CVE-2018-4437

HIGH

Safari < 12.0.2 - Memory Corruption

Title source: llm
STIX 2.1

Description

Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.

References (6)

Core 6
Core References
Vendor Advisory x_refsource_misc
https://support.apple.com/kb/HT209343
Vendor Advisory x_refsource_misc
https://support.apple.com/kb/HT209342
Vendor Advisory x_refsource_misc
https://support.apple.com/kb/HT209340
Vendor Advisory x_refsource_misc
https://support.apple.com/kb/HT209344
Vendor Advisory x_refsource_misc
https://support.apple.com/kb/HT209346
Vendor Advisory x_refsource_misc
https://support.apple.com/kb/HT209345

Scores

CVSS v3 8.8
EPSS 0.0147
EPSS Percentile 70.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (6)
apple/icloud < 7.9
apple/iphone_os < 12.1.1
apple/itunes < 12.9.2
apple/safari < 12.0.2
apple/tvos < 12.1.1
apple/watchos < 5.1.2
Published Apr 03, 2019
Tracked Since Feb 18, 2026