-09-17
Apple
CVE-2018-4474: Safari 122018-09-17