VDB
CVE-2023-41976
CVE-2023-41976
PUBLISHED
CVSS 8.699999809265137 HIGH
In Apple Safari existieren mehrere Schwachstellen. Diese bestehen in den Komponenten "WebKit" und "WebKit Process Model" und treten beim Verarbeiten von Webinhalten auf. Ein entfernter, anonymer Angreifer kann diese Schwachstelle ausnutzen, um beliebigen Programmcode auszuführen oder einen Denial of Service Zustand herbeizuführen. Zur erfolgreichen Ausnutzung ist eine Benutzeraktion erforderlich.
EPSS 0.26% · 50.2th percentile
Risk Scores
CVSS 4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.26%
50.2th percentile
Timeline
- Oct 25, 2023 CVE Published
- Oct 26, 2023 EPSS Score
- Nov 26, 2023 EPSS Score
- Dec 27, 2023 EPSS Score
- Jan 27, 2024 EPSS Score
- Mar 29, 2024 EPSS Score
- Apr 29, 2024 EPSS Score
- May 9, 2024 PoC Published
- May 30, 2024 EPSS Score
- Jun 29, 2024 EPSS Score
- Jul 30, 2024 EPSS Score
- Aug 30, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2744.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-2744 advisory
- https://support.apple.com/en-us/HT213986 advisory
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2753.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-2753 advisory
- https://support.apple.com/en-us/HT213983 advisory
- https://support.apple.com/en-us/HT213984 advisory
- https://support.apple.com/en-us/HT213985 advisory
- https://jhftss.github.io/CVE-2023-42942-xpcroleaccountd-Root-Privilege-Escalation/ advisory
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2754.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-2754 advisory
- https://support.apple.com/en-us/HT213981 advisory
- https://support.apple.com/en-us/HT213982 advisory