cbcvebase.

Apple iOS vulnerabilities

1,765 known vulnerabilities affecting apple/ios.

Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
227
Exploited in wild
30
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7

Vulnerabilities

Page 24 of 89
CVE-2019-8530MEDIUMCVSS 5.5≥ unspecified, < iOS 12.22019-12-18
CVE-2019-8530 [MEDIUM] CVE-2019-8530: This issue was addressed with improved checks. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4 This issue was addressed with improved checks. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2. A malicious application may be able to overwrite arbitrary files.
nvdapple
CVE-2019-8554MEDIUMCVSS 6.5≥ unspecified, < iOS 12.22019-12-18
CVE-2019-8554 [MEDIUM] CVE-2019-8554: A permissions issue existed in the handling of motion and orientation data. This issue was addressed A permissions issue existed in the handling of motion and orientation data. This issue was addressed with improved restrictions. This issue is fixed in iOS 12.2. A website may be able to access sensor information without user consent.
nvdapple
CVE-2019-8510MEDIUMCVSS 5.5≥ unspecified, < iOS 12.22019-12-18
CVE-2019-8510 [MEDIUM] CWE-125 CVE-2019-8510: An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to determine kernel memory layout.
nvdapple
CVE-2019-8615MEDIUMCVSS 6.5≥ unspecified, < iOS 12.32019-12-18
CVE-2019-8615 [MEDIUM] CWE-125 CVE-2019-8615: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2019-8794MEDIUMCVSS 5.5≥ unspecified, < iOS 13.2 and iPadOS 13.22019-12-18
CVE-2019-8794 [MEDIUM] CWE-20 CVE-2019-8794: A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.2 a A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to read restricted memory.
nvd
CVE-2019-8560MEDIUMCVSS 5.5≥ unspecified, < iOS 12.32019-12-18
CVE-2019-8560 [MEDIUM] CWE-125 CVE-2019-8560: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.3, An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to read restricted memory.
nvdapple
CVE-2019-8568MEDIUMCVSS 5.5≥ unspecified, < iOS 12.32019-12-18
CVE-2019-8568 [MEDIUM] CWE-59 CVE-2019-8568: A validation issue existed in the handling of symlinks. This issue was addressed with improved valid A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A local user may be able to modify protected parts of the file system.
nvdapple
CVE-2019-8760MEDIUMCVSS 6.8≥ unspecified, < iOS 132019-12-18
CVE-2019-8760 [MEDIUM] CWE-287 CVE-2019-8760: This issue was addressed by improving Face ID machine learning models. This issue is fixed in iOS 13 This issue was addressed by improving Face ID machine learning models. This issue is fixed in iOS 13. A 3D model constructed to look like the enrolled user may authenticate via Face ID.
nvdapple
CVE-2019-8769MEDIUMCVSS 4.3≥ unspecified, < iOS 13.1 and iPadOS 13.12019-12-18
CVE-2019-8769 [MEDIUM] CVE-2019-8769: An issue existed in the drawing of web page elements. The issue was addressed with improved logic. T An issue existed in the drawing of web page elements. The issue was addressed with improved logic. This issue is fixed in iOS 13.1 and iPadOS 13.1, macOS Catalina 10.15. Visiting a maliciously crafted website may reveal browsing history.
nvd
CVE-2019-7284MEDIUMCVSS 4.3≥ unspecified, < iOS 12.22019-12-18
CVE-2019-7284 [MEDIUM] CVE-2019-7284: This issue was addressed with improved checks. This issue is fixed in iOS 12.2. Processing a malicio This issue was addressed with improved checks. This issue is fixed in iOS 12.2. Processing a maliciously crafted mail message may lead to S/MIME signature spoofing.
nvdapple
CVE-2019-8793MEDIUMCVSS 5.5≥ unspecified, < iOS 13.2 and iPadOS 13.22019-12-18
CVE-2019-8793 [MEDIUM] CVE-2019-8793: A consistency issue existed in deciding when to show the screen recording indicator. The issue was r A consistency issue existed in deciding when to show the screen recording indicator. The issue was resolved with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2. A local user may be able to record the screen without a visible screen recording indicator.
nvd
CVE-2019-8804MEDIUMCVSS 5.7≥ unspecified, < iOS 13.2 and iPadOS 13.22019-12-18
CVE-2019-8804 [MEDIUM] CWE-287 CVE-2019-8804: An inconsistency in Wi-Fi network configuration settings was addressed. This issue is fixed in iOS 1 An inconsistency in Wi-Fi network configuration settings was addressed. This issue is fixed in iOS 13.2 and iPadOS 13.2. An attacker in physical proximity may be able to force a user onto a malicious Wi-Fi network during device setup.
nvd
CVE-2019-8813MEDIUMCVSS 6.1≥ unspecified, < iOS 13.2 and iPadOS 13.22019-12-18
CVE-2019-8813 [MEDIUM] CWE-79 CVE-2019-8813: A logic issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPad A logic issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd
CVE-2019-8626MEDIUMCVSS 6.5≥ unspecified, < iOS 12.32019-12-18
CVE-2019-8626 [MEDIUM] CWE-20 CVE-2019-8626: An input validation issue was addressed with improved input validation. This issue is fixed in iOS 1 An input validation issue was addressed with improved input validation. This issue is fixed in iOS 12.3, watchOS 5.2.1. Processing a maliciously crafted message may lead to a denial of service.
nvdapple
CVE-2019-8742LOWCVSS 2.4≥ unspecified, < iOS 132019-12-18
CVE-2019-8742 [LOW] CVE-2019-8742: The issue was addressed by restricting options offered on a locked device. This issue is fixed in iO The issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 13. A person with physical access to an iOS device may be able to access contacts from the lock screen.
nvdapple
CVE-2019-8698LOWCVSS 3.3≥ unspecified, < iOS 12.42019-12-18
CVE-2019-8698 [LOW] CWE-20 CVE-2019-8698: A validation issue existed in the entitlement verification. This issue was addressed with improved v A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in iOS 12.4, tvOS 12.4. A malicious application may be able to restrict access to websites.
nvdapple
CVE-2019-8541LOWCVSS 3.3≥ unspecified, < iOS 12.22019-12-18
CVE-2019-8541 [LOW] CVE-2019-8541: A privacy issue existed in motion sensor calibration. This issue was addressed with improved motion A privacy issue existed in motion sensor calibration. This issue was addressed with improved motion sensor processing. This issue is fixed in iOS 12.2, watchOS 5.2. A malicious app may be able to track users between installs.
nvdapple
CVE-2019-8630LOWCVSS 3.3≥ unspecified, < iOS 12.32019-12-18
CVE-2019-8630 [LOW] CVE-2019-8630: The issue was addressed with improved UI handling. This issue is fixed in iOS 12.3. The lock screen The issue was addressed with improved UI handling. This issue is fixed in iOS 12.3. The lock screen may show a locked icon after unlocking.
nvdapple
CVE-2019-8682LOWCVSS 2.4≥ unspecified, < iOS 12.42019-12-18
CVE-2019-8682 [LOW] CWE-306 CVE-2019-8682: The issue was addressed with improved UI handling. This issue is fixed in iOS 12.4, watchOS 5.3. A u The issue was addressed with improved UI handling. This issue is fixed in iOS 12.4, watchOS 5.3. A user may inadvertently complete an in-app purchase while on the lock screen.
nvdapple
CVE-2019-8566LOWCVSS 3.3≥ unspecified, < iOS 12.22019-12-18
CVE-2019-8566 [LOW] CWE-20 CVE-2019-8566: An API issue existed in the handling of microphone data. This issue was addressed with improved vali An API issue existed in the handling of microphone data. This issue was addressed with improved validation. This issue is fixed in iOS 12.2. A malicious application may be able to access the microphone without indication to the user.
nvdapple
Apple iOS vulnerabilities | cvebase