CVE-2019-8800
published 2019-12-18CVE-2019-8800: A memory corruption issue was addressed with improved validation. This issue is fixed in Xcode 11.2. Processing a maliciously crafted file may lead to…
PriorityP338high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.98%
58.6th percentile
A memory corruption issue was addressed with improved validation. This issue is fixed in Xcode 11.2. Processing a maliciously crafted file may lead to arbitrary code execution.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | xcode | < 11.2 | 11.2 |
| apple | xcode | — | — |
| apple | xcode | >= unspecified < Xcode 11.2 | Xcode 11.2 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_cisco8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vrf5-f827-8842: A memory corruption issue was addressed with improved validation
ghsa_unreviewed·2022-05-24
CVE-2019-8800 [MEDIUM] CWE-119 GHSA-vrf5-f827-8842: A memory corruption issue was addressed with improved validation
A memory corruption issue was addressed with improved validation. This issue is fixed in Xcode 11.2. Processing a maliciously crafted file may lead to arbitrary code execution.
Cisco
Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware Cross-Site Scripting Vulnerability
vendor_cisco·2020-01-08·CVSS 5.4
CVE-2019-16008 [MEDIUM] CWE-79 Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware Cross-Site Scripting Vulnerability
Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware Cross-Site Scripting Vulnerability
A vulnerability in the web-based GUI of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of an affected system.
The vulnerability is due to insufficient validation of user-supplied input by the web-based GUI of an affected system. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Cisco has released software u
Apple
CVE-2019-8800: Xcode 11.2
vendor_apple·2019-10-31·CVSS 7.8
CVE-2019-8800 [HIGH] CVE-2019-8800: Xcode 11.2
Apple Security Update: About the security content of Xcode 11.2
Product: Xcode
Version: 11.2
CVE: CVE-2019-8800
Component: Git
Impact: Git could allow a remote malicious user to bypass security restrictions, caused by a flaw in the --export-marks option of git fast-import
Description: An input validation issue was addressed.
Cisco
Cisco IP Phone 7800 and 8800 Series Session Initiation Protocol Denial of Service Vulnerability
vendor_cisco·2019-07-03·CVSS 5.3
CVE-2019-1922 [MEDIUM] CWE-476 Cisco IP Phone 7800 and 8800 Series Session Initiation Protocol Denial of Service Vulnerability
Cisco IP Phone 7800 and 8800 Series Session Initiation Protocol Denial of Service Vulnerability
A vulnerability in Cisco SIP IP Phone Software for Cisco IP Phone 7800 Series and 8800 Series could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected phone.
The vulnerability is due to insufficient validation of input Session Initiation Protocol (SIP) packets. An attacker could exploit this vulnerability by altering the SIP replies that are sent to the affected phone during the registration process. A successful exploit could allow the attacker to cause the phone to reboot and not complete the registration process.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps
Cisco
Cisco IP Phone 7800 Series and 8800 Series Session Initiation Protocol XML Denial of Service Vulnerability
vendor_cisco·2019-05-01·CVSS 7.5
CVE-2019-1635 [HIGH] CWE-399 Cisco IP Phone 7800 Series and 8800 Series Session Initiation Protocol XML Denial of Service Vulnerability
Cisco IP Phone 7800 Series and 8800 Series Session Initiation Protocol XML Denial of Service Vulnerability
A vulnerability in the call-handling functionality of Session Initiation Protocol (SIP) Software for Cisco IP Phone 7800 Series and 8800 Series could allow an unauthenticated, remote attacker to cause an affected phone to reload unexpectedly, resulting in a temporary denial of service (DoS) condition.
The vulnerability is due to incomplete error handling when XML data within a SIP packet is parsed. An attacker could exploit this vulnerability by sending a SIP packet that contains a malicious XML payload to an affected phone. A successful exploit could allow the attacker to cause the affected phone to reload unexpectedly, resulting in a temporary DoS condition.
Cisco has released soft
Cisco
Cisco IP Phone 8800 Series Path Traversal Vulnerability
vendor_cisco·2019-03-20·CVSS 8.1
CVE-2019-1765 [HIGH] CWE-22 Cisco IP Phone 8800 Series Path Traversal Vulnerability
Cisco IP Phone 8800 Series Path Traversal Vulnerability
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an authenticated, remote attacker to write arbitrary files to the filesystem.
The vulnerability is due to insufficient input validation and file-level permissions. An attacker could exploit this vulnerability by uploading invalid files to an affected device. A successful exploit could allow the attacker to write files in arbitrary locations on the filesystem.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/Cisc
Cisco
Cisco IP Phone 8800 Series Cross-Site Request Forgery Vulnerability
vendor_cisco·2019-03-20·CVSS 8.1
CVE-2019-1764 [HIGH] CWE-352 Cisco IP Phone 8800 Series Cross-Site Request Forgery Vulnerability
Cisco IP Phone 8800 Series Cross-Site Request Forgery Vulnerability
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack.
The vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading an authenticated user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on a targeted device via a web browser and with the privileges of the user.
Cisco has released software updates that address this vulnerability. There are no workarounds that add
Cisco
Cisco IP Phone 8800 Series Authorization Bypass Vulnerability
vendor_cisco·2019-03-20·CVSS 7.5
CVE-2019-1763 [HIGH] CWE-284 Cisco IP Phone 8800 Series Authorization Bypass Vulnerability
Cisco IP Phone 8800 Series Authorization Bypass Vulnerability
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to bypass authorization, access critical services, and cause a denial of service (DoS) condition.
The vulnerability exists because the software fails to sanitize URLs before it handles requests. An attacker could exploit this vulnerability by submitting a crafted URL. A successful exploit could allow the attacker to gain unauthorized access to critical services and cause a DoS condition.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the follo
Cisco
Cisco IP Phone 8800 Series File Upload Denial of Service Vulnerability
vendor_cisco·2019-03-20·CVSS 7.5
CVE-2019-1766 [HIGH] CWE-20 Cisco IP Phone 8800 Series File Upload Denial of Service Vulnerability
Cisco IP Phone 8800 Series File Upload Denial of Service Vulnerability
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition.
The vulnerability exists because the affected software does not restrict the maximum size of certain files that can be written to disk. An attacker who has valid administrator credentials for an affected system could exploit this vulnerability by sending a crafted, remote connection request to an affected system. A successful exploit could allow the attacker to write a file that consumes most of the available disk space on the system, causing application function
Cisco
Cisco IP Phone 7800 Series and 8800 Series Remote Code Execution Vulnerability
vendor_cisco·2019-03-20·CVSS 7.5
CVE-2019-1716 [HIGH] CWE-20 Cisco IP Phone 7800 Series and 8800 Series Remote Code Execution Vulnerability
Cisco IP Phone 7800 Series and 8800 Series Remote Code Execution Vulnerability
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 7800 Series and Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code.
The vulnerability exists because the software improperly validates user-supplied input during user authentication. An attacker could exploit this vulnerability by connecting to an affected device using HTTP and supplying malicious user credentials. A successful exploit could allow the attacker to trigger a reload of an affected device, resulting in a DoS condition, or to execute arbitrary code with the privileges of the app user.
Cisc
Cisco
Cisco IP Phone 7800 and 8800 Series Cisco Discovery Protocol and Link Layer Discovery Protocol Denial of Service Vulnerability
vendor_cisco·2019-02-20·CVSS 6.5
CVE-2019-1684 [MEDIUM] CWE-399 Cisco IP Phone 7800 and 8800 Series Cisco Discovery Protocol and Link Layer Discovery Protocol Denial of Service Vulnerability
Cisco IP Phone 7800 and 8800 Series Cisco Discovery Protocol and Link Layer Discovery Protocol Denial of Service Vulnerability
A vulnerability in the Cisco Discovery Protocol or Link Layer Discovery Protocol (LLDP) implementation for the Cisco IP Phone 7800 and 8800 Series could allow an unauthenticated, adjacent attacker to cause an affected phone to reload unexpectedly, resulting in a temporary denial of service (DoS) condition.
The vulnerability is due to missing length validation of certain Cisco Discovery Protocol or LLDP packet header fields. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol or LLDP packet to the targeted phone. A successful exploit could allow the attacker to cause the affected phone to reload unexpectedly, resulting in a
Cisco
Cisco IP Phone 7800 and 8800 Series Session Initiation Protocol Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1922 Cisco IP Phone 7800 and 8800 Series Session Initiation Protocol Denial of Service Vulnerability
CVE-2019-1922: Cisco IP Phone 7800 and 8800 Series Session Initiation Protocol Denial of Service Vulnerability
A vulnerability in Cisco SIP IP Phone Software for Cisco IP Phone 7800 Series and 8800 Series could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected phone. The vulnerability is due to insufficient validation of input Session Initiation Protocol (SIP) packets. An attacker could exploit this vulnerability by altering the SIP replies that are sent to the affected phone during the registration process. A successful exploit could allow the attacker to cause the phone to reboot and not complete the registration process. There are no
CVSS: 3.0
CWE: CWE-476, CWE-476
Bug IDs: CSCvc61672
Cisco
Cisco IP Phone 8800 Series Cross-Site Request Forgery Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1764 Cisco IP Phone 8800 Series Cross-Site Request Forgery Vulnerability
CVE-2019-1764: Cisco IP Phone 8800 Series Cross-Site Request Forgery Vulnerability
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack. The vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading an authenticated user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on a targeted device via a web browser and with the privileges of the user. Cisco has released software updates that address this vulnerability. There are no
CVSS:
Cisco
Cisco IP Phone 8800 Series Path Traversal Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1765 Cisco IP Phone 8800 Series Path Traversal Vulnerability
CVE-2019-1765: Cisco IP Phone 8800 Series Path Traversal Vulnerability
