cbcvebase.
CVE-2019-8625
published 2019-12-18

CVE-2019-8625: A logic issue was addressed with improved state management. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for…

medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
A logic issue was addressed with improved state management. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing maliciously crafted web content may lead to universal cross site scripting.

Affected

15 ranges
VendorProductVersion rangeFixed in
appleicloud< 7.147.14
appleicloud>= 10.0 < 10.710.7
appleicloud_for_windows
appleicloud_for_windows
appleicloud_for_windows>= unspecified < iCloud for Windows 10.7iCloud for Windows 10.7
appleicloud_for_windows>= unspecified < iCloud for Windows 7.14iCloud for Windows 7.14
appleios
appleitunes< 12.10.112.10.1
appleitunes_12.10.1_for_windows
appleitunes_for_windows>= unspecified < iTunes for Windows 12.10.1iTunes for Windows 12.10.1
applesafari
appletvos
appletvos>= unspecified < tvOS 13tvOS 13
debianwebkit2gtk< webkit2gtk 2.26.0-1 (bookworm)webkit2gtk 2.26.0-1 (bookworm)
webkitgtkwebkitgtk< 2.26.42.26.4

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.1MEDIUM