7.8

CVE-2019-8602

A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. A malicious application may be able to elevate privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ iCloud SwPlatform windows Version < 7.12
Apple ≫ iCloud SwPlatform windows Version >= 10.0 < 10.4
Apple ≫ iTunes SwPlatform windows Version < 12.9.5
Apple ≫ Safari Version < 12.1.1
Apple ≫ iPhone OS Version < 12.3
Apple ≫ macOS X Version < 10.14.5
Apple ≫ tvOS Version < 12.3
Apple ≫ watchOS Version < 5.2.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 10.26% 0.951
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://support.apple.com/HT210118
Vendor Advisory
https://support.apple.com/HT210119
Vendor Advisory
https://support.apple.com/HT210120
Vendor Advisory
https://support.apple.com/HT210124
Vendor Advisory
https://support.apple.com/HT210125
Vendor Advisory
https://support.apple.com/HT210212
Vendor Advisory
https://support.apple.com/HT210122
Vendor Advisory
https://research.checkpoint.com/2019/select-code_execution-from-using-sqlite/