CVE-2019-8756Out-of-bounds Write in Apple Macos

Severity
9.8CRITICALNVD
EPSS
1.3%
top 20.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 27
Latest updateMay 24

Description

Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Catalina 10.15, iOS 13, iCloud for Windows 7.14, iCloud for Windows 10.7, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, watchOS 6, iTunes 12.10.1 for Windows. Multiple issues in libxml2.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages9 packages

CVEListV5apple/macosunspecified10.15+3
NVDapple/icloud10.010.7+1
NVDapple/mac_os_x< 10.15
CVEListV5apple/tvosunspecified13
NVDapple/tvos< 13

🔴Vulnerability Details

2
GHSA
GHSA-pwrm-58c4-f474: Multiple memory corruption issues were addressed with improved input validation2022-05-24
CVEList
CVE-2019-8756: Multiple memory corruption issues were addressed with improved input validation2020-10-27

📋Vendor Advisories

8
Apple
CVE-2019-8756: macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-0062019-10-29
Apple
CVE-2019-8756: iTunes 12.10.1 for Windows2019-10-07
Apple
CVE-2019-8756: macOS Catalina 10.152019-10-07
Apple
CVE-2019-8756: iCloud for Windows 10.72019-10-07
Apple
CVE-2019-8756: iCloud for Windows 7.142019-10-07
CVE-2019-8756 — Out-of-bounds Write in Apple Macos | cvebase