/
cyberknowledge
/
CVE
ОбзорДокументацияВойти
/
cyberknowledge
/
CVE
Код
Запросы
0
Задачи
Вики
Пакеты
0
Релизы
0
CI/CD
Аналитика
ДокументацияПоддержка
Политика конфиденциальностиПользовательское соглашениеПолитика использования «cookies»Согласие субъекта персональных данных
2026 ©
samples/cve.csv
130 строк987 KB

Zeros312

Rename sample/ to samples/; remove README from samples
30 июн 2026, 21:21
30 июн 2026, 21:2183c96cb
100 строк
CVE-2019-8763
2019-12-18 20:33:24+03:00
2026-06-17 02:42:34.037000+03:00
PUBLISHED
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.1 and iPadOS 13.1, tvOS 13, Safari 13.0.1, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing maliciously crafted web content may lead to arbitrary code execution.
HIGH
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210635', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210636', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210637', 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210635', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210636', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210637', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.773795+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210635', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210636', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210637', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.054Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.1 and iPadOS 13.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Safari', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Safari 13.0.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 10.7', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows (Legacy)', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 7.14', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210635', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210636', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210637', 'tags': ['x_refsource_MISC']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.1 and iPadOS 13.1, tvOS 13, Safari 13.0.1, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing maliciously crafted web content may lead to arbitrary code execution.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2020-03-15T06:06:15.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'iOS 13.1 and iPadOS 13.1', 'version_affected': '<'}]}, 'product_name': 'iOS'}, {'version': {'version_data': [{'version_value': 'tvOS 13', 'version_affected': '<'}]}, 'product_name': 'tvOS'}, {'version': {'version_data': [{'version_value': 'Safari 13.0.1', 'version_affected': '<'}]}, 'product_name': 'Safari'}, {'version': {'version_data': [{'version_value': 'iTunes for Windows 12.10.1', 'version_affected': '<'}]}, 'product_name': 'iTunes for Windows'}, {'version': {'version_data': [{'version_value': 'iCloud for Windows 10.7', 'version_affected': '<'}]}, 'product_name': 'iCloud for Windows'}, {'version': {'version_data': [{'version_value': 'iCloud for Windows 7.14', 'version_affected': '<'}]}, 'product_name': 'iCloud for Windows (Legacy)'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210635', 'name': 'https://support.apple.com/HT210635', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210636', 'name': 'https://support.apple.com/HT210636', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210637', 'name': 'https://support.apple.com/HT210637', 'refsource': 'MISC'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'refsource': 'GENTOO'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.1 and iPadOS 13.1, tvOS 13, Safari 13.0.1, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing maliciously crafted web content may lead to arbitrary code execution.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8763', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8763', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.054Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:24.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8763', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 6.8, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.1 and iPadOS 13.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Safari', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Safari 13.0.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 10.7', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows (Legacy)', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 7.14', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:39.317', 'references': [{'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210635', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210636', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210637', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210635', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210636', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210637', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-787'}]}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.1 and iPadOS 13.1, tvOS 13, Safari 13.0.1, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing maliciously crafted web content may lead to arbitrary code execution.'}, {'lang': 'es', 'value': 'Múltiples problemas de corrupción de memoria fueron abordados mejorando el manejo de la memoria. Este problema es corregido en iOS versión 13.1 y iPadOS versión 13.1, tvOS versión 13, Safari versión 13.0.1, iTunes para Windows versión 12.10.1, iCloud para Windows versión 10.7, iCloud para Windows versión 7.14. El procesamiento de contenido web diseñado maliciosamente puede conllevar a una ejecución de código arbitrario.'}], 'lastModified': '2026-06-17T02:42:34.037', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': 'CD51BEFE-B28D-412A-996D-ADA104E4EC17', 'versionEndExcluding': '7.14'}, {'criteria': 'cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': '3AB3D55F-1566-4705-98C9-6D56F8F156F0', 'versionEndExcluding': '10.7', 'versionStartIncluding': '10.0'}, {'criteria': 'cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': '397F21E9-3B36-49AE-92E3-B5B1FC7773D1', 'versionEndExcluding': '12.10.1'}, {'criteria': 'cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '6BD0E131-6A79-47DA-B8A8-1478B1EDD9FE', 'versionEndExcluding': '13.0.1'}, {'criteria': 'cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E1B56C2A-63FE-410E-96A2-AA757E55086D', 'versionEndExcluding': '13.1'}, {'criteria': 'cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '74FC47CB-6F80-4521-BE54-47B5630FF496', 'versionEndExcluding': '13.1'}, {'criteria': 'cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E6FCD7CE-EC26-4952-A34D-2221AA4F223B', 'versionEndExcluding': '13'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8764
2019-12-18 20:33:22+03:00
2026-06-17 02:42:34.150000+03:00
PUBLISHED
A logic issue was addressed with improved state management. This issue is fixed in watchOS 6.1. Processing maliciously crafted web content may lead to universal cross site scripting.
MEDIUM
6.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
[{'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.773795+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:36.675Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'watchOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'watchOS 6.1', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}], 'descriptions': [{'lang': 'en', 'value': 'A logic issue was addressed with improved state management. This issue is fixed in watchOS 6.1. Processing maliciously crafted web content may lead to universal cross site scripting.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Processing maliciously crafted web content may lead to universal cross site scripting'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2020-03-15T06:06:13.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'watchOS 6.1', 'version_affected': '<'}]}, 'product_name': 'watchOS'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210724', 'name': 'https://support.apple.com/HT210724', 'refsource': 'MISC'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'refsource': 'GENTOO'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'A logic issue was addressed with improved state management. This issue is fixed in watchOS 6.1. Processing maliciously crafted web content may lead to universal cross site scripting.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Processing maliciously crafted web content may lead to universal cross site scripting'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8764', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8764', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:36.675Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:22.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8764', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 4.3, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:N/I:P/A:N', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'NONE'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 6.1, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N', 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}, 'impactScore': 2.7, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'watchOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'watchOS 6.1', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:39.380', 'references': [{'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-79'}]}], 'descriptions': [{'lang': 'en', 'value': 'A logic issue was addressed with improved state management. This issue is fixed in watchOS 6.1. Processing maliciously crafted web content may lead to universal cross site scripting.'}, {'lang': 'es', 'value': 'Un problema lógico fue abordado mejorando la gestión del estado. Este problema es corregido en watchOS versión 6.1. El procesamiento de contenido web diseñado maliciosamente puede conllevar a un ataque de tipo cross site scripting universal.'}], 'lastModified': '2026-06-17T02:42:34.150', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '277FA1BB-BB95-49DD-B50C-00F4BEE9DDE1', 'versionEndExcluding': '6.1'}], 'operator': 'OR'}]}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:webkitgtk:webkitgtk\\+:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '2B5A34D4-70EC-43A8-8C46-6FF6361540EE', 'versionEndExcluding': '2.26.4'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8765
2019-12-18 20:33:22+03:00
2026-06-17 02:42:34.253000+03:00
PUBLISHED
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in watchOS 6.1. Processing maliciously crafted web content may lead to arbitrary code execution.
HIGH
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:20.197198+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.497Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'watchOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'watchOS 6.1', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in watchOS 6.1. Processing maliciously crafted web content may lead to arbitrary code execution.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2020-03-15T06:06:21.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'watchOS 6.1', 'version_affected': '<'}]}, 'product_name': 'watchOS'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210724', 'name': 'https://support.apple.com/HT210724', 'refsource': 'MISC'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'refsource': 'GENTOO'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in watchOS 6.1. Processing maliciously crafted web content may lead to arbitrary code execution.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8765', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8765', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.497Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:22.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8765', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 6.8, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'watchOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'watchOS 6.1', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:39.583', 'references': [{'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-787'}]}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in watchOS 6.1. Processing maliciously crafted web content may lead to arbitrary code execution.'}, {'lang': 'es', 'value': 'Múltiples problemas de corrupción de memoria fueron abordados mejorando el manejo de la memoria. Este problema es corregido en watchOS versión 6.1. El procesamiento de contenido web diseñado maliciosamente puede conllevar a una ejecución de código arbitrario.'}], 'lastModified': '2026-06-17T02:42:34.253', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '277FA1BB-BB95-49DD-B50C-00F4BEE9DDE1', 'versionEndExcluding': '6.1'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8766
2019-12-18 20:33:23+03:00
2026-06-17 02:42:34.357000+03:00
PUBLISHED
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in watchOS 6.1, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to arbitrary code execution.
HIGH
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210727', 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210727', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:20.197198+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210727', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:36.287Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'watchOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'watchOS 6.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 11.0', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210727', 'tags': ['x_refsource_MISC']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in watchOS 6.1, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to arbitrary code execution.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2020-03-15T06:06:07.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'watchOS 6.1', 'version_affected': '<'}]}, 'product_name': 'watchOS'}, {'version': {'version_data': [{'version_value': 'iCloud for Windows 11.0', 'version_affected': '<'}]}, 'product_name': 'iCloud for Windows'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210724', 'name': 'https://support.apple.com/HT210724', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210727', 'name': 'https://support.apple.com/HT210727', 'refsource': 'MISC'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'refsource': 'GENTOO'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in watchOS 6.1, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to arbitrary code execution.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8766', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8766', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:36.287Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:23.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8766', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 6.8, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'watchOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'watchOS 6.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 11.0', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:39.677', 'references': [{'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210727', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210727', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-787'}]}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in watchOS 6.1, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to arbitrary code execution.'}, {'lang': 'es', 'value': 'Múltiples problemas de corrupción de memoria fueron abordados mejorando el manejo de la memoria. Este problema es corregido en watchOS versión 6.1, iCloud para Windows versión 11.0. El procesamiento de contenido web diseñado maliciosamente puede conllevar a una ejecución de código arbitrario.'}], 'lastModified': '2026-06-17T02:42:34.357', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': '156D40D5-B2E9-44E3-B899-FA246C320939', 'versionEndExcluding': '10.8'}, {'criteria': 'cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '277FA1BB-BB95-49DD-B50C-00F4BEE9DDE1', 'versionEndExcluding': '6.1'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8768
2019-12-18 20:33:22+03:00
2026-06-17 02:42:34.563000+03:00
PUBLISHED
"Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This issue is fixed in macOS Catalina 10.15. A user may be unable to delete browsing history items.
MEDIUM
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
[{'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210634', 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210634', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:20.197198+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210634', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.033Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210634', 'tags': ['x_refsource_MISC']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}], 'descriptions': [{'lang': 'en', 'value': '"Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This issue is fixed in macOS Catalina 10.15. A user may be unable to delete browsing history items.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'A user may be unable to delete browsing history items'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2020-03-15T06:06:10.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'macOS Catalina 10.15', 'version_affected': '<'}]}, 'product_name': 'macOS'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210634', 'name': 'https://support.apple.com/HT210634', 'refsource': 'MISC'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'refsource': 'GENTOO'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': '"Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This issue is fixed in macOS Catalina 10.15. A user may be unable to delete browsing history items.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'A user may be unable to delete browsing history items'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8768', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8768', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.033Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:22.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8768', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 5.0, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:P/I:N/A:N', 'authentication': 'NONE', 'integrityImpact': 'NONE', 'accessComplexity': 'LOW', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 10.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}, 'impactScore': 1.4, 'exploitabilityScore': 3.9}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:39.770', 'references': [{'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210634', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210634', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-459'}]}], 'descriptions': [{'lang': 'en', 'value': '"Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This issue is fixed in macOS Catalina 10.15. A user may be unable to delete browsing history items.'}, {'lang': 'es', 'value': '"Clear History and Website Data" no borró el historial. El problema fue abordado con una eliminación de datos mejorada. Este problema es corregido en macOS Catalina versión 10.15. Puede ser que un usuario no sea capaz de eliminar elementos del historial de navegación.'}], 'lastModified': '2026-06-17T02:42:34.563', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E28B89FF-E2E1-498A-AF43-C8DE5DA352CD', 'versionEndExcluding': '10.15'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8769
2019-12-18 20:33:22+03:00
2026-06-17 02:42:34.663000+03:00
PUBLISHED
An issue existed in the drawing of web page elements. The issue was addressed with improved logic. This issue is fixed in iOS 13.1 and iPadOS 13.1, macOS Catalina 10.15. Visiting a maliciously crafted website may reveal browsing history.
MEDIUM
4.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
[{'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210634', 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210634', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.773795+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210634', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:36.891Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.1 and iPadOS 13.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210634', 'tags': ['x_refsource_MISC']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}], 'descriptions': [{'lang': 'en', 'value': 'An issue existed in the drawing of web page elements. The issue was addressed with improved logic. This issue is fixed in iOS 13.1 and iPadOS 13.1, macOS Catalina 10.15. Visiting a maliciously crafted website may reveal browsing history.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Visiting a maliciously crafted website may reveal browsing history'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2020-03-15T06:06:24.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'iOS 13.1 and iPadOS 13.1', 'version_affected': '<'}]}, 'product_name': 'iOS'}, {'version': {'version_data': [{'version_value': 'macOS Catalina 10.15', 'version_affected': '<'}]}, 'product_name': 'macOS'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210634', 'name': 'https://support.apple.com/HT210634', 'refsource': 'MISC'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'refsource': 'GENTOO'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'An issue existed in the drawing of web page elements. The issue was addressed with improved logic. This issue is fixed in iOS 13.1 and iPadOS 13.1, macOS Catalina 10.15. Visiting a maliciously crafted website may reveal browsing history.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Visiting a maliciously crafted website may reveal browsing history'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8769', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8769', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:36.891Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:22.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8769', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 4.3, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:P/I:N/A:N', 'authentication': 'NONE', 'integrityImpact': 'NONE', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}, 'impactScore': 1.4, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.1 and iPadOS 13.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:39.897', 'references': [{'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210634', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210634', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'NVD-CWE-noinfo'}]}], 'descriptions': [{'lang': 'en', 'value': 'An issue existed in the drawing of web page elements. The issue was addressed with improved logic. This issue is fixed in iOS 13.1 and iPadOS 13.1, macOS Catalina 10.15. Visiting a maliciously crafted website may reveal browsing history.'}, {'lang': 'es', 'value': 'Se presentó un problema en el dibujado de los elementos de una página web. El problema fue abordado con una lógica mejorada. Este problema es corregido en iOS versión 13.1 y iPadOS versión 13.1, macOS Catalina 10.15. Visitar un sitio web diseñado maliciosamente puede revelar el historial de navegación.'}], 'lastModified': '2026-06-17T02:42:34.663', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E1B56C2A-63FE-410E-96A2-AA757E55086D', 'versionEndExcluding': '13.1'}, {'criteria': 'cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '74FC47CB-6F80-4521-BE54-47B5630FF496', 'versionEndExcluding': '13.1'}, {'criteria': 'cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E28B89FF-E2E1-498A-AF43-C8DE5DA352CD', 'versionEndExcluding': '10.15'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8770
2019-12-18 20:33:22+03:00
2026-06-17 02:42:34.770000+03:00
PUBLISHED
The issue was addressed with improved permissions logic. This issue is fixed in macOS Catalina 10.15. A malicious application may be able to access recent documents.
MEDIUM
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
[{'url': 'https://support.apple.com/HT210634', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210634', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.773795+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210634', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.109Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210634', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'The issue was addressed with improved permissions logic. This issue is fixed in macOS Catalina 10.15. A malicious application may be able to access recent documents.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'A malicious application may be able to access recent documents'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2019-12-18T17:33:22.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'macOS Catalina 10.15', 'version_affected': '<'}]}, 'product_name': 'macOS'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210634', 'name': 'https://support.apple.com/HT210634', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'The issue was addressed with improved permissions logic. This issue is fixed in macOS Catalina 10.15. A malicious application may be able to access recent documents.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'A malicious application may be able to access recent documents'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8770', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8770', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.109Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:22.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8770', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 4.3, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:P/I:N/A:N', 'authentication': 'NONE', 'integrityImpact': 'NONE', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 3.6, 'exploitabilityScore': 1.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:40.053', 'references': [{'url': 'https://support.apple.com/HT210634', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210634', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'NVD-CWE-noinfo'}]}], 'descriptions': [{'lang': 'en', 'value': 'The issue was addressed with improved permissions logic. This issue is fixed in macOS Catalina 10.15. A malicious application may be able to access recent documents.'}, {'lang': 'es', 'value': 'El problema fue abordado con una lógica de permisos mejorada. Este problema es corregido en macOS Catalina versión 10.15. Una aplicación maliciosa puede acceder a documentos recientes.'}], 'lastModified': '2026-06-17T02:42:34.770', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E28B89FF-E2E1-498A-AF43-C8DE5DA352CD', 'versionEndExcluding': '10.15'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2022-42286
2023-01-13 05:06:23.110000+03:00
2026-06-17 05:04:39.227000+03:00
PUBLISHED
DGX A100 SBIOS contains a vulnerability in Bds, which may lead to code execution, denial of service, or escalation of privileges.
MEDIUM
6.0
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
[{'url': 'https://nvidia.custhelp.com/app/answers/detail/a_id/5435', 'source': 'psirt@nvidia.com'}, {'url': 'https://nvidia.custhelp.com/app/answers/detail/a_id/5435', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:17:20.066418+03:00
2026-06-27 08:26:40.077172+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://nvidia.custhelp.com/app/answers/detail/a_id/5435', 'tags': ['x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-03T13:03:46.019Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'other': {'type': 'ssvc', 'content': {'id': 'CVE-2022-42286', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-04-07T18:02:37.100912Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-04-07T18:02:45.241Z'}}], 'cna': {'source': {'discovery': 'UNKNOWN'}, 'impacts': [{'descriptions': [{'lang': 'en', 'value': 'Code Execution, Denial of Service, Escalation of Privileges'}]}], 'metrics': [{'format': 'CVSS', 'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'NONE'}, 'scenarios': [{'lang': 'en', 'value': 'GENERAL'}]}], 'affected': [{'vendor': 'NVIDIA', 'product': 'NVIDIA DGX servers', 'versions': [{'status': 'affected', 'version': 'All SBIOS firmware versions prior to 1.18'}], 'defaultStatus': 'unaffected'}], 'references': [{'url': 'https://nvidia.custhelp.com/app/answers/detail/a_id/5435'}], 'x_generator': {'engine': 'Vulnogram 0.1.0-dev'}, 'descriptions': [{'lang': 'en', 'value': 'DGX A100 SBIOS contains a vulnerability in Bds, which may lead to code execution, denial of service, or escalation of privileges.', 'supportingMedia': [{'type': 'text/html', 'value': 'DGX A100 SBIOS contains a vulnerability in Bds, which may lead to code execution, denial of service, or escalation of privileges.', 'base64': True}]}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-119', 'description': 'CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer'}]}], 'providerMetadata': {'orgId': '9576f279-3576-44b5-a4af-b9a8644b2de6', 'shortName': 'nvidia', 'dateUpdated': '2023-01-13T02:06:23.110Z'}}}, 'cveMetadata': {'cveId': 'CVE-2022-42286', 'state': 'PUBLISHED', 'dateUpdated': '2025-04-07T18:02:45.241Z', 'dateReserved': '2022-10-03T14:20:26.207Z', 'assignerOrgId': '9576f279-3576-44b5-a4af-b9a8644b2de6', 'datePublished': '2023-01-13T02:06:23.110Z', 'assignerShortName': 'nvidia'}, 'dataVersion': '5.1'}
{'id': 'CVE-2022-42286', 'cveTags': [], 'metrics': {'ssvcV203': [{'source': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'ssvcData': {'id': 'CVE-2022-42286', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-04-07T18:02:37.100912Z'}}], 'cvssMetricV31': [{'type': 'Secondary', 'source': 'psirt@nvidia.com', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.0, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'NONE'}, 'impactScore': 5.2, 'exploitabilityScore': 0.8}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 1.8}]}, 'affected': [{'source': 'psirt@nvidia.com', 'affectedData': [{'vendor': 'NVIDIA', 'product': 'NVIDIA DGX servers', 'versions': [{'status': 'affected', 'version': 'All SBIOS firmware versions prior to 1.18'}], 'defaultStatus': 'unaffected'}]}], 'published': '2023-01-13T04:15:08.473', 'references': [{'url': 'https://nvidia.custhelp.com/app/answers/detail/a_id/5435', 'tags': ['Vendor Advisory'], 'source': 'psirt@nvidia.com'}, {'url': 'https://nvidia.custhelp.com/app/answers/detail/a_id/5435', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Secondary', 'source': 'psirt@nvidia.com', 'description': [{'lang': 'en', 'value': 'CWE-119'}]}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'NVD-CWE-noinfo'}]}], 'descriptions': [{'lang': 'en', 'value': 'DGX A100 SBIOS contains a vulnerability in Bds, which may lead to code execution, denial of service, or escalation of privileges.'}, {'lang': 'es', 'value': 'DGX A100 SBIOS contiene una vulnerabilidad en Bds, que puede provocar la ejecución de código, denegación de servicio o escalada de privilegios.'}], 'lastModified': '2026-06-17T05:04:39.227', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:nvidia:sbios:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '7195E4E2-A8B1-451A-AD17-9EC738020241', 'versionEndExcluding': '1.18'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:nvidia:dgx_a100:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '8807CB65-5F49-42E8-B5D8-36943418ADB9'}], 'operator': 'OR'}], 'operator': 'AND'}], 'sourceIdentifier': 'psirt@nvidia.com'}
CVE-2019-8772
2019-12-18 20:33:22+03:00
2026-06-17 02:42:34.970000+03:00
PUBLISHED
An issue existed in the handling of links in encrypted PDFs. This issue was addressed by adding a confirmation prompt. This issue is fixed in macOS Catalina 10.15. An attacker may be able to exfiltrate the contents of an encrypted PDF.
HIGH
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
[{'url': 'https://support.apple.com/HT210634', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/kb/HT210722', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210634', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/kb/HT210722', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:20.197198+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/kb/HT210722', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'https://support.apple.com/HT210634', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.152Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/kb/HT210722', 'tags': ['x_refsource_CONFIRM']}, {'url': 'https://support.apple.com/HT210634', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'An issue existed in the handling of links in encrypted PDFs. This issue was addressed by adding a confirmation prompt. This issue is fixed in macOS Catalina 10.15. An attacker may be able to exfiltrate the contents of an encrypted PDF.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'An attacker may be able to exfiltrate the contents of an encrypted PDF'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2020-02-12T01:06:05.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'macOS Catalina 10.15', 'version_affected': '<'}]}, 'product_name': 'macOS'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/kb/HT210722', 'name': 'https://support.apple.com/kb/HT210722', 'refsource': 'CONFIRM'}, {'url': 'https://support.apple.com/HT210634', 'name': 'https://support.apple.com/HT210634', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'An issue existed in the handling of links in encrypted PDFs. This issue was addressed by adding a confirmation prompt. This issue is fixed in macOS Catalina 10.15. An attacker may be able to exfiltrate the contents of an encrypted PDF.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'An attacker may be able to exfiltrate the contents of an encrypted PDF'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8772', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8772', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.152Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:22.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8772', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 5.0, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:P/I:N/A:N', 'authentication': 'NONE', 'integrityImpact': 'NONE', 'accessComplexity': 'LOW', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 10.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 3.6, 'exploitabilityScore': 3.9}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:40.147', 'references': [{'url': 'https://support.apple.com/HT210634', 'tags': ['Release Notes', 'Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/kb/HT210722', 'tags': ['Release Notes', 'Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210634', 'tags': ['Release Notes', 'Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/kb/HT210722', 'tags': ['Release Notes', 'Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'NVD-CWE-noinfo'}]}], 'descriptions': [{'lang': 'en', 'value': 'An issue existed in the handling of links in encrypted PDFs. This issue was addressed by adding a confirmation prompt. This issue is fixed in macOS Catalina 10.15. An attacker may be able to exfiltrate the contents of an encrypted PDF.'}, {'lang': 'es', 'value': 'Se presentó un problema en el manejo de enlaces en archivos PDF encriptados. Este problema fue corregido agregando un mensaje de confirmación. Este problema es corregido en macOS Catalina versión 10.15. Un atacante puede exfiltrar el contenido de un PDF encriptado.'}], 'lastModified': '2026-06-17T02:42:34.970', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E28B89FF-E2E1-498A-AF43-C8DE5DA352CD', 'versionEndExcluding': '10.15'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8775
2019-12-18 20:33:23+03:00
2026-06-17 02:42:35.300000+03:00
PUBLISHED
The issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 13.1 and iPadOS 13.1. A person with physical access to an iOS device may be able to access contacts from the lock screen.
LOW
2.4
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
[{'url': 'https://support.apple.com/HT210603', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210603', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.773795+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210603', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:36.682Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.1 and iPadOS 13.1', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210603', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'The issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 13.1 and iPadOS 13.1. A person with physical access to an iOS device may be able to access contacts from the lock screen.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'A person with physical access to an iOS device may be able to access contacts from the lock screen'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2019-12-18T17:33:23.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'iOS 13.1 and iPadOS 13.1', 'version_affected': '<'}]}, 'product_name': 'iOS'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210724', 'name': 'https://support.apple.com/HT210724', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210603', 'name': 'https://support.apple.com/HT210603', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'The issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 13.1 and iPadOS 13.1. A person with physical access to an iOS device may be able to access contacts from the lock screen.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'A person with physical access to an iOS device may be able to access contacts from the lock screen'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8775', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8775', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:36.682Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:23.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8775', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 2.1, 'accessVector': 'LOCAL', 'vectorString': 'AV:L/AC:L/Au:N/C:N/I:N/A:P', 'authentication': 'NONE', 'integrityImpact': 'NONE', 'accessComplexity': 'LOW', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'NONE'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'LOW', 'obtainAllPrivilege': False, 'exploitabilityScore': 3.9, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 2.4, 'attackVector': 'PHYSICAL', 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}, 'impactScore': 1.4, 'exploitabilityScore': 0.9}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.1 and iPadOS 13.1', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:40.270', 'references': [{'url': 'https://support.apple.com/HT210603', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210603', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'NVD-CWE-noinfo'}]}], 'descriptions': [{'lang': 'en', 'value': 'The issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 13.1 and iPadOS 13.1. A person with physical access to an iOS device may be able to access contacts from the lock screen.'}, {'lang': 'es', 'value': 'El problema fue abordado restringiendo las opciones ofrecidas en un dispositivo bloqueado. Este problema es corregido en iOS versión 13.1 y iPadOS versión 13.1. Una persona con acceso físico a un dispositivo con iOS puede acceder a los contactos desde la pantalla de bloqueo.'}], 'lastModified': '2026-06-17T02:42:35.300', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E1B56C2A-63FE-410E-96A2-AA757E55086D', 'versionEndExcluding': '13.1'}, {'criteria': 'cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '74FC47CB-6F80-4521-BE54-47B5630FF496', 'versionEndExcluding': '13.1'}, {'criteria': 'cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '277FA1BB-BB95-49DD-B50C-00F4BEE9DDE1', 'versionEndExcluding': '6.1'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8779
2019-12-18 20:33:22+03:00
2026-06-17 02:42:35.720000+03:00
PUBLISHED
A logic issue applied the incorrect restrictions. This issue was addressed by updating the logic to apply the correct restrictions. This issue is fixed in iOS 13.1.1 and iPadOS 13.1.1. Third party app extensions may not receive the correct sandbox restrictions.
CRITICAL
10.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
[{'url': 'https://support.apple.com/HT210624', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210624', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.773795+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210624', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.200Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.1.1 and iPadOS 13.1.1', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210624', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'A logic issue applied the incorrect restrictions. This issue was addressed by updating the logic to apply the correct restrictions. This issue is fixed in iOS 13.1.1 and iPadOS 13.1.1. Third party app extensions may not receive the correct sandbox restrictions.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Third party app extensions may not receive the correct sandbox restrictions'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2019-12-18T17:33:22.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'iOS 13.1.1 and iPadOS 13.1.1', 'version_affected': '<'}]}, 'product_name': 'iOS'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210624', 'name': 'https://support.apple.com/HT210624', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'A logic issue applied the incorrect restrictions. This issue was addressed by updating the logic to apply the correct restrictions. This issue is fixed in iOS 13.1.1 and iPadOS 13.1.1. Third party app extensions may not receive the correct sandbox restrictions.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Third party app extensions may not receive the correct sandbox restrictions'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8779', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8779', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.200Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:22.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8779', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 7.5, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'LOW', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'HIGH', 'obtainAllPrivilege': False, 'exploitabilityScore': 10.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 10.0, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 6.0, 'exploitabilityScore': 3.9}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.1.1 and iPadOS 13.1.1', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:40.397', 'references': [{'url': 'https://support.apple.com/HT210624', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210624', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-668'}]}], 'descriptions': [{'lang': 'en', 'value': 'A logic issue applied the incorrect restrictions. This issue was addressed by updating the logic to apply the correct restrictions. This issue is fixed in iOS 13.1.1 and iPadOS 13.1.1. Third party app extensions may not receive the correct sandbox restrictions.'}, {'lang': 'es', 'value': 'Un problema lógico aplicó las restricciones incorrectas. Este problema fue abordado actualizando la lógica para aplicar las restricciones correctas. Este problema es corregido en iOS versión 13.1.1 y iPadOS versión 13.1.1. Las extensiones de aplicaciones de terceros pueden no recibir las restricciones de sandbox correctas.'}], 'lastModified': '2026-06-17T02:42:35.720', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '05CE1E0C-3D1E-4661-8011-E231D9E5113B', 'versionEndExcluding': '13.1.1'}, {'criteria': 'cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'F6124AFA-93F3-4C04-A155-EB215733C5CF', 'versionEndExcluding': '13.1.1'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8781
2019-12-18 20:33:22+03:00
2026-06-17 02:42:36+03:00
PUBLISHED
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15. An application may be able to execute arbitrary code with kernel privileges.
HIGH
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'https://support.apple.com/HT210634', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210634', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:20.197198+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210634', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.170Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210634', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15. An application may be able to execute arbitrary code with kernel privileges.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'An application may be able to execute arbitrary code with kernel privileges'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2019-12-18T17:33:22.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'macOS Catalina 10.15', 'version_affected': '<'}]}, 'product_name': 'macOS'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210634', 'name': 'https://support.apple.com/HT210634', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15. An application may be able to execute arbitrary code with kernel privileges.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'An application may be able to execute arbitrary code with kernel privileges'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8781', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8781', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.170Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:22.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8781', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 9.3, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:C/I:C/A:C', 'authentication': 'NONE', 'integrityImpact': 'COMPLETE', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'COMPLETE', 'confidentialityImpact': 'COMPLETE'}, 'acInsufInfo': False, 'impactScore': 10.0, 'baseSeverity': 'HIGH', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 1.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:40.507', 'references': [{'url': 'https://support.apple.com/HT210634', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210634', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-787'}]}], 'descriptions': [{'lang': 'en', 'value': 'A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15. An application may be able to execute arbitrary code with kernel privileges.'}, {'lang': 'es', 'value': 'Un problema de corrupción de memoria fue abordado mejorando la gestión del estado. Este problema es corregido en macOS Catalina versión 10.15. Una aplicación puede ejecutar código arbitrario con privilegios de kernel.'}], 'lastModified': '2026-06-17T02:42:36.000', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E28B89FF-E2E1-498A-AF43-C8DE5DA352CD', 'versionEndExcluding': '10.15'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8782
2019-12-18 20:33:23+03:00
2026-06-17 02:42:36.130000+03:00
PUBLISHED
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to arbitrary code execution.
HIGH
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210725', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210727', 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210721', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210725', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210727', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.773795+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210727', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210725', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.302Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Safari', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Safari 13.0.3', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 11.0', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210727', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210725', 'tags': ['x_refsource_MISC']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to arbitrary code execution.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2020-03-15T06:06:29.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'iOS 13.2 and iPadOS 13.2', 'version_affected': '<'}]}, 'product_name': 'iOS'}, {'version': {'version_data': [{'version_value': 'tvOS 13.2', 'version_affected': '<'}]}, 'product_name': 'tvOS'}, {'version': {'version_data': [{'version_value': 'Safari 13.0.3', 'version_affected': '<'}]}, 'product_name': 'Safari'}, {'version': {'version_data': [{'version_value': 'iTunes for Windows 12.10.2', 'version_affected': '<'}]}, 'product_name': 'iTunes for Windows'}, {'version': {'version_data': [{'version_value': 'iCloud for Windows 11.0', 'version_affected': '<'}]}, 'product_name': 'iCloud for Windows'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210727', 'name': 'https://support.apple.com/HT210727', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210721', 'name': 'https://support.apple.com/HT210721', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210726', 'name': 'https://support.apple.com/HT210726', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210723', 'name': 'https://support.apple.com/HT210723', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210725', 'name': 'https://support.apple.com/HT210725', 'refsource': 'MISC'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'refsource': 'GENTOO'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to arbitrary code execution.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8782', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8782', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.302Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:23.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8782', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 6.8, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Safari', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Safari 13.0.3', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 11.0', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:40.617', 'references': [{'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210725', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210727', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210725', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210727', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-787'}]}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to arbitrary code execution.'}, {'lang': 'es', 'value': 'Múltiples problemas de corrupción de memoria fueron abordados mejorando el manejo de la memoria. Este problema es corregido en iOS versión 13.2 y iPadOS versión 13.2, tvOS versión 13.2, Safari versión 13.0.3, iTunes para Windows versión 12.10.2, iCloud para Windows versión 11.0. El procesamiento de contenido web diseñado maliciosamente puede conllevar a una ejecución de código arbitrario.'}], 'lastModified': '2026-06-17T02:42:36.130', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': 'F2F63E96-27FA-4637-8081-A9B76C7385F8', 'versionEndIncluding': '10.8', 'versionStartIncluding': '10.0'}, {'criteria': 'cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': '4A70FE53-CD3F-4296-B209-64C6F24CE3A7', 'versionEndExcluding': '12.10.2'}, {'criteria': 'cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '9DD4F307-7772-4B9B-8C77-E445EA39ADB8', 'versionEndExcluding': '13.0.3'}, {'criteria': 'cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AD59FD8B-5C11-469A-91E8-B3EB904AB1EF', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '13864229-C006-4C72-AAE3-90F009375CA5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A03A6988-48E4-4108-9A9B-8671BFF4C3A5', 'versionEndExcluding': '13.2'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8783
2019-12-18 20:33:24+03:00
2026-06-17 02:42:36.267000+03:00
PUBLISHED
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.
HIGH
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210725', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210727', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210728', 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210721', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210725', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210727', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210728', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.773795+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210727', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210728', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210725', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.219Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Safari', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Safari 13.0.3', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 11.0', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows (Legacy)', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 7.15', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210727', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210728', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210725', 'tags': ['x_refsource_MISC']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2020-03-15T06:06:25.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'iOS 13.2 and iPadOS 13.2', 'version_affected': '<'}]}, 'product_name': 'iOS'}, {'version': {'version_data': [{'version_value': 'tvOS 13.2', 'version_affected': '<'}]}, 'product_name': 'tvOS'}, {'version': {'version_data': [{'version_value': 'Safari 13.0.3', 'version_affected': '<'}]}, 'product_name': 'Safari'}, {'version': {'version_data': [{'version_value': 'iTunes for Windows 12.10.2', 'version_affected': '<'}]}, 'product_name': 'iTunes for Windows'}, {'version': {'version_data': [{'version_value': 'iCloud for Windows 11.0', 'version_affected': '<'}]}, 'product_name': 'iCloud for Windows'}, {'version': {'version_data': [{'version_value': 'iCloud for Windows 7.15', 'version_affected': '<'}]}, 'product_name': 'iCloud for Windows (Legacy)'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210727', 'name': 'https://support.apple.com/HT210727', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210721', 'name': 'https://support.apple.com/HT210721', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210726', 'name': 'https://support.apple.com/HT210726', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210723', 'name': 'https://support.apple.com/HT210723', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210728', 'name': 'https://support.apple.com/HT210728', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210725', 'name': 'https://support.apple.com/HT210725', 'refsource': 'MISC'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'refsource': 'GENTOO'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8783', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8783', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.219Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:24.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8783', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 6.8, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Safari', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Safari 13.0.3', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 11.0', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows (Legacy)', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 7.15', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:40.757', 'references': [{'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210725', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210727', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210728', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210725', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210727', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210728', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-787'}]}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.'}, {'lang': 'es', 'value': 'Múltiples problemas de corrupción de memoria fueron abordados mejorando el manejo de la memoria. Este problema es corregido en iOS versión 13.2 y iPadOS versión 13.2, tvOS versión 13.2, Safari versión 13.0.3, iTunes para Windows versión 12.10.2, iCloud para Windows versión 11.0, iCloud para Windows versión 7.15. El procesamiento de contenido web diseñado maliciosamente puede conllevar a una ejecución de código arbitrario.'}], 'lastModified': '2026-06-17T02:42:36.267', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': 'B730AB98-7AF7-4F18-BEB4-AEE484D2586B', 'versionEndExcluding': '7.15'}, {'criteria': 'cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': '3599AAD1-DA6B-4E53-B166-BE36ADF48D11', 'versionEndExcluding': '10.8', 'versionStartIncluding': '10.0'}, {'criteria': 'cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': '4A70FE53-CD3F-4296-B209-64C6F24CE3A7', 'versionEndExcluding': '12.10.2'}, {'criteria': 'cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '9DD4F307-7772-4B9B-8C77-E445EA39ADB8', 'versionEndExcluding': '13.0.3'}, {'criteria': 'cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '2EDBE557-B798-4432-990E-AFB9596A4AB4', 'versionEndIncluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '13864229-C006-4C72-AAE3-90F009375CA5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A03A6988-48E4-4108-9A9B-8671BFF4C3A5', 'versionEndExcluding': '13.2'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8784
2019-12-18 20:33:23+03:00
2026-06-17 02:42:36.390000+03:00
PUBLISHED
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. An application may be able to execute arbitrary code with system privileges.
HIGH
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'https://support.apple.com/HT210721', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210722', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210727', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210728', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210722', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210727', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210728', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.773795+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210727', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210722', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210728', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.302Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 11.0', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows (Legacy)', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 7.15', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210727', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210722', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210728', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. An application may be able to execute arbitrary code with system privileges.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'An application may be able to execute arbitrary code with system privileges'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2019-12-18T17:33:23.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'iOS 13.2 and iPadOS 13.2', 'version_affected': '<'}]}, 'product_name': 'iOS'}, {'version': {'version_data': [{'version_value': 'macOS Catalina 10.15.1', 'version_affected': '<'}]}, 'product_name': 'macOS'}, {'version': {'version_data': [{'version_value': 'iTunes for Windows 12.10.2', 'version_affected': '<'}]}, 'product_name': 'iTunes for Windows'}, {'version': {'version_data': [{'version_value': 'iCloud for Windows 11.0', 'version_affected': '<'}]}, 'product_name': 'iCloud for Windows'}, {'version': {'version_data': [{'version_value': 'iCloud for Windows 7.15', 'version_affected': '<'}]}, 'product_name': 'iCloud for Windows (Legacy)'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210727', 'name': 'https://support.apple.com/HT210727', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210721', 'name': 'https://support.apple.com/HT210721', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210722', 'name': 'https://support.apple.com/HT210722', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210726', 'name': 'https://support.apple.com/HT210726', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210728', 'name': 'https://support.apple.com/HT210728', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. An application may be able to execute arbitrary code with system privileges.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'An application may be able to execute arbitrary code with system privileges'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8784', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8784', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.302Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:23.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8784', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 9.3, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:C/I:C/A:C', 'authentication': 'NONE', 'integrityImpact': 'COMPLETE', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'COMPLETE', 'confidentialityImpact': 'COMPLETE'}, 'acInsufInfo': False, 'impactScore': 10.0, 'baseSeverity': 'HIGH', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 1.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 11.0', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows (Legacy)', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 7.15', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:40.913', 'references': [{'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210722', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210727', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210728', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210722', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210727', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210728', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-787'}]}], 'descriptions': [{'lang': 'en', 'value': 'A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. An application may be able to execute arbitrary code with system privileges.'}, {'lang': 'es', 'value': 'Un problema de corrupción de memoria fue abordado mejorando el manejo de la memoria. Este problema es corregido en iOS versión 13.2 y iPadOS versión 13.2, macOS Catalina versión 10.15.1, iTunes para Windows versión 12.10.2, iCloud para Windows versión 11.0, iCloud para Windows versión 7.15. Una aplicación puede ejecutar código arbitrario con privilegios system.'}], 'lastModified': '2026-06-17T02:42:36.390', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': 'B730AB98-7AF7-4F18-BEB4-AEE484D2586B', 'versionEndExcluding': '7.15'}, {'criteria': 'cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': '3599AAD1-DA6B-4E53-B166-BE36ADF48D11', 'versionEndExcluding': '10.8', 'versionStartIncluding': '10.0'}, {'criteria': 'cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': '4A70FE53-CD3F-4296-B209-64C6F24CE3A7', 'versionEndExcluding': '12.10.2'}, {'criteria': 'cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AD59FD8B-5C11-469A-91E8-B3EB904AB1EF', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '13864229-C006-4C72-AAE3-90F009375CA5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E773457A-E670-4DDA-86E2-0923C1DCD9BA', 'versionEndExcluding': '10.15.1'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8785
2019-12-18 20:33:24+03:00
2026-06-17 02:42:36.500000+03:00
PUBLISHED
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with system privileges.
HIGH
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'https://support.apple.com/HT210721', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210722', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210722', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.773795+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210722', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:36.955Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'watchOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'watchOS 6.1', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210722', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with system privileges.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'An application may be able to execute arbitrary code with system privileges'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2019-12-18T17:33:24.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'iOS 13.2 and iPadOS 13.2', 'version_affected': '<'}]}, 'product_name': 'iOS'}, {'version': {'version_data': [{'version_value': 'macOS Catalina 10.15.1', 'version_affected': '<'}]}, 'product_name': 'macOS'}, {'version': {'version_data': [{'version_value': 'tvOS 13.2', 'version_affected': '<'}]}, 'product_name': 'tvOS'}, {'version': {'version_data': [{'version_value': 'watchOS 6.1', 'version_affected': '<'}]}, 'product_name': 'watchOS'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210724', 'name': 'https://support.apple.com/HT210724', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210721', 'name': 'https://support.apple.com/HT210721', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210722', 'name': 'https://support.apple.com/HT210722', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210723', 'name': 'https://support.apple.com/HT210723', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with system privileges.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'An application may be able to execute arbitrary code with system privileges'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8785', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8785', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:36.955Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:24.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8785', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 9.3, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:C/I:C/A:C', 'authentication': 'NONE', 'integrityImpact': 'COMPLETE', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'COMPLETE', 'confidentialityImpact': 'COMPLETE'}, 'acInsufInfo': False, 'impactScore': 10.0, 'baseSeverity': 'HIGH', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 1.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'watchOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'watchOS 6.1', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:41.037', 'references': [{'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210722', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210722', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-787'}]}], 'descriptions': [{'lang': 'en', 'value': 'A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with system privileges.'}, {'lang': 'es', 'value': 'Un problema de corrupción de memoria fue abordado mejorando el manejo de la memoria. Este problema es corregido en iOS versión 13.2 y iPadOS versión 13.2, macOS Catalina versión 10.15.1, tvOS versión 13.2, watchOS versión 6.1. Una aplicación puede ejecutar código arbitrario con privilegios system.'}], 'lastModified': '2026-06-17T02:42:36.500', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '2EDBE557-B798-4432-990E-AFB9596A4AB4', 'versionEndIncluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '13864229-C006-4C72-AAE3-90F009375CA5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E773457A-E670-4DDA-86E2-0923C1DCD9BA', 'versionEndExcluding': '10.15.1'}, {'criteria': 'cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A03A6988-48E4-4108-9A9B-8671BFF4C3A5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '277FA1BB-BB95-49DD-B50C-00F4BEE9DDE1', 'versionEndExcluding': '6.1'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8786
2019-12-18 20:33:23+03:00
2026-06-17 02:42:36.617000+03:00
PUBLISHED
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with kernel privileges.
HIGH
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'https://support.apple.com/HT210721', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210722', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210722', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:20.197198+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210722', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:36.654Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'watchOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'watchOS 6.1', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210722', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with kernel privileges.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'An application may be able to execute arbitrary code with kernel privileges'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2019-12-18T17:33:23.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'iOS 13.2 and iPadOS 13.2', 'version_affected': '<'}]}, 'product_name': 'iOS'}, {'version': {'version_data': [{'version_value': 'macOS Catalina 10.15.1', 'version_affected': '<'}]}, 'product_name': 'macOS'}, {'version': {'version_data': [{'version_value': 'tvOS 13.2', 'version_affected': '<'}]}, 'product_name': 'tvOS'}, {'version': {'version_data': [{'version_value': 'watchOS 6.1', 'version_affected': '<'}]}, 'product_name': 'watchOS'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210724', 'name': 'https://support.apple.com/HT210724', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210721', 'name': 'https://support.apple.com/HT210721', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210722', 'name': 'https://support.apple.com/HT210722', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210723', 'name': 'https://support.apple.com/HT210723', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with kernel privileges.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'An application may be able to execute arbitrary code with kernel privileges'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8786', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8786', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:36.654Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:23.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8786', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 9.3, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:C/I:C/A:C', 'authentication': 'NONE', 'integrityImpact': 'COMPLETE', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'COMPLETE', 'confidentialityImpact': 'COMPLETE'}, 'acInsufInfo': False, 'impactScore': 10.0, 'baseSeverity': 'HIGH', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 1.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'watchOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'watchOS 6.1', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:41.163', 'references': [{'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210722', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210722', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-787'}]}], 'descriptions': [{'lang': 'en', 'value': 'A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with kernel privileges.'}, {'lang': 'es', 'value': 'Un problema de corrupción de memoria fue abordado mejorando el manejo de la memoria. Este problema es corregido en iOS versión 13.2 y iPadOS versión 13.2, macOS Catalina versión 10.15.1, tvOS versión 13.2, watchOS versión 6.1. Una aplicación puede ejecutar código arbitrario con privilegios de kernel.'}], 'lastModified': '2026-06-17T02:42:36.617', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AD59FD8B-5C11-469A-91E8-B3EB904AB1EF', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '13864229-C006-4C72-AAE3-90F009375CA5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E773457A-E670-4DDA-86E2-0923C1DCD9BA', 'versionEndExcluding': '10.15.1'}, {'criteria': 'cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A03A6988-48E4-4108-9A9B-8671BFF4C3A5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '277FA1BB-BB95-49DD-B50C-00F4BEE9DDE1', 'versionEndExcluding': '6.1'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8787
2019-12-18 20:33:24+03:00
2026-06-17 02:42:36.773000+03:00
PUBLISHED
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. A remote attacker may be able to leak memory.
HIGH
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
[{'url': 'https://support.apple.com/HT210721', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210722', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210722', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.773795+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210722', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:36.934Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'watchOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'watchOS 6.1', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210722', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. A remote attacker may be able to leak memory.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'A remote attacker may be able to leak memory'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2019-12-18T17:33:24.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'iOS 13.2 and iPadOS 13.2', 'version_affected': '<'}]}, 'product_name': 'iOS'}, {'version': {'version_data': [{'version_value': 'macOS Catalina 10.15.1', 'version_affected': '<'}]}, 'product_name': 'macOS'}, {'version': {'version_data': [{'version_value': 'tvOS 13.2', 'version_affected': '<'}]}, 'product_name': 'tvOS'}, {'version': {'version_data': [{'version_value': 'watchOS 6.1', 'version_affected': '<'}]}, 'product_name': 'watchOS'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210724', 'name': 'https://support.apple.com/HT210724', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210721', 'name': 'https://support.apple.com/HT210721', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210722', 'name': 'https://support.apple.com/HT210722', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210723', 'name': 'https://support.apple.com/HT210723', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. A remote attacker may be able to leak memory.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'A remote attacker may be able to leak memory'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8787', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8787', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:36.934Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:24.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8787', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 5.0, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:P/I:N/A:N', 'authentication': 'NONE', 'integrityImpact': 'NONE', 'accessComplexity': 'LOW', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 10.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 3.6, 'exploitabilityScore': 3.9}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'watchOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'watchOS 6.1', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:41.287', 'references': [{'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210722', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210722', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-125'}]}], 'descriptions': [{'lang': 'en', 'value': 'An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. A remote attacker may be able to leak memory.'}, {'lang': 'es', 'value': 'Una lectura fuera de límites fue abordada con una comprobación de entrada mejorada. Este problema es corregido en iOS versión 13.2 y iPadOS versión 13.2, macOS Catalina versión 10.15.1, tvOS versión 13.2, watchOS versión 6.1. Un atacante remoto puede ser capaz de filtrar la memoria.'}], 'lastModified': '2026-06-17T02:42:36.773', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '2EDBE557-B798-4432-990E-AFB9596A4AB4', 'versionEndIncluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '13864229-C006-4C72-AAE3-90F009375CA5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E773457A-E670-4DDA-86E2-0923C1DCD9BA', 'versionEndExcluding': '10.15.1'}, {'criteria': 'cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A03A6988-48E4-4108-9A9B-8671BFF4C3A5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '277FA1BB-BB95-49DD-B50C-00F4BEE9DDE1', 'versionEndExcluding': '6.1'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8788
2019-12-18 20:33:23+03:00
2026-06-17 02:42:37.077000+03:00
PUBLISHED
An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1. Improper URL processing may lead to data exfiltration.
HIGH
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
[{'url': 'https://support.apple.com/HT210721', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210722', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210722', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.773795+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210722', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:36.949Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15.1', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210722', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1. Improper URL processing may lead to data exfiltration.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Improper URL processing may lead to data exfiltration'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2019-12-18T17:33:23.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'iOS 13.2 and iPadOS 13.2', 'version_affected': '<'}]}, 'product_name': 'iOS'}, {'version': {'version_data': [{'version_value': 'macOS Catalina 10.15.1', 'version_affected': '<'}]}, 'product_name': 'macOS'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210721', 'name': 'https://support.apple.com/HT210721', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210722', 'name': 'https://support.apple.com/HT210722', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1. Improper URL processing may lead to data exfiltration.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Improper URL processing may lead to data exfiltration'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8788', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8788', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:36.949Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:23.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8788', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 5.0, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:P/I:N/A:N', 'authentication': 'NONE', 'integrityImpact': 'NONE', 'accessComplexity': 'LOW', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 10.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 3.6, 'exploitabilityScore': 3.9}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15.1', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:41.413', 'references': [{'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210722', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210722', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-20'}]}], 'descriptions': [{'lang': 'en', 'value': 'An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1. Improper URL processing may lead to data exfiltration.'}, {'lang': 'es', 'value': 'Se presentó un problema en el análisis de las URL. Este problema fue abordado con una comprobación de entrada mejorada. Este problema es corregido en iOS versión 13.2 y iPadOS versión 13.2, macOS Catalina versión 10.15.1. El procesamiento incorrecto de URL puede conllevar a la exfiltración de datos.'}], 'lastModified': '2026-06-17T02:42:37.077', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AD59FD8B-5C11-469A-91E8-B3EB904AB1EF', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '13864229-C006-4C72-AAE3-90F009375CA5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E773457A-E670-4DDA-86E2-0923C1DCD9BA', 'versionEndExcluding': '10.15.1'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8789
2019-12-18 20:33:23+03:00
2026-06-17 02:42:37.183000+03:00
PUBLISHED
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1. Parsing a maliciously crafted iBooks file may lead to disclosure of user information.
MEDIUM
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
[{'url': 'https://support.apple.com/HT210721', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210722', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210722', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.773795+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210722', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.051Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15.1', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210722', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1. Parsing a maliciously crafted iBooks file may lead to disclosure of user information.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Parsing a maliciously crafted iBooks file may lead to disclosure of user information'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2019-12-18T17:33:23.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'iOS 13.2 and iPadOS 13.2', 'version_affected': '<'}]}, 'product_name': 'iOS'}, {'version': {'version_data': [{'version_value': 'macOS Catalina 10.15.1', 'version_affected': '<'}]}, 'product_name': 'macOS'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210721', 'name': 'https://support.apple.com/HT210721', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210722', 'name': 'https://support.apple.com/HT210722', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1. Parsing a maliciously crafted iBooks file may lead to disclosure of user information.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Parsing a maliciously crafted iBooks file may lead to disclosure of user information'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8789', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8789', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.051Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:23.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8789', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 4.3, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:P/I:N/A:N', 'authentication': 'NONE', 'integrityImpact': 'NONE', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 3.6, 'exploitabilityScore': 1.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15.1', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:41.520', 'references': [{'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210722', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210722', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-59'}]}], 'descriptions': [{'lang': 'en', 'value': 'A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1. Parsing a maliciously crafted iBooks file may lead to disclosure of user information.'}, {'lang': 'es', 'value': 'Se presentó un problema de comprobación en el manejo de enlaces simbólicos. Este problema fue abordado con una comprobación mejorada de los enlaces simbólicos. Este problema es corregido en iOS versión 13.2 y iPadOS versión 13.2, macOS Catalina versión 10.15.1. Analizar un archivo iBooks diseñado maliciosamente puede conllevar a una divulgación de información del usuario.'}], 'lastModified': '2026-06-17T02:42:37.183', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AD59FD8B-5C11-469A-91E8-B3EB904AB1EF', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '13864229-C006-4C72-AAE3-90F009375CA5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E773457A-E670-4DDA-86E2-0923C1DCD9BA', 'versionEndExcluding': '10.15.1'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8791
2019-12-18 20:33:23+03:00
2026-06-17 02:42:37.387000+03:00
PUBLISHED
An issue existed in the parsing of URL schemes. This issue was addressed with improved URL validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to an open redirect.
MEDIUM
6.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
[{'url': 'https://support.apple.com/HT210744', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210745', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210744', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210745', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.773795+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210744', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210745', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.471Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'Shazam-Android', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Shazam Android App Version 9.25.0', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Shazam-iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Shazam iOS App Version 12.11.0', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210744', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210745', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'An issue existed in the parsing of URL schemes. This issue was addressed with improved URL validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to an open redirect.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Processing a maliciously crafted URL may lead to an open redirect'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2019-12-18T17:33:23.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'Shazam Android App Version 9.25.0', 'version_affected': '<'}]}, 'product_name': 'Shazam-Android'}, {'version': {'version_data': [{'version_value': 'Shazam iOS App Version 12.11.0', 'version_affected': '<'}]}, 'product_name': 'Shazam-iOS'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210744', 'name': 'https://support.apple.com/HT210744', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210745', 'name': 'https://support.apple.com/HT210745', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'An issue existed in the parsing of URL schemes. This issue was addressed with improved URL validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to an open redirect.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Processing a maliciously crafted URL may lead to an open redirect'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8791', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8791', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.471Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:23.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8791', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 5.8, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:P/I:P/A:N', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 4.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 6.1, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N', 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}, 'impactScore': 2.7, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'Shazam-Android', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Shazam Android App Version 9.25.0', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Shazam-iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Shazam iOS App Version 12.11.0', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:41.647', 'references': [{'url': 'https://support.apple.com/HT210744', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210745', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210744', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210745', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-601'}]}], 'descriptions': [{'lang': 'en', 'value': 'An issue existed in the parsing of URL schemes. This issue was addressed with improved URL validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to an open redirect.'}, {'lang': 'es', 'value': 'Se presentó un problema en el análisis de los esquemas de URL. Este problema fue abordado con una comprobación de URL mejorada. Este problema fue corregido en Shazam Android App versión 9.25.0 y Shazam iOS App versión 12.11.0. El procesamiento de una URL diseñada maliciosamente puede conllevar a un redireccionamiento abierto.'}], 'lastModified': '2026-06-17T02:42:37.387', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:apple:shazam:*:*:*:*:*:iphone_os:*:*', 'vulnerable': True, 'matchCriteriaId': '901CD767-C378-4185-A443-DED17BEBAF60', 'versionEndExcluding': '9.25.0'}, {'criteria': 'cpe:2.3:a:apple:shazam:*:*:*:*:*:android:*:*', 'vulnerable': True, 'matchCriteriaId': '90312868-463B-4AD7-92FE-AD399DEFD3ED', 'versionEndExcluding': '12.11.0'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8792
2019-12-18 20:33:23+03:00
2026-06-17 02:42:37.490000+03:00
PUBLISHED
An injection issue was addressed with improved validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to arbitrary javascript code execution.
HIGH
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'https://support.apple.com/HT210744', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210745', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210744', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210745', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.773795+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210744', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210745', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.523Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'Shazam-Android', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Shazam Android App Version 9.25.0', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Shazam-iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Shazam iOS App Version 12.11.0', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210744', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210745', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'An injection issue was addressed with improved validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to arbitrary javascript code execution.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Processing a maliciously crafted URL may lead to arbitrary javascript code execution'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2019-12-18T17:33:23.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'Shazam Android App Version 9.25.0', 'version_affected': '<'}]}, 'product_name': 'Shazam-Android'}, {'version': {'version_data': [{'version_value': 'Shazam iOS App Version 12.11.0', 'version_affected': '<'}]}, 'product_name': 'Shazam-iOS'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210744', 'name': 'https://support.apple.com/HT210744', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210745', 'name': 'https://support.apple.com/HT210745', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'An injection issue was addressed with improved validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to arbitrary javascript code execution.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Processing a maliciously crafted URL may lead to arbitrary javascript code execution'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8792', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8792', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.523Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:23.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8792', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 6.8, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'Shazam-Android', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Shazam Android App Version 9.25.0', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Shazam-iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Shazam iOS App Version 12.11.0', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:41.803', 'references': [{'url': 'https://support.apple.com/HT210744', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210745', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210744', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210745', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-74'}]}], 'descriptions': [{'lang': 'en', 'value': 'An injection issue was addressed with improved validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to arbitrary javascript code execution.'}, {'lang': 'es', 'value': 'Un problema de inyección fue abordado con una comprobación mejorada. Este problema fue corregido en Shazam Android App versión 9.25.0 y Shazam iOS App versión 12.11.0. El procesamiento de una URL diseñada maliciosamente puede conllevar a una ejecución arbitraria de código JavaScript.'}], 'lastModified': '2026-06-17T02:42:37.490', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:apple:shazam:9.25.0:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '582482F2-982D-415C-BD27-6C85E84D64E0'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:google:android:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'F8B9FEC8-73B6-43B8-B24E-1F7C20D91D26'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:apple:shazam:12.11.0:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'B6F2450C-E659-4848-8D32-E3251922DA32'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'B5415705-33E5-46D5-8E4D-9EBADC8C5705'}], 'operator': 'OR'}], 'operator': 'AND'}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8793
2019-12-18 20:33:23+03:00
2026-06-17 02:42:37.650000+03:00
PUBLISHED
A consistency issue existed in deciding when to show the screen recording indicator. The issue was resolved with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2. A local user may be able to record the screen without a visible screen recording indicator.
MEDIUM
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
[{'url': 'https://support.apple.com/HT210721', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:20.197198+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.080Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'A consistency issue existed in deciding when to show the screen recording indicator. The issue was resolved with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2. A local user may be able to record the screen without a visible screen recording indicator.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'A local user may be able to record the screen without a visible screen recording indicator'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2019-12-18T17:33:23.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'iOS 13.2 and iPadOS 13.2', 'version_affected': '<'}]}, 'product_name': 'iOS'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210721', 'name': 'https://support.apple.com/HT210721', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'A consistency issue existed in deciding when to show the screen recording indicator. The issue was resolved with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2. A local user may be able to record the screen without a visible screen recording indicator.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'A local user may be able to record the screen without a visible screen recording indicator'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8793', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8793', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.080Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:23.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8793', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 2.1, 'accessVector': 'LOCAL', 'vectorString': 'AV:L/AC:L/Au:N/C:P/I:N/A:N', 'authentication': 'NONE', 'integrityImpact': 'NONE', 'accessComplexity': 'LOW', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'LOW', 'obtainAllPrivilege': False, 'exploitabilityScore': 3.9, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'impactScore': 3.6, 'exploitabilityScore': 1.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:41.927', 'references': [{'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'NVD-CWE-noinfo'}]}], 'descriptions': [{'lang': 'en', 'value': 'A consistency issue existed in deciding when to show the screen recording indicator. The issue was resolved with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2. A local user may be able to record the screen without a visible screen recording indicator.'}, {'lang': 'es', 'value': 'Se presentó un problema de coherencia al decidir cuándo mostrar el indicador de grabación de pantalla. El problema fue resuelto con una mejor gestión del estado. Este problema es corregido en iOS versión 13.2 y iPadOS versión 13.2. Un usuario local puede ser capaz de grabar la pantalla sin un indicador de grabación de pantalla visible.'}], 'lastModified': '2026-06-17T02:42:37.650', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AD59FD8B-5C11-469A-91E8-B3EB904AB1EF', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '13864229-C006-4C72-AAE3-90F009375CA5', 'versionEndExcluding': '13.2'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8794
2019-12-18 20:33:24+03:00
2026-06-17 02:42:37.753000+03:00
PUBLISHED
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to read restricted memory.
