CVE-2019-8507
published 2019-12-18CVE-2019-8507: Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Mojave 10.14.4. Processing malicious data may…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.33%
25.7th percentile
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Mojave 10.14.4. Processing malicious data may lead to unexpected application termination.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | < 10.14.4 | 10.14.4 |
| apple | macos | >= unspecified < macOS Mojave 10.14.4 | macOS Mojave 10.14.4 |
| apple | macos_mojave_10.14.4_security_update_2019-002_high_sierra_security_update_2019-0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rxgh-9c22-r8rj: Multiple memory corruption issues were addressed with improved input validation
ghsa_unreviewed·2022-05-24
CVE-2019-8507 [LOW] GHSA-rxgh-9c22-r8rj: Multiple memory corruption issues were addressed with improved input validation
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Mojave 10.14.4. Processing malicious data may lead to unexpected application termination.
Apple
CVE-2019-8507: macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra
vendor_apple·2019-03-25·CVSS 5.5
CVE-2019-8507 [MEDIUM] CVE-2019-8507: macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra
Apple Security Update: About the security content of macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra
Product: macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra
CVE: CVE-2019-8507
Component: QuartzCore
Impact: Processing malicious data may lead to unexpected application termination
Description: Multiple memory corruption issues were addressed with improved input validation.
No detection rules found.
No public exploits indexed.
Fortinet
Critical Apache Log4j Vulnerability Updates | FortiGuard Labs
blogs_fortinet·2021-12-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] Critical Apache Log4j Vulnerability Updates | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Critical Apache Log4j Vulnerability Updates
By Shunichi Imano, James Slaughter, and Geri Revay | December 21, 2021
Beginning December 9th, most of the internet-connected world was forced to reckon with a critical new vulnerability discovered in the Apache Log4j framework deployed in countless servers. Officially labeled CVE-2021-44228, but colloquially known as “Log4Shell”, this vulnerability is both trivial to exploit and allows for full remote code execution on a target system. This has earned the vulnerability a CVSS score of 10 – the maximum.
On December 14th, the Apache Software Foundation revealed a second Log4j vulnerability (CVE-2021-45046). It was initially identified as a Denial-of-Service (DoS) vulnerability with a CVSS score of 3.7 and modera
Fortinet
“BlueKeep” Vulnerability (CVE-2019-0708) within Cloud/Datacenter Machines: How to Safeguard Yourself?
blogs_fortinet·2019-06-12·CVSS 9.8
CVE-2019-0708 [CRITICAL] “BlueKeep” Vulnerability (CVE-2019-0708) within Cloud/Datacenter Machines: How to Safeguard Yourself?
FORTIGUARD LABS THREAT RESEARCH
“BlueKeep” Vulnerability (CVE-2019-0708) within Cloud/Datacenter Machines: How to Safeguard Yourself?
By Kushal Arvind Shah | June 12, 2019
Afew weeks back, FortiGuard Labs heard of the BlueKeep RDP Wormable Vulnerability [CVE-2019-0708]. According to Microsoft, this vulnerability affects the Remote Desktop Protocol (RDP) service included in older versions of Windows OS, such as Windows XP, Windows Vista, Windows 7, Windows Server 2003, Windows Server 2008, and Windows Server 2008R2.
Recently, there was an article by Robert Graham of Errata Security saying that nearly 1 million machines are still vulnerable to this critical vulnerability. Microsoft and even the NSA have recently issued advisories asking users to patch their systems to avoid another attack
Fortinet
Detailed Analysis of macOS Vulnerability CVE-2019-8507
blogs_fortinet·2019-04-23·CVSS 5.5
CVE-2019-8507 [MEDIUM] Detailed Analysis of macOS Vulnerability CVE-2019-8507
FORTIGUARD LABS THREAT RESEARCH
Detailed Analysis of macOS Vulnerability CVE-2019-8507
By Kai Lu | April 23, 2019
FortiGuard Labs Threat Analysis Report on an Memory Corruption Vulnerability in QuartzCore while Handling Shape Object.
On March 25, 2019, Apple released macOS Mojave 10.14.4 and iOS 12.2. These two updates fixed a number of security vulnerabilities, including CVE-2019-8507 in QuartzCore (aka CoreAnimation), which I reported to Apple on January 3, 2019 using our FortiGuard Labs responsible disclosure process, read more. For more details on the Apple updates, please refer to https://support.apple.com/en-us/HT209600. In this blog I will provide a detailed analysis of this issue on macOS. Some of the analysis techniques used can be found in my previous blog, “Detailed Analysi
Fortinet
WordPress WooCommerce XSS Vulnerability – Hijacking a Customer Account with a Crafted Image
blogs_fortinet·2019-03-04·CVSS 6.1
[MEDIUM] WordPress WooCommerce XSS Vulnerability – Hijacking a Customer Account with a Crafted Image
FORTIGUARD LABS THREAT RESEARCH
WordPress WooCommerce XSS Vulnerability – Hijacking a Customer Account with a Crafted Image
By Zhouyuan Yang | March 04, 2019
Overview
The FortiGuard Labs team recently discovered a Cross-Site Scripting (XSS) vulnerability in WooCommerce. WooCommerce is an open-source eCommerce platform built on WordPress. According to BuiltWith statistics, WooCommerce is the No. 1 eCommerce platform, owning 22% of global market share in 2018.
