8.8

CVE-2019-6215

Exploit
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ Safari Version < 12.0.3
Apple ≫ iPhone OS Version < 12.1.3
Apple ≫ tvOS Version < 12.1.2
Apple ≫ watchOS Version < 5.1.3
Apple ≫ iCloud Version < 7.10
   Microsoft ≫ Windows Version -
Apple ≫ iTunes Version < 12.9.3
   Microsoft ≫ Windows Version -
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 9.76% 0.949
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

https://support.apple.com/HT209443
Vendor Advisory
https://support.apple.com/HT209447
Vendor Advisory
https://support.apple.com/HT209450
Vendor Advisory
https://support.apple.com/HT209451
Vendor Advisory
http://www.securityfocus.com/bid/106691
Third Party Advisory
VDB Entry
https://security.gentoo.org/glsa/201903-12
Third Party Advisory
https://support.apple.com/HT209449
Vendor Advisory
https://usn.ubuntu.com/3889-1/
Third Party Advisory
https://www.exploit-db.com/exploits/46448/
Third Party Advisory
Exploit
VDB Entry