VDB

GCVE-110-NCSC-2024-457

GCVE-110-NCSC-2024-457
Advisory PublishedCVSS 9.1/10
Vulnetix · Advisory published November 20, 2024
Apple heeft meerdere kwetsbaarheden verholpen in iOS en iPadOS.

Weaknesses (CWE)

CWE-122Heap-based Buffer OverflowCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-787Out-of-bounds WriteCWE-200Exposure of Sensitive Information to an Unauthorized ActorCWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')CWE-285Improper AuthorizationCWE-284Improper Access ControlCWE-404Improper Resource Shutdown or ReleaseCWE-275-CWE-942Permissive Cross-domain Policy with Untrusted DomainsCWE-190Integer Overflow or WraparoundCWE-287Improper Authentication

Risk Scores

CVSS 3.1
9.1/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersionsPlatforms
appleios__18
appleipados__17.7
appleios__17.7
appleipados__18

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

482 records in the GCVE database · Updated August 26, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›