5.5

CVE-2019-8582

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iCloud for Windows 7.12, tvOS 12.3, iTunes 12.9.5 for Windows, macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, iOS 12.3. Processing a maliciously crafted font may result in the disclosure of process memory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ iCloud SwPlatform windows Version < 7.12
Apple ≫ iTunes SwPlatform windows Version < 12.9.5
Apple ≫ iPhone OS Version < 12.3
Apple ≫ macOS X Version < 10.14.5
Apple ≫ tvOS Version < 12.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.39% 0.694
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

https://support.apple.com/en-us/HT210119
Vendor Advisory
https://support.apple.com/en-us/HT210118
Vendor Advisory
https://support.apple.com/en-us/HT210120
Vendor Advisory
https://support.apple.com/en-us/HT210124
Vendor Advisory
https://support.apple.com/en-us/HT210125
Vendor Advisory