CVE-2018-4121
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
- Apple Safari
- < 11.1
- Apple Iphone Os
- < 11.3
- Apple Tvos
- < 11.3
- Apple Watchos
- < 4.3
- Fix
- Available
- CVSS 3.0
- 8.8 HIGH
- EPSS
- 13.2% (96th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2018-04-03
CVE-2018-4121 at NVD
5 known exploits for CVE-2018-4121
Proof-of-concept code and exploit modules indexed by Sploitus
WebKitGTK+ Memory Corruption / Code Execution Vulnerability
Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Apple Safari
Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Apple Safari
WebKit - WebAssembly Parsing Does not Correctly Check Section Order Vulnerability
WebKit - WebAssembly Parsing Does not Correctly Check Section Order