Searching
..

Click anywhere to stop

KLA11603
Multiple vulnerabilities in Apple iCloud

Updated: 01/22/2024
Detect date
?
10/30/2019
Severity
?
Critical
Description

Multiple vulnerabilities were found in Apple iCloud. Malicious users can exploit these vulnerabilities to execute arbitrary code, perform cross-site scripting attack, cause denial of service.

Below is a complete list of vulnerabilities:

  1. A memory corruption vulnerability in libxslt can be exploited remotely to execute arbitrary code;
  2. Vulnerabilitiy in WebKit can be exploited remotely via specially crafted text file to execute arbitrary code;
  3. Multiple memory corruption vulnerabilities in WebKit Process Model can be exploited to execute arbitrary code;
  4. Multiple memory corruption vulnerabilities in WebKit can be exploited to execute arbitrary code;
  5. A logic vulnerability in WebKit can be exploited to perform cross-site scripting attacks;
  6. A memory corruption vulnerability in Graphics Driver can be exploited to execute arbitrary code;
  7. The HTTP referrer header vulnerability in WebKit can be exploited to obtain sensitive information.
Exploitation

Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.

Affected products

Apple iCloud earlier than 7.15
Apple iCloud earlier than 11.0

Solution

Update to the latest version
Download iCloud

Original advisories

HT210728
HT210727

Impacts
?
ACE 
[?]

DoS 
[?]

SB 
[?]

XSS/CSS 
[?]

SUI 
[?]
Related products
Apple iCloud
CVE-IDS
?
Find out the statistics of the vulnerabilities spreading in your region