An integer overflow was addressed with improved input validation. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, macOS Ventura 13.6.8, iOS 17.6 and iPadOS 17.6, watchOS 10.6, tvOS 17.6, visionOS 1.3, macOS Sonoma 14.6. Processing a maliciously crafted file may lead to unexpected app termination.
References
Configurations
Configuration 1 (hide)
|
History
10 Dec 2024, 14:35
Type | Values Removed | Values Added |
---|---|---|
First Time |
Apple ipados
Apple iphone Os Apple tvos Apple watchos Apple macos Apple Apple visionos |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
CWE | CWE-190 | |
CPE | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
|
References | () https://support.apple.com/en-us/HT214124 - Vendor Advisory | |
References | () https://support.apple.com/en-us/HT214120 - Vendor Advisory | |
References | () http://seclists.org/fulldisclosure/2024/Jul/22 - Mailing List | |
References | () http://seclists.org/fulldisclosure/2024/Jul/16 - Mailing List | |
References | () http://seclists.org/fulldisclosure/2024/Jul/23 - Mailing List | |
References | () https://support.apple.com/en-us/HT214123 - Vendor Advisory | |
References | () https://support.apple.com/en-us/HT214122 - Vendor Advisory | |
References | () https://support.apple.com/en-us/HT214117 - Vendor Advisory | |
References | () http://seclists.org/fulldisclosure/2024/Jul/21 - Mailing List | |
References | () http://seclists.org/fulldisclosure/2024/Jul/18 - Mailing List | |
References | () http://seclists.org/fulldisclosure/2024/Jul/17 - Mailing List | |
References | () http://seclists.org/fulldisclosure/2024/Jul/19 - Mailing List | |
References | () https://support.apple.com/en-us/HT214116 - Vendor Advisory | |
References | () https://support.apple.com/en-us/HT214119 - Vendor Advisory |
30 Jul 2024, 02:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
29 Jul 2024, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-29 23:15
Updated : 2025-03-19 15:15
NVD link : CVE-2024-40784
Mitre link : CVE-2024-40784
JSON object : View
Products Affected
apple
- tvos
- watchos
- ipados
- macos
- visionos
- iphone_os
CWE
CWE-190
Integer Overflow or Wraparound