cbcvebase.
CVE-2019-8794
published 2019-12-18

CVE-2019-8794: A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS…

PriorityP423medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
0.92%
56.6th percentile
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to read restricted memory.

Affected

13 ranges
VendorProductVersion rangeFixed in
appleios>= unspecified < iOS 13.2 and iPadOS 13.2iOS 13.2 and iPadOS 13.2
appleios_13.2_and_ipados
appleipados< 13.213.2
appleiphone_os< 13.213.2
applemac_os_x< 10.15.110.15.1
applemacos>= unspecified < macOS Catalina 10.15.1macOS Catalina 10.15.1
applemacos_catalina_10.15.1_security_update_2019-001_and_security_update_2019-006
appletvos< 13.213.2
appletvos
appletvos>= unspecified < tvOS 13.2tvOS 13.2
applewatchos< 6.16.1
applewatchos
applewatchos>= unspecified < watchOS 6.1watchOS 6.1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.