9.3

CVE-2019-8844

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafted web content may lead to arbitrary code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ iCloud SwPlatform windows Version < 7.16
Apple ≫ iCloud SwPlatform windows Version >= 10.0 < 10.9
Apple ≫ iTunes SwPlatform windows Version < 12.10.3
Apple ≫ Safari Version < 13.0.4
Apple ≫ iPadOS Version < 13.3
Apple ≫ iPhone OS Version < 13.3
Apple ≫ tvOS Version < 13.3
Apple ≫ watchOS Version < 6.1.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.18% 0.805
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://support.apple.com/en-us/HT210785
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT210789
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT210790
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT210793
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT210794
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT210795
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT210792
Vendor Advisory
Release Notes