CVE-2022-22589
18.03.2022, 18:15
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing a maliciously crafted mail message may lead to running arbitrary javascript.Enginsight
| Vendor | Product | Version |
|---|---|---|
| apple | safari | 𝑥 < 15.3 |
| apple | ipados | 𝑥 < 15.3 |
| apple | iphone_os | 𝑥 < 15.3 |
| apple | mac_os_x | 10.15 ≤ 𝑥 < 10.15.7 |
| apple | mac_os_x | 10.15.7 |
| apple | mac_os_x | 10.15.7:security_update_2020 |
| apple | mac_os_x | 10.15.7:security_update_2020-001 |
| apple | mac_os_x | 10.15.7:security_update_2020-005 |
| apple | mac_os_x | 10.15.7:security_update_2020-007 |
| apple | mac_os_x | 10.15.7:security_update_2021-001 |
| apple | mac_os_x | 10.15.7:security_update_2021-002 |
| apple | mac_os_x | 10.15.7:security_update_2021-003 |
| apple | mac_os_x | 10.15.7:security_update_2021-006 |
| apple | mac_os_x | 10.15.7:security_update_2021-007 |
| apple | mac_os_x | 10.15.7:security_update_2021-008 |
| apple | mac_os_x | 10.15.7:security_update_2022-001 |
| apple | mac_os_x | 10.15.7:security_update_2022-002 |
| apple | mac_os_x | 10.15.7:supplemental_update |
| apple | macos | 11.0 ≤ 𝑥 < 11.6.6 |
| apple | macos | 12.0.0 ≤ 𝑥 < 12.2 |
| apple | tvos | 𝑥 < 15.3 |
| apple | watchos | 𝑥 < 8.4 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| webkit2gtk |
| ||||||||||||||
| wpewebkit |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| qtwebkit-opensource-src |
| ||||||||||||||||||||
| qtwebkit-source |
| ||||||||||||||||||||
| webkit2gtk |
| ||||||||||||||||||||
| webkitgtk |
| ||||||||||||||||||||
| wpewebkit |
|
References