This XSS vulnerability (CVE-2019-9168) exists in the zoom display of the Photoswipe function, where WooCommerce failed to sterilize an image’s title and caption data This vulnerability may allow an attacker to inject arbitrary code into a WooCommerce-powered website. When a victim visits the webpage with the attack code inserted, th
Fortinet
Detailed Analysis of macOS/iOS Vulnerability CVE-2019-6231
blogs_fortinet·2019-01-24·CVSS 5.5
CVE-2019-6231 [MEDIUM] Detailed Analysis of macOS/iOS Vulnerability CVE-2019-6231
FORTIGUARD LABS THREAT RESEARCH
Detailed Analysis of macOS/iOS Vulnerability CVE-2019-6231
By Kai Lu | January 24, 2019
FortiGuard Labs Threat Analysis
The QuartzCore Out-of-Bounds Read Vulnerability in CA::Render::Decoder::decode_colorspace
On Jan 22, 2019, Apple released macOS Mojave 10.14.3 and iOS 12.1.3. These two updates fixed a number of security vulnerabilities, including CVE-2019-6231 found in QuartzCore (aka. CoreAnimation). (For more details on the Apple updates, please refer to: https://support.apple.com/en-us/HT209446 and https://support.apple.com/en-us/HT209443.)
I found this issue in macOS Mojave 10.14.2 on Dec 14, 2018 and reported it to Apple on Dec 21, 2018. However, Apple responded that said this issue had been fixed in the macOS Mojave 10.14.3 beta that was rele
Fortinet
A Wrap Up of ToorCon 19 at San Diego
blogs_fortinet·2017-09-18
A Wrap Up of ToorCon 19 at San Diego
FORTIGUARD LABS THREAT RESEARCH
A Wrap Up of ToorCon 19 at San Diego
By Kai Lu | September 18, 2017
ToorCon 19 San Diego was held Monday August 28th to Sunday September 3rd, 2017 at The Westin San Diego. It included three parts. The first was training workshops focused on various aspects of computer security. These took place on Aug 28-31. The second was a Seminar held on Sep 1. The third part was the formal Conference that ran from Sep 1-3.
I was honored to be able to present my research, Dig Deep into FlexiSpy for Android at ToorCon 19. FlexiSpy for Android is a spy app with full IM tracking, VoIP call recording, and live call interception. It also can spy on messages, GPS, multimedia, Internet, applications, etc. In short, FlexiSpy can take full control of an Android mobile phone or
Fortinet
Remote Password Change Vulnerability in HPE Vertica Analytic Database
blogs_fortinet·2017-04-20·CVSS 9.8
CVE-2017-5802 [CRITICAL] Remote Password Change Vulnerability in HPE Vertica Analytic Database
FORTIGUARD LABS THREAT RESEARCH
Remote Password Change Vulnerability in HPE Vertica Analytic Database
By Honggang Ren | April 20, 2017
Summary
On March 24 2017, I discovered and reported on a remote password change vulnerability in Hewlett-Packard Enterprise’s (HPE) Vertica Analytic Database. This week, HPE released Security Bulletin HPESBGN03734, which contains the fix for this vulnerability and identifies it as CVE-2017-5802.
Fueled by ever-growing volumes of Big Data found in many corporations and government agencies, HPE's Vertica Analytics Platform provides an SQL analytics solution built from the ground up to handle massive volumes of data and delivers blazingly fast Big Data analytics. At the core of the Vertica Analytics Platform is a column-oriented, relational database named V
Fortinet
Looking Back at Fortinet’s Security Research and Vulnerability Discoveries
blogs_fortinet·2017-02-21
Looking Back at Fortinet’s Security Research and Vulnerability Discoveries
FORTIGUARD LABS THREAT RESEARCH
Looking Back at Fortinet’s Security Research and Vulnerability Discoveries
By Peixue Li | February 21, 2017
In an effort to provide more proactive protections in Fortinet products and to more effectively identify and defeat network threats, the Fortinet security research team works on discovering potential threats in popular products. As a result, over the past year we have discovered 84 vulnerabilities that have been reported to their respective vendors as part of our responsible vulnerability disclosure process. Fortinet protections against these discoveries were released to Fortinet products at the same time these vulnerabilities were reported to their vendors. As a result, Fortinet products have been able to proactively protect Fortinet customers’ netw
2019-12-18
Published