CVE-2018-4377
Apple Security Advisory 2018-10-30-6
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue affected versions prior to iOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.
Existía un problema de cross-Site Scripting (XSS) en Safari. Este problema se abordó con una validación de URL mejorada. El problema afectaba a iOS en versiones anteriores a la 12.1, watchOS en versiones anteriores a la 5.1, Safari en versiones anteriores a la 12.0.1, iTunes en versiones anteriores a la 12.9.1 y iCloud para Windows en versiones anteriores a la 7.8.
iCloud for Windows 7.8 is now available and addresses code execution, cross site scripting, denial of service, and resource exhaustion vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-01-02 CVE Reserved
- 2018-10-31 CVE Published
- 2024-08-05 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (5)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.apple.com/kb/HT209192 | 2019-04-05 | |
https://support.apple.com/kb/HT209195 | 2019-04-05 | |
https://support.apple.com/kb/HT209196 | 2019-04-05 | |
https://support.apple.com/kb/HT209197 | 2019-04-05 | |
https://support.apple.com/kb/HT209198 | 2019-04-05 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apple Search vendor "Apple" | Icloud Search vendor "Apple" for product "Icloud" | < 7.8 Search vendor "Apple" for product "Icloud" and version " < 7.8" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Apple Search vendor "Apple" | Itunes Search vendor "Apple" for product "Itunes" | < 12.9.1 Search vendor "Apple" for product "Itunes" and version " < 12.9.1" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | < 12.0.1 Search vendor "Apple" for product "Safari" and version " < 12.0.1" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | < 12.1 Search vendor "Apple" for product "Iphone Os" and version " < 12.1" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Watchos Search vendor "Apple" for product "Watchos" | < 5.1 Search vendor "Apple" for product "Watchos" and version " < 5.1" | - |
Affected
|