CVE-2022-42795
published 2022-11-01CVE-2022-42795: A memory consumption issue was addressed with improved memory handling. This issue is fixed in tvOS 16, iOS 16, macOS Ventura 13, watchOS 9. Processing a…
PriorityP349high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.29%
67.0th percentile
A memory consumption issue was addressed with improved memory handling. This issue is fixed in tvOS 16, iOS 16, macOS Ventura 13, watchOS 9. Processing a maliciously crafted image may lead to arbitrary code execution.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | < 16.0 | 16.0 |
| apple | macos | < 13.0 | 13.0 |
| apple | macos | >= unspecified < 13 | 13 |
| apple | macos | >= unspecified < 16 | 16 |
| apple | macos_ventura | — | — |
| apple | tvos | < 16.0 | 16.0 |
| apple | tvos | — | — |
| apple | watchos | < 9.0 | 9.0 |
| apple | watchos | >= unspecified < 9 | 9 |
| apple | watchos | >= unspecified < 16 | 16 |
| apple | watchos_9 | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3v85-hh9x-mfgc: A memory consumption issue was addressed with improved memory handling
ghsa_unreviewed·2022-11-02
CVE-2022-42795 [HIGH] CWE-787 GHSA-3v85-hh9x-mfgc: A memory consumption issue was addressed with improved memory handling
A memory consumption issue was addressed with improved memory handling. This issue is fixed in tvOS 16, iOS 16, macOS Ventura 13, watchOS 9. Processing a maliciously crafted image may lead to arbitrary code execution.
Apple
CVE-2022-42795: macOS Ventura 13
vendor_apple·2022-10-24·CVSS 8.8
CVE-2022-42795 [HIGH] CVE-2022-42795: macOS Ventura 13
Apple Security Update: About the security content of macOS Ventura 13
Product: macOS Ventura
Version: 13
CVE: CVE-2022-42795
Component: Accelerate Framework
Impact: Processing a maliciously crafted image may lead to arbitrary code execution
Description: A memory consumption issue was addressed with improved memory handling.
Apple
CVE-2022-42795: tvOS 16
vendor_apple·2022-09-12·CVSS 8.8
CVE-2022-42795 [HIGH] CVE-2022-42795: tvOS 16
Apple Security Update: About the security content of tvOS 16
Product: tvOS
Version: 16
CVE: CVE-2022-42795
Component: Accelerate Framework
Impact: Processing a maliciously crafted image may lead to arbitrary code execution
Description: A memory consumption issue was addressed with improved memory handling.
Apple
CVE-2022-42795: watchOS 9
vendor_apple·2022-09-12·CVSS 8.8
CVE-2022-42795 [HIGH] CVE-2022-42795: watchOS 9
Apple Security Update: About the security content of watchOS 9
Product: watchOS 9
CVE: CVE-2022-42795
Component: Accelerate Framework
Impact: Processing a maliciously crafted image may lead to arbitrary code execution
Description: A memory consumption issue was addressed with improved memory handling.
Apple
CVE-2022-42795: iOS 16
vendor_apple·2022-09-12·CVSS 8.8
CVE-2022-42795 [HIGH] CVE-2022-42795: iOS 16
Apple Security Update: About the security content of iOS 16
Product: iOS
Version: 16
CVE: CVE-2022-42795
Component: Accelerate Framework
Impact: Processing a maliciously crafted image may lead to arbitrary code execution
Description: A memory consumption issue was addressed with improved memory handling.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://support.apple.com/en-us/HT213446https://support.apple.com/en-us/HT213486https://support.apple.com/en-us/HT213487https://support.apple.com/en-us/HT213488https://support.apple.com/en-us/HT213446https://support.apple.com/en-us/HT213486https://support.apple.com/en-us/HT213487https://support.apple.com/en-us/HT213488
2022-11-01
Published