MEDIUM
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
[{'url': 'https://support.apple.com/HT210721', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210722', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210722', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:20.197198+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210722', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.206Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'watchOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'watchOS 6.1', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210722', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to read restricted memory.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'An application may be able to read restricted memory'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2019-12-18T17:33:24.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'iOS 13.2 and iPadOS 13.2', 'version_affected': '<'}]}, 'product_name': 'iOS'}, {'version': {'version_data': [{'version_value': 'macOS Catalina 10.15.1', 'version_affected': '<'}]}, 'product_name': 'macOS'}, {'version': {'version_data': [{'version_value': 'tvOS 13.2', 'version_affected': '<'}]}, 'product_name': 'tvOS'}, {'version': {'version_data': [{'version_value': 'watchOS 6.1', 'version_affected': '<'}]}, 'product_name': 'watchOS'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210724', 'name': 'https://support.apple.com/HT210724', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210721', 'name': 'https://support.apple.com/HT210721', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210722', 'name': 'https://support.apple.com/HT210722', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210723', 'name': 'https://support.apple.com/HT210723', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to read restricted memory.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'An application may be able to read restricted memory'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8794', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8794', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.206Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:24.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8794', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 4.3, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:P/I:N/A:N', 'authentication': 'NONE', 'integrityImpact': 'NONE', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 3.6, 'exploitabilityScore': 1.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'watchOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'watchOS 6.1', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:42.053', 'references': [{'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210722', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210722', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-20'}]}], 'descriptions': [{'lang': 'en', 'value': 'A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to read restricted memory.'}, {'lang': 'es', 'value': 'Un problema de comprobación fue abordado mejorando el saneamiento de la entrada. Este problema es corregido en iOS versión 13.2 y iPadOS versión 13.2, macOS Catalina versión 10.15.1, tvOS versión 13.2, watchOS versión 6.1. Una aplicación puede ser capaz de leer la memoria restringida.'}], 'lastModified': '2026-06-17T02:42:37.753', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AD59FD8B-5C11-469A-91E8-B3EB904AB1EF', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '13864229-C006-4C72-AAE3-90F009375CA5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E773457A-E670-4DDA-86E2-0923C1DCD9BA', 'versionEndExcluding': '10.15.1'}, {'criteria': 'cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A03A6988-48E4-4108-9A9B-8671BFF4C3A5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '277FA1BB-BB95-49DD-B50C-00F4BEE9DDE1', 'versionEndExcluding': '6.1'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8795
2019-12-18 20:33:23+03:00
2026-06-17 02:42:37.863000+03:00
PUBLISHED
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2. An application may be able to execute arbitrary code with system privileges.
HIGH
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'https://support.apple.com/HT210721', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:20.197198+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.562Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2. An application may be able to execute arbitrary code with system privileges.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'An application may be able to execute arbitrary code with system privileges'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2019-12-18T17:33:23.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'iOS 13.2 and iPadOS 13.2', 'version_affected': '<'}]}, 'product_name': 'iOS'}, {'version': {'version_data': [{'version_value': 'tvOS 13.2', 'version_affected': '<'}]}, 'product_name': 'tvOS'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210721', 'name': 'https://support.apple.com/HT210721', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210723', 'name': 'https://support.apple.com/HT210723', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2. An application may be able to execute arbitrary code with system privileges.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'An application may be able to execute arbitrary code with system privileges'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8795', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8795', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.562Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:23.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8795', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 9.3, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:C/I:C/A:C', 'authentication': 'NONE', 'integrityImpact': 'COMPLETE', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'COMPLETE', 'confidentialityImpact': 'COMPLETE'}, 'acInsufInfo': False, 'impactScore': 10.0, 'baseSeverity': 'HIGH', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 1.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:42.177', 'references': [{'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-787'}]}], 'descriptions': [{'lang': 'en', 'value': 'A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2. An application may be able to execute arbitrary code with system privileges.'}, {'lang': 'es', 'value': 'Un problema de corrupción de memoria fue abordado mejorando el manejo de la memoria. Este problema es corregido en iOS versión 13.2 y iPadOS versión 13.2, tvOS versión 13.2. Una aplicación puede ejecutar código arbitrario con privilegios system.'}], 'lastModified': '2026-06-17T02:42:37.863', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AD59FD8B-5C11-469A-91E8-B3EB904AB1EF', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '13864229-C006-4C72-AAE3-90F009375CA5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A03A6988-48E4-4108-9A9B-8671BFF4C3A5', 'versionEndExcluding': '13.2'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8797
2019-12-18 20:33:24+03:00
2026-06-17 02:42:38.083000+03:00
PUBLISHED
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with system privileges.
HIGH
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'https://support.apple.com/HT210721', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210722', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210722', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:20.197198+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210722', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.450Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'watchOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'watchOS 6.1', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210722', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with system privileges.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'An application may be able to execute arbitrary code with system privileges'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2019-12-18T17:33:24.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'iOS 13.2 and iPadOS 13.2', 'version_affected': '<'}]}, 'product_name': 'iOS'}, {'version': {'version_data': [{'version_value': 'macOS Catalina 10.15.1', 'version_affected': '<'}]}, 'product_name': 'macOS'}, {'version': {'version_data': [{'version_value': 'tvOS 13.2', 'version_affected': '<'}]}, 'product_name': 'tvOS'}, {'version': {'version_data': [{'version_value': 'watchOS 6.1', 'version_affected': '<'}]}, 'product_name': 'watchOS'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210724', 'name': 'https://support.apple.com/HT210724', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210721', 'name': 'https://support.apple.com/HT210721', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210722', 'name': 'https://support.apple.com/HT210722', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210723', 'name': 'https://support.apple.com/HT210723', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with system privileges.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'An application may be able to execute arbitrary code with system privileges'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8797', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8797', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.450Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:24.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8797', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 9.3, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:C/I:C/A:C', 'authentication': 'NONE', 'integrityImpact': 'COMPLETE', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'COMPLETE', 'confidentialityImpact': 'COMPLETE'}, 'acInsufInfo': False, 'impactScore': 10.0, 'baseSeverity': 'HIGH', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 1.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'watchOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'watchOS 6.1', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:42.287', 'references': [{'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210722', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210722', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-787'}]}], 'descriptions': [{'lang': 'en', 'value': 'A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with system privileges.'}, {'lang': 'es', 'value': 'Un problema de corrupción de memoria fue abordado mejorando el manejo de la memoria. Este problema es corregido en iOS versión 13.2 y iPadOS versión 13.2, macOS Catalina versión 10.15.1, tvOS versión 13.2, watchOS versión 6.1. Una aplicación puede ejecutar código arbitrario con privilegios system.'}], 'lastModified': '2026-06-17T02:42:38.083', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AD59FD8B-5C11-469A-91E8-B3EB904AB1EF', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '13864229-C006-4C72-AAE3-90F009375CA5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E773457A-E670-4DDA-86E2-0923C1DCD9BA', 'versionEndExcluding': '10.15.1'}, {'criteria': 'cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A03A6988-48E4-4108-9A9B-8671BFF4C3A5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '277FA1BB-BB95-49DD-B50C-00F4BEE9DDE1', 'versionEndExcluding': '6.1'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8798
2019-12-18 20:33:24+03:00
2026-06-17 02:42:38.183000+03:00
PUBLISHED
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with system privileges.
MEDIUM
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
[{'url': 'https://support.apple.com/HT210721', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210722', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210722', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:20.197198+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210722', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.136Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'watchOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'watchOS 6.1', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210722', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with system privileges.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'An application may be able to execute arbitrary code with system privileges'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2019-12-18T17:33:24.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'iOS 13.2 and iPadOS 13.2', 'version_affected': '<'}]}, 'product_name': 'iOS'}, {'version': {'version_data': [{'version_value': 'macOS Catalina 10.15.1', 'version_affected': '<'}]}, 'product_name': 'macOS'}, {'version': {'version_data': [{'version_value': 'tvOS 13.2', 'version_affected': '<'}]}, 'product_name': 'tvOS'}, {'version': {'version_data': [{'version_value': 'watchOS 6.1', 'version_affected': '<'}]}, 'product_name': 'watchOS'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210724', 'name': 'https://support.apple.com/HT210724', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210721', 'name': 'https://support.apple.com/HT210721', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210722', 'name': 'https://support.apple.com/HT210722', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210723', 'name': 'https://support.apple.com/HT210723', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with system privileges.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'An application may be able to execute arbitrary code with system privileges'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8798', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8798', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.136Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:24.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8798', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 2.1, 'accessVector': 'LOCAL', 'vectorString': 'AV:L/AC:L/Au:N/C:P/I:N/A:N', 'authentication': 'NONE', 'integrityImpact': 'NONE', 'accessComplexity': 'LOW', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'LOW', 'obtainAllPrivilege': False, 'exploitabilityScore': 3.9, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'impactScore': 3.6, 'exploitabilityScore': 1.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'watchOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'watchOS 6.1', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:42.413', 'references': [{'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210722', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210722', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-787'}]}], 'descriptions': [{'lang': 'en', 'value': 'A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with system privileges.'}, {'lang': 'es', 'value': 'Un problema de corrupción de memoria fue abordado mejorando el manejo de la memoria. Este problema es corregido en iOS versión 13.2 y iPadOS versión 13.2, macOS Catalina versión 10.15.1, tvOS versión 13.2, watchOS versión 6.1. Una aplicación puede ejecutar código arbitrario con privilegios system.'}], 'lastModified': '2026-06-17T02:42:38.183', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AD59FD8B-5C11-469A-91E8-B3EB904AB1EF', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '13864229-C006-4C72-AAE3-90F009375CA5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E773457A-E670-4DDA-86E2-0923C1DCD9BA', 'versionEndExcluding': '10.15.1'}, {'criteria': 'cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A03A6988-48E4-4108-9A9B-8671BFF4C3A5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '277FA1BB-BB95-49DD-B50C-00F4BEE9DDE1', 'versionEndExcluding': '6.1'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8800
2019-12-18 20:33:23+03:00
2026-06-17 02:42:38.400000+03:00
PUBLISHED
A memory corruption issue was addressed with improved validation. This issue is fixed in Xcode 11.2. Processing a maliciously crafted file may lead to arbitrary code execution.
HIGH
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'https://support.apple.com/HT210729', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210729', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:20.197198+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210729', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.487Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'Xcode', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Xcode 11.2', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210729', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'A memory corruption issue was addressed with improved validation. This issue is fixed in Xcode 11.2. Processing a maliciously crafted file may lead to arbitrary code execution.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Processing a maliciously crafted file may lead to arbitrary code execution'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2019-12-18T17:33:23.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'Xcode 11.2', 'version_affected': '<'}]}, 'product_name': 'Xcode'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210729', 'name': 'https://support.apple.com/HT210729', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'A memory corruption issue was addressed with improved validation. This issue is fixed in Xcode 11.2. Processing a maliciously crafted file may lead to arbitrary code execution.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Processing a maliciously crafted file may lead to arbitrary code execution'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8800', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8800', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.487Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:23.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8800', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 6.8, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 1.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'Xcode', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Xcode 11.2', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:42.537', 'references': [{'url': 'https://support.apple.com/HT210729', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210729', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-787'}]}], 'descriptions': [{'lang': 'en', 'value': 'A memory corruption issue was addressed with improved validation. This issue is fixed in Xcode 11.2. Processing a maliciously crafted file may lead to arbitrary code execution.'}, {'lang': 'es', 'value': 'Un problema de corrupción de memoria fue abordado con una comprobación mejorada. Este problema es corregido en Xcode versión 11.2. El procesamiento de un archivo diseñado maliciosamente puede conllevar a una ejecución de código arbitrario.'}], 'lastModified': '2026-06-17T02:42:38.400', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:apple:xcode:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'D6CC130E-C550-42B2-AA9C-A1326B30C51F', 'versionEndExcluding': '11.2'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8801
2019-12-18 20:33:23+03:00
2026-06-17 02:42:38.497000+03:00
PUBLISHED
A dynamic library loading issue existed in iTunes setup. This was addressed with improved path searching. This issue is fixed in macOS Catalina 10.15.1, iTunes for Windows 12.10.2. Running the iTunes installer in an untrusted directory may result in arbitrary code execution.
HIGH
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'https://support.apple.com/HT210722', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210722', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:20.197198+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210722', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.015Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210722', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'A dynamic library loading issue existed in iTunes setup. This was addressed with improved path searching. This issue is fixed in macOS Catalina 10.15.1, iTunes for Windows 12.10.2. Running the iTunes installer in an untrusted directory may result in arbitrary code execution.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Running the iTunes installer in an untrusted directory may result in arbitrary code execution'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2019-12-18T17:33:23.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'macOS Catalina 10.15.1', 'version_affected': '<'}]}, 'product_name': 'macOS'}, {'version': {'version_data': [{'version_value': 'iTunes for Windows 12.10.2', 'version_affected': '<'}]}, 'product_name': 'iTunes for Windows'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210722', 'name': 'https://support.apple.com/HT210722', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210726', 'name': 'https://support.apple.com/HT210726', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'A dynamic library loading issue existed in iTunes setup. This was addressed with improved path searching. This issue is fixed in macOS Catalina 10.15.1, iTunes for Windows 12.10.2. Running the iTunes installer in an untrusted directory may result in arbitrary code execution.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Running the iTunes installer in an untrusted directory may result in arbitrary code execution'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8801', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8801', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.015Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:23.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8801', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 4.4, 'accessVector': 'LOCAL', 'vectorString': 'AV:L/AC:M/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 3.4, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 1.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:42.663', 'references': [{'url': 'https://support.apple.com/HT210722', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210722', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-426'}]}], 'descriptions': [{'lang': 'en', 'value': 'A dynamic library loading issue existed in iTunes setup. This was addressed with improved path searching. This issue is fixed in macOS Catalina 10.15.1, iTunes for Windows 12.10.2. Running the iTunes installer in an untrusted directory may result in arbitrary code execution.'}, {'lang': 'es', 'value': 'Un problema de carga dinámica de la biblioteca existía en la configuración de iTunes. Esto fue abordado con una mejor búsqueda de ruta. Este problema es corregido en macOS Catalina versión 10.15.1, iTunes para Windows versión 12.10.2. Ejecutar el instalador de iTunes en un directorio no confiable puede resultar en una ejecución de código arbitrario.'}], 'lastModified': '2026-06-17T02:42:38.497', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': '4A70FE53-CD3F-4296-B209-64C6F24CE3A7', 'versionEndExcluding': '12.10.2'}, {'criteria': 'cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E773457A-E670-4DDA-86E2-0923C1DCD9BA', 'versionEndExcluding': '10.15.1'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8802
2019-12-18 20:33:23+03:00
2026-06-17 02:42:38.593000+03:00
PUBLISHED
A validation issue was addressed with improved logic. This issue is fixed in macOS Catalina 10.15.1. A malicious application may be able to gain root privileges.
HIGH
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'https://support.apple.com/HT210722', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210722', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.773795+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210722', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.150Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15.1', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210722', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'A validation issue was addressed with improved logic. This issue is fixed in macOS Catalina 10.15.1. A malicious application may be able to gain root privileges.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'A malicious application may be able to gain root privileges'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2019-12-18T17:33:23.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'macOS Catalina 10.15.1', 'version_affected': '<'}]}, 'product_name': 'macOS'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210722', 'name': 'https://support.apple.com/HT210722', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'A validation issue was addressed with improved logic. This issue is fixed in macOS Catalina 10.15.1. A malicious application may be able to gain root privileges.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'A malicious application may be able to gain root privileges'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8802', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8802', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.150Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:23.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8802', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 9.3, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:C/I:C/A:C', 'authentication': 'NONE', 'integrityImpact': 'COMPLETE', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'COMPLETE', 'confidentialityImpact': 'COMPLETE'}, 'acInsufInfo': False, 'impactScore': 10.0, 'baseSeverity': 'HIGH', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 1.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15.1', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:42.770', 'references': [{'url': 'https://support.apple.com/HT210722', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210722', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-20'}]}], 'descriptions': [{'lang': 'en', 'value': 'A validation issue was addressed with improved logic. This issue is fixed in macOS Catalina 10.15.1. A malicious application may be able to gain root privileges.'}, {'lang': 'es', 'value': 'Un problema de comprobación fue abordado con una lógica mejorada. Este problema es corregido en macOS Catalina versión 10.15.1. Una aplicación maliciosa puede alcanzar privilegios root.'}], 'lastModified': '2026-06-17T02:42:38.593', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E773457A-E670-4DDA-86E2-0923C1DCD9BA', 'versionEndExcluding': '10.15.1'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8803
2019-12-18 20:33:24+03:00
2026-06-17 02:42:38.693000+03:00
PUBLISHED
An authentication issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. A local attacker may be able to login to the account of a previously logged in user without valid credentials..
HIGH
8.4
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
[{'url': 'https://support.apple.com/HT210721', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210722', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210722', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.773795+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210722', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.374Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'watchOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'watchOS 6.1', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210722', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'An authentication issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. A local attacker may be able to login to the account of a previously logged in user without valid credentials..'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'A local attacker may be able to login to the account of a previously logged in user without valid credentials.'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2019-12-18T17:33:24.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'iOS 13.2 and iPadOS 13.2', 'version_affected': '<'}]}, 'product_name': 'iOS'}, {'version': {'version_data': [{'version_value': 'macOS Catalina 10.15.1', 'version_affected': '<'}]}, 'product_name': 'macOS'}, {'version': {'version_data': [{'version_value': 'tvOS 13.2', 'version_affected': '<'}]}, 'product_name': 'tvOS'}, {'version': {'version_data': [{'version_value': 'watchOS 6.1', 'version_affected': '<'}]}, 'product_name': 'watchOS'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210724', 'name': 'https://support.apple.com/HT210724', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210721', 'name': 'https://support.apple.com/HT210721', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210722', 'name': 'https://support.apple.com/HT210722', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210723', 'name': 'https://support.apple.com/HT210723', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'An authentication issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. A local attacker may be able to login to the account of a previously logged in user without valid credentials..'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'A local attacker may be able to login to the account of a previously logged in user without valid credentials.'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8803', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8803', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.374Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:24.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8803', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 4.6, 'accessVector': 'LOCAL', 'vectorString': 'AV:L/AC:L/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'LOW', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 3.9, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 2.5}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'watchOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'watchOS 6.1', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:42.850', 'references': [{'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210722', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210722', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-613'}]}], 'descriptions': [{'lang': 'en', 'value': 'An authentication issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. A local attacker may be able to login to the account of a previously logged in user without valid credentials..'}, {'lang': 'es', 'value': 'Un problema de autenticación fue abordado con una gestión de estado mejorada. Este problema es corregido en iOS versión 13.2 y iPadOS versión 13.2, macOS Catalina versión 10.15.1, tvOS versión 13.2, watchOS versión 6.1. Un atacante local puede iniciar sesión en la cuenta de un usuario que haya iniciado sesión previamente sin credenciales válidas.'}], 'lastModified': '2026-06-17T02:42:38.693', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AD59FD8B-5C11-469A-91E8-B3EB904AB1EF', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '13864229-C006-4C72-AAE3-90F009375CA5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E773457A-E670-4DDA-86E2-0923C1DCD9BA', 'versionEndExcluding': '10.15.1'}, {'criteria': 'cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A03A6988-48E4-4108-9A9B-8671BFF4C3A5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '277FA1BB-BB95-49DD-B50C-00F4BEE9DDE1', 'versionEndExcluding': '6.1'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8804
2019-12-18 20:33:23+03:00
2026-06-17 02:42:38.800000+03:00
PUBLISHED
An inconsistency in Wi-Fi network configuration settings was addressed. This issue is fixed in iOS 13.2 and iPadOS 13.2. An attacker in physical proximity may be able to force a user onto a malicious Wi-Fi network during device setup.
MEDIUM
5.7
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
[{'url': 'https://support.apple.com/HT210721', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.773795+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.475Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'An inconsistency in Wi-Fi network configuration settings was addressed. This issue is fixed in iOS 13.2 and iPadOS 13.2. An attacker in physical proximity may be able to force a user onto a malicious Wi-Fi network during device setup.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'An attacker in physical proximity may be able to force a user onto a malicious Wi-Fi network during device setup'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2019-12-18T17:33:23.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'iOS 13.2 and iPadOS 13.2', 'version_affected': '<'}]}, 'product_name': 'iOS'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210721', 'name': 'https://support.apple.com/HT210721', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'An inconsistency in Wi-Fi network configuration settings was addressed. This issue is fixed in iOS 13.2 and iPadOS 13.2. An attacker in physical proximity may be able to force a user onto a malicious Wi-Fi network during device setup.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'An attacker in physical proximity may be able to force a user onto a malicious Wi-Fi network during device setup'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8804', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8804', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.475Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:23.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8804', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 2.9, 'accessVector': 'ADJACENT_NETWORK', 'vectorString': 'AV:A/AC:M/Au:N/C:N/I:P/A:N', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'NONE'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'LOW', 'obtainAllPrivilege': False, 'exploitabilityScore': 5.5, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.7, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}, 'impactScore': 3.6, 'exploitabilityScore': 2.1}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:42.977', 'references': [{'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-287'}]}], 'descriptions': [{'lang': 'en', 'value': 'An inconsistency in Wi-Fi network configuration settings was addressed. This issue is fixed in iOS 13.2 and iPadOS 13.2. An attacker in physical proximity may be able to force a user onto a malicious Wi-Fi network during device setup.'}, {'lang': 'es', 'value': 'Una inconsistencia fue abordada en los ajustes de configuración de la red Wi-Fi. Este problema es corregido en iOS versión 13.2 y iPadOS versión 13.2. Un atacante en proximidad física puede ser capaz de forzar a un usuario sobre una red Wi-Fi maliciosa durante la configuración del dispositivo.'}], 'lastModified': '2026-06-17T02:42:38.800', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '2EDBE557-B798-4432-990E-AFB9596A4AB4', 'versionEndIncluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '13864229-C006-4C72-AAE3-90F009375CA5', 'versionEndExcluding': '13.2'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8805
2019-12-18 20:33:23+03:00
2026-06-17 02:42:38.907000+03:00
PUBLISHED
A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in macOS Catalina 10.15.1. An application may be able to execute arbitrary code with system privileges.
HIGH
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'https://support.apple.com/HT210722', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210722', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:20.197198+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210722', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.448Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15.1', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210722', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in macOS Catalina 10.15.1. An application may be able to execute arbitrary code with system privileges.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'An application may be able to execute arbitrary code with system privileges'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2019-12-18T17:33:23.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'macOS Catalina 10.15.1', 'version_affected': '<'}]}, 'product_name': 'macOS'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210722', 'name': 'https://support.apple.com/HT210722', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in macOS Catalina 10.15.1. An application may be able to execute arbitrary code with system privileges.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'An application may be able to execute arbitrary code with system privileges'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8805', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8805', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.448Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:23.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8805', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 9.3, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:C/I:C/A:C', 'authentication': 'NONE', 'integrityImpact': 'COMPLETE', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'COMPLETE', 'confidentialityImpact': 'COMPLETE'}, 'acInsufInfo': False, 'impactScore': 10.0, 'baseSeverity': 'HIGH', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 1.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15.1', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:43.083', 'references': [{'url': 'https://support.apple.com/HT210722', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210722', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'NVD-CWE-noinfo'}]}], 'descriptions': [{'lang': 'en', 'value': 'A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in macOS Catalina 10.15.1. An application may be able to execute arbitrary code with system privileges.'}, {'lang': 'es', 'value': 'Se presentó un problema de comprobación en la verificación de derechos. Este problema fue abordado con una comprobación mejorada de los derechos del proceso. Este problema es corregido en macOS Catalina versión 10.15.1. Una aplicación puede ejecutar código arbitrario con privilegios system.'}], 'lastModified': '2026-06-17T02:42:38.907', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E773457A-E670-4DDA-86E2-0923C1DCD9BA', 'versionEndExcluding': '10.15.1'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8806
2019-12-18 20:33:23+03:00
2026-06-17 02:42:39.007000+03:00
PUBLISHED
A memory corruption issue was addressed with improved validation. This issue is fixed in Xcode 11.2. Processing a maliciously crafted file may lead to arbitrary code execution.
HIGH
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'https://support.apple.com/HT210729', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210729', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.773795+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210729', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.470Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'Xcode', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Xcode 11.2', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210729', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'A memory corruption issue was addressed with improved validation. This issue is fixed in Xcode 11.2. Processing a maliciously crafted file may lead to arbitrary code execution.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Processing a maliciously crafted file may lead to arbitrary code execution'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2019-12-18T17:33:23.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'Xcode 11.2', 'version_affected': '<'}]}, 'product_name': 'Xcode'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210729', 'name': 'https://support.apple.com/HT210729', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'A memory corruption issue was addressed with improved validation. This issue is fixed in Xcode 11.2. Processing a maliciously crafted file may lead to arbitrary code execution.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Processing a maliciously crafted file may lead to arbitrary code execution'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8806', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8806', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.470Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:23.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8806', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 6.8, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 1.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'Xcode', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Xcode 11.2', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:43.210', 'references': [{'url': 'https://support.apple.com/HT210729', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210729', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-787'}]}], 'descriptions': [{'lang': 'en', 'value': 'A memory corruption issue was addressed with improved validation. This issue is fixed in Xcode 11.2. Processing a maliciously crafted file may lead to arbitrary code execution.'}, {'lang': 'es', 'value': 'Un problema de corrupción de memoria fue abordado con una comprobación mejorada. Este problema es corregido en Xcode 11.2. El procesamiento de un archivo diseñado maliciosamente puede conllevar a una ejecución de código arbitrario.'}], 'lastModified': '2026-06-17T02:42:39.007', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:apple:xcode:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'D6CC130E-C550-42B2-AA9C-A1326B30C51F', 'versionEndExcluding': '11.2'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8807
2019-12-18 20:33:23+03:00
2026-06-17 02:42:39.107000+03:00
PUBLISHED
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.1. An application may be able to execute arbitrary code with system privileges.
HIGH
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'https://support.apple.com/HT210722', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210722', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.773795+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210722', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.011Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15.1', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210722', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.1. An application may be able to execute arbitrary code with system privileges.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'An application may be able to execute arbitrary code with system privileges'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2019-12-18T17:33:23.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'macOS Catalina 10.15.1', 'version_affected': '<'}]}, 'product_name': 'macOS'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210722', 'name': 'https://support.apple.com/HT210722', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.1. An application may be able to execute arbitrary code with system privileges.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'An application may be able to execute arbitrary code with system privileges'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8807', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8807', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.011Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:23.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8807', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 9.3, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:C/I:C/A:C', 'authentication': 'NONE', 'integrityImpact': 'COMPLETE', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'COMPLETE', 'confidentialityImpact': 'COMPLETE'}, 'acInsufInfo': False, 'impactScore': 10.0, 'baseSeverity': 'HIGH', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 1.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15.1', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:43.333', 'references': [{'url': 'https://support.apple.com/HT210722', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210722', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-787'}]}], 'descriptions': [{'lang': 'en', 'value': 'A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.1. An application may be able to execute arbitrary code with system privileges.'}, {'lang': 'es', 'value': 'Un problema de corrupción de memoria fue abordado mejorando el manejo de la memoria. Este problema es corregido en macOS Catalina versión 10.15.1. Una aplicación puede ejecutar código arbitrario con privilegios system.'}], 'lastModified': '2026-06-17T02:42:39.107', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E773457A-E670-4DDA-86E2-0923C1DCD9BA', 'versionEndExcluding': '10.15.1'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8808
2019-12-18 20:33:24+03:00
2026-06-17 02:42:39.210000+03:00
PUBLISHED
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2. Processing maliciously crafted web content may lead to arbitrary code execution.
HIGH
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210725', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210721', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210725', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.773795+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210725', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.255Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'watchOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'watchOS 6.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Safari', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Safari 13.0.3', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210725', 'tags': ['x_refsource_MISC']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2. Processing maliciously crafted web content may lead to arbitrary code execution.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2020-03-15T06:06:08.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'iOS 13.2 and iPadOS 13.2', 'version_affected': '<'}]}, 'product_name': 'iOS'}, {'version': {'version_data': [{'version_value': 'tvOS 13.2', 'version_affected': '<'}]}, 'product_name': 'tvOS'}, {'version': {'version_data': [{'version_value': 'watchOS 6.1', 'version_affected': '<'}]}, 'product_name': 'watchOS'}, {'version': {'version_data': [{'version_value': 'Safari 13.0.3', 'version_affected': '<'}]}, 'product_name': 'Safari'}, {'version': {'version_data': [{'version_value': 'iTunes for Windows 12.10.2', 'version_affected': '<'}]}, 'product_name': 'iTunes for Windows'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210724', 'name': 'https://support.apple.com/HT210724', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210721', 'name': 'https://support.apple.com/HT210721', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210726', 'name': 'https://support.apple.com/HT210726', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210723', 'name': 'https://support.apple.com/HT210723', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210725', 'name': 'https://support.apple.com/HT210725', 'refsource': 'MISC'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'refsource': 'GENTOO'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2. Processing maliciously crafted web content may lead to arbitrary code execution.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8808', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8808', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.255Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:24.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8808', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 6.8, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'watchOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'watchOS 6.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Safari', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Safari 13.0.3', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:43.460', 'references': [{'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210725', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210725', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-787'}]}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2. Processing maliciously crafted web content may lead to arbitrary code execution.'}, {'lang': 'es', 'value': 'Múltiples problemas de corrupción de memoria fueron abordados mejorando el manejo de la memoria. Este problema es corregido en iOS versión 13.2 y iPadOS versión 13.2, tvOS versión 13.2, watchOS versión 6.1, Safari versión 13.0.3, iTunes para Windows versión 12.10.2. El procesamiento de contenido web diseñado maliciosamente puede conllevar a una ejecución de código arbitrario.'}], 'lastModified': '2026-06-17T02:42:39.210', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': '4A70FE53-CD3F-4296-B209-64C6F24CE3A7', 'versionEndExcluding': '12.10.2'}, {'criteria': 'cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '9DD4F307-7772-4B9B-8C77-E445EA39ADB8', 'versionEndExcluding': '13.0.3'}, {'criteria': 'cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AD59FD8B-5C11-469A-91E8-B3EB904AB1EF', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '13864229-C006-4C72-AAE3-90F009375CA5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A03A6988-48E4-4108-9A9B-8671BFF4C3A5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '277FA1BB-BB95-49DD-B50C-00F4BEE9DDE1', 'versionEndExcluding': '6.1'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2026-46130
2026-05-28 12:35:45.387000+03:00
2026-06-14 20:56:41.180000+03:00
PUBLISHED
In the Linux kernel, the following vulnerability has been resolved: dm-verity-fec: fix reading parity bytes split across blocks (take 3) fec_decode_bufs() assumes that the parity bytes of the first RS codeword it decodes are never split across parity blocks. This assumption is false. Consider v->fec->block_size == 4096 && v->fec->roots == 17 && fio->nbufs == 1, for example. In that case, each call to fec_decode_bufs() consumes v->fec->roots * (fio->nbufs << DM_VERITY_FEC_BUF_RS_BITS) = 272 parity bytes. Considering that the parity data for each message block starts on a block boundary, the byte alignment in the parity data will iterate through 272*i mod 4096 until the 3 parity blocks have been consumed. On the 16th call (i=15), the alignment will be 4080 bytes into the first block. Only 16 bytes remain in that block, but 17 parity bytes will be needed. The code reads out-of-bounds from the parity block buffer. Fortunately this doesn't normally happen, since it can occur only for certain non-default values of fec_roots *and* when the maximum number of buffers couldn't be allocated due to low memory. For example with block_size=4096 only the following cases are affected: fec_roots=17: nbufs in [1, 3, 5, 15] fec_roots=19: nbufs in [1, 229] fec_roots=21: nbufs in [1, 3, 5, 13, 15, 39, 65, 195] fec_roots=23: nbufs in [1, 89] Regardless, fix it by refactoring how the parity blocks are read.
[{'url': 'https://git.kernel.org/stable/c/3d1b4e2d8ac0a1a1390a117f61ce0ca1c47e3bcb'}, {'url': 'https://git.kernel.org/stable/c/430a05cb926f6bdf53e81460a2c3a553257f3f61'}]
cve.org
2026-05-28 14:30:04.458386+03:00
2026-06-14 22:44:46.870750+03:00
{'dataType': 'CVE_RECORD', 'containers': {'cna': {'title': 'dm-verity-fec: fix reading parity bytes split across blocks (take 3)', 'affected': [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6df90c02bae468a3a6110bafbc659884d0c4966c', 'lessThan': '3d1b4e2d8ac0a1a1390a117f61ce0ca1c47e3bcb', 'versionType': 'git'}, {'status': 'affected', 'version': '6df90c02bae468a3a6110bafbc659884d0c4966c', 'lessThan': '430a05cb926f6bdf53e81460a2c3a553257f3f61', 'versionType': 'git'}, {'status': 'affected', 'version': '6bc6ee31113b05db605694491bdeb2b1730142f1', 'versionType': 'git'}, {'status': 'affected', 'version': '12caa73a28f0ae147ec0356b45091edf2462462b', 'versionType': 'git'}, {'status': 'affected', 'version': 'fc8943886629e26de34867db302c74d465510826', 'versionType': 'git'}, {'status': 'affected', 'version': '6.1.125', 'lessThan': '6.2', 'versionType': 'semver'}, {'status': 'affected', 'version': '6.6.72', 'lessThan': '6.7', 'versionType': 'semver'}, {'status': 'affected', 'version': '6.12.10', 'lessThan': '6.13', 'versionType': 'semver'}], 'programFiles': ['drivers/md/dm-verity-fec.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.13'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.13', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '7.0.7', 'versionType': 'semver', 'lessThanOrEqual': '7.0.*'}, {'status': 'unaffected', 'version': '7.1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/md/dm-verity-fec.c'], 'defaultStatus': 'affected'}], 'references': [{'url': 'https://git.kernel.org/stable/c/3d1b4e2d8ac0a1a1390a117f61ce0ca1c47e3bcb'}, {'url': 'https://git.kernel.org/stable/c/430a05cb926f6bdf53e81460a2c3a553257f3f61'}], 'x_generator': {'engine': 'bippy-1.2.0'}, 'descriptions': [{'lang': 'en', 'value': "In the Linux kernel, the following vulnerability has been resolved:\n\ndm-verity-fec: fix reading parity bytes split across blocks (take 3)\n\nfec_decode_bufs() assumes that the parity bytes of the first RS codeword\nit decodes are never split across parity blocks.\n\nThis assumption is false. Consider v->fec->block_size == 4096 &&\nv->fec->roots == 17 && fio->nbufs == 1, for example. In that case, each\ncall to fec_decode_bufs() consumes v->fec->roots * (fio->nbufs <<\nDM_VERITY_FEC_BUF_RS_BITS) = 272 parity bytes.\n\nConsidering that the parity data for each message block starts on a\nblock boundary, the byte alignment in the parity data will iterate\nthrough 272*i mod 4096 until the 3 parity blocks have been consumed. On\nthe 16th call (i=15), the alignment will be 4080 bytes into the first\nblock. Only 16 bytes remain in that block, but 17 parity bytes will be\nneeded. The code reads out-of-bounds from the parity block buffer.\n\nFortunately this doesn't normally happen, since it can occur only for\ncertain non-default values of fec_roots *and* when the maximum number of\nbuffers couldn't be allocated due to low memory. For example with\nblock_size=4096 only the following cases are affected:\n\n fec_roots=17: nbufs in [1, 3, 5, 15]\n fec_roots=19: nbufs in [1, 229]\n fec_roots=21: nbufs in [1, 3, 5, 13, 15, 39, 65, 195]\n fec_roots=23: nbufs in [1, 89]\n\nRegardless, fix it by refactoring how the parity blocks are read."}], 'cpeApplicability': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*', 'vulnerable': True, 'versionEndExcluding': '7.0.7', 'versionStartIncluding': '6.13'}, {'criteria': 'cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*', 'vulnerable': True, 'versionEndExcluding': '7.1', 'versionStartIncluding': '6.13'}, {'criteria': 'cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*', 'vulnerable': True, 'versionStartIncluding': '6.1.125'}, {'criteria': 'cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*', 'vulnerable': True, 'versionStartIncluding': '6.6.72'}, {'criteria': 'cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*', 'vulnerable': True, 'versionStartIncluding': '6.12.10'}], 'operator': 'OR'}]}], 'providerMetadata': {'orgId': '416baaa9-dc9f-4396-8d5f-8c081fb06d67', 'shortName': 'Linux', 'dateUpdated': '2026-06-14T17:56:41.180Z'}}}, 'cveMetadata': {'cveId': 'CVE-2026-46130', 'state': 'PUBLISHED', 'dateUpdated': '2026-06-14T17:56:41.180Z', 'dateReserved': '2026-05-13T15:03:33.099Z', 'assignerOrgId': '416baaa9-dc9f-4396-8d5f-8c081fb06d67', 'datePublished': '2026-05-28T09:35:45.387Z', 'assignerShortName': 'Linux'}, 'dataVersion': '5.2'}
{'id': 'CVE-2026-46130', 'cveTags': [], 'metrics': {}, 'published': '2026-05-28T10:16:28.570', 'references': [{'url': 'https://git.kernel.org/stable/c/3d1b4e2d8ac0a1a1390a117f61ce0ca1c47e3bcb', 'source': '416baaa9-dc9f-4396-8d5f-8c081fb06d67'}, {'url': 'https://git.kernel.org/stable/c/430a05cb926f6bdf53e81460a2c3a553257f3f61', 'source': '416baaa9-dc9f-4396-8d5f-8c081fb06d67'}], 'vulnStatus': 'Awaiting Analysis', 'descriptions': [{'lang': 'en', 'value': "In the Linux kernel, the following vulnerability has been resolved:\n\ndm-verity-fec: fix reading parity bytes split across blocks (take 3)\n\nfec_decode_bufs() assumes that the parity bytes of the first RS codeword\nit decodes are never split across parity blocks.\n\nThis assumption is false. Consider v->fec->block_size == 4096 &&\nv->fec->roots == 17 && fio->nbufs == 1, for example. In that case, each\ncall to fec_decode_bufs() consumes v->fec->roots * (fio->nbufs <<\nDM_VERITY_FEC_BUF_RS_BITS) = 272 parity bytes.\n\nConsidering that the parity data for each message block starts on a\nblock boundary, the byte alignment in the parity data will iterate\nthrough 272*i mod 4096 until the 3 parity blocks have been consumed. On\nthe 16th call (i=15), the alignment will be 4080 bytes into the first\nblock. Only 16 bytes remain in that block, but 17 parity bytes will be\nneeded. The code reads out-of-bounds from the parity block buffer.\n\nFortunately this doesn't normally happen, since it can occur only for\ncertain non-default values of fec_roots *and* when the maximum number of\nbuffers couldn't be allocated due to low memory. For example with\nblock_size=4096 only the following cases are affected:\n\n fec_roots=17: nbufs in [1, 3, 5, 15]\n fec_roots=19: nbufs in [1, 229]\n fec_roots=21: nbufs in [1, 3, 5, 13, 15, 39, 65, 195]\n fec_roots=23: nbufs in [1, 89]\n\nRegardless, fix it by refactoring how the parity blocks are read."}], 'lastModified': '2026-05-28T13:44:01.663', 'sourceIdentifier': '416baaa9-dc9f-4396-8d5f-8c081fb06d67'}
CVE-2019-8811
2019-12-18 20:33:24+03:00
2026-06-17 02:42:39.440000+03:00
PUBLISHED
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.
HIGH
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210725', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210727', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210728', 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210721', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210725', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210727', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210728', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.773795+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210727', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210728', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210725', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.061Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'watchOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'watchOS 6.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Safari', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Safari 13.0.3', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 11.0', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows (Legacy)', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 7.15', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210727', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210728', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210725', 'tags': ['x_refsource_MISC']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2020-03-15T06:06:30.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'iOS 13.2 and iPadOS 13.2', 'version_affected': '<'}]}, 'product_name': 'iOS'}, {'version': {'version_data': [{'version_value': 'tvOS 13.2', 'version_affected': '<'}]}, 'product_name': 'tvOS'}, {'version': {'version_data': [{'version_value': 'watchOS 6.1', 'version_affected': '<'}]}, 'product_name': 'watchOS'}, {'version': {'version_data': [{'version_value': 'Safari 13.0.3', 'version_affected': '<'}]}, 'product_name': 'Safari'}, {'version': {'version_data': [{'version_value': 'iTunes for Windows 12.10.2', 'version_affected': '<'}]}, 'product_name': 'iTunes for Windows'}, {'version': {'version_data': [{'version_value': 'iCloud for Windows 11.0', 'version_affected': '<'}]}, 'product_name': 'iCloud for Windows'}, {'version': {'version_data': [{'version_value': 'iCloud for Windows 7.15', 'version_affected': '<'}]}, 'product_name': 'iCloud for Windows (Legacy)'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210724', 'name': 'https://support.apple.com/HT210724', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210727', 'name': 'https://support.apple.com/HT210727', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210721', 'name': 'https://support.apple.com/HT210721', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210726', 'name': 'https://support.apple.com/HT210726', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210723', 'name': 'https://support.apple.com/HT210723', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210728', 'name': 'https://support.apple.com/HT210728', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210725', 'name': 'https://support.apple.com/HT210725', 'refsource': 'MISC'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'refsource': 'GENTOO'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8811', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8811', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.061Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:24.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8811', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 6.8, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'watchOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'watchOS 6.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Safari', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Safari 13.0.3', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 11.0', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows (Legacy)', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 7.15', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:43.583', 'references': [{'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210725', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210727', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210728', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210725', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210727', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210728', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-787'}]}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.'}, {'lang': 'es', 'value': 'Múltiples problemas de corrupción de memoria fueron abordados mejorando el manejo de la memoria. Este problema es corregido en iOS versión 13.2 y iPadOS versión 13.2, tvOS versión 13.2, watchOS versión 6.1, Safari versión 13.0.3, iTunes para Windows versión 12.10.2, iCloud para Windows versión 11.0, iCloud para Windows versión 7.15. El procesamiento de contenido web diseñado maliciosamente puede conllevar a una ejecución de código arbitrario.'}], 'lastModified': '2026-06-17T02:42:39.440', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': 'B730AB98-7AF7-4F18-BEB4-AEE484D2586B', 'versionEndExcluding': '7.15'}, {'criteria': 'cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': '40795999-C39E-4D39-A734-70EDCF0D11A7', 'versionEndIncluding': '10.4', 'versionStartIncluding': '10.0'}, {'criteria': 'cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': '4A70FE53-CD3F-4296-B209-64C6F24CE3A7', 'versionEndExcluding': '12.10.2'}, {'criteria': 'cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '9DD4F307-7772-4B9B-8C77-E445EA39ADB8', 'versionEndExcluding': '13.0.3'}, {'criteria': 'cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AD59FD8B-5C11-469A-91E8-B3EB904AB1EF', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '13864229-C006-4C72-AAE3-90F009375CA5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A03A6988-48E4-4108-9A9B-8671BFF4C3A5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '277FA1BB-BB95-49DD-B50C-00F4BEE9DDE1', 'versionEndExcluding': '6.1'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8812
2019-12-18 20:33:24+03:00
2026-06-17 02:42:39.573000+03:00
PUBLISHED
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2. Processing maliciously crafted web content may lead to arbitrary code execution.
HIGH
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210725', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210721', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210725', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:20.197198+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210725', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.250Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'watchOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'watchOS 6.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Safari', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Safari 13.0.3', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210725', 'tags': ['x_refsource_MISC']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2. Processing maliciously crafted web content may lead to arbitrary code execution.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2020-03-15T06:06:23.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'iOS 13.2 and iPadOS 13.2', 'version_affected': '<'}]}, 'product_name': 'iOS'}, {'version': {'version_data': [{'version_value': 'tvOS 13.2', 'version_affected': '<'}]}, 'product_name': 'tvOS'}, {'version': {'version_data': [{'version_value': 'watchOS 6.1', 'version_affected': '<'}]}, 'product_name': 'watchOS'}, {'version': {'version_data': [{'version_value': 'Safari 13.0.3', 'version_affected': '<'}]}, 'product_name': 'Safari'}, {'version': {'version_data': [{'version_value': 'iTunes for Windows 12.10.2', 'version_affected': '<'}]}, 'product_name': 'iTunes for Windows'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210724', 'name': 'https://support.apple.com/HT210724', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210721', 'name': 'https://support.apple.com/HT210721', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210726', 'name': 'https://support.apple.com/HT210726', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210723', 'name': 'https://support.apple.com/HT210723', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210725', 'name': 'https://support.apple.com/HT210725', 'refsource': 'MISC'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'refsource': 'GENTOO'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2. Processing maliciously crafted web content may lead to arbitrary code execution.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8812', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8812', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.250Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:24.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8812', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 6.8, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'watchOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'watchOS 6.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Safari', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Safari 13.0.3', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:43.740', 'references': [{'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210725', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210725', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-787'}]}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2. Processing maliciously crafted web content may lead to arbitrary code execution.'}, {'lang': 'es', 'value': 'Múltiples problemas de corrupción de memoria fueron abordados mejorando el manejo de la memoria. Este problema es corregido en iOS versión 13.2 y iPadOS versión 13.2, tvOS versión 13.2, watchOS versión 6.1, Safari versión 13.0.3, iTunes para Windows versión 12.10.2. El procesamiento de contenido web diseñado maliciosamente puede conllevar a una ejecución de código arbitrario.'}], 'lastModified': '2026-06-17T02:42:39.573', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': '4A70FE53-CD3F-4296-B209-64C6F24CE3A7', 'versionEndExcluding': '12.10.2'}, {'criteria': 'cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '9DD4F307-7772-4B9B-8C77-E445EA39ADB8', 'versionEndExcluding': '13.0.3'}, {'criteria': 'cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AD59FD8B-5C11-469A-91E8-B3EB904AB1EF', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '13864229-C006-4C72-AAE3-90F009375CA5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A03A6988-48E4-4108-9A9B-8671BFF4C3A5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '277FA1BB-BB95-49DD-B50C-00F4BEE9DDE1', 'versionEndExcluding': '6.1'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8813
2019-12-18 20:33:24+03:00
2026-06-17 02:42:39.693000+03:00
PUBLISHED
A logic issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to universal cross site scripting.
MEDIUM
6.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
[{'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210725', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210727', 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210721', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210725', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210727', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.773795+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210727', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210725', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.235Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Safari', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Safari 13.0.3', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 11.0', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210727', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210725', 'tags': ['x_refsource_MISC']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}], 'descriptions': [{'lang': 'en', 'value': 'A logic issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to universal cross site scripting.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Processing maliciously crafted web content may lead to universal cross site scripting'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2020-03-15T06:06:25.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'iOS 13.2 and iPadOS 13.2', 'version_affected': '<'}]}, 'product_name': 'iOS'}, {'version': {'version_data': [{'version_value': 'tvOS 13.2', 'version_affected': '<'}]}, 'product_name': 'tvOS'}, {'version': {'version_data': [{'version_value': 'Safari 13.0.3', 'version_affected': '<'}]}, 'product_name': 'Safari'}, {'version': {'version_data': [{'version_value': 'iTunes for Windows 12.10.2', 'version_affected': '<'}]}, 'product_name': 'iTunes for Windows'}, {'version': {'version_data': [{'version_value': 'iCloud for Windows 11.0', 'version_affected': '<'}]}, 'product_name': 'iCloud for Windows'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210727', 'name': 'https://support.apple.com/HT210727', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210721', 'name': 'https://support.apple.com/HT210721', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210726', 'name': 'https://support.apple.com/HT210726', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210723', 'name': 'https://support.apple.com/HT210723', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210725', 'name': 'https://support.apple.com/HT210725', 'refsource': 'MISC'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'refsource': 'GENTOO'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'A logic issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to universal cross site scripting.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Processing maliciously crafted web content may lead to universal cross site scripting'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8813', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8813', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.235Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:24.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8813', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 4.3, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:N/I:P/A:N', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'NONE'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 6.1, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N', 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}, 'impactScore': 2.7, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Safari', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Safari 13.0.3', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 11.0', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:43.867', 'references': [{'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210725', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210727', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210725', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210727', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-79'}]}], 'descriptions': [{'lang': 'en', 'value': 'A logic issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to universal cross site scripting.'}, {'lang': 'es', 'value': 'Un problema lógico fue abordado mejorando la gestión del estado. Este problema es corregido en iOS versión 13.2 y iPadOS versión 13.2, tvOS versión 13.2, Safari versión 13.0.3, iTunes para Windows versión 12.10.2, iCloud para Windows versión 11.0. El procesamiento de contenido web diseñado maliciosamente puede conllevar a un ataque de tipo cross site scripting universal.'}], 'lastModified': '2026-06-17T02:42:39.693', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': '156D40D5-B2E9-44E3-B899-FA246C320939', 'versionEndExcluding': '10.8'}, {'criteria': 'cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': '4A70FE53-CD3F-4296-B209-64C6F24CE3A7', 'versionEndExcluding': '12.10.2'}, {'criteria': 'cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '9DD4F307-7772-4B9B-8C77-E445EA39ADB8', 'versionEndExcluding': '13.0.3'}, {'criteria': 'cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AD59FD8B-5C11-469A-91E8-B3EB904AB1EF', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '13864229-C006-4C72-AAE3-90F009375CA5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A03A6988-48E4-4108-9A9B-8671BFF4C3A5', 'versionEndExcluding': '13.2'}], 'operator': 'OR'}]}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:webkitgtk:webkitgtk\\+:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '2B5A34D4-70EC-43A8-8C46-6FF6361540EE', 'versionEndExcluding': '2.26.4'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8814
2019-12-18 20:33:24+03:00
2026-06-17 02:42:39.810000+03:00
PUBLISHED
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.
HIGH
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210725', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210727', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210728', 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210721', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210725', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210727', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210728', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.773795+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210727', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210728', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210725', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.036Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Safari', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Safari 13.0.3', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 11.0', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows (Legacy)', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 7.15', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210727', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210728', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210725', 'tags': ['x_refsource_MISC']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2020-03-15T06:06:09.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'iOS 13.2 and iPadOS 13.2', 'version_affected': '<'}]}, 'product_name': 'iOS'}, {'version': {'version_data': [{'version_value': 'tvOS 13.2', 'version_affected': '<'}]}, 'product_name': 'tvOS'}, {'version': {'version_data': [{'version_value': 'Safari 13.0.3', 'version_affected': '<'}]}, 'product_name': 'Safari'}, {'version': {'version_data': [{'version_value': 'iTunes for Windows 12.10.2', 'version_affected': '<'}]}, 'product_name': 'iTunes for Windows'}, {'version': {'version_data': [{'version_value': 'iCloud for Windows 11.0', 'version_affected': '<'}]}, 'product_name': 'iCloud for Windows'}, {'version': {'version_data': [{'version_value': 'iCloud for Windows 7.15', 'version_affected': '<'}]}, 'product_name': 'iCloud for Windows (Legacy)'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210727', 'name': 'https://support.apple.com/HT210727', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210721', 'name': 'https://support.apple.com/HT210721', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210726', 'name': 'https://support.apple.com/HT210726', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210723', 'name': 'https://support.apple.com/HT210723', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210728', 'name': 'https://support.apple.com/HT210728', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210725', 'name': 'https://support.apple.com/HT210725', 'refsource': 'MISC'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'refsource': 'GENTOO'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8814', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8814', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.036Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:24.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8814', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 9.3, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:C/I:C/A:C', 'authentication': 'NONE', 'integrityImpact': 'COMPLETE', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'COMPLETE', 'confidentialityImpact': 'COMPLETE'}, 'acInsufInfo': False, 'impactScore': 10.0, 'baseSeverity': 'HIGH', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Safari', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Safari 13.0.3', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 11.0', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows (Legacy)', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 7.15', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:43.990', 'references': [{'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210725', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210727', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210728', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210725', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210727', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210728', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-787'}]}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.'}, {'lang': 'es', 'value': 'Múltiples problemas de corrupción de memoria fueron abordados mejorando el manejo de la memoria. Este problema es corregido en iOS versión 13.2 y iPadOS versión 13.2, tvOS versión 13.2, Safari versión 13.0.3, iTunes para Windows versión 12.10.2, iCloud para Windows versión 11.0, iCloud para Windows versión 7.15. El procesamiento de contenido web diseñado maliciosamente puede conllevar a una ejecución de código arbitrario.'}], 'lastModified': '2026-06-17T02:42:39.810', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': 'B730AB98-7AF7-4F18-BEB4-AEE484D2586B', 'versionEndExcluding': '7.15'}, {'criteria': 'cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': '40795999-C39E-4D39-A734-70EDCF0D11A7', 'versionEndIncluding': '10.4', 'versionStartIncluding': '10.0'}, {'criteria': 'cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': '4A70FE53-CD3F-4296-B209-64C6F24CE3A7', 'versionEndExcluding': '12.10.2'}, {'criteria': 'cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '9DD4F307-7772-4B9B-8C77-E445EA39ADB8', 'versionEndExcluding': '13.0.3'}, {'criteria': 'cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AD59FD8B-5C11-469A-91E8-B3EB904AB1EF', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '13864229-C006-4C72-AAE3-90F009375CA5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A03A6988-48E4-4108-9A9B-8671BFF4C3A5', 'versionEndExcluding': '13.2'}], 'operator': 'OR'}]}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '33C068A4-3780-4EAB-A937-6082DF847564'}, {'criteria': 'cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '51EF4996-72F4-4FA4-814F-F5991E7A8318'}, {'criteria': 'cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '825ECE2D-E232-46E0-A047-074B34DB1E97'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8815
2019-12-18 20:33:24+03:00
2026-06-17 02:42:39.937000+03:00
PUBLISHED
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.
HIGH
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210725', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210727', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210728', 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210721', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210725', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210727', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210728', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.773795+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210727', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210728', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210725', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.471Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Safari', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Safari 13.0.3', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 11.0', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows (Legacy)', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 7.15', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210727', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210728', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210725', 'tags': ['x_refsource_MISC']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2020-03-15T06:06:26.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'iOS 13.2 and iPadOS 13.2', 'version_affected': '<'}]}, 'product_name': 'iOS'}, {'version': {'version_data': [{'version_value': 'tvOS 13.2', 'version_affected': '<'}]}, 'product_name': 'tvOS'}, {'version': {'version_data': [{'version_value': 'Safari 13.0.3', 'version_affected': '<'}]}, 'product_name': 'Safari'}, {'version': {'version_data': [{'version_value': 'iTunes for Windows 12.10.2', 'version_affected': '<'}]}, 'product_name': 'iTunes for Windows'}, {'version': {'version_data': [{'version_value': 'iCloud for Windows 11.0', 'version_affected': '<'}]}, 'product_name': 'iCloud for Windows'}, {'version': {'version_data': [{'version_value': 'iCloud for Windows 7.15', 'version_affected': '<'}]}, 'product_name': 'iCloud for Windows (Legacy)'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210727', 'name': 'https://support.apple.com/HT210727', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210721', 'name': 'https://support.apple.com/HT210721', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210726', 'name': 'https://support.apple.com/HT210726', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210723', 'name': 'https://support.apple.com/HT210723', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210728', 'name': 'https://support.apple.com/HT210728', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210725', 'name': 'https://support.apple.com/HT210725', 'refsource': 'MISC'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'refsource': 'GENTOO'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8815', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8815', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.471Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:24.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8815', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 9.3, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:C/I:C/A:C', 'authentication': 'NONE', 'integrityImpact': 'COMPLETE', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'COMPLETE', 'confidentialityImpact': 'COMPLETE'}, 'acInsufInfo': False, 'impactScore': 10.0, 'baseSeverity': 'HIGH', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Safari', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Safari 13.0.3', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 11.0', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows (Legacy)', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 7.15', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:44.100', 'references': [{'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210725', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210727', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210728', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210725', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210727', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210728', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-787'}]}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.'}, {'lang': 'es', 'value': 'Múltiples problemas de corrupción de memoria fueron abordados mejorando el manejo de la memoria. Este problema es corregido en iOS versión 13.2 y iPadOS versión 13.2, tvOS versión 13.2, Safari versión 13.0.3, iTunes para Windows versión 12.10.2, iCloud para Windows versión 11.0, iCloud para Windows versión 7.15. El procesamiento de contenido web diseñado maliciosamente puede conllevar a una ejecución de código arbitrario.'}], 'lastModified': '2026-06-17T02:42:39.937', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': 'B730AB98-7AF7-4F18-BEB4-AEE484D2586B', 'versionEndExcluding': '7.15'}, {'criteria': 'cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': '40795999-C39E-4D39-A734-70EDCF0D11A7', 'versionEndIncluding': '10.4', 'versionStartIncluding': '10.0'}, {'criteria': 'cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': '4A70FE53-CD3F-4296-B209-64C6F24CE3A7', 'versionEndExcluding': '12.10.2'}, {'criteria': 'cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '9DD4F307-7772-4B9B-8C77-E445EA39ADB8', 'versionEndExcluding': '13.0.3'}, {'criteria': 'cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AD59FD8B-5C11-469A-91E8-B3EB904AB1EF', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '13864229-C006-4C72-AAE3-90F009375CA5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A03A6988-48E4-4108-9A9B-8671BFF4C3A5', 'versionEndExcluding': '13.2'}], 'operator': 'OR'}]}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '33C068A4-3780-4EAB-A937-6082DF847564'}, {'criteria': 'cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '51EF4996-72F4-4FA4-814F-F5991E7A8318'}, {'criteria': 'cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '825ECE2D-E232-46E0-A047-074B34DB1E97'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8816
2019-12-18 20:33:24+03:00
2026-06-17 02:42:40.067000+03:00
PUBLISHED
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.
HIGH
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210725', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210727', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210728', 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210721', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210725', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210727', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210728', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.773795+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210727', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210728', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210725', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.219Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'watchOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'watchOS 6.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Safari', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Safari 13.0.3', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 11.0', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows (Legacy)', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 7.15', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210727', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210728', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210725', 'tags': ['x_refsource_MISC']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2020-03-15T06:06:27.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'iOS 13.2 and iPadOS 13.2', 'version_affected': '<'}]}, 'product_name': 'iOS'}, {'version': {'version_data': [{'version_value': 'tvOS 13.2', 'version_affected': '<'}]}, 'product_name': 'tvOS'}, {'version': {'version_data': [{'version_value': 'watchOS 6.1', 'version_affected': '<'}]}, 'product_name': 'watchOS'}, {'version': {'version_data': [{'version_value': 'Safari 13.0.3', 'version_affected': '<'}]}, 'product_name': 'Safari'}, {'version': {'version_data': [{'version_value': 'iTunes for Windows 12.10.2', 'version_affected': '<'}]}, 'product_name': 'iTunes for Windows'}, {'version': {'version_data': [{'version_value': 'iCloud for Windows 11.0', 'version_affected': '<'}]}, 'product_name': 'iCloud for Windows'}, {'version': {'version_data': [{'version_value': 'iCloud for Windows 7.15', 'version_affected': '<'}]}, 'product_name': 'iCloud for Windows (Legacy)'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210724', 'name': 'https://support.apple.com/HT210724', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210727', 'name': 'https://support.apple.com/HT210727', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210721', 'name': 'https://support.apple.com/HT210721', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210726', 'name': 'https://support.apple.com/HT210726', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210723', 'name': 'https://support.apple.com/HT210723', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210728', 'name': 'https://support.apple.com/HT210728', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210725', 'name': 'https://support.apple.com/HT210725', 'refsource': 'MISC'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'refsource': 'GENTOO'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8816', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8816', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.219Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:24.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8816', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 9.3, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:C/I:C/A:C', 'authentication': 'NONE', 'integrityImpact': 'COMPLETE', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'COMPLETE', 'confidentialityImpact': 'COMPLETE'}, 'acInsufInfo': False, 'impactScore': 10.0, 'baseSeverity': 'HIGH', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'watchOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'watchOS 6.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Safari', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Safari 13.0.3', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 11.0', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows (Legacy)', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 7.15', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:44.210', 'references': [{'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210725', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210727', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210728', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210725', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210727', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210728', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-787'}]}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.'}, {'lang': 'es', 'value': 'Múltiples problemas de corrupción de memoria fueron abordados mejorando el manejo de la memoria. Este problema es corregido en iOS versión 13.2 y iPadOS versión 13.2, tvOS versión 13.2, watchOS versión 6.1, Safari versión 13.0.3, iTunes para Windows versión 12.10.2, iCloud para Windows versión 11.0, iCloud para Windows versión 7.15. El procesamiento de contenido web diseñado maliciosamente puede conllevar a una ejecución de código arbitrario.'}], 'lastModified': '2026-06-17T02:42:40.067', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': 'B730AB98-7AF7-4F18-BEB4-AEE484D2586B', 'versionEndExcluding': '7.15'}, {'criteria': 'cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': '40795999-C39E-4D39-A734-70EDCF0D11A7', 'versionEndIncluding': '10.4', 'versionStartIncluding': '10.0'}, {'criteria': 'cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': '4A70FE53-CD3F-4296-B209-64C6F24CE3A7', 'versionEndExcluding': '12.10.2'}, {'criteria': 'cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '9DD4F307-7772-4B9B-8C77-E445EA39ADB8', 'versionEndExcluding': '13.0.3'}, {'criteria': 'cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AD59FD8B-5C11-469A-91E8-B3EB904AB1EF', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '13864229-C006-4C72-AAE3-90F009375CA5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A03A6988-48E4-4108-9A9B-8671BFF4C3A5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '277FA1BB-BB95-49DD-B50C-00F4BEE9DDE1', 'versionEndExcluding': '6.1'}], 'operator': 'OR'}]}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '33C068A4-3780-4EAB-A937-6082DF847564'}, {'criteria': 'cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '51EF4996-72F4-4FA4-814F-F5991E7A8318'}, {'criteria': 'cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '825ECE2D-E232-46E0-A047-074B34DB1E97'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8817
2019-12-18 20:33:24+03:00
2026-06-17 02:42:40.197000+03:00
PUBLISHED
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.1. An application may be able to read restricted memory.
MEDIUM
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
[{'url': 'https://support.apple.com/HT210722', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210722', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:20.197198+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210722', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.514Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15.1', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210722', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.1. An application may be able to read restricted memory.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'An application may be able to read restricted memory'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2019-12-18T17:33:24.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'macOS Catalina 10.15.1', 'version_affected': '<'}]}, 'product_name': 'macOS'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210722', 'name': 'https://support.apple.com/HT210722', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.1. An application may be able to read restricted memory.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'An application may be able to read restricted memory'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8817', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8817', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.514Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:24.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8817', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 4.3, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:P/I:N/A:N', 'authentication': 'NONE', 'integrityImpact': 'NONE', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 3.6, 'exploitabilityScore': 1.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'macOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'macOS Catalina 10.15.1', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:44.317', 'references': [{'url': 'https://support.apple.com/HT210722', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210722', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-20'}]}], 'descriptions': [{'lang': 'en', 'value': 'A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.1. An application may be able to read restricted memory.'}, {'lang': 'es', 'value': 'Un problema de comprobación fue abordado mejorando el saneamiento de la entrada. Este problema es corregido en macOS Catalina versión 10.15.1. Una aplicación puede ser capaz de leer la memoria restringida.'}], 'lastModified': '2026-06-17T02:42:40.197', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E773457A-E670-4DDA-86E2-0923C1DCD9BA', 'versionEndExcluding': '10.15.1'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8819
2019-12-18 20:33:24+03:00
2026-06-17 02:42:40.300000+03:00
PUBLISHED
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.
HIGH
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210725', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210727', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210728', 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210721', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210725', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210727', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210728', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:20.197198+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210727', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210728', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210725', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.276Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Safari', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Safari 13.0.3', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 11.0', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows (Legacy)', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 7.15', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210727', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210728', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210725', 'tags': ['x_refsource_MISC']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2020-03-15T06:06:18.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'iOS 13.2 and iPadOS 13.2', 'version_affected': '<'}]}, 'product_name': 'iOS'}, {'version': {'version_data': [{'version_value': 'tvOS 13.2', 'version_affected': '<'}]}, 'product_name': 'tvOS'}, {'version': {'version_data': [{'version_value': 'Safari 13.0.3', 'version_affected': '<'}]}, 'product_name': 'Safari'}, {'version': {'version_data': [{'version_value': 'iTunes for Windows 12.10.2', 'version_affected': '<'}]}, 'product_name': 'iTunes for Windows'}, {'version': {'version_data': [{'version_value': 'iCloud for Windows 11.0', 'version_affected': '<'}]}, 'product_name': 'iCloud for Windows'}, {'version': {'version_data': [{'version_value': 'iCloud for Windows 7.15', 'version_affected': '<'}]}, 'product_name': 'iCloud for Windows (Legacy)'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210727', 'name': 'https://support.apple.com/HT210727', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210721', 'name': 'https://support.apple.com/HT210721', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210726', 'name': 'https://support.apple.com/HT210726', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210723', 'name': 'https://support.apple.com/HT210723', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210728', 'name': 'https://support.apple.com/HT210728', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210725', 'name': 'https://support.apple.com/HT210725', 'refsource': 'MISC'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'refsource': 'GENTOO'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8819', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8819', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.276Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:24.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8819', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 6.8, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Safari', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Safari 13.0.3', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 11.0', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows (Legacy)', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 7.15', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:44.413', 'references': [{'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210725', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210727', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210728', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210725', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210727', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210728', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-787'}]}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.'}, {'lang': 'es', 'value': 'Múltiples problemas de corrupción de memoria fueron abordados mejorando el manejo de la memoria. Este problema es corregido en iOS versión 13.2 y iPadOS versión 13.2, tvOS versión 13.2, Safari versión 13.0.3, iTunes para Windows versión 12.10.2, iCloud para Windows versión 11.0, iCloud para Windows versión 7.15. El procesamiento de contenido web diseñado maliciosamente puede conllevar a una ejecución de código arbitrario.'}], 'lastModified': '2026-06-17T02:42:40.300', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': 'B730AB98-7AF7-4F18-BEB4-AEE484D2586B', 'versionEndExcluding': '7.15'}, {'criteria': 'cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': '3599AAD1-DA6B-4E53-B166-BE36ADF48D11', 'versionEndExcluding': '10.8', 'versionStartIncluding': '10.0'}, {'criteria': 'cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': '4A70FE53-CD3F-4296-B209-64C6F24CE3A7', 'versionEndExcluding': '12.10.2'}, {'criteria': 'cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '9DD4F307-7772-4B9B-8C77-E445EA39ADB8', 'versionEndExcluding': '13.0.3'}, {'criteria': 'cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AD59FD8B-5C11-469A-91E8-B3EB904AB1EF', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '13864229-C006-4C72-AAE3-90F009375CA5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A03A6988-48E4-4108-9A9B-8671BFF4C3A5', 'versionEndExcluding': '13.2'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8820
2019-12-18 20:33:24+03:00
2026-06-17 02:42:40.423000+03:00
PUBLISHED
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.
HIGH
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210725', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210727', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210728', 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210721', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210725', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210727', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210728', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:20.197198+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210727', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210728', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210725', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.135Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'watchOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'watchOS 6.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Safari', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Safari 13.0.3', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 11.0', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows (Legacy)', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 7.15', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210724', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210727', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210728', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210725', 'tags': ['x_refsource_MISC']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2020-03-15T06:06:17.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'iOS 13.2 and iPadOS 13.2', 'version_affected': '<'}]}, 'product_name': 'iOS'}, {'version': {'version_data': [{'version_value': 'tvOS 13.2', 'version_affected': '<'}]}, 'product_name': 'tvOS'}, {'version': {'version_data': [{'version_value': 'watchOS 6.1', 'version_affected': '<'}]}, 'product_name': 'watchOS'}, {'version': {'version_data': [{'version_value': 'Safari 13.0.3', 'version_affected': '<'}]}, 'product_name': 'Safari'}, {'version': {'version_data': [{'version_value': 'iTunes for Windows 12.10.2', 'version_affected': '<'}]}, 'product_name': 'iTunes for Windows'}, {'version': {'version_data': [{'version_value': 'iCloud for Windows 11.0', 'version_affected': '<'}]}, 'product_name': 'iCloud for Windows'}, {'version': {'version_data': [{'version_value': 'iCloud for Windows 7.15', 'version_affected': '<'}]}, 'product_name': 'iCloud for Windows (Legacy)'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210724', 'name': 'https://support.apple.com/HT210724', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210727', 'name': 'https://support.apple.com/HT210727', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210721', 'name': 'https://support.apple.com/HT210721', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210726', 'name': 'https://support.apple.com/HT210726', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210723', 'name': 'https://support.apple.com/HT210723', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210728', 'name': 'https://support.apple.com/HT210728', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210725', 'name': 'https://support.apple.com/HT210725', 'refsource': 'MISC'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'refsource': 'GENTOO'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8820', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8820', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.135Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:24.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8820', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 6.8, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'watchOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'watchOS 6.1', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Safari', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Safari 13.0.3', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 11.0', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows (Legacy)', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 7.15', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:44.507', 'references': [{'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210725', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210727', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210728', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210724', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210725', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210727', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210728', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-787'}]}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.'}, {'lang': 'es', 'value': 'Múltiples problemas de corrupción de memoria fueron abordados mejorando el manejo de la memoria. Este problema es corregido en iOS versión 13.2 y iPadOS versión 13.2, tvOS versión 13.2, watchOS versión 6.1, Safari versión 13.0.3, iTunes para Windows versión 12.10.2, iCloud para Windows versión 11.0, iCloud para Windows versión 7.15. El procesamiento de contenido web diseñado maliciosamente puede conllevar a una ejecución de código arbitrario.'}], 'lastModified': '2026-06-17T02:42:40.423', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': 'B730AB98-7AF7-4F18-BEB4-AEE484D2586B', 'versionEndExcluding': '7.15'}, {'criteria': 'cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': '3599AAD1-DA6B-4E53-B166-BE36ADF48D11', 'versionEndExcluding': '10.8', 'versionStartIncluding': '10.0'}, {'criteria': 'cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': '4A70FE53-CD3F-4296-B209-64C6F24CE3A7', 'versionEndExcluding': '12.10.2'}, {'criteria': 'cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '9DD4F307-7772-4B9B-8C77-E445EA39ADB8', 'versionEndExcluding': '13.0.3'}, {'criteria': 'cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AD59FD8B-5C11-469A-91E8-B3EB904AB1EF', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '13864229-C006-4C72-AAE3-90F009375CA5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A03A6988-48E4-4108-9A9B-8671BFF4C3A5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '277FA1BB-BB95-49DD-B50C-00F4BEE9DDE1', 'versionEndExcluding': '6.1'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8821
2019-12-18 20:33:24+03:00
2026-06-17 02:42:40.557000+03:00
PUBLISHED
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.
HIGH
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210725', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210727', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210728', 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210721', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210725', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210727', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210728', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:20.197198+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210727', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210728', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210725', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.159Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Safari', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Safari 13.0.3', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 11.0', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows (Legacy)', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 7.15', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210727', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210728', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210725', 'tags': ['x_refsource_MISC']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2020-03-15T06:06:31.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'iOS 13.2 and iPadOS 13.2', 'version_affected': '<'}]}, 'product_name': 'iOS'}, {'version': {'version_data': [{'version_value': 'tvOS 13.2', 'version_affected': '<'}]}, 'product_name': 'tvOS'}, {'version': {'version_data': [{'version_value': 'Safari 13.0.3', 'version_affected': '<'}]}, 'product_name': 'Safari'}, {'version': {'version_data': [{'version_value': 'iTunes for Windows 12.10.2', 'version_affected': '<'}]}, 'product_name': 'iTunes for Windows'}, {'version': {'version_data': [{'version_value': 'iCloud for Windows 11.0', 'version_affected': '<'}]}, 'product_name': 'iCloud for Windows'}, {'version': {'version_data': [{'version_value': 'iCloud for Windows 7.15', 'version_affected': '<'}]}, 'product_name': 'iCloud for Windows (Legacy)'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210727', 'name': 'https://support.apple.com/HT210727', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210721', 'name': 'https://support.apple.com/HT210721', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210726', 'name': 'https://support.apple.com/HT210726', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210723', 'name': 'https://support.apple.com/HT210723', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210728', 'name': 'https://support.apple.com/HT210728', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210725', 'name': 'https://support.apple.com/HT210725', 'refsource': 'MISC'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'refsource': 'GENTOO'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8821', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8821', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.159Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:24.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8821', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 6.8, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Safari', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Safari 13.0.3', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 11.0', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows (Legacy)', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 7.15', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:44.630', 'references': [{'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210725', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210727', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210728', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210725', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210727', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210728', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-787'}]}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.'}, {'lang': 'es', 'value': 'Múltiples problemas de corrupción de memoria fueron abordados mejorando el manejo de la memoria. Este problema es corregido en iOS versión 13.2 y iPadOS versión 13.2, tvOS versión 13.2, Safari versión 13.0.3, iTunes para Windows versión 12.10.2, iCloud para Windows versión 11.0, iCloud para Windows versión 7.15. El procesamiento de contenido web diseñado maliciosamente puede conllevar a una ejecución de código arbitrario.'}], 'lastModified': '2026-06-17T02:42:40.557', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': 'B730AB98-7AF7-4F18-BEB4-AEE484D2586B', 'versionEndExcluding': '7.15'}, {'criteria': 'cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': '3599AAD1-DA6B-4E53-B166-BE36ADF48D11', 'versionEndExcluding': '10.8', 'versionStartIncluding': '10.0'}, {'criteria': 'cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': '4A70FE53-CD3F-4296-B209-64C6F24CE3A7', 'versionEndExcluding': '12.10.2'}, {'criteria': 'cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '9DD4F307-7772-4B9B-8C77-E445EA39ADB8', 'versionEndExcluding': '13.0.3'}, {'criteria': 'cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AD59FD8B-5C11-469A-91E8-B3EB904AB1EF', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '13864229-C006-4C72-AAE3-90F009375CA5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A03A6988-48E4-4108-9A9B-8671BFF4C3A5', 'versionEndExcluding': '13.2'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2022-42287
2023-01-13 05:07:42.144000+03:00
2026-06-17 05:04:39.343000+03:00
PUBLISHED
NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can upload and download arbitrary files under certain circumstances, which may lead to denial of service, escalation of privileges, information disclosure and data tampering.
MEDIUM
6.0
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
[{'url': 'https://nvidia.custhelp.com/app/answers/detail/a_id/5435', 'source': 'psirt@nvidia.com'}, {'url': 'https://nvidia.custhelp.com/app/answers/detail/a_id/5435', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:17:19.859482+03:00
2026-06-27 08:26:40.077172+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://nvidia.custhelp.com/app/answers/detail/a_id/5435', 'tags': ['x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-03T13:03:45.911Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'other': {'type': 'ssvc', 'content': {'id': 'CVE-2022-42287', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-04-07T17:58:00.917881Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-04-07T17:58:09.579Z'}}], 'cna': {'source': {'discovery': 'UNKNOWN'}, 'impacts': [{'descriptions': [{'lang': 'en', 'value': 'Denial of Service, Escalation of Privileges, Information Disclosure, Data Tampering'}]}], 'metrics': [{'format': 'CVSS', 'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'scenarios': [{'lang': 'en', 'value': 'GENERAL'}]}], 'affected': [{'vendor': 'NVIDIA', 'product': 'NVIDIA DGX servers', 'versions': [{'status': 'affected', 'version': 'All BMC firmware versions prior to 00.19.07'}], 'defaultStatus': 'unaffected'}], 'references': [{'url': 'https://nvidia.custhelp.com/app/answers/detail/a_id/5435'}], 'x_generator': {'engine': 'Vulnogram 0.1.0-dev'}, 'descriptions': [{'lang': 'en', 'value': 'NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can upload and download arbitrary files under certain circumstances, which may lead to denial of service, escalation of privileges, information disclosure and data tampering.', 'supportingMedia': [{'type': 'text/html', 'value': 'NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can upload and download arbitrary files under certain circumstances, which may lead to denial of service, escalation of privileges, information disclosure and data tampering.', 'base64': True}]}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-22', 'description': "CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"}]}], 'providerMetadata': {'orgId': '9576f279-3576-44b5-a4af-b9a8644b2de6', 'shortName': 'nvidia', 'dateUpdated': '2023-01-13T02:07:42.144Z'}}}, 'cveMetadata': {'cveId': 'CVE-2022-42287', 'state': 'PUBLISHED', 'dateUpdated': '2025-04-07T17:58:09.579Z', 'dateReserved': '2022-10-03T14:20:26.207Z', 'assignerOrgId': '9576f279-3576-44b5-a4af-b9a8644b2de6', 'datePublished': '2023-01-13T02:07:42.144Z', 'assignerShortName': 'nvidia'}, 'dataVersion': '5.1'}
{'id': 'CVE-2022-42287', 'cveTags': [], 'metrics': {'ssvcV203': [{'source': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'ssvcData': {'id': 'CVE-2022-42287', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-04-07T17:58:00.917881Z'}}], 'cvssMetricV31': [{'type': 'Secondary', 'source': 'psirt@nvidia.com', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.0, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.2, 'exploitabilityScore': 0.8}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 1.8}]}, 'affected': [{'source': 'psirt@nvidia.com', 'affectedData': [{'vendor': 'NVIDIA', 'product': 'NVIDIA DGX servers', 'versions': [{'status': 'affected', 'version': 'All BMC firmware versions prior to 00.19.07'}], 'defaultStatus': 'unaffected'}]}], 'published': '2023-01-13T04:15:08.557', 'references': [{'url': 'https://nvidia.custhelp.com/app/answers/detail/a_id/5435', 'tags': ['Vendor Advisory'], 'source': 'psirt@nvidia.com'}, {'url': 'https://nvidia.custhelp.com/app/answers/detail/a_id/5435', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Secondary', 'source': 'psirt@nvidia.com', 'description': [{'lang': 'en', 'value': 'CWE-22'}]}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-434'}]}], 'descriptions': [{'lang': 'en', 'value': 'NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can upload and download arbitrary files under certain circumstances, which may lead to denial of service, escalation of privileges, information disclosure and data tampering.'}, {'lang': 'es', 'value': 'NVIDIA BMC contiene una vulnerabilidad en el controlador IPMI, donde un atacante autorizado puede cargar y descargar archivos arbitrarios bajo ciertas circunstancias, lo que puede provocar denegación de servicio, escalada de privilegios, divulgación de información y manipulación de datos.'}], 'lastModified': '2026-06-17T05:04:39.343', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:nvidia:bmc:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '2BF2BE11-5340-45D4-901E-6DE5153EEF14', 'versionEndExcluding': '00.19.07'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:nvidia:dgx_a100:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '8807CB65-5F49-42E8-B5D8-36943418ADB9'}], 'operator': 'OR'}], 'operator': 'AND'}], 'sourceIdentifier': 'psirt@nvidia.com'}
CVE-2022-42288
2023-01-13 05:09:02.245000+03:00
2026-06-17 05:04:39.460000+03:00
PUBLISHED
NVIDIA BMC contains a vulnerability in IPMI handler, where an unauthorized attacker can use certain oracles to guess a valid BMC username, which may lead to an information disclosure.
MEDIUM
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
[{'url': 'https://nvidia.custhelp.com/app/answers/detail/a_id/5435', 'source': 'psirt@nvidia.com'}, {'url': 'https://nvidia.custhelp.com/app/answers/detail/a_id/5435', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:17:20.066418+03:00
2026-06-27 08:26:40.077172+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://nvidia.custhelp.com/app/answers/detail/a_id/5435', 'tags': ['x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-03T13:03:45.977Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'other': {'type': 'ssvc', 'content': {'id': 'CVE-2022-42288', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-04-07T17:56:18.807806Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-04-07T17:56:27.043Z'}}], 'cna': {'source': {'discovery': 'UNKNOWN'}, 'impacts': [{'descriptions': [{'lang': 'en', 'value': 'Information Disclosure'}]}], 'metrics': [{'format': 'CVSS', 'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}, 'scenarios': [{'lang': 'en', 'value': 'GENERAL'}]}], 'affected': [{'vendor': 'NVIDIA', 'product': 'NVIDIA DGX servers', 'versions': [{'status': 'affected', 'version': 'All BMC firmware versions prior to 00.19.07'}], 'defaultStatus': 'unaffected'}], 'references': [{'url': 'https://nvidia.custhelp.com/app/answers/detail/a_id/5435'}], 'x_generator': {'engine': 'Vulnogram 0.1.0-dev'}, 'descriptions': [{'lang': 'en', 'value': 'NVIDIA BMC contains a vulnerability in IPMI handler, where an unauthorized attacker can use certain oracles to guess a valid BMC username, which may lead to an information disclosure.', 'supportingMedia': [{'type': 'text/html', 'value': 'NVIDIA BMC contains a vulnerability in IPMI handler, where an unauthorized attacker can use certain oracles to guess a valid BMC username, which may lead to an information disclosure.', 'base64': True}]}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-208', 'description': 'CWE-208'}]}], 'providerMetadata': {'orgId': '9576f279-3576-44b5-a4af-b9a8644b2de6', 'shortName': 'nvidia', 'dateUpdated': '2023-01-13T02:09:02.245Z'}}}, 'cveMetadata': {'cveId': 'CVE-2022-42288', 'state': 'PUBLISHED', 'dateUpdated': '2025-04-07T17:56:27.043Z', 'dateReserved': '2022-10-03T14:20:26.207Z', 'assignerOrgId': '9576f279-3576-44b5-a4af-b9a8644b2de6', 'datePublished': '2023-01-13T02:09:02.245Z', 'assignerShortName': 'nvidia'}, 'dataVersion': '5.1'}
{'id': 'CVE-2022-42288', 'cveTags': [], 'metrics': {'ssvcV203': [{'source': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'ssvcData': {'id': 'CVE-2022-42288', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'yes'}, {'technicalImpact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-04-07T17:56:18.807806Z'}}], 'cvssMetricV31': [{'type': 'Secondary', 'source': 'psirt@nvidia.com', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}, 'impactScore': 1.4, 'exploitabilityScore': 3.9}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}, 'impactScore': 1.4, 'exploitabilityScore': 3.9}]}, 'affected': [{'source': 'psirt@nvidia.com', 'affectedData': [{'vendor': 'NVIDIA', 'product': 'NVIDIA DGX servers', 'versions': [{'status': 'affected', 'version': 'All BMC firmware versions prior to 00.19.07'}], 'defaultStatus': 'unaffected'}]}], 'published': '2023-01-13T04:15:08.660', 'references': [{'url': 'https://nvidia.custhelp.com/app/answers/detail/a_id/5435', 'tags': ['Vendor Advisory'], 'source': 'psirt@nvidia.com'}, {'url': 'https://nvidia.custhelp.com/app/answers/detail/a_id/5435', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Secondary', 'source': 'psirt@nvidia.com', 'description': [{'lang': 'en', 'value': 'CWE-208'}]}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-203'}]}], 'descriptions': [{'lang': 'en', 'value': 'NVIDIA BMC contains a vulnerability in IPMI handler, where an unauthorized attacker can use certain oracles to guess a valid BMC username, which may lead to an information disclosure.'}, {'lang': 'es', 'value': 'NVIDIA BMC contiene una vulnerabilidad en el controlador IPMI, donde un atacante no autorizado puede utilizar ciertos oráculos para adivinar un nombre de usuario de BMC válido, lo que puede dar lugar a una divulgación de información.'}], 'lastModified': '2026-06-17T05:04:39.460', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:nvidia:dgx_a100_firmware:*:*:*:*:bmc:*:*:*', 'vulnerable': True, 'matchCriteriaId': '063DAD57-7DC7-46E6-A5C6-B4D1A3CE7F19', 'versionEndExcluding': '00.19.07'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:nvidia:dgx_a100:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '8807CB65-5F49-42E8-B5D8-36943418ADB9'}], 'operator': 'OR'}], 'operator': 'AND'}], 'sourceIdentifier': 'psirt@nvidia.com'}
CVE-2019-8822
2019-12-18 20:33:24+03:00
2026-06-17 02:42:40.687000+03:00
PUBLISHED
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.
HIGH
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210725', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210727', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210728', 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210721', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210725', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210727', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210728', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.773795+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210727', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210728', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210725', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.370Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Safari', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Safari 13.0.3', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 11.0', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows (Legacy)', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 7.15', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210727', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210728', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210725', 'tags': ['x_refsource_MISC']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2020-03-15T06:06:22.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'iOS 13.2 and iPadOS 13.2', 'version_affected': '<'}]}, 'product_name': 'iOS'}, {'version': {'version_data': [{'version_value': 'tvOS 13.2', 'version_affected': '<'}]}, 'product_name': 'tvOS'}, {'version': {'version_data': [{'version_value': 'Safari 13.0.3', 'version_affected': '<'}]}, 'product_name': 'Safari'}, {'version': {'version_data': [{'version_value': 'iTunes for Windows 12.10.2', 'version_affected': '<'}]}, 'product_name': 'iTunes for Windows'}, {'version': {'version_data': [{'version_value': 'iCloud for Windows 11.0', 'version_affected': '<'}]}, 'product_name': 'iCloud for Windows'}, {'version': {'version_data': [{'version_value': 'iCloud for Windows 7.15', 'version_affected': '<'}]}, 'product_name': 'iCloud for Windows (Legacy)'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210727', 'name': 'https://support.apple.com/HT210727', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210721', 'name': 'https://support.apple.com/HT210721', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210726', 'name': 'https://support.apple.com/HT210726', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210723', 'name': 'https://support.apple.com/HT210723', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210728', 'name': 'https://support.apple.com/HT210728', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210725', 'name': 'https://support.apple.com/HT210725', 'refsource': 'MISC'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'refsource': 'GENTOO'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8822', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8822', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.370Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:24.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8822', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 6.8, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Safari', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Safari 13.0.3', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 11.0', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows (Legacy)', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 7.15', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:44.740', 'references': [{'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210725', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210727', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210728', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210725', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210727', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210728', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-787'}]}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.'}, {'lang': 'es', 'value': 'Múltiples problemas de corrupción de memoria fueron abordados mejorando el manejo de la memoria. Este problema es corregido en iOS versión 13.2 y iPadOS versión 13.2, tvOS versión 13.2, Safari versión 13.0.3, iTunes para Windows versión 12.10.2, iCloud para Windows versión 11.0, iCloud para Windows versión 7.15. El procesamiento de contenido web diseñado maliciosamente puede conllevar a una ejecución de código arbitrario.'}], 'lastModified': '2026-06-17T02:42:40.687', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': 'B730AB98-7AF7-4F18-BEB4-AEE484D2586B', 'versionEndExcluding': '7.15'}, {'criteria': 'cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': '40795999-C39E-4D39-A734-70EDCF0D11A7', 'versionEndIncluding': '10.4', 'versionStartIncluding': '10.0'}, {'criteria': 'cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': '4A70FE53-CD3F-4296-B209-64C6F24CE3A7', 'versionEndExcluding': '12.10.2'}, {'criteria': 'cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '9DD4F307-7772-4B9B-8C77-E445EA39ADB8', 'versionEndExcluding': '13.0.3'}, {'criteria': 'cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AD59FD8B-5C11-469A-91E8-B3EB904AB1EF', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '13864229-C006-4C72-AAE3-90F009375CA5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A03A6988-48E4-4108-9A9B-8671BFF4C3A5', 'versionEndExcluding': '13.2'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8823
2019-12-18 20:33:24+03:00
2026-06-17 02:42:40.813000+03:00
PUBLISHED
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.