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an authenticated, remote attacker to write arbitrary files to the filesystem. The vulnerability is due to insufficient input validation and file-level permissions. An attacker could exploit this vulnerability by uploading invalid files to an affected device. A successful exploit could allow the attacker to write files in arbitrary locations on the filesystem. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-22, CWE-22
Bug IDs: CSCvn56213, CSCvo57138
Cisco
Cisco IP Phone 7800 and 8800 Series Cisco Discovery Protocol and Link Layer Discovery Protocol Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1684 Cisco IP Phone 7800 and 8800 Series Cisco Discovery Protocol and Link Layer Discovery Protocol Denial of Service Vulnerability
CVE-2019-1684: Cisco IP Phone 7800 and 8800 Series Cisco Discovery Protocol and Link Layer Discovery Protocol Denial of Service Vulnerability
A vulnerability in the Cisco Discovery Protocol or Link Layer Discovery Protocol (LLDP) implementation for the Cisco IP Phone 7800 and 8800 Series could allow an unauthenticated, adjacent attacker to cause an affected phone to reload unexpectedly, resulting in a temporary denial of service (DoS) condition. The vulnerability is due to missing length validation of certain Cisco Discovery Protocol or LLDP packet header fields. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol or LLDP packet to the targeted phone. A successful exploit could allow the attacker to cause the affected phone to reload unexpectedly, r
Cisco
Cisco IP Phone 8800 Series File Upload Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1766 Cisco IP Phone 8800 Series File Upload Denial of Service Vulnerability
CVE-2019-1766: Cisco IP Phone 8800 Series File Upload Denial of Service Vulnerability
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software does not restrict the maximum size of certain files that can be written to disk. An attacker who has valid administrator credentials for an affected system could exploit this vulnerability by sending a crafted, remote connection request to an affected system. A successful exploit could allow the attacker to write a file that consumes most of the available disk space on the system, causing applic
Cisco
Cisco IP Phone 7800 Series and 8800 Series Session Initiation Protocol XML Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1635 Cisco IP Phone 7800 Series and 8800 Series Session Initiation Protocol XML Denial of Service Vulnerability
CVE-2019-1635: Cisco IP Phone 7800 Series and 8800 Series Session Initiation Protocol XML Denial of Service Vulnerability
A vulnerability in the call-handling functionality of Session Initiation Protocol (SIP) Software for Cisco IP Phone 7800 Series and 8800 Series could allow an unauthenticated, remote attacker to cause an affected phone to reload unexpectedly, resulting in a temporary denial of service (DoS) condition. The vulnerability is due to incomplete error handling when XML data within a SIP packet is parsed. An attacker could exploit this vulnerability by sending a SIP packet that contains a malicious XML payload to an affected phone. A successful exploit could allow the attacker to cause the affected phone to reload unexpectedly, resulting in a temporary DoS condition. Cisco has
Cisco
Cisco IP Phone 7800 Series and 8800 Series Remote Code Execution Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1716 Cisco IP Phone 7800 Series and 8800 Series Remote Code Execution Vulnerability
CVE-2019-1716: Cisco IP Phone 7800 Series and 8800 Series Remote Code Execution Vulnerability
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 7800 Series and Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code. The vulnerability exists because the software improperly validates user-supplied input during user authentication. An attacker could exploit this vulnerability by connecting to an affected device using HTTP and supplying malicious user credentials. A successful exploit could allow the attacker to trigger a reload of an affected device, resulting in a DoS condition, or to execute arbitrary code with the privileges of the
Cisco
Cisco IP Phone 8800 Series Authorization Bypass Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1763 Cisco IP Phone 8800 Series Authorization Bypass Vulnerability
CVE-2019-1763: Cisco IP Phone 8800 Series Authorization Bypass Vulnerability
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to bypass authorization, access critical services, and cause a denial of service (DoS) condition. The vulnerability exists because the software fails to sanitize URLs before it handles requests. An attacker could exploit this vulnerability by submitting a crafted URL. A successful exploit could allow the attacker to gain unauthorized access to critical services and cause a DoS condition. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-284, CWE-284
Bug IDs: CSCvn56175, CSCvo58414
Cisco
Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware Cross-Site Scripting Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-16008 Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware Cross-Site Scripting Vulnerability
CVE-2019-16008: Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware Cross-Site Scripting Vulnerability
A vulnerability in the web-based GUI of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of an affected system. The vulnerability is due to insufficient validation of user-supplied input by the web-based GUI of an affected system. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. Cisco has rele
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-12-18
Published