VDB

CVE-2021-1857

CVE-2021-1857 PUBLISHED CVSS 6.5 MEDIUM

A memory initialization issue was addressed with improved memory handling. This issue is fixed in iTunes 12.11.3 for Windows, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iCloud for Windows 12.3, macOS Big Sur 11.3, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing maliciously crafted web content may disclose sensitive user information.

EPSS 0.60% · 70.1th percentile

Risk Scores

CVSS v3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
0.60%
70.1th percentile

Affected Products

VendorProductVersions
applemac_os_x10.14.6, 10.15.1, 10.15.3
appleitunes0
ApplemacOSunspecified, unspecified, unspecified
applewatchos0
AppleiOS and iPadOSunspecified
AppleiTunes for Windowsunspecified
applemacos11.0
appletvos0
AppletvOSunspecified
appleicloud0
AppleiCloud for Windowsunspecified
appleipados0
appleiphone_os0
ApplewatchOSunspecified

Timeline

  • Apr 27, 2021 CVE Published
  • Sep 9, 2021 EPSS Score
  • Sep 17, 2021 EPSS Score
  • Nov 6, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 1, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Jun 24, 2022 EPSS Score
  • Aug 22, 2022 EPSS Score
  • Oct 19, 2022 EPSS Score
  • Dec 16, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›