HIGH
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210725', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210727', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210728', 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210721', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210725', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210727', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210728', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.773795+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210727', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210728', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.apple.com/HT210725', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.189Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Safari', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Safari 13.0.3', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 11.0', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows (Legacy)', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 7.15', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210727', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210721', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210726', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210723', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210728', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.apple.com/HT210725', 'tags': ['x_refsource_MISC']}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2020-03-15T06:06:18.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'iOS 13.2 and iPadOS 13.2', 'version_affected': '<'}]}, 'product_name': 'iOS'}, {'version': {'version_data': [{'version_value': 'tvOS 13.2', 'version_affected': '<'}]}, 'product_name': 'tvOS'}, {'version': {'version_data': [{'version_value': 'Safari 13.0.3', 'version_affected': '<'}]}, 'product_name': 'Safari'}, {'version': {'version_data': [{'version_value': 'iTunes for Windows 12.10.2', 'version_affected': '<'}]}, 'product_name': 'iTunes for Windows'}, {'version': {'version_data': [{'version_value': 'iCloud for Windows 11.0', 'version_affected': '<'}]}, 'product_name': 'iCloud for Windows'}, {'version': {'version_data': [{'version_value': 'iCloud for Windows 7.15', 'version_affected': '<'}]}, 'product_name': 'iCloud for Windows (Legacy)'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210727', 'name': 'https://support.apple.com/HT210727', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210721', 'name': 'https://support.apple.com/HT210721', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210726', 'name': 'https://support.apple.com/HT210726', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210723', 'name': 'https://support.apple.com/HT210723', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210728', 'name': 'https://support.apple.com/HT210728', 'refsource': 'MISC'}, {'url': 'https://support.apple.com/HT210725', 'name': 'https://support.apple.com/HT210725', 'refsource': 'MISC'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'name': 'GLSA-202003-22', 'refsource': 'GENTOO'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Processing maliciously crafted web content may lead to arbitrary code execution'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8823', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8823', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.189Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:24.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8823', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 6.8, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'iOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iOS 13.2 and iPadOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'tvOS', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'tvOS 13.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'Safari', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'Safari 13.0.3', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iTunes for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iTunes for Windows 12.10.2', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 11.0', 'versionType': 'custom'}]}, {'vendor': 'Apple', 'product': 'iCloud for Windows (Legacy)', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'iCloud for Windows 7.15', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:44.880', 'references': [{'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210725', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210727', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210728', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://security.gentoo.org/glsa/202003-22', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210721', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210723', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210725', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210726', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210727', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://support.apple.com/HT210728', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-787'}]}], 'descriptions': [{'lang': 'en', 'value': 'Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.'}, {'lang': 'es', 'value': 'Múltiples problemas de corrupción de memoria fueron abordados mejorando el manejo de la memoria. Este problema es corregido en iOS versión 13.2 y iPadOS versión 13.2, tvOS versión 13.2, Safari versión 13.0.3, iTunes para Windows versión 12.10.2, iCloud para Windows versión 11.0, iCloud para Windows versión 7.15. El procesamiento de contenido web diseñado maliciosamente puede conllevar a una ejecución de código arbitrario.'}], 'lastModified': '2026-06-17T02:42:40.813', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': 'B730AB98-7AF7-4F18-BEB4-AEE484D2586B', 'versionEndExcluding': '7.15'}, {'criteria': 'cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': '40795999-C39E-4D39-A734-70EDCF0D11A7', 'versionEndIncluding': '10.4', 'versionStartIncluding': '10.0'}, {'criteria': 'cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*', 'vulnerable': True, 'matchCriteriaId': '4A70FE53-CD3F-4296-B209-64C6F24CE3A7', 'versionEndExcluding': '12.10.2'}, {'criteria': 'cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '9DD4F307-7772-4B9B-8C77-E445EA39ADB8', 'versionEndExcluding': '13.0.3'}, {'criteria': 'cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AD59FD8B-5C11-469A-91E8-B3EB904AB1EF', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '13864229-C006-4C72-AAE3-90F009375CA5', 'versionEndExcluding': '13.2'}, {'criteria': 'cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A03A6988-48E4-4108-9A9B-8671BFF4C3A5', 'versionEndExcluding': '13.2'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2019-8849
2019-12-18 20:33:24+03:00
2026-06-17 02:42:43.523000+03:00
PUBLISHED
The issue was addressed by signaling that an executable stack is not required. This issue is fixed in SwiftNIO SSL 2.4.1. A SwiftNIO application using TLS may be able to execute arbitrary code.
CRITICAL
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
[{'url': 'https://support.apple.com/HT210772', 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210772', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.773795+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.apple.com/HT210772', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T21:31:37.467Z'}}], 'cna': {'affected': [{'vendor': 'Apple', 'product': 'Swift-Ubuntu', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'SwiftNIO SSL 2.4.1', 'versionType': 'custom'}]}], 'references': [{'url': 'https://support.apple.com/HT210772', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'The issue was addressed by signaling that an executable stack is not required. This issue is fixed in SwiftNIO SSL 2.4.1. A SwiftNIO application using TLS may be able to execute arbitrary code.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'A SwiftNIO application using TLS may be able to execute arbitrary code'}]}], 'providerMetadata': {'orgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'shortName': 'apple', 'dateUpdated': '2019-12-18T17:33:24.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'SwiftNIO SSL 2.4.1', 'version_affected': '<'}]}, 'product_name': 'Swift-Ubuntu'}]}, 'vendor_name': 'Apple'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.apple.com/HT210772', 'name': 'https://support.apple.com/HT210772', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'The issue was addressed by signaling that an executable stack is not required. This issue is fixed in SwiftNIO SSL 2.4.1. A SwiftNIO application using TLS may be able to execute arbitrary code.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'A SwiftNIO application using TLS may be able to execute arbitrary code'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-8849', 'STATE': 'PUBLIC', 'ASSIGNER': 'product-security@apple.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-8849', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T21:31:37.467Z', 'dateReserved': '2019-02-18T00:00:00.000Z', 'assignerOrgId': '286789f9-fbc2-4510-9f9a-43facdede74c', 'datePublished': '2019-12-18T17:33:24.000Z', 'assignerShortName': 'apple'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-8849', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 7.5, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'LOW', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'HIGH', 'obtainAllPrivilege': False, 'exploitabilityScore': 10.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 3.9}]}, 'affected': [{'source': 'product-security@apple.com', 'affectedData': [{'vendor': 'Apple', 'product': 'Swift-Ubuntu', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': 'SwiftNIO SSL 2.4.1', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T18:15:44.990', 'references': [{'url': 'https://support.apple.com/HT210772', 'tags': ['Vendor Advisory'], 'source': 'product-security@apple.com'}, {'url': 'https://support.apple.com/HT210772', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'NVD-CWE-noinfo'}]}], 'descriptions': [{'lang': 'en', 'value': 'The issue was addressed by signaling that an executable stack is not required. This issue is fixed in SwiftNIO SSL 2.4.1. A SwiftNIO application using TLS may be able to execute arbitrary code.'}, {'lang': 'es', 'value': 'El problema fue abordado señalando que una pila ejecutable no es requerida. Este problema es corregido en SwiftNIO SSL versión 2.4.1. Una aplicación SwiftNIO que usa TLS puede ejecutar código arbitrario.'}], 'lastModified': '2026-06-17T02:42:43.523', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:apple:swiftnio_ssl:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '47BC1C25-F49E-458F-AC68-EA9755B0B7CF', 'versionEndExcluding': '2.4.1'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'product-security@apple.com'}
CVE-2020-12415
2020-07-09 17:39:37+03:00
2026-06-17 02:51:47.520000+03:00
PUBLISHED
When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to be served from a subdirectory. This could cause the appcache to be used to service requests for the top level directory. This vulnerability affects Firefox < 78.
MEDIUM
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
[{'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html', 'source': 'security@mozilla.org'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html', 'source': 'security@mozilla.org'}, {'url': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1586630', 'source': 'security@mozilla.org'}, {'url': 'https://security.gentoo.org/glsa/202007-10', 'source': 'security@mozilla.org'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'source': 'security@mozilla.org'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1586630', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://security.gentoo.org/glsa/202007-10', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:55.755087+03:00
2026-06-27 08:25:53.850778+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1586630', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html', 'name': 'openSUSE-SU-2020:0983', 'tags': ['vendor-advisory', 'x_refsource_SUSE', 'x_transferred']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html', 'name': 'openSUSE-SU-2020:1017', 'tags': ['vendor-advisory', 'x_refsource_SUSE', 'x_transferred']}, {'url': 'https://security.gentoo.org/glsa/202007-10', 'name': 'GLSA-202007-10', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T11:56:51.740Z'}}], 'cna': {'affected': [{'vendor': 'Mozilla', 'product': 'Firefox', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': '78', 'versionType': 'custom'}]}], 'references': [{'url': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'tags': ['x_refsource_MISC']}, {'url': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1586630', 'tags': ['x_refsource_MISC']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html', 'name': 'openSUSE-SU-2020:0983', 'tags': ['vendor-advisory', 'x_refsource_SUSE']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html', 'name': 'openSUSE-SU-2020:1017', 'tags': ['vendor-advisory', 'x_refsource_SUSE']}, {'url': 'https://security.gentoo.org/glsa/202007-10', 'name': 'GLSA-202007-10', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}], 'descriptions': [{'lang': 'en', 'value': 'When "%2F" was present in a manifest URL, Firefox\'s AppCache behavior may have become confused and allowed a manifest to be served from a subdirectory. This could cause the appcache to be used to service requests for the top level directory. This vulnerability affects Firefox < 78.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'AppCache manifest poisoning due to url encoded character processing'}]}], 'providerMetadata': {'orgId': 'f16b083a-5664-49f3-a51e-8d479e5ed7fe', 'shortName': 'mozilla', 'dateUpdated': '2020-07-27T01:06:32.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': '78', 'version_affected': '<'}]}, 'product_name': 'Firefox'}]}, 'vendor_name': 'Mozilla'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'name': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'refsource': 'MISC'}, {'url': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1586630', 'name': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1586630', 'refsource': 'MISC'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html', 'name': 'openSUSE-SU-2020:0983', 'refsource': 'SUSE'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html', 'name': 'openSUSE-SU-2020:1017', 'refsource': 'SUSE'}, {'url': 'https://security.gentoo.org/glsa/202007-10', 'name': 'GLSA-202007-10', 'refsource': 'GENTOO'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'When "%2F" was present in a manifest URL, Firefox\'s AppCache behavior may have become confused and allowed a manifest to be served from a subdirectory. This could cause the appcache to be used to service requests for the top level directory. This vulnerability affects Firefox < 78.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'AppCache manifest poisoning due to url encoded character processing'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2020-12415', 'STATE': 'PUBLIC', 'ASSIGNER': 'security@mozilla.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2020-12415', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T11:56:51.740Z', 'dateReserved': '2020-04-28T00:00:00.000Z', 'assignerOrgId': 'f16b083a-5664-49f3-a51e-8d479e5ed7fe', 'datePublished': '2020-07-09T14:39:37.000Z', 'assignerShortName': 'mozilla'}, 'dataVersion': '5.1'}
{'id': 'CVE-2020-12415', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 4.3, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:N/I:P/A:N', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'NONE'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}, 'impactScore': 3.6, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'security@mozilla.org', 'affectedData': [{'vendor': 'Mozilla', 'product': 'Firefox', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': '78', 'versionType': 'custom'}]}]}], 'published': '2020-07-09T15:15:11.617', 'references': [{'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'security@mozilla.org'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'security@mozilla.org'}, {'url': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1586630', 'tags': ['Issue Tracking', 'Permissions Required', 'Vendor Advisory'], 'source': 'security@mozilla.org'}, {'url': 'https://security.gentoo.org/glsa/202007-10', 'tags': ['Third Party Advisory'], 'source': 'security@mozilla.org'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'tags': ['Vendor Advisory'], 'source': 'security@mozilla.org'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1586630', 'tags': ['Issue Tracking', 'Permissions Required', 'Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://security.gentoo.org/glsa/202007-10', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-276'}]}], 'descriptions': [{'lang': 'en', 'value': 'When "%2F" was present in a manifest URL, Firefox\'s AppCache behavior may have become confused and allowed a manifest to be served from a subdirectory. This could cause the appcache to be used to service requests for the top level directory. This vulnerability affects Firefox < 78.'}, {'lang': 'es', 'value': 'Cuando "%2F" estaba presente en una URL de manifiesto, el comportamiento de AppCache de Firefox puede haber sido confundido y permitir que sea servido un manifiesto desde un subdirectorio. Esto podría hacer que el appcache sea usado para atender peticiones para el directorio de nivel superior. Esta vulnerabilidad afecta a Firefox versiones anteriores a 78'}], 'lastModified': '2026-06-17T02:51:47.520', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '09FA5356-4843-47D3-964C-86A6C3859F3C', 'versionEndExcluding': '78.0'}], 'operator': 'OR'}]}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'B620311B-34A3-48A6-82DF-6F078D7A4493'}, {'criteria': 'cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'B009C22E-30A4-4288-BCF6-C3E81DEAF45A'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'security@mozilla.org'}
CVE-2012-2656
2019-12-18 21:16:54+03:00
2026-06-16 23:41:49.260000+03:00
PUBLISHED
An XML eXternal Entity (XXE) issue exists in Restlet 1.1.10 in an endpoint using XML transport, which lets a remote attacker obtain sensitive information.
HIGH
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
[{'url': 'http://www.openwall.com/lists/oss-security/2012/05/29/11', 'source': 'secalert@redhat.com'}, {'url': 'http://www.openwall.com/lists/oss-security/2012/05/29/9', 'source': 'secalert@redhat.com'}, {'url': 'https://access.redhat.com/security/cve/cve-2012-2656', 'source': 'secalert@redhat.com'}, {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-2656', 'source': 'secalert@redhat.com'}, {'url': 'https://security-tracker.debian.org/tracker/CVE-2012-2656', 'source': 'secalert@redhat.com'}, {'url': 'http://www.openwall.com/lists/oss-security/2012/05/29/11', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://www.openwall.com/lists/oss-security/2012/05/29/9', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://access.redhat.com/security/cve/cve-2012-2656', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-2656', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://security-tracker.debian.org/tracker/CVE-2012-2656', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:17:54.689702+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://security-tracker.debian.org/tracker/CVE-2012-2656', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-2656', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://access.redhat.com/security/cve/cve-2012-2656', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.openwall.com/lists/oss-security/2012/05/29/9', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.openwall.com/lists/oss-security/2012/05/29/11', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-06T19:42:32.418Z'}}], 'cna': {'affected': [{'vendor': 'www.restlet.org/', 'product': 'Restlet', 'versions': [{'status': 'affected', 'version': '1.1.10'}]}], 'datePublic': '2010-09-11T00:00:00.000Z', 'references': [{'url': 'https://security-tracker.debian.org/tracker/CVE-2012-2656', 'tags': ['x_refsource_MISC']}, {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-2656', 'tags': ['x_refsource_MISC']}, {'url': 'https://access.redhat.com/security/cve/cve-2012-2656', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.openwall.com/lists/oss-security/2012/05/29/9', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.openwall.com/lists/oss-security/2012/05/29/11', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'An XML eXternal Entity (XXE) issue exists in Restlet 1.1.10 in an endpoint using XML transport, which lets a remote attacker obtain sensitive information.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'vulnerability in Restlet'}]}], 'providerMetadata': {'orgId': '53f830b8-0a3f-465b-8143-3b8a9948e749', 'shortName': 'redhat', 'dateUpdated': '2019-12-18T18:16:54.000Z'}}}, 'cveMetadata': {'cveId': 'CVE-2012-2656', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-06T19:42:32.418Z', 'dateReserved': '2012-05-14T00:00:00.000Z', 'assignerOrgId': '53f830b8-0a3f-465b-8143-3b8a9948e749', 'datePublished': '2019-12-18T18:16:54.000Z', 'assignerShortName': 'redhat'}, 'dataVersion': '5.1'}
{'id': 'CVE-2012-2656', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 5.0, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:P/I:N/A:N', 'authentication': 'NONE', 'integrityImpact': 'NONE', 'accessComplexity': 'LOW', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 10.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 3.6, 'exploitabilityScore': 3.9}]}, 'affected': [{'source': 'secalert@redhat.com', 'affectedData': [{'vendor': 'www.restlet.org/', 'product': 'Restlet', 'versions': [{'status': 'affected', 'version': '1.1.10'}]}]}], 'published': '2019-12-18T19:15:11.593', 'references': [{'url': 'http://www.openwall.com/lists/oss-security/2012/05/29/11', 'tags': ['Mailing List', 'Patch', 'Third Party Advisory'], 'source': 'secalert@redhat.com'}, {'url': 'http://www.openwall.com/lists/oss-security/2012/05/29/9', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'secalert@redhat.com'}, {'url': 'https://access.redhat.com/security/cve/cve-2012-2656', 'tags': ['Third Party Advisory'], 'source': 'secalert@redhat.com'}, {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-2656', 'tags': ['Issue Tracking', 'Third Party Advisory'], 'source': 'secalert@redhat.com'}, {'url': 'https://security-tracker.debian.org/tracker/CVE-2012-2656', 'tags': ['Third Party Advisory'], 'source': 'secalert@redhat.com'}, {'url': 'http://www.openwall.com/lists/oss-security/2012/05/29/11', 'tags': ['Mailing List', 'Patch', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://www.openwall.com/lists/oss-security/2012/05/29/9', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://access.redhat.com/security/cve/cve-2012-2656', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-2656', 'tags': ['Issue Tracking', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://security-tracker.debian.org/tracker/CVE-2012-2656', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-611'}]}], 'descriptions': [{'lang': 'en', 'value': 'An XML eXternal Entity (XXE) issue exists in Restlet 1.1.10 in an endpoint using XML transport, which lets a remote attacker obtain sensitive information.'}, {'lang': 'es', 'value': 'Se presenta un problema de XML eXternal Entity (XXE) en Restlet versión 1.1.10 en un endpoint que utiliza transporte XML, lo que permite a un atacante remoto obtener información confidencial.'}], 'lastModified': '2026-06-16T23:41:49.260', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:talend:restlet:1.1.10:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'CE5E88AC-6B7E-4E12-8889-424D70E4F174'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'secalert@redhat.com'}
CVE-2019-19844
2019-12-18 21:07:11+03:00
2026-06-17 02:27:20.267000+03:00
PUBLISHED
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of Unicode characters) would allow an attacker to be sent a password reset token for the matched user account. (One mitigation in the new releases is to send password reset tokens only to the registered user email address.)
CRITICAL
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
[{'url': 'http://packetstormsecurity.com/files/155872/Django-Account-Hijack.html', 'source': 'cve@mitre.org'}, {'url': 'https://docs.djangoproject.com/en/dev/releases/security/', 'source': 'cve@mitre.org'}, {'url': 'https://groups.google.com/forum/#%21topic/django-announce/3oaB2rVH3a0', 'source': 'cve@mitre.org'}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCM2DPUI7TOZWN4A6JFQFUVQ2XGE7GUD/', 'source': 'cve@mitre.org'}, {'url': 'https://seclists.org/bugtraq/2020/Jan/9', 'source': 'cve@mitre.org'}, {'url': 'https://security.gentoo.org/glsa/202004-17', 'source': 'cve@mitre.org'}, {'url': 'https://security.netapp.com/advisory/ntap-20200110-0003/', 'source': 'cve@mitre.org'}, {'url': 'https://usn.ubuntu.com/4224-1/', 'source': 'cve@mitre.org'}, {'url': 'https://www.debian.org/security/2020/dsa-4598', 'source': 'cve@mitre.org'}, {'url': 'https://www.djangoproject.com/weblog/2019/dec/18/security-releases/', 'source': 'cve@mitre.org'}, {'url': 'http://packetstormsecurity.com/files/155872/Django-Account-Hijack.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://docs.djangoproject.com/en/dev/releases/security/', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://groups.google.com/forum/#%21topic/django-announce/3oaB2rVH3a0', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCM2DPUI7TOZWN4A6JFQFUVQ2XGE7GUD/', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://seclists.org/bugtraq/2020/Jan/9', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://security.gentoo.org/glsa/202004-17', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://security.netapp.com/advisory/ntap-20200110-0003/', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://usn.ubuntu.com/4224-1/', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://www.debian.org/security/2020/dsa-4598', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://www.djangoproject.com/weblog/2019/dec/18/security-releases/', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:15.698920+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://docs.djangoproject.com/en/dev/releases/security/', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://groups.google.com/forum/#%21topic/django-announce/3oaB2rVH3a0', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://www.djangoproject.com/weblog/2019/dec/18/security-releases/', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'https://usn.ubuntu.com/4224-1/', 'name': 'USN-4224-1', 'tags': ['vendor-advisory', 'x_refsource_UBUNTU', 'x_transferred']}, {'url': 'https://www.debian.org/security/2020/dsa-4598', 'name': 'DSA-4598', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN', 'x_transferred']}, {'url': 'https://seclists.org/bugtraq/2020/Jan/9', 'name': '20200108 [SECURITY] [DSA 4598-1] python-django security update', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://packetstormsecurity.com/files/155872/Django-Account-Hijack.html', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://security.netapp.com/advisory/ntap-20200110-0003/', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCM2DPUI7TOZWN4A6JFQFUVQ2XGE7GUD/', 'name': 'FEDORA-2020-adb4f0143a', 'tags': ['vendor-advisory', 'x_refsource_FEDORA', 'x_transferred']}, {'url': 'https://security.gentoo.org/glsa/202004-17', 'name': 'GLSA-202004-17', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-05T02:25:12.834Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://docs.djangoproject.com/en/dev/releases/security/', 'tags': ['x_refsource_MISC']}, {'url': 'https://groups.google.com/forum/#%21topic/django-announce/3oaB2rVH3a0', 'tags': ['x_refsource_MISC']}, {'url': 'https://www.djangoproject.com/weblog/2019/dec/18/security-releases/', 'tags': ['x_refsource_CONFIRM']}, {'url': 'https://usn.ubuntu.com/4224-1/', 'name': 'USN-4224-1', 'tags': ['vendor-advisory', 'x_refsource_UBUNTU']}, {'url': 'https://www.debian.org/security/2020/dsa-4598', 'name': 'DSA-4598', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN']}, {'url': 'https://seclists.org/bugtraq/2020/Jan/9', 'name': '20200108 [SECURITY] [DSA 4598-1] python-django security update', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://packetstormsecurity.com/files/155872/Django-Account-Hijack.html', 'tags': ['x_refsource_MISC']}, {'url': 'https://security.netapp.com/advisory/ntap-20200110-0003/', 'tags': ['x_refsource_CONFIRM']}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCM2DPUI7TOZWN4A6JFQFUVQ2XGE7GUD/', 'name': 'FEDORA-2020-adb4f0143a', 'tags': ['vendor-advisory', 'x_refsource_FEDORA']}, {'url': 'https://security.gentoo.org/glsa/202004-17', 'name': 'GLSA-202004-17', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}], 'descriptions': [{'lang': 'en', 'value': "Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of Unicode characters) would allow an attacker to be sent a password reset token for the matched user account. (One mitigation in the new releases is to send password reset tokens only to the registered user email address.)"}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2020-05-01T01:06:13.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://docs.djangoproject.com/en/dev/releases/security/', 'name': 'https://docs.djangoproject.com/en/dev/releases/security/', 'refsource': 'MISC'}, {'url': 'https://groups.google.com/forum/#!topic/django-announce/3oaB2rVH3a0', 'name': 'https://groups.google.com/forum/#!topic/django-announce/3oaB2rVH3a0', 'refsource': 'MISC'}, {'url': 'https://www.djangoproject.com/weblog/2019/dec/18/security-releases/', 'name': 'https://www.djangoproject.com/weblog/2019/dec/18/security-releases/', 'refsource': 'CONFIRM'}, {'url': 'https://usn.ubuntu.com/4224-1/', 'name': 'USN-4224-1', 'refsource': 'UBUNTU'}, {'url': 'https://www.debian.org/security/2020/dsa-4598', 'name': 'DSA-4598', 'refsource': 'DEBIAN'}, {'url': 'https://seclists.org/bugtraq/2020/Jan/9', 'name': '20200108 [SECURITY] [DSA 4598-1] python-django security update', 'refsource': 'BUGTRAQ'}, {'url': 'http://packetstormsecurity.com/files/155872/Django-Account-Hijack.html', 'name': 'http://packetstormsecurity.com/files/155872/Django-Account-Hijack.html', 'refsource': 'MISC'}, {'url': 'https://security.netapp.com/advisory/ntap-20200110-0003/', 'name': 'https://security.netapp.com/advisory/ntap-20200110-0003/', 'refsource': 'CONFIRM'}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HCM2DPUI7TOZWN4A6JFQFUVQ2XGE7GUD/', 'name': 'FEDORA-2020-adb4f0143a', 'refsource': 'FEDORA'}, {'url': 'https://security.gentoo.org/glsa/202004-17', 'name': 'GLSA-202004-17', 'refsource': 'GENTOO'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': "Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of Unicode characters) would allow an attacker to be sent a password reset token for the matched user account. (One mitigation in the new releases is to send password reset tokens only to the registered user email address.)"}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-19844', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-19844', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-05T02:25:12.834Z', 'dateReserved': '2019-12-17T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2019-12-18T18:07:11.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-19844', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 5.0, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:N/I:P/A:N', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'LOW', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'NONE'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 10.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 3.9}]}, 'affected': [{'source': 'cve@mitre.org', 'affectedData': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}]}], 'published': '2019-12-18T19:15:11.780', 'references': [{'url': 'http://packetstormsecurity.com/files/155872/Django-Account-Hijack.html', 'source': 'cve@mitre.org'}, {'url': 'https://docs.djangoproject.com/en/dev/releases/security/', 'tags': ['Vendor Advisory'], 'source': 'cve@mitre.org'}, {'url': 'https://groups.google.com/forum/#%21topic/django-announce/3oaB2rVH3a0', 'source': 'cve@mitre.org'}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCM2DPUI7TOZWN4A6JFQFUVQ2XGE7GUD/', 'source': 'cve@mitre.org'}, {'url': 'https://seclists.org/bugtraq/2020/Jan/9', 'source': 'cve@mitre.org'}, {'url': 'https://security.gentoo.org/glsa/202004-17', 'source': 'cve@mitre.org'}, {'url': 'https://security.netapp.com/advisory/ntap-20200110-0003/', 'source': 'cve@mitre.org'}, {'url': 'https://usn.ubuntu.com/4224-1/', 'tags': ['Third Party Advisory'], 'source': 'cve@mitre.org'}, {'url': 'https://www.debian.org/security/2020/dsa-4598', 'source': 'cve@mitre.org'}, {'url': 'https://www.djangoproject.com/weblog/2019/dec/18/security-releases/', 'tags': ['Vendor Advisory'], 'source': 'cve@mitre.org'}, {'url': 'http://packetstormsecurity.com/files/155872/Django-Account-Hijack.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://docs.djangoproject.com/en/dev/releases/security/', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://groups.google.com/forum/#%21topic/django-announce/3oaB2rVH3a0', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCM2DPUI7TOZWN4A6JFQFUVQ2XGE7GUD/', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://seclists.org/bugtraq/2020/Jan/9', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://security.gentoo.org/glsa/202004-17', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://security.netapp.com/advisory/ntap-20200110-0003/', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://usn.ubuntu.com/4224-1/', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://www.debian.org/security/2020/dsa-4598', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://www.djangoproject.com/weblog/2019/dec/18/security-releases/', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-640'}]}], 'descriptions': [{'lang': 'en', 'value': "Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of Unicode characters) would allow an attacker to be sent a password reset token for the matched user account. (One mitigation in the new releases is to send password reset tokens only to the registered user email address.)"}, {'lang': 'es', 'value': 'Django versiones anteriores a 1.11.27, versiones 2.x anteriores a 2.2.9 y versiones 3.x anteriores a 3.0.1, permite tomar el control de la cuenta. Una dirección de correo electrónico diseñada adecuadamente (que es igual a la dirección de correo electrónico de un usuario existente después de la transformación de mayúsculas y minúsculas de los caracteres Unicode) permitiría a un atacante enviarle un token de restablecimiento de contraseña para la cuenta de usuario coincidente. (Una mitigación en las nuevas versiones es enviar tokens de restablecimiento de contraseña solo a la dirección de correo electrónico del usuario registrado).'}], 'lastModified': '2026-06-17T02:27:20.267', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'B19BDC93-017C-444E-BE89-E5951564C6F1', 'versionEndExcluding': '1.11.27'}, {'criteria': 'cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '72FE3431-6956-4197-B0B7-9263888FF1FC', 'versionEndExcluding': '2.2.9', 'versionStartIncluding': '2.2'}, {'criteria': 'cpe:2.3:a:djangoproject:django:3.0:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'C23D9FE4-31F5-4A23-916E-8EC763886DC9'}], 'operator': 'OR'}]}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'F7016A2A-8365-4F1A-89A2-7A19F2BCAE5B'}, {'criteria': 'cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*', 'vulnerable': True, 'matchCriteriaId': '23A7C53F-B80F-4E6A-AFA9-58EEA84BE11D'}, {'criteria': 'cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'CD783B0C-9246-47D9-A937-6144FE8BFF0F'}, {'criteria': 'cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A31C8344-3E02-4EB8-8BD8-4C84B7959624'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'cve@mitre.org'}
CVE-2019-19887
2019-12-18 21:40:43+03:00
2026-06-17 02:27:23.793000+03:00
PUBLISHED
bitstr_tell at bitstr.c in ffjpeg through 2019-08-21 has a NULL pointer dereference related to jfif_encode.
MEDIUM
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
[{'url': 'https://github.com/rockcarry/ffjpeg/issues/14', 'source': 'cve@mitre.org'}, {'url': 'https://github.com/rockcarry/ffjpeg/issues/14', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:15.937311+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://github.com/rockcarry/ffjpeg/issues/14', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-05T02:32:09.358Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://github.com/rockcarry/ffjpeg/issues/14', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'bitstr_tell at bitstr.c in ffjpeg through 2019-08-21 has a NULL pointer dereference related to jfif_encode.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2019-12-18T18:40:43.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://github.com/rockcarry/ffjpeg/issues/14', 'name': 'https://github.com/rockcarry/ffjpeg/issues/14', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'bitstr_tell at bitstr.c in ffjpeg through 2019-08-21 has a NULL pointer dereference related to jfif_encode.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-19887', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-19887', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-05T02:32:09.358Z', 'dateReserved': '2019-12-18T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2019-12-18T18:40:43.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-19887', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 4.3, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:N/I:N/A:P', 'authentication': 'NONE', 'integrityImpact': 'NONE', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'NONE'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}, 'impactScore': 3.6, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'cve@mitre.org', 'affectedData': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}]}], 'published': '2019-12-18T19:15:11.843', 'references': [{'url': 'https://github.com/rockcarry/ffjpeg/issues/14', 'tags': ['Exploit', 'Third Party Advisory'], 'source': 'cve@mitre.org'}, {'url': 'https://github.com/rockcarry/ffjpeg/issues/14', 'tags': ['Exploit', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-476'}]}], 'descriptions': [{'lang': 'en', 'value': 'bitstr_tell at bitstr.c in ffjpeg through 2019-08-21 has a NULL pointer dereference related to jfif_encode.'}, {'lang': 'es', 'value': 'La función bitstr_tell en el archivo bitstr.c en ffjpeg hasta 21-08-2019, presenta una desreferencia del puntero NULL relacionada con jfif_encode.'}], 'lastModified': '2026-06-17T02:27:23.793', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:rockcarry:ffjpeg:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '5D9E7EB6-DB1F-4806-AFFE-531905453943', 'versionEndIncluding': '2019-08-21'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'cve@mitre.org'}
CVE-2019-19888
2019-12-18 21:40:33+03:00
2026-06-17 02:27:23.900000+03:00
PUBLISHED
jfif_decode in jfif.c in ffjpeg through 2019-08-21 has a divide-by-zero error.
MEDIUM
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
[{'url': 'https://github.com/rockcarry/ffjpeg/issues/13', 'source': 'cve@mitre.org'}, {'url': 'https://github.com/rockcarry/ffjpeg/issues/13', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:15.937311+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://github.com/rockcarry/ffjpeg/issues/13', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-05T02:32:09.288Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://github.com/rockcarry/ffjpeg/issues/13', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'jfif_decode in jfif.c in ffjpeg through 2019-08-21 has a divide-by-zero error.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2019-12-18T18:40:33.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://github.com/rockcarry/ffjpeg/issues/13', 'name': 'https://github.com/rockcarry/ffjpeg/issues/13', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'jfif_decode in jfif.c in ffjpeg through 2019-08-21 has a divide-by-zero error.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-19888', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-19888', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-05T02:32:09.288Z', 'dateReserved': '2019-12-18T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2019-12-18T18:40:33.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-19888', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 4.3, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:N/I:N/A:P', 'authentication': 'NONE', 'integrityImpact': 'NONE', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'NONE'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}, 'impactScore': 3.6, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'cve@mitre.org', 'affectedData': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}]}], 'published': '2019-12-18T19:15:11.937', 'references': [{'url': 'https://github.com/rockcarry/ffjpeg/issues/13', 'tags': ['Exploit', 'Third Party Advisory'], 'source': 'cve@mitre.org'}, {'url': 'https://github.com/rockcarry/ffjpeg/issues/13', 'tags': ['Exploit', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-369'}]}], 'descriptions': [{'lang': 'en', 'value': 'jfif_decode in jfif.c in ffjpeg through 2019-08-21 has a divide-by-zero error.'}, {'lang': 'es', 'value': 'La función jfif_decode en el archivo jfif.c en ffjpeg hasta 21-08-2019, presenta un error de división por cero.'}], 'lastModified': '2026-06-17T02:27:23.900', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:rockcarry:ffjpeg:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '5D9E7EB6-DB1F-4806-AFFE-531905453943', 'versionEndIncluding': '2019-08-21'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'cve@mitre.org'}
CVE-2022-42289
2023-01-13 05:09:44.143000+03:00
2026-06-17 05:04:39.580000+03:00
PUBLISHED
NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering.
HIGH
7.2
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
[{'url': 'https://nvidia.custhelp.com/app/answers/detail/a_id/5435', 'source': 'psirt@nvidia.com'}, {'url': 'https://nvidia.custhelp.com/app/answers/detail/a_id/5435', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:17:20.066418+03:00
2026-06-27 08:26:40.077172+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://nvidia.custhelp.com/app/answers/detail/a_id/5435', 'tags': ['x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-03T13:03:45.915Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'other': {'type': 'ssvc', 'content': {'id': 'CVE-2022-42289', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-04-07T17:52:55.655024Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-04-07T17:55:58.137Z'}}], 'cna': {'source': {'discovery': 'UNKNOWN'}, 'impacts': [{'descriptions': [{'lang': 'en', 'value': 'Code Execution, Denial of Service, Information Disclosure, Data Tampering'}]}], 'metrics': [{'format': 'CVSS', 'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.2, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'scenarios': [{'lang': 'en', 'value': 'GENERAL'}]}], 'affected': [{'vendor': 'NVIDIA', 'product': 'NVIDIA DGX servers', 'versions': [{'status': 'affected', 'version': 'All BMC firmware versions prior to 00.19.07'}], 'defaultStatus': 'unaffected'}], 'references': [{'url': 'https://nvidia.custhelp.com/app/answers/detail/a_id/5435'}], 'x_generator': {'engine': 'Vulnogram 0.1.0-dev'}, 'descriptions': [{'lang': 'en', 'value': 'NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering.', 'supportingMedia': [{'type': 'text/html', 'value': 'NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering.', 'base64': True}]}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-78', 'description': "CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}]}], 'providerMetadata': {'orgId': '9576f279-3576-44b5-a4af-b9a8644b2de6', 'shortName': 'nvidia', 'dateUpdated': '2023-01-13T02:09:44.143Z'}}}, 'cveMetadata': {'cveId': 'CVE-2022-42289', 'state': 'PUBLISHED', 'dateUpdated': '2025-04-07T17:55:58.137Z', 'dateReserved': '2022-10-03T14:20:26.208Z', 'assignerOrgId': '9576f279-3576-44b5-a4af-b9a8644b2de6', 'datePublished': '2023-01-13T02:09:44.143Z', 'assignerShortName': 'nvidia'}, 'dataVersion': '5.1'}
{'id': 'CVE-2022-42289', 'cveTags': [], 'metrics': {'ssvcV203': [{'source': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'ssvcData': {'id': 'CVE-2022-42289', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-04-07T17:52:55.655024Z'}}], 'cvssMetricV31': [{'type': 'Secondary', 'source': 'psirt@nvidia.com', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.2, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 1.2}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'psirt@nvidia.com', 'affectedData': [{'vendor': 'NVIDIA', 'product': 'NVIDIA DGX servers', 'versions': [{'status': 'affected', 'version': 'All BMC firmware versions prior to 00.19.07'}], 'defaultStatus': 'unaffected'}]}], 'published': '2023-01-13T04:15:08.730', 'references': [{'url': 'https://nvidia.custhelp.com/app/answers/detail/a_id/5435', 'tags': ['Vendor Advisory'], 'source': 'psirt@nvidia.com'}, {'url': 'https://nvidia.custhelp.com/app/answers/detail/a_id/5435', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Secondary', 'source': 'psirt@nvidia.com', 'description': [{'lang': 'en', 'value': 'CWE-78'}]}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-78'}]}], 'descriptions': [{'lang': 'en', 'value': 'NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering.'}, {'lang': 'es', 'value': 'NVIDIA BMC contiene una vulnerabilidad en SPX REST API, donde un atacante autorizado puede inyectar comandos de shell arbitrarios, lo que puede provocar la ejecución de código, denegación de servicio, divulgación de información y manipulación de datos.'}], 'lastModified': '2026-06-17T05:04:39.580', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:nvidia:dgx_a100_firmware:*:*:*:*:bmc:*:*:*', 'vulnerable': True, 'matchCriteriaId': '063DAD57-7DC7-46E6-A5C6-B4D1A3CE7F19', 'versionEndExcluding': '00.19.07'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:nvidia:dgx_a100:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '8807CB65-5F49-42E8-B5D8-36943418ADB9'}], 'operator': 'OR'}], 'operator': 'AND'}], 'sourceIdentifier': 'psirt@nvidia.com'}
CVE-2024-53009
2025-07-08 15:48:44.614000+03:00
2026-06-17 08:08:00.890000+03:00
PUBLISHED
Memory corruption while operating the mailbox in Automotive.
MEDIUM
5.3
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
[{'url': 'https://docs.qualcomm.com/product/publicresources/securitybulletin/july-2025-bulletin.html', 'source': 'product-security@qualcomm.com'}]
cve.org
2026-05-27 22:17:47.633020+03:00
2026-06-27 08:27:50.412724+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CISA ADP Vulnrichment', 'metrics': [{'other': {'type': 'ssvc', 'content': {'id': 'CVE-2024-53009', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-07-08T14:25:26.872348Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-07-08T16:11:19.907Z'}}], 'cna': {'title': 'Improper Validation of Array Index in Automotive Autonomy', 'metrics': [{'format': 'CVSS', 'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'LOW'}, 'scenarios': [{'lang': 'en', 'value': 'GENERAL'}]}], 'affected': [{'vendor': 'Qualcomm, Inc.', 'product': 'Snapdragon', 'versions': [{'status': 'affected', 'version': 'AQT1000'}, {'status': 'affected', 'version': 'AR8035'}, {'status': 'affected', 'version': 'FastConnect 6200'}, {'status': 'affected', 'version': 'FastConnect 6700'}, {'status': 'affected', 'version': 'FastConnect 6800'}, {'status': 'affected', 'version': 'FastConnect 6900'}, {'status': 'affected', 'version': 'FastConnect 7800'}, {'status': 'affected', 'version': 'QAM8255P'}, {'status': 'affected', 'version': 'QAM8295P'}, {'status': 'affected', 'version': 'QAM8620P'}, {'status': 'affected', 'version': 'QAM8650P'}, {'status': 'affected', 'version': 'QAM8775P'}, {'status': 'affected', 'version': 'QAMSRV1H'}, {'status': 'affected', 'version': 'QAMSRV1M'}, {'status': 'affected', 'version': 'QCA6174A'}, {'status': 'affected', 'version': 'QCA6310'}, {'status': 'affected', 'version': 'QCA6335'}, {'status': 'affected', 'version': 'QCA6391'}, {'status': 'affected', 'version': 'QCA6420'}, {'status': 'affected', 'version': 'QCA6421'}, {'status': 'affected', 'version': 'QCA6426'}, {'status': 'affected', 'version': 'QCA6430'}, {'status': 'affected', 'version': 'QCA6431'}, {'status': 'affected', 'version': 'QCA6436'}, {'status': 'affected', 'version': 'QCA6564A'}, {'status': 'affected', 'version': 'QCA6564AU'}, {'status': 'affected', 'version': 'QCA6574'}, {'status': 'affected', 'version': 'QCA6574A'}, {'status': 'affected', 'version': 'QCA6574AU'}, {'status': 'affected', 'version': 'QCA6584AU'}, {'status': 'affected', 'version': 'QCA6595'}, {'status': 'affected', 'version': 'QCA6595AU'}, {'status': 'affected', 'version': 'QCA6678AQ'}, {'status': 'affected', 'version': 'QCA6688AQ'}, {'status': 'affected', 'version': 'QCA6696'}, {'status': 'affected', 'version': 'QCA6698AQ'}, {'status': 'affected', 'version': 'QCA6698AU'}, {'status': 'affected', 'version': 'QCA6797AQ'}, {'status': 'affected', 'version': 'QCA8081'}, {'status': 'affected', 'version': 'QCA8337'}, {'status': 'affected', 'version': 'QCA9377'}, {'status': 'affected', 'version': 'QCC710'}, {'status': 'affected', 'version': 'QCM5430'}, {'status': 'affected', 'version': 'QCM6490'}, {'status': 'affected', 'version': 'QCM8550'}, {'status': 'affected', 'version': 'QCN6224'}, {'status': 'affected', 'version': 'QCN6274'}, {'status': 'affected', 'version': 'QCN9011'}, {'status': 'affected', 'version': 'QCN9012'}, {'status': 'affected', 'version': 'QCN9274'}, {'status': 'affected', 'version': 'QCS5430'}, {'status': 'affected', 'version': 'QCS615'}, {'status': 'affected', 'version': 'QCS6490'}, {'status': 'affected', 'version': 'QCS8300'}, {'status': 'affected', 'version': 'QCS8550'}, {'status': 'affected', 'version': 'QCS9100'}, {'status': 'affected', 'version': 'QDU1000'}, {'status': 'affected', 'version': 'QDU1010'}, {'status': 'affected', 'version': 'QDU1110'}, {'status': 'affected', 'version': 'QDU1210'}, {'status': 'affected', 'version': 'QDX1010'}, {'status': 'affected', 'version': 'QDX1011'}, {'status': 'affected', 'version': 'QEP8111'}, {'status': 'affected', 'version': 'QFW7114'}, {'status': 'affected', 'version': 'QFW7124'}, {'status': 'affected', 'version': 'QMP1000'}, {'status': 'affected', 'version': 'QRU1032'}, {'status': 'affected', 'version': 'QRU1052'}, {'status': 'affected', 'version': 'QRU1062'}, {'status': 'affected', 'version': 'QSM8350'}, {'status': 'affected', 'version': 'Qualcomm Video Collaboration VC3 Platform'}, {'status': 'affected', 'version': 'Robotics RB3 Platform'}, {'status': 'affected', 'version': 'SA6145P'}, {'status': 'affected', 'version': 'SA6150P'}, {'status': 'affected', 'version': 'SA6155'}, {'status': 'affected', 'version': 'SA6155P'}, {'status': 'affected', 'version': 'SA7255P'}, {'status': 'affected', 'version': 'SA7775P'}, {'status': 'affected', 'version': 'SA8145P'}, {'status': 'affected', 'version': 'SA8150P'}, {'status': 'affected', 'version': 'SA8155'}, {'status': 'affected', 'version': 'SA8155P'}, {'status': 'affected', 'version': 'SA8195P'}, {'status': 'affected', 'version': 'SA8255P'}, {'status': 'affected', 'version': 'SA8295P'}, {'status': 'affected', 'version': 'SA8530P'}, {'status': 'affected', 'version': 'SA8540P'}, {'status': 'affected', 'version': 'SA8620P'}, {'status': 'affected', 'version': 'SA8650P'}, {'status': 'affected', 'version': 'SA8770P'}, {'status': 'affected', 'version': 'SA8775P'}, {'status': 'affected', 'version': 'SA9000P'}, {'status': 'affected', 'version': 'SC8380XP'}, {'status': 'affected', 'version': 'SD 675'}, {'status': 'affected', 'version': 'SD 8 Gen1 5G'}, {'status': 'affected', 'version': 'SD 8CX'}, {'status': 'affected', 'version': 'SD670'}, {'status': 'affected', 'version': 'SD675'}, {'status': 'affected', 'version': 'SD855'}, {'status': 'affected', 'version': 'SD865 5G'}, {'status': 'affected', 'version': 'SDX55'}, {'status': 'affected', 'version': 'SDX57M'}, {'status': 'affected', 'version': 'SDX80M'}, {'status': 'affected', 'version': 'SG8275P'}, {'status': 'affected', 'version': 'SM4635'}, {'status': 'affected', 'version': 'SM7250P'}, {'status': 'affected', 'version': 'SM8550P'}, {'status': 'affected', 'version': 'SM8735'}, {'status': 'affected', 'version': 'SM8750'}, {'status': 'affected', 'version': 'SM8750P'}, {'status': 'affected', 'version': 'Snapdragon 670 Mobile Platform'}, {'status': 'affected', 'version': 'Snapdragon 675 Mobile Platform'}, {'status': 'affected', 'version': 'Snapdragon 678 Mobile Platform (SM6150-AC)'}, {'status': 'affected', 'version': 'Snapdragon 765 5G Mobile Platform (SM7250-AA)'}, {'status': 'affected', 'version': 'Snapdragon 765G 5G Mobile Platform (SM7250-AB)'}, {'status': 'affected', 'version': 'Snapdragon 768G 5G Mobile Platform (SM7250-AC)'}, {'status': 'affected', 'version': 'Snapdragon 8 Gen 1 Mobile Platform'}, {'status': 'affected', 'version': 'Snapdragon 8 Gen 2 Mobile Platform'}, {'status': 'affected', 'version': 'Snapdragon 8 Gen 3 Mobile Platform'}, {'status': 'affected', 'version': 'Snapdragon 8+ Gen 2 Mobile Platform'}, {'status': 'affected', 'version': 'Snapdragon 845 Mobile Platform'}, {'status': 'affected', 'version': 'Snapdragon 850 Mobile Compute Platform'}, {'status': 'affected', 'version': 'Snapdragon 855 Mobile Platform'}, {'status': 'affected', 'version': 'Snapdragon 855+/860 Mobile Platform (SM8150-AC)'}, {'status': 'affected', 'version': 'Snapdragon 865 5G Mobile Platform'}, {'status': 'affected', 'version': 'Snapdragon 865+ 5G Mobile Platform (SM8250-AB)'}, {'status': 'affected', 'version': 'Snapdragon 870 5G Mobile Platform (SM8250-AC)'}, {'status': 'affected', 'version': 'Snapdragon 888 5G Mobile Platform'}, {'status': 'affected', 'version': 'Snapdragon 888+ 5G Mobile Platform (SM8350-AC)'}, {'status': 'affected', 'version': 'Snapdragon 8c Compute Platform (SC8180X-AD) "Poipu Lite"'}, {'status': 'affected', 'version': 'Snapdragon 8c Compute Platform (SC8180XP-AD) "Poipu Lite"'}, {'status': 'affected', 'version': 'Snapdragon 8cx Compute Platform (SC8180X-AA, AB)'}, {'status': 'affected', 'version': 'Snapdragon 8cx Compute Platform (SC8180XP-AC, AF) "Poipu Pro"'}, {'status': 'affected', 'version': 'Snapdragon 8cx Gen 2 5G Compute Platform (SC8180X-AC, AF) "Poipu Pro"'}, {'status': 'affected', 'version': 'Snapdragon 8cx Gen 2 5G Compute Platform (SC8180XP-AA, AB)'}, {'status': 'affected', 'version': 'Snapdragon 8cx Gen 3 Compute Platform (SC8280XP-AB, BB)'}, {'status': 'affected', 'version': 'Snapdragon AR1 Gen 1 Platform'}, {'status': 'affected', 'version': 'Snapdragon AR1 Gen 1 Platform "Luna1"'}, {'status': 'affected', 'version': 'Snapdragon AR2 Gen 1 Platform'}, {'status': 'affected', 'version': 'Snapdragon Auto 5G Modem-RF Gen 2'}, {'status': 'affected', 'version': 'Snapdragon X24 LTE Modem'}, {'status': 'affected', 'version': 'Snapdragon X32 5G Modem-RF System'}, {'status': 'affected', 'version': 'Snapdragon X35 5G Modem-RF System'}, {'status': 'affected', 'version': 'Snapdragon X50 5G Modem-RF System'}, {'status': 'affected', 'version': 'Snapdragon X55 5G Modem-RF System'}, {'status': 'affected', 'version': 'Snapdragon X62 5G Modem-RF System'}, {'status': 'affected', 'version': 'Snapdragon X65 5G Modem-RF System'}, {'status': 'affected', 'version': 'Snapdragon X72 5G Modem-RF System'}, {'status': 'affected', 'version': 'Snapdragon X75 5G Modem-RF System'}, {'status': 'affected', 'version': 'Snapdragon XR2 5G Platform'}, {'status': 'affected', 'version': 'SRV1H'}, {'status': 'affected', 'version': 'SRV1L'}, {'status': 'affected', 'version': 'SRV1M'}, {'status': 'affected', 'version': 'SSG2115P'}, {'status': 'affected', 'version': 'SSG2125P'}, {'status': 'affected', 'version': 'SXR1230P'}, {'status': 'affected', 'version': 'SXR2130'}, {'status': 'affected', 'version': 'SXR2230P'}, {'status': 'affected', 'version': 'SXR2250P'}, {'status': 'affected', 'version': 'SXR2330P'}, {'status': 'affected', 'version': 'Vision Intelligence 300 Platform'}, {'status': 'affected', 'version': 'Vision Intelligence 400 Platform'}, {'status': 'affected', 'version': 'WCD9326'}, {'status': 'affected', 'version': 'WCD9340'}, {'status': 'affected', 'version': 'WCD9341'}, {'status': 'affected', 'version': 'WCD9370'}, {'status': 'affected', 'version': 'WCD9375'}, {'status': 'affected', 'version': 'WCD9378'}, {'status': 'affected', 'version': 'WCD9380'}, {'status': 'affected', 'version': 'WCD9385'}, {'status': 'affected', 'version': 'WCD9390'}, {'status': 'affected', 'version': 'WCD9395'}, {'status': 'affected', 'version': 'WCN3950'}, {'status': 'affected', 'version': 'WCN3980'}, {'status': 'affected', 'version': 'WCN3988'}, {'status': 'affected', 'version': 'WCN3990'}, {'status': 'affected', 'version': 'WCN7750'}, {'status': 'affected', 'version': 'WCN7860'}, {'status': 'affected', 'version': 'WCN7861'}, {'status': 'affected', 'version': 'WCN7880'}, {'status': 'affected', 'version': 'WCN7881'}, {'status': 'affected', 'version': 'WSA8810'}, {'status': 'affected', 'version': 'WSA8815'}, {'status': 'affected', 'version': 'WSA8830'}, {'status': 'affected', 'version': 'WSA8832'}, {'status': 'affected', 'version': 'WSA8835'}, {'status': 'affected', 'version': 'WSA8840'}, {'status': 'affected', 'version': 'WSA8845'}, {'status': 'affected', 'version': 'WSA8845H'}], 'platforms': ['Snapdragon Auto', 'Snapdragon CCW', 'Snapdragon Compute', 'Snapdragon Consumer IOT', 'Snapdragon Industrial IOT', 'Snapdragon MDM', 'Snapdragon Mobile', 'Snapdragon Technology'], 'defaultStatus': 'unaffected'}], 'references': [{'url': 'https://docs.qualcomm.com/product/publicresources/securitybulletin/july-2025-bulletin.html'}], 'descriptions': [{'lang': 'en', 'value': 'Memory corruption while operating the mailbox in Automotive.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-129', 'description': 'CWE-129 Improper Validation of Array Index'}]}], 'providerMetadata': {'orgId': '2cfc7d3e-20d3-47ac-8db7-1b7285aff15f', 'shortName': 'qualcomm', 'dateUpdated': '2025-07-08T12:48:44.614Z'}}}, 'cveMetadata': {'cveId': 'CVE-2024-53009', 'state': 'PUBLISHED', 'dateUpdated': '2025-07-08T16:11:19.907Z', 'dateReserved': '2024-11-19T01:01:57.500Z', 'assignerOrgId': '2cfc7d3e-20d3-47ac-8db7-1b7285aff15f', 'datePublished': '2025-07-08T12:48:44.614Z', 'assignerShortName': 'qualcomm'}, 'dataVersion': '5.1'}
{'id': 'CVE-2024-53009', 'cveTags': [], 'metrics': {'ssvcV203': [{'source': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'ssvcData': {'id': 'CVE-2024-53009', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-07-08T14:25:26.872348Z'}}], 'cvssMetricV31': [{'type': 'Secondary', 'source': 'product-security@qualcomm.com', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'LOW'}, 'impactScore': 3.4, 'exploitabilityScore': 1.8}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 1.8}]}, 'affected': [{'source': 'product-security@qualcomm.com', 'affectedData': [{'vendor': 'Qualcomm, Inc.', 'product': 'Snapdragon', 'versions': [{'status': 'affected', 'version': 'AQT1000'}, {'status': 'affected', 'version': 'AR8035'}, {'status': 'affected', 'version': 'FastConnect 6200'}, {'status': 'affected', 'version': 'FastConnect 6700'}, {'status': 'affected', 'version': 'FastConnect 6800'}, {'status': 'affected', 'version': 'FastConnect 6900'}, {'status': 'affected', 'version': 'FastConnect 7800'}, {'status': 'affected', 'version': 'QAM8255P'}, {'status': 'affected', 'version': 'QAM8295P'}, {'status': 'affected', 'version': 'QAM8620P'}, {'status': 'affected', 'version': 'QAM8650P'}, {'status': 'affected', 'version': 'QAM8775P'}, {'status': 'affected', 'version': 'QAMSRV1H'}, {'status': 'affected', 'version': 'QAMSRV1M'}, {'status': 'affected', 'version': 'QCA6174A'}, {'status': 'affected', 'version': 'QCA6310'}, {'status': 'affected', 'version': 'QCA6335'}, {'status': 'affected', 'version': 'QCA6391'}, {'status': 'affected', 'version': 'QCA6420'}, {'status': 'affected', 'version': 'QCA6421'}, {'status': 'affected', 'version': 'QCA6426'}, {'status': 'affected', 'version': 'QCA6430'}, {'status': 'affected', 'version': 'QCA6431'}, {'status': 'affected', 'version': 'QCA6436'}, {'status': 'affected', 'version': 'QCA6564A'}, {'status': 'affected', 'version': 'QCA6564AU'}, {'status': 'affected', 'version': 'QCA6574'}, {'status': 'affected', 'version': 'QCA6574A'}, {'status': 'affected', 'version': 'QCA6574AU'}, {'status': 'affected', 'version': 'QCA6584AU'}, {'status': 'affected', 'version': 'QCA6595'}, {'status': 'affected', 'version': 'QCA6595AU'}, {'status': 'affected', 'version': 'QCA6678AQ'}, {'status': 'affected', 'version': 'QCA6688AQ'}, {'status': 'affected', 'version': 'QCA6696'}, {'status': 'affected', 'version': 'QCA6698AQ'}, {'status': 'affected', 'version': 'QCA6698AU'}, {'status': 'affected', 'version': 'QCA6797AQ'}, {'status': 'affected', 'version': 'QCA8081'}, {'status': 'affected', 'version': 'QCA8337'}, {'status': 'affected', 'version': 'QCA9377'}, {'status': 'affected', 'version': 'QCC710'}, {'status': 'affected', 'version': 'QCM5430'}, {'status': 'affected', 'version': 'QCM6490'}, {'status': 'affected', 'version': 'QCM8550'}, {'status': 'affected', 'version': 'QCN6224'}, {'status': 'affected', 'version': 'QCN6274'}, {'status': 'affected', 'version': 'QCN9011'}, {'status': 'affected', 'version': 'QCN9012'}, {'status': 'affected', 'version': 'QCN9274'}, {'status': 'affected', 'version': 'QCS5430'}, {'status': 'affected', 'version': 'QCS615'}, {'status': 'affected', 'version': 'QCS6490'}, {'status': 'affected', 'version': 'QCS8300'}, {'status': 'affected', 'version': 'QCS8550'}, {'status': 'affected', 'version': 'QCS9100'}, {'status': 'affected', 'version': 'QDU1000'}, {'status': 'affected', 'version': 'QDU1010'}, {'status': 'affected', 'version': 'QDU1110'}, {'status': 'affected', 'version': 'QDU1210'}, {'status': 'affected', 'version': 'QDX1010'}, {'status': 'affected', 'version': 'QDX1011'}, {'status': 'affected', 'version': 'QEP8111'}, {'status': 'affected', 'version': 'QFW7114'}, {'status': 'affected', 'version': 'QFW7124'}, {'status': 'affected', 'version': 'QMP1000'}, {'status': 'affected', 'version': 'QRU1032'}, {'status': 'affected', 'version': 'QRU1052'}, {'status': 'affected', 'version': 'QRU1062'}, {'status': 'affected', 'version': 'QSM8350'}, {'status': 'affected', 'version': 'Qualcomm Video Collaboration VC3 Platform'}, {'status': 'affected', 'version': 'Robotics RB3 Platform'}, {'status': 'affected', 'version': 'SA6145P'}, {'status': 'affected', 'version': 'SA6150P'}, {'status': 'affected', 'version': 'SA6155'}, {'status': 'affected', 'version': 'SA6155P'}, {'status': 'affected', 'version': 'SA7255P'}, {'status': 'affected', 'version': 'SA7775P'}, {'status': 'affected', 'version': 'SA8145P'}, {'status': 'affected', 'version': 'SA8150P'}, {'status': 'affected', 'version': 'SA8155'}, {'status': 'affected', 'version': 'SA8155P'}, {'status': 'affected', 'version': 'SA8195P'}, {'status': 'affected', 'version': 'SA8255P'}, {'status': 'affected', 'version': 'SA8295P'}, {'status': 'affected', 'version': 'SA8530P'}, {'status': 'affected', 'version': 'SA8540P'}, {'status': 'affected', 'version': 'SA8620P'}, {'status': 'affected', 'version': 'SA8650P'}, {'status': 'affected', 'version': 'SA8770P'}, {'status': 'affected', 'version': 'SA8775P'}, {'status': 'affected', 'version': 'SA9000P'}, {'status': 'affected', 'version': 'SC8380XP'}, {'status': 'affected', 'version': 'SD 675'}, {'status': 'affected', 'version': 'SD 8 Gen1 5G'}, {'status': 'affected', 'version': 'SD 8CX'}, {'status': 'affected', 'version': 'SD670'}, {'status': 'affected', 'version': 'SD675'}, {'status': 'affected', 'version': 'SD855'}, {'status': 'affected', 'version': 'SD865 5G'}, {'status': 'affected', 'version': 'SDX55'}, {'status': 'affected', 'version': 'SDX57M'}, {'status': 'affected', 'version': 'SDX80M'}, {'status': 'affected', 'version': 'SG8275P'}, {'status': 'affected', 'version': 'SM4635'}, {'status': 'affected', 'version': 'SM7250P'}, {'status': 'affected', 'version': 'SM8550P'}, {'status': 'affected', 'version': 'SM8735'}, {'status': 'affected', 'version': 'SM8750'}, {'status': 'affected', 'version': 'SM8750P'}, {'status': 'affected', 'version': 'Snapdragon 670 Mobile Platform'}, {'status': 'affected', 'version': 'Snapdragon 675 Mobile Platform'}, {'status': 'affected', 'version': 'Snapdragon 678 Mobile Platform (SM6150-AC)'}, {'status': 'affected', 'version': 'Snapdragon 765 5G Mobile Platform (SM7250-AA)'}, {'status': 'affected', 'version': 'Snapdragon 765G 5G Mobile Platform (SM7250-AB)'}, {'status': 'affected', 'version': 'Snapdragon 768G 5G Mobile Platform (SM7250-AC)'}, {'status': 'affected', 'version': 'Snapdragon 8 Gen 1 Mobile Platform'}, {'status': 'affected', 'version': 'Snapdragon 8 Gen 2 Mobile Platform'}, {'status': 'affected', 'version': 'Snapdragon 8 Gen 3 Mobile Platform'}, {'status': 'affected', 'version': 'Snapdragon 8+ Gen 2 Mobile Platform'}, {'status': 'affected', 'version': 'Snapdragon 845 Mobile Platform'}, {'status': 'affected', 'version': 'Snapdragon 850 Mobile Compute Platform'}, {'status': 'affected', 'version': 'Snapdragon 855 Mobile Platform'}, {'status': 'affected', 'version': 'Snapdragon 855+/860 Mobile Platform (SM8150-AC)'}, {'status': 'affected', 'version': 'Snapdragon 865 5G Mobile Platform'}, {'status': 'affected', 'version': 'Snapdragon 865+ 5G Mobile Platform (SM8250-AB)'}, {'status': 'affected', 'version': 'Snapdragon 870 5G Mobile Platform (SM8250-AC)'}, {'status': 'affected', 'version': 'Snapdragon 888 5G Mobile Platform'}, {'status': 'affected', 'version': 'Snapdragon 888+ 5G Mobile Platform (SM8350-AC)'}, {'status': 'affected', 'version': 'Snapdragon 8c Compute Platform (SC8180X-AD) "Poipu Lite"'}, {'status': 'affected', 'version': 'Snapdragon 8c Compute Platform (SC8180XP-AD) "Poipu Lite"'}, {'status': 'affected', 'version': 'Snapdragon 8cx Compute Platform (SC8180X-AA, AB)'}, {'status': 'affected', 'version': 'Snapdragon 8cx Compute Platform (SC8180XP-AC, AF) "Poipu Pro"'}, {'status': 'affected', 'version': 'Snapdragon 8cx Gen 2 5G Compute Platform (SC8180X-AC, AF) "Poipu Pro"'}, {'status': 'affected', 'version': 'Snapdragon 8cx Gen 2 5G Compute Platform (SC8180XP-AA, AB)'}, {'status': 'affected', 'version': 'Snapdragon 8cx Gen 3 Compute Platform (SC8280XP-AB, BB)'}, {'status': 'affected', 'version': 'Snapdragon AR1 Gen 1 Platform'}, {'status': 'affected', 'version': 'Snapdragon AR1 Gen 1 Platform "Luna1"'}, {'status': 'affected', 'version': 'Snapdragon AR2 Gen 1 Platform'}, {'status': 'affected', 'version': 'Snapdragon Auto 5G Modem-RF Gen 2'}, {'status': 'affected', 'version': 'Snapdragon X24 LTE Modem'}, {'status': 'affected', 'version': 'Snapdragon X32 5G Modem-RF System'}, {'status': 'affected', 'version': 'Snapdragon X35 5G Modem-RF System'}, {'status': 'affected', 'version': 'Snapdragon X50 5G Modem-RF System'}, {'status': 'affected', 'version': 'Snapdragon X55 5G Modem-RF System'}, {'status': 'affected', 'version': 'Snapdragon X62 5G Modem-RF System'}, {'status': 'affected', 'version': 'Snapdragon X65 5G Modem-RF System'}, {'status': 'affected', 'version': 'Snapdragon X72 5G Modem-RF System'}, {'status': 'affected', 'version': 'Snapdragon X75 5G Modem-RF System'}, {'status': 'affected', 'version': 'Snapdragon XR2 5G Platform'}, {'status': 'affected', 'version': 'SRV1H'}, {'status': 'affected', 'version': 'SRV1L'}, {'status': 'affected', 'version': 'SRV1M'}, {'status': 'affected', 'version': 'SSG2115P'}, {'status': 'affected', 'version': 'SSG2125P'}, {'status': 'affected', 'version': 'SXR1230P'}, {'status': 'affected', 'version': 'SXR2130'}, {'status': 'affected', 'version': 'SXR2230P'}, {'status': 'affected', 'version': 'SXR2250P'}, {'status': 'affected', 'version': 'SXR2330P'}, {'status': 'affected', 'version': 'Vision Intelligence 300 Platform'}, {'status': 'affected', 'version': 'Vision Intelligence 400 Platform'}, {'status': 'affected', 'version': 'WCD9326'}, {'status': 'affected', 'version': 'WCD9340'}, {'status': 'affected', 'version': 'WCD9341'}, {'status': 'affected', 'version': 'WCD9370'}, {'status': 'affected', 'version': 'WCD9375'}, {'status': 'affected', 'version': 'WCD9378'}, {'status': 'affected', 'version': 'WCD9380'}, {'status': 'affected', 'version': 'WCD9385'}, {'status': 'affected', 'version': 'WCD9390'}, {'status': 'affected', 'version': 'WCD9395'}, {'status': 'affected', 'version': 'WCN3950'}, {'status': 'affected', 'version': 'WCN3980'}, {'status': 'affected', 'version': 'WCN3988'}, {'status': 'affected', 'version': 'WCN3990'}, {'status': 'affected', 'version': 'WCN7750'}, {'status': 'affected', 'version': 'WCN7860'}, {'status': 'affected', 'version': 'WCN7861'}, {'status': 'affected', 'version': 'WCN7880'}, {'status': 'affected', 'version': 'WCN7881'}, {'status': 'affected', 'version': 'WSA8810'}, {'status': 'affected', 'version': 'WSA8815'}, {'status': 'affected', 'version': 'WSA8830'}, {'status': 'affected', 'version': 'WSA8832'}, {'status': 'affected', 'version': 'WSA8835'}, {'status': 'affected', 'version': 'WSA8840'}, {'status': 'affected', 'version': 'WSA8845'}, {'status': 'affected', 'version': 'WSA8845H'}], 'platforms': ['Snapdragon Auto', 'Snapdragon CCW', 'Snapdragon Compute', 'Snapdragon Consumer IOT', 'Snapdragon Industrial IOT', 'Snapdragon MDM', 'Snapdragon Mobile', 'Snapdragon Technology'], 'defaultStatus': 'unaffected'}]}], 'published': '2025-07-08T13:15:28.460', 'references': [{'url': 'https://docs.qualcomm.com/product/publicresources/securitybulletin/july-2025-bulletin.html', 'tags': ['Vendor Advisory'], 'source': 'product-security@qualcomm.com'}], 'vulnStatus': 'Analyzed', 'weaknesses': [{'type': 'Secondary', 'source': 'product-security@qualcomm.com', 'description': [{'lang': 'en', 'value': 'CWE-129'}]}], 'descriptions': [{'lang': 'en', 'value': 'Memory corruption while operating the mailbox in Automotive.'}, {'lang': 'es', 'value': 'Corrupción de memoria al operar el buzón en Automotive.'}], 'lastModified': '2026-06-17T08:08:00.890', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:aqt1000_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'EC6FCE91-BF38-49ED-8FFB-429BAFEE7832'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:aqt1000:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '715A9F94-5F9E-45E5-B07B-699410C01478'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:ar8035_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'C88B9C86-2E8E-4DCE-A30C-02977CC00F00'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:ar8035:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'EE473A5A-5CFC-4F08-A173-30717F8BD0D7'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:fastconnect_6200_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'CDE1CBDE-3D28-463C-B215-AA7DF373EF09'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:fastconnect_6200:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '66BD3B88-7CF9-482D-A2DD-67F6ACF4CC57'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:fastconnect_6700_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '82B82E87-F3F4-466F-A76B-C8809121FF6F'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:fastconnect_6700:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '419A132E-E42C-4395-B74B-788A39DF1D13'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:fastconnect_6800_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'D89F035A-2388-48FC-AEBB-8429C6880F4A'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:fastconnect_6800:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'CA13EF4E-AAE6-45F4-9E41-78310E37CE81'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_865_5g_mobile_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '0627B052-B244-492C-9257-9E85ACCE0B19'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_865_5g_mobile:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'B6285755-E27F-4538-8F48-5F9DCDC4CB09'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_865\\+_5g_mobile_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '8130D33F-B5B7-439D-A35B-AD662C35B690'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_865\\+_5g_mobile:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'A89428FC-0EB0-4121-B674-664EAD761DD0'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_870_5g_mobile_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AE2EBD77-F5C5-43DE-BD01-788471DB8262'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_870_5g_mobile:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '4C666B23-5049-424C-80A5-BC45F579DECD'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_888_5g_mobile_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'F461BDE7-E847-4FF4-8D05-598FBF76D7B6'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_888_5g_mobile:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '0BC46263-C6FF-4BC0-83A5-D5A17954DB5F'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_888\\+_5g_mobile_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '3F2F6A7B-053D-4C18-883E-32DD0E317D04'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_888\\+_5g_mobile:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '60739810-16B9-48FA-8DB5-E0AD336F6912'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sc8180x-ad_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '2802A422-CCEA-4634-B164-09AC35C00C2F'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sc8180x-ad:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '8AB65F7E-6921-44AA-8B2C-C4814BD51A7F'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sc8180xp-ad_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E7EB4CA4-CEAF-4D8C-AE28-5373CC5E46D7'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sc8180xp-ad:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '9B12A03C-20D1-452A-99E6-BA94C02BA982'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sc8180x-aaab_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '328838FB-9338-4BB1-8492-9F3E6628F105'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sc8180x-aaab:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '3C73B5E9-9786-4D98-B701-7341A6673410'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sc8180xp-acaf_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '360E939C-2089-4402-9D72-EF3014EBB330'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sc8180xp-acaf:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '784952CE-8A95-4288-A672-36CCC3B5FB18'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sc8180x-acaf_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '84B9DA10-0264-4226-AA31-B5C7DAEA8BB0'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sc8180x-acaf:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '7DF82CE3-F715-4039-9473-9B47888A6501'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sc8180xp-aaab_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '04274F69-E871-4EEC-A66B-698048D00225'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sc8180xp-aaab:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '0D40E4D1-64B4-4E16-B43E-90A0627EE07D'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sc8280xp-abbb_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A7EA3A08-8624-4B78-AD75-828A3DF4CC52'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sc8280xp-abbb:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '57E75758-F191-45B7-86A8-7F4EC08D2965'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_ar1_gen_1_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A69D9315-2233-4C4E-8651-8E32C4BA5866'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_ar1_gen_1:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '27DFA1D7-0459-401A-9E00-A5E700AC9C9F'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_ar2_gen_1_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '7BB4A33E-6647-447E-BDA3-24246D49C5DD'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_ar2_gen_1:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '1046CC3E-FB12-4527-9978-DCC40EEE8938'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_auto_5g_modem-rf_gen_2_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'EE5FCA7F-1FBE-42AA-B4E6-09CEA02A33EC'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_auto_5g_modem-rf_gen_2:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'E2D789BC-43F5-40FB-A191-163C01BA5FBE'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_x24_lte_modem_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '5CAB1351-A614-4E73-B58E-7D624695C657'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_x24_lte_modem:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '4494AAD7-D132-41DB-9756-CAD1F3F7AE7E'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_x32_5g_modem-rf_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '1D8A51B5-5115-47E5-A8B5-96B9965749C7'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_x32_5g_modem-rf:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'DDA76CAB-ADE3-45FA-A859-2A9E7C00746C'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_x35_5g_modem-rf_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '7B42EAAC-230A-4901-8B3A-45EF95087109'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_x35_5g_modem-rf:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '19E8F0E4-F768-4EC4-A9C1-1291A7C79E23'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_x50_5g_modem-rf_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'B0945BED-18AD-4B6E-92EC-E5421D333B95'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_x50_5g_modem-rf:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '067F3D3D-59C4-4245-9385-F8A9697779E8'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_x55_5g_modem-rf_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '6DD56A4A-BBE6-4AE4-A4C1-4914E997F08C'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_x55_5g_modem-rf:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '6DE28E8F-0A21-497B-9082-79EB74E1CF33'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_x62_5g_modem-rf_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '97280725-88AA-4872-B765-79F754FF33BF'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_x62_5g_modem-rf:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'AA7B7E02-88A4-48FF-9107-CD41EA38E43F'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_x65_5g_modem-rf_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'CF9DE2CE-4765-4696-ABFE-4808EF77C8D9'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_x65_5g_modem-rf:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '8031F868-16B3-4173-835A-0F818471CF4F'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_x72_5g_modem-rf_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '5E674785-B392-4007-A4AE-DACF2745704F'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_x72_5g_modem-rf:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '7C48D223-A41F-4D49-B526-4695DD93349A'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_x75_5g_modem-rf_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'D82AAC94-6D8C-4EB7-ADDF-544AFCA809D6'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_x75_5g_modem-rf:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '6A169176-2CBF-44B6-B4C8-C93D72E6D77D'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_xr2_5g_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '665811D8-F648-4F32-A375-FAF9C9E928B3'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_xr2_5g:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '2A537932-6EAD-411B-83FF-48CF050F603A'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:srv1h_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '0CD199F5-DA68-4BEB-AA99-11572DA26B4F'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:srv1h:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '8ACA2D4D-FC77-4C1A-8278-1C27B3EA3303'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:srv1l_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'B88B3A43-24DD-44EB-AEF1-B7ECAB97C0FB'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:srv1l:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '07602885-8BEA-4820-A8F5-41E909718FBA'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:srv1m_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E4B29E7F-8BFE-466A-B357-63F8A2160C4E'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:srv1m:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '6D55CC7D-2E65-4CA9-9892-B6FBCC087E6F'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:ssg2115p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A146E52D-4AFC-47B4-920F-DAC76077DF25'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:ssg2115p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '2BA4BA00-C8D1-4DAC-8030-CB5EEC7D4591'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:ssg2125p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'EA41907C-1CDE-42F3-B21D-5D53B2F06AF7'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:ssg2125p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'EDC270A7-205C-41EB-A2E5-2A381A16BFBB'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sxr1230p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'BE3236D6-0D01-4D05-B580-8888B99BAA5D'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sxr1230p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '7E1753FC-F3CD-4B50-886D-8E16D9301A84'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sxr2130_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '9F9FA3B1-E4E4-4D9B-A99C-7BF958D4B993'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sxr2130:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '95762B01-2762-45BD-8388-5DB77EA6139C'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sxr2230p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'CD6444F6-A477-4B4C-8A09-C22C47CCE45B'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sxr2230p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'F3E20681-4FC4-46E2-AF77-BCF03BC8E77E'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sxr2250p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '68A93ED1-F509-439E-AE7B-F0EC87AE759F'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sxr2250p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'FB5E2A98-EDD0-4298-911D-EC7527D5A424'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sxr2330p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '568C5B08-AC42-48D3-8029-A65689EEBE75'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sxr2330p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '56DD2B49-0A36-443C-BECB-4115E271A415'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:vision_intelligence_300_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'C33CAF7D-F810-41D3-9BFE-C61E7758CE84'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:vision_intelligence_300:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '3B4BAC93-2C2A-4A73-A652-CD6B2F608CDD'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:vision_intelligence_400_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A8E976A6-4785-4F88-9035-0F6F0509A642'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:vision_intelligence_400:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '16204302-0B17-4759-A4C8-E8B0301BBCAB'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:wcd9326_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '3A2FAD34-B7C5-400A-8575-A12CDE65ACBE'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:wcd9326:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '5A39A2E5-6D8D-4F6E-98CB-96DB1975A4BC'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:wcd9340_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '8BA28CC6-C8BB-4F50-BFE3-A59F664A4F54'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:wcd9340:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '94D2BDF1-764C-48BA-8944-3275E8768078'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:wcd9341_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'CE852339-1CAE-4983-9757-8F00EDEF1141'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:wcd9341:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '4D9E96B3-F1BB-46F8-B715-7DF90180F1E1'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:fastconnect_6900_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E670F500-9B71-4BBE-B5DA-221D35803C89'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:fastconnect_6900:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '9ADEB5C5-B79A-4F45-B7D3-75945B38DB6C'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:fastconnect_7800_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'B3053D68-C5D8-4D47-A4F0-9F3AF2289E1D'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:fastconnect_7800:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '638DBC7F-456F-487D-BED2-2214DFF8BEE2'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qam8255p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '3723C7B1-A7E2-401F-8D6D-189350F6BCA5'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qam8255p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'B12B89EF-7B12-481E-BCBC-F12B9D16321A'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qam8295p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'C2D9E281-B382-41AC-84CB-5B1063E5AC51'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qam8295p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '44EBEBD5-98C3-493B-A108-FD4DE6FFBE97'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qam8620p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'DBAC2260-52E3-49DE-97EA-F80DBD837FD3'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qam8620p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '17599B8D-5753-4408-B4CD-AAA65C826922'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qam8650p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '295E75BD-2A6C-4A76-A376-A9977DDB17FF'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qam8650p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'BD37AA1A-B911-45BF-9BCC-C772FA83E657'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qam8775p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '49B2DF91-BE6B-4E9E-B63C-98DADD29AD6B'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qam8775p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '58170126-928F-4AE5-B5AF-5ED4710F9BA2'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qamsrv1h_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'F8673334-5E11-4E95-B33D-3029499F71DF'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qamsrv1h:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'EC0B32F6-5EF0-4591-99D7-D0E9B09DEC5A'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qamsrv1m_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'CE03AB2A-3ED9-4489-8E5B-4FCF8BAA8559'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qamsrv1m:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '9E646738-6A87-4470-9640-6A5A1DF3AF78'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qca6174a_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '4FF653D0-15CF-4A10-8D8E-BE56F4DAB890'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qca6174a:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'C31FA74C-6659-4457-BC32-257624F43C66'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qca6310_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '62DC4FBB-D9CB-43EB-829E-0A892306D0E2'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qca6310:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '5B0F8ED6-EAE7-44EA-A8C6-F5AD408261F0'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qca6335_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '966CDA56-809F-4FF4-909D-0DD92F44CF67'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qca6335:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'C90747B4-2CC0-4816-A994-58E00F5ADA05'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qca6391_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '83B53119-1B2F-4978-B7F5-33B84BE73B68'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qca6391:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '6FEBC0C5-CAA1-475C-96C2-B8D24B2E4536'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qca6420_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '7E16994A-6DBA-426C-ADD2-B1E8B49FEDBF'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qca6420:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '47E674DE-55AB-44E5-8E00-C804FC9D4DC0'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qca6421_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '503CEDEF-99D0-4432-88A0-295340743606'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qca6421:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'CE9115A0-0D87-49BE-9A9B-091DBF8D9E6E'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qca6426_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A344E78F-D15A-460E-8EF8-7C6FC39F2D5E'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qca6426:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '8FF5EC23-4884-4C2B-8E77-50B1E8E28A3D'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qca6430_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '95AFC483-1468-43FC-96FA-A56165C290E0'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qca6430:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '0A963FDF-6FF4-4F48-834E-2A14D241716D'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qca6431_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '76FD6A24-B6F4-4C65-968F-AFF90A1A60B8'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qca6431:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '34661A30-92C3-4F0D-ABD1-8DA8E928DFF9'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qca6436_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '04F574BC-9AB2-4B83-A466-556ECEBBD3DF'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qca6436:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'A34D021D-C043-4EFD-9AB3-B2174528CBA3'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qca6564a_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '886124F6-B397-4EB6-8E01-6012E468ABE9'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qca6564a:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '93ED74CE-6BF2-4983-8780-07D5336745B3'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qca6564au_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'B59672A0-2FA6-46CC-B75A-C599B842AFB9'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qca6564au:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '3847F4A5-90A5-4C84-B43F-0DDD81BD79CE'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qca6574_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '9B828AC8-4A01-4537-B2BD-8180C99F5C32'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qca6574:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '66C16E1E-9D4A-4F20-B697-833FDCCA86FB'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qca6574a_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '828CFB37-76A6-4927-9D00-AF9A1C432DD6'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qca6574a:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '11405993-5903-4716-B452-370281034B42'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qca6574au_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'D527E2B1-2A46-4FBA-9F7A-F5543677C8FB'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qca6574au:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '8374DDB3-D484-4141-AE0C-42333D2721F6'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qca6584au_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'C3DDA896-576C-44B8-85B6-F71F473F776B'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qca6584au:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '51A87BDA-5B24-4212-BAB3-D2BBB2F4162E'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qca6595_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '643EC76D-2836-48E6-81DA-78C4883C33CA'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qca6595:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '477F6529-4CE1-44FC-B6EE-D24D44C71AE7'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qca6595au_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '288F637F-22F8-47CF-B67F-C798A730A1BD'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qca6595au:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'D0996EA3-1C92-4933-BE34-9CF625E59FE7'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qca6678aq_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'D001127D-8160-42F0-B8B9-2FAA2976B530'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qca6678aq:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'C9EB615F-FD4C-450B-AB25-E936FD9816C4'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qca6688aq_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AFBD264F-F24A-4CDD-B316-9514A61B91E7'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qca6688aq:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '94CC5BC4-011D-4D2B-8891-97FBF61FD783'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qca6696_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '0AE207DB-9770-40ED-961D-FDA75965826F'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qca6696:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '0E23922D-C37F-476F-A623-4C1458A9156F'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qca6698aq_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '5FA1F8F4-EAF2-4704-A8A6-19AD3CA1B577'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qca6698aq:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'B3F7853D-09EE-476F-B48D-BB30AEB4A67D'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qca6698au_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '3ACA09C0-84A5-493A-A9BD-EF95A8330D54'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qca6698au:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '3A2397BD-431C-4730-92E3-17A5C2445A65'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qca6797aq_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '797295C2-535C-46A9-A725-E1A5405F0436'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qca6797aq:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '8BFC575E-594E-4711-94B1-2DC8D03B9AC4'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qca8081_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '1D1C53DC-D2F3-4C92-9725-9A85340AF026'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qca8081:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'ED0585FF-E390-46E8-8701-70964A4057BB'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qca8337_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '2FA8F9DA-1386-4961-B9B2-484E4347852A'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qca8337:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '117289C8-7484-4EAE-8F35-A25768F00EED'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qca9377_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'C4D2B46E-3996-42FD-B932-09E92C02EC8A'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qca9377:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '98E58C63-F253-4DCC-8A14-48FEB64B4C3D'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qcc710_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '2A75D017-032F-4369-917C-567EE2A809F2'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qcc710:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '107F0423-608C-404D-B58B-616A6494418F'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qcm5430_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '4EC5F81B-AA24-4E3C-9FC8-53E010AC977E'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qcm5430:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'B5C66DAD-0D85-46B8-92D7-6D68B9429E9A'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qcm6490_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'ADD6D51E-5787-42A6-8A02-4EBBAFFF9C94'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qcm6490:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '99AA0291-B822-4CAD-BA17-81B632FC3FEF'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qcm8550_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '646B241B-2971-4929-9FB6-7A4CBF801CBB'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qcm8550:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '5654FFB5-9A89-4399-AFAB-0A26726DEC81'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:wcd9370_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '1295D869-F4DD-4766-B4AA-3513752F43B4'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:wcd9370:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'B98784DC-3143-4D38-AD28-DBBDCCAB4272'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:wcd9375_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '34143ABA-7D09-429F-A65C-3A33438BF62C'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:wcd9375:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '9D56DFE3-5EF1-4B23-BBD5-0203FBF9CCEC'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:wcd9378_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '4CFDBB5B-0A4F-4032-874F-D2A7EF933FB0'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:wcd9378:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'D28A12D6-CC60-4BE9-ADEE-FAB58B05440F'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:wcd9380_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '70292B01-617F-44AD-AF77-1AFC1450523D'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:wcd9380:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'FA94C6D6-85DB-4031-AAF4-C399019AE16D'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:wcd9385_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '92B17201-8185-47F1-9720-5AB4ECD11B22'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:wcd9385:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'E1FA2EB9-416F-4D69-8786-386CC73978AE'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:wcd9390_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '896F1C04-9957-440F-BF01-C3772CC3B3DF'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:wcd9390:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'A90555EB-47A7-4717-92D5-35B561825F06'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:wcd9395_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '699056F6-1517-4F25-AE07-4FFCF6923B9F'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:wcd9395:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'E4C023D2-6FF5-4FFC-B9F2-895979166580'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:wcn3950_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '3FEF2DB6-00F5-4B07-953B-EF58B31267F1'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:wcn3950:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '120E8F0F-EBEB-4565-9927-2D473F783EF7'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:wcn3980_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '9C6E9038-9B18-4958-BE1E-215901C9B4B2'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:wcn3980:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'B36D3274-F8D0-49C5-A6D5-95F5DC6D1950'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:wcn3988_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E4BFB25F-013B-48E3-99FF-3E8687F94423'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:wcn3988:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'BF676C5B-838B-446C-A689-6A25AB8A87E2'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:wcn3990_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '2744A053-5BD9-45A9-A2FC-791BCA0CCD4C'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:wcn3990:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'D5F28E29-520F-469E-B048-62DE2EF07ADD'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:wcn7750_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'F0B2800F-B0A7-489E-BD70-B2EAAF45DE7A'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:wcn7750:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '1AEA0D7B-F3F7-4A6F-B222-192412FEECD3'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:wcn7860_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '2EB8794F-7998-424E-AF68-E4A4F9310F65'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:wcn7860:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '799D69CE-3FCC-4B19-8B00-9AF38111D983'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:wcn7861_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '57608D47-894C-4895-B4B3-4733D55D57DB'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:wcn7861:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '2FFD2C38-1A61-4BED-ABFA-DAE0C4B78620'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:wcn7880_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '63735D33-9F09-4841-9FE0-0D9AB604BECF'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:wcn7880:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'E826F765-4C2E-4319-BBC4-DEB02AAD783F'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:wcn7881_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'D765C392-5F38-4E6A-9E88-59629E7A6911'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:wcn7881:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'FAE8F4F9-F692-4EC0-A3FE-2CDD681DCBFD'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:wsa8810_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '15307882-7039-43E9-9BA3-035045988B99'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:wsa8810:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'AA85B322-E593-4499-829A-CC6D70BAE884'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:wsa8815_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E839A0B9-64C3-4C7A-82B7-D2AAF65928F8'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:wsa8815:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '7E870D82-DE3B-4199-A730-C8FB545BAA98'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:wsa8830_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '11B69595-E488-4590-A150-CE5BE08B5E13'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:wsa8830:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'BF680174-5FA6-47D9-8EAB-CC2A37A7BD42'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:wsa8832_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '7ACAD26E-B79E-4659-91A5-D301281F7D36'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:wsa8832:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'F0E46DA6-9494-4D92-A4AE-A272AF6ACCCC'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:wsa8835_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'F80BC68E-7476-4A40-9F48-53722FE9A5BF'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:wsa8835:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '6B36F4B2-BAA3-45AD-9967-0EB482C99708'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:wsa8840_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'CA33DE15-C177-43B3-AD50-FF797753D12E'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:wsa8840:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'AE1A5841-5BCB-4033-ACB9-23F3FCA65309'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:wsa8845_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '5B47BF35-3AA0-4667-842E-19B0FE30BF3C'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:wsa8845:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '8A071672-9405-4418-9141-35CEADBB65AF'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:wsa8845h_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'BB7CF473-8B25-4851-91F2-1BD693CCDC85'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:wsa8845h:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '91E591F2-8F72-4A5A-9264-2742EB2DABDA'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qcn6224_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '5F4362D2-30A3-4388-ABB6-293878AD7036'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qcn6224:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'BB6AE9A7-386A-473B-9BD5-DA37B1E696C5'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qcn6274_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '88376C1D-AC4D-4EB0-AF6A-274D020F5859'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qcn6274:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'E15BA4B4-C97F-45C0-A4AD-7E46387F19A6'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qcn9011_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '9306C34D-47E4-40CF-89F4-BA5263655D13'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qcn9011:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '02BA009F-24E1-4953-BA95-2A5BC1CDBDBB'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qcn9012_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '61F34DD2-9DC0-49E5-BC85-1543EA199477'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qcn9012:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '1A06879F-6FE9-448A-8186-8347D76F872B'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qcn9274_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '9129A244-AB8C-4AA4-BFBB-37F84D66BD3E'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qcn9274:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '41F243A1-3C0B-4780-95BF-69A4E1A91F18'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qcs5430_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'B6926498-667C-4866-B3DD-A7E20B8F4D7F'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qcs5430:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'CEFEBC7A-80C0-4E4F-B9C7-53EECF86B6B5'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qcs615_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '5A369459-FC20-4F7C-A8D9-89E132900F37'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qcs615:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'B8444225-A03E-44D7-8BB8-6102EF3A2356'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qcs6490_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '403AE561-6C9E-49F3-A5D6-C48DDD51D663'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qcs6490:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '6FAC140F-FC5E-4C88-B777-7F5EBF49A695'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qcs8300_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '0661B631-68E0-45DD-A9BD-943AB98181A8'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qcs8300:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '306FF958-DC05-453E-9CAB-A479B63E9F09'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qcs8550_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'FFF23DDB-98A0-4343-ADD3-5AB9C2383E7E'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qcs8550:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '5ACB8AFB-5B91-4AA1-BA3A-1AF0B3503080'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qcs9100_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '057E49CC-28C0-4A82-A895-6E681AB1E22F'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qcs9100:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '6A7FE265-B8C2-4423-9F13-A64111248D65'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qdu1000_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '407EE4D5-1F52-40D6-B85A-E49915D6EF2D'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qdu1000:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '5846C9DD-63E5-482D-BE01-3A1E89CC0EDE'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qdu1010_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '6B6A4AA9-E35B-4B25-9FD3-BFB907B822DB'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qdu1010:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '5AC8538B-6663-4CF7-BD4A-9766C04CBAB5'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qdu1110_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '7F5F9F3D-1F57-4D16-972E-AF39E438E4C3'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qdu1110:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '53D6BEFE-AA21-4786-B11C-A6683AC06622'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qdu1210_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '32E0EBD5-A846-44F9-9DEC-1C6711C96A5B'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qdu1210:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'C68F8102-788C-4EF3-83E4-56DF764DFFBC'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qdx1010_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '6B7AB84B-55D0-45EB-ABA8-F69E5179507E'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qdx1010:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'B908A65E-F3B2-417A-91EE-1BE855BABD2E'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qdx1011_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '6554B2E1-AE96-40CE-A19F-C7516CDBC41A'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qdx1011:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '1991232B-B58F-481E-A7EE-0546E64C12CC'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qep8111_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'BEB4913D-940F-49CC-951A-9704CCEE636C'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qep8111:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '4E93E1D2-4546-4D60-B53D-20CF09551766'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qfw7114_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '