Showing 4 vulnerabilities on this page for icloud

Signals CISA KEV Ransomware Nuclei
Apple vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Safari, tvOS, iCloud for Windows, iOS, iPadOS, macOS Ventura, and watchOS Same Origin Policy Bypass Vulnerability

A logic issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, iOS 15.7.2 and iPadOS 15.7.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may bypass Same Origin Policy.

CWE-345Dec 15, 2022
CVSS5.5v3.1EPSS0.197%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Apple icloud Improper Authentication

Multiple issues were addressed with improved logic. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.

CWE-287Oct 16, 2020
CVSS8.8v3.1EPSS2.19%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Apple iOS, iPadOS, tvOS, watchOS, Safari, iTunes for Windows, iCloud for Windows, iCloud for Windows Web Content Vulnerability

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously crafted web content may lead to arbitrary code execution.

Jun 9, 2020
CVSS8.8v3.1EPSS8.21%PoCs2SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Apple safari Improper Restriction of Operations within the Bounds of a Memory Buffer

An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CWE-119Jun 8, 2018
CVSS8.8v3.1EPSS53.3%PoCs4SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX