Apple tvOS vulnerabilities
2,227 known vulnerabilities affecting apple/tvos.
Total CVEs
2,227
CISA KEV
41
actively exploited
Public exploits
199
Exploited in wild
31
Severity breakdown
CRITICAL148HIGH1222MEDIUM795LOW59UNKNOWN3
Vulnerabilities
Page 66 of 112
CVE-2019-8813MEDIUMCVSS 6.1fixed in 13.2≥ unspecified, < tvOS 13.22019-12-18
CVE-2019-8813 [MEDIUM] CWE-79 CVE-2019-8813: A logic issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPad
A logic issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
CVE-2019-8615MEDIUMCVSS 6.5fixed in 12.3≥ unspecified, < tvOS 12.32019-12-18
CVE-2019-8615 [MEDIUM] CWE-125 CVE-2019-8615: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2019-8530MEDIUMCVSS 5.5fixed in 12.2≥ unspecified, < tvOS 12.22019-12-18
CVE-2019-8530 [MEDIUM] CVE-2019-8530: This issue was addressed with improved checks. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4
This issue was addressed with improved checks. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2. A malicious application may be able to overwrite arbitrary files.
nvdapple
CVE-2019-8510MEDIUMCVSS 5.5fixed in 12.2≥ unspecified, < tvOS 12.22019-12-18
CVE-2019-8510 [MEDIUM] CWE-125 CVE-2019-8510: An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to determine kernel memory layout.
nvdapple
CVE-2019-8705MEDIUMCVSS 5.5fixed in 13≥ unspecified, < tvOS 132019-12-18
CVE-2019-8705 [MEDIUM] CWE-787 CVE-2019-8705: A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Catal
A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15, tvOS 13. Processing a maliciously crafted movie may result in the disclosure of process memory.
nvdapple
CVE-2019-8540MEDIUMCVSS 5.5fixed in 12.2≥ unspecified, < tvOS 12.22019-12-18
CVE-2019-8540 [MEDIUM] CWE-665 CVE-2019-8540: A memory initialization issue was addressed with improved memory handling. This issue is fixed in iO
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to determine kernel memory layout.
nvdapple
CVE-2019-8794MEDIUMCVSS 5.5fixed in 13.2≥ unspecified, < tvOS 13.22019-12-18
CVE-2019-8794 [MEDIUM] CWE-20 CVE-2019-8794: A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.2 a
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to read restricted memory.
nvdapple
CVE-2019-8649MEDIUMCVSS 6.1PoCfixed in 12.4≥ unspecified, < tvOS 12.42019-12-18
CVE-2019-8649 [MEDIUM] CWE-79 CVE-2019-8649: A logic issue existed in the handling of synchronous page loads. This issue was addressed with impro
A logic issue existed in the handling of synchronous page loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to universal cross sit
nvdapple
CVE-2019-8560MEDIUMCVSS 5.5fixed in 12.3≥ unspecified, < tvOS 12.32019-12-18
CVE-2019-8560 [MEDIUM] CWE-125 CVE-2019-8560: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.3,
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to read restricted memory.
nvdapple
CVE-2019-8568MEDIUMCVSS 5.5fixed in 12.3≥ unspecified, < tvOS 12.32019-12-18
CVE-2019-8568 [MEDIUM] CWE-59 CVE-2019-8568: A validation issue existed in the handling of symlinks. This issue was addressed with improved valid
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A local user may be able to modify protected parts of the file system.
nvdapple
CVE-2019-8608MEDIUMCVSS 6.3fixed in 12.3≥ unspecified, < tvOS 12.32019-12-18
CVE-2019-8608 [MEDIUM] CWE-416 CVE-2019-8608: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2019-8598MEDIUMCVSS 5.5fixed in 12.3≥ unspecified, < tvOS 12.32019-12-18
CVE-2019-8598 [MEDIUM] CWE-119 CVE-2019-8598: An input validation issue was addressed with improved input validation. This issue is fixed in iOS 1
An input validation issue was addressed with improved input validation. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. A malicious application may be able to read restricted memory.
nvdapple
CVE-2019-8502LOWCVSS 3.3fixed in 12.2≥ unspecified, < tvOS 12.22019-12-18
CVE-2019-8502 [LOW] CWE-20 CVE-2019-8502: An API issue existed in the handling of dictation requests. This issue was addressed with improved v
An API issue existed in the handling of dictation requests. This issue was addressed with improved validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to initiate a Dictation request without user authorization.
nvdapple
CVE-2019-8698LOWCVSS 3.3fixed in 12.4≥ unspecified, < tvOS 12.42019-12-18
CVE-2019-8698 [LOW] CWE-20 CVE-2019-8698: A validation issue existed in the entitlement verification. This issue was addressed with improved v
A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in iOS 12.4, tvOS 12.4. A malicious application may be able to restrict access to websites.
nvdapple
CVE-2019-14899HIGHCVSS 7.4fixed in 13.4.82019-12-11
CVE-2019-14899 [HIGH] CWE-300 CVE-2019-14899: A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a mal
A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences about the websites they are visiting, and determine the correct sequence and acknowledgement numbers in use, allowing the bad actor to in
nvdapple
CVE-2019-15903HIGHCVSS 7.5v13.32019-12-10
CVE-2019-15903 [HIGH] CVE-2019-15903: tvOS 13.3
Apple Security Update: About the security content of tvOS 13.3
Product: tvOS
Version: 13.3
CVE: CVE-2019-15903
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2019-15163HIGHCVSS 7.5v13.32019-12-10
CVE-2019-15163 [HIGH] CVE-2019-15163: tvOS 13.3
Apple Security Update: About the security content of tvOS 13.3
Product: tvOS
Version: 13.3
CVE: CVE-2019-15163
Component: CVE-2019-15163
apple
CVE-2019-15164MEDIUMCVSS 5.3v13.32019-12-10
CVE-2019-15164 [MEDIUM] CVE-2019-15164: tvOS 13.3
Apple Security Update: About the security content of tvOS 13.3
Product: tvOS
Version: 13.3
CVE: CVE-2019-15164
Component: CVE-2019-15164
apple
CVE-2019-15161MEDIUMCVSS 5.3v13.32019-12-10
CVE-2019-15161 [MEDIUM] CVE-2019-15161: tvOS 13.3
Apple Security Update: About the security content of tvOS 13.3
Product: tvOS
Version: 13.3
CVE: CVE-2019-15161
Component: CVE-2019-15161
apple
CVE-2019-15162MEDIUMCVSS 5.3v13.32019-12-10
CVE-2019-15162 [MEDIUM] CVE-2019-15162: tvOS 13.3
Apple Security Update: About the security content of tvOS 13.3
Product: tvOS
Version: 13.3
CVE: CVE-2019-15162
Component: CVE-2019-15162
apple