Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xr5q-3f3c-4cmf

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted BMP image.

ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted BMP image.

EPSS

Процентиль: 78%
0.01191
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
почти 16 лет назад

ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted BMP image.

EPSS

Процентиль: 78%
0.01191
Низкий

Дефекты

CWE-200