mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-05-29 01:31:20 +00:00
284 lines
8.4 KiB
JSON
284 lines
8.4 KiB
JSON
{
|
|
"id": "CVE-2019-8506",
|
|
"sourceIdentifier": "product-security@apple.com",
|
|
"published": "2019-12-18T18:15:22.880",
|
|
"lastModified": "2025-02-28T14:47:04.510",
|
|
"vulnStatus": "Analyzed",
|
|
"cveTags": [],
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "Se solucion\u00f3 un problema de confusi\u00f3n de tipos mejorando el manejo de la memoria. Este problema es corregido en iOS versi\u00f3n 12.2, tvOS versi\u00f3n 12.2, watchOS versi\u00f3n 5.2, Safari versi\u00f3n 12.1, iTunes versi\u00f3n 12.9.4 para Windows, iCloud para Windows versi\u00f3n 7.11. El procesamiento de contenido web dise\u00f1ado maliciosamente puede conllevar a una ejecuci\u00f3n de c\u00f3digo arbitrario."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV31": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"cvssData": {
|
|
"version": "3.1",
|
|
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
|
|
"baseScore": 8.8,
|
|
"baseSeverity": "HIGH",
|
|
"attackVector": "NETWORK",
|
|
"attackComplexity": "LOW",
|
|
"privilegesRequired": "NONE",
|
|
"userInteraction": "REQUIRED",
|
|
"scope": "UNCHANGED",
|
|
"confidentialityImpact": "HIGH",
|
|
"integrityImpact": "HIGH",
|
|
"availabilityImpact": "HIGH"
|
|
},
|
|
"exploitabilityScore": 2.8,
|
|
"impactScore": 5.9
|
|
},
|
|
{
|
|
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
|
|
"type": "Secondary",
|
|
"cvssData": {
|
|
"version": "3.1",
|
|
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
|
|
"baseScore": 8.8,
|
|
"baseSeverity": "HIGH",
|
|
"attackVector": "NETWORK",
|
|
"attackComplexity": "LOW",
|
|
"privilegesRequired": "NONE",
|
|
"userInteraction": "REQUIRED",
|
|
"scope": "UNCHANGED",
|
|
"confidentialityImpact": "HIGH",
|
|
"integrityImpact": "HIGH",
|
|
"availabilityImpact": "HIGH"
|
|
},
|
|
"exploitabilityScore": 2.8,
|
|
"impactScore": 5.9
|
|
}
|
|
],
|
|
"cvssMetricV2": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"cvssData": {
|
|
"version": "2.0",
|
|
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
|
|
"baseScore": 9.3,
|
|
"accessVector": "NETWORK",
|
|
"accessComplexity": "MEDIUM",
|
|
"authentication": "NONE",
|
|
"confidentialityImpact": "COMPLETE",
|
|
"integrityImpact": "COMPLETE",
|
|
"availabilityImpact": "COMPLETE"
|
|
},
|
|
"baseSeverity": "HIGH",
|
|
"exploitabilityScore": 8.6,
|
|
"impactScore": 10.0,
|
|
"acInsufInfo": false,
|
|
"obtainAllPrivilege": false,
|
|
"obtainUserPrivilege": false,
|
|
"obtainOtherPrivilege": false,
|
|
"userInteractionRequired": true
|
|
}
|
|
]
|
|
},
|
|
"cisaExploitAdd": "2022-05-04",
|
|
"cisaActionDue": "2022-05-25",
|
|
"cisaRequiredAction": "Apply updates per vendor instructions.",
|
|
"cisaVulnerabilityName": "Apple Multiple Products Type Confusion Vulnerability",
|
|
"weaknesses": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-843"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
|
|
"type": "Secondary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-843"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"configurations": [
|
|
{
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*",
|
|
"versionEndExcluding": "7.11",
|
|
"matchCriteriaId": "0B7B3A93-FF67-4AA7-8177-3A2F43BA63BE"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*",
|
|
"versionEndExcluding": "12.9.4",
|
|
"matchCriteriaId": "A87496C6-1F96-4A50-855B-A9DCC6EA9DFC"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
|
|
"versionEndExcluding": "12.1",
|
|
"matchCriteriaId": "7A4D2F39-ACFD-4AB1-9437-71192A56AECB"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
|
|
"versionEndExcluding": "12.2",
|
|
"matchCriteriaId": "1531E802-5419-4B38-8C0C-BDCBC272648F"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*",
|
|
"versionEndExcluding": "12.2",
|
|
"matchCriteriaId": "98912716-69F2-4372-98F0-BD6CCA9AAEB9"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
|
|
"versionEndExcluding": "5.2",
|
|
"matchCriteriaId": "8962A4FE-AE67-421E-9635-B03E2EBCDF19"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "33C068A4-3780-4EAB-A937-6082DF847564"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "51EF4996-72F4-4FA4-814F-F5991E7A8318"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "825ECE2D-E232-46E0-A047-074B34DB1E97"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "https://support.apple.com/HT209599",
|
|
"source": "product-security@apple.com",
|
|
"tags": [
|
|
"Vendor Advisory",
|
|
"Release Notes"
|
|
]
|
|
},
|
|
{
|
|
"url": "https://support.apple.com/HT209601",
|
|
"source": "product-security@apple.com",
|
|
"tags": [
|
|
"Vendor Advisory",
|
|
"Release Notes"
|
|
]
|
|
},
|
|
{
|
|
"url": "https://support.apple.com/HT209602",
|
|
"source": "product-security@apple.com",
|
|
"tags": [
|
|
"Vendor Advisory",
|
|
"Release Notes"
|
|
]
|
|
},
|
|
{
|
|
"url": "https://support.apple.com/HT209603",
|
|
"source": "product-security@apple.com",
|
|
"tags": [
|
|
"Vendor Advisory",
|
|
"Release Notes"
|
|
]
|
|
},
|
|
{
|
|
"url": "https://support.apple.com/HT209604",
|
|
"source": "product-security@apple.com",
|
|
"tags": [
|
|
"Vendor Advisory",
|
|
"Release Notes"
|
|
]
|
|
},
|
|
{
|
|
"url": "https://support.apple.com/HT209605",
|
|
"source": "product-security@apple.com",
|
|
"tags": [
|
|
"Vendor Advisory",
|
|
"Release Notes"
|
|
]
|
|
},
|
|
{
|
|
"url": "https://support.apple.com/HT209599",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108",
|
|
"tags": [
|
|
"Vendor Advisory",
|
|
"Release Notes"
|
|
]
|
|
},
|
|
{
|
|
"url": "https://support.apple.com/HT209601",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108",
|
|
"tags": [
|
|
"Vendor Advisory",
|
|
"Release Notes"
|
|
]
|
|
},
|
|
{
|
|
"url": "https://support.apple.com/HT209602",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108",
|
|
"tags": [
|
|
"Vendor Advisory",
|
|
"Release Notes"
|
|
]
|
|
},
|
|
{
|
|
"url": "https://support.apple.com/HT209603",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108",
|
|
"tags": [
|
|
"Vendor Advisory",
|
|
"Release Notes"
|
|
]
|
|
},
|
|
{
|
|
"url": "https://support.apple.com/HT209604",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108",
|
|
"tags": [
|
|
"Vendor Advisory",
|
|
"Release Notes"
|
|
]
|
|
},
|
|
{
|
|
"url": "https://support.apple.com/HT209605",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108",
|
|
"tags": [
|
|
"Vendor Advisory",
|
|
"Release Notes"
|
|
]
|
|
}
|
|
]
|
|
} |