MEDIUM🇵🇱 Wersja polska

CVE-2024-54540

CVSS 4.3v3.1pub. 2025-01-15upd. 2025-03-24

The issue was addressed with improved input sanitization. This issue is fixed in Apple Music 1.5.0.152 for Windows. Processing maliciously crafted web content may disclose internal states of the app.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
  • Apple Music

    APP
    Apple
    < 1.5.0.152
  • Microsoft Windows 10 22h2

    OS
    Microsoft
    all versions
  • Microsoft Windows 11 24h2

    OS
    Microsoft
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2026-33824CRITICAL9.8⚠ KEVPL ✓same product

Double free w Windows IKE Extension umożliwia zdalne wykonanie kodu

CVE-2026-62815CRITICAL9.8same product

Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.

CVE-2026-49798CRITICAL9.3PL ✓same product

Use-after-free w Windows Kernel umożliwia lokalne privilege escalation

CVE-2026-42990CRITICAL9.8PL ✓same product

Heap buffer overflow w sterowniku ODBC SQL Server — zdalne wykonanie kodu

CVE-2026-49172CRITICAL9.8PL ✓same product

Heap-based buffer overflow w Windows FTP Service umożliwiający RCE