CVE-2024-23284
MEDIUMApple Safari < 17.4 - Denial of Service
Title source: ruleDescription
A logic issue was addressed with improved state management. This issue is fixed in tvOS 17.4, macOS Sonoma 14.4, visionOS 1.1, iOS 17.4 and iPadOS 17.4, watchOS 10.4, iOS 16.7.6 and iPadOS 16.7.6, Safari 17.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
References (22)
... and 2 more
Scores
CVSS v3
6.5
EPSS
0.0056
EPSS Percentile
68.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Classification
CWE
CWE-693
Status
published
Affected Products (12)
apple/safari
< 17.4
apple/ipados
< 16.7.6
apple/iphone_os
< 16.7.6
apple/macos
< 14.4
apple/tvos
< 17.4
apple/visionos
< 1.1
apple/watchos
< 10.4
fedoraproject/fedora
fedoraproject/fedora
fedoraproject/fedora
webkitgtk/webkitgtk
< 2.44.0
wpewebkit/wpe_webkit
< 2.44.0
Timeline
Published
Mar 08, 2024
Tracked Since
Feb 18, 2026