Apple iPadOS vulnerabilities

1,835 known vulnerabilities affecting apple/ipados.

Total CVEs
1,835
CISA KEV
79
actively exploited
Public exploits
8
Exploited in wild
62
Severity breakdown
CRITICAL105HIGH806MEDIUM800LOW124

Vulnerabilities

Page 91 of 92
CVE-2019-19906HIGHCVSS 7.5v13.62019-12-19
CVE-2019-19906 [HIGH] CWE-193 CVE-2019-19906: cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote deni cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.
nvd
CVE-2019-8779CRITICALCVSS 10.0fixed in 13.1.12019-12-18
CVE-2019-8779 [CRITICAL] CWE-668 CVE-2019-8779: A logic issue applied the incorrect restrictions. This issue was addressed by updating the logic to A logic issue applied the incorrect restrictions. This issue was addressed by updating the logic to apply the correct restrictions. This issue is fixed in iOS 13.1.1 and iPadOS 13.1.1. Third party app extensions may not receive the correct sandbox restrictions.
nvd
CVE-2019-8785HIGHCVSS 7.8≤ 13.22019-12-18
CVE-2019-8785 [HIGH] CWE-787 CVE-2019-8785: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13 A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with system privileges.
nvd
CVE-2019-8763HIGHCVSS 8.8fixed in 13.12019-12-18
CVE-2019-8763 [HIGH] CWE-787 CVE-2019-8763: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.1 and iPadOS 13.1, tvOS 13, Safari 13.0.1, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8803HIGHCVSS 8.4fixed in 13.22019-12-18
CVE-2019-8803 [HIGH] CWE-613 CVE-2019-8803: An authentication issue was addressed with improved state management. This issue is fixed in iOS 13. An authentication issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. A local attacker may be able to login to the account of a previously logged in user without valid credentials..
nvd
CVE-2019-8816HIGHCVSS 8.8fixed in 13.22019-12-18
CVE-2019-8816 [HIGH] CWE-787 CVE-2019-8816: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8812HIGHCVSS 8.8fixed in 13.22019-12-18
CVE-2019-8812 [HIGH] CWE-787 CVE-2019-8812: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8787HIGHCVSS 7.5≤ 13.22019-12-18
CVE-2019-8787 [HIGH] CWE-125 CVE-2019-8787: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.2 An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. A remote attacker may be able to leak memory.
nvd
CVE-2019-8822HIGHCVSS 8.8fixed in 13.22019-12-18
CVE-2019-8822 [HIGH] CWE-787 CVE-2019-8822: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8820HIGHCVSS 8.8PoCfixed in 13.22019-12-18
CVE-2019-8820 [HIGH] CWE-787 CVE-2019-8820: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8823HIGHCVSS 8.8fixed in 13.22019-12-18
CVE-2019-8823 [HIGH] CWE-787 CVE-2019-8823: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8811HIGHCVSS 8.8fixed in 13.22019-12-18
CVE-2019-8811 [HIGH] CWE-787 CVE-2019-8811: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8797HIGHCVSS 7.8fixed in 13.22019-12-18
CVE-2019-8797 [HIGH] CWE-787 CVE-2019-8797: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13 A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with system privileges.
nvd
CVE-2019-8788HIGHCVSS 7.5fixed in 13.22019-12-18
CVE-2019-8788 [HIGH] CWE-20 CVE-2019-8788: An issue existed in the parsing of URLs. This issue was addressed with improved input validation. Th An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1. Improper URL processing may lead to data exfiltration.
nvd
CVE-2019-8808HIGHCVSS 8.8fixed in 13.22019-12-18
CVE-2019-8808 [HIGH] CWE-787 CVE-2019-8808: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8819HIGHCVSS 8.8fixed in 13.22019-12-18
CVE-2019-8819 [HIGH] CWE-787 CVE-2019-8819: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8784HIGHCVSS 7.8fixed in 13.22019-12-18
CVE-2019-8784 [HIGH] CWE-787 CVE-2019-8784: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13 A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. An application may be able to execute arbitrary code with system privileges.
nvd
CVE-2019-8786HIGHCVSS 7.8fixed in 13.22019-12-18
CVE-2019-8786 [HIGH] CWE-787 CVE-2019-8786: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13 A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2019-8782HIGHCVSS 8.8fixed in 13.22019-12-18
CVE-2019-8782 [HIGH] CWE-787 CVE-2019-8782: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8815HIGHCVSS 8.8fixed in 13.22019-12-18
CVE-2019-8815 [HIGH] CWE-787 CVE-2019-8815: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd