CVE Vulnerabilities

CVE-2017-2388

NULL Pointer Dereference

Published: Apr 02, 2017 | Modified: Apr 20, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the IOFireWireFamily component. It allows attackers to cause a denial of service (NULL pointer dereference) via a crafted app.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
Mac_os_xApple*10.12.3 (including)

Potential Mitigations

References