cbcvebase.
CVE-2019-8582
published 2020-10-27

CVE-2019-8582: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iCloud for Windows 7.12, tvOS 12.3, iTunes 12.9.5 for Windows, macOS…

PriorityP424medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
1.39%
69.5th percentile
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iCloud for Windows 7.12, tvOS 12.3, iTunes 12.9.5 for Windows, macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, iOS 12.3. Processing a maliciously crafted font may result in the disclosure of process memory.

Affected

15 ranges
VendorProductVersion rangeFixed in
appleicloud< 7.127.12
appleicloud_for_windows
appleios
appleios>= unspecified < 12.312.3
appleiphone_os< 12.312.3
appleitunes< 12.9.512.9.5
appleitunes_for_windows
applemac_os_x< 10.14.510.14.5
applemacos>= unspecified < 10.1410.14
applemacos>= unspecified < 12.312.3
applemacos>= unspecified < 12.912.9
applemacos>= unspecified < 7.127.12
applemacos_mojave_10.14.5_security_update_2019-003_high_sierra_security_update_2019-0
appletvos< 12.312.3
appletvos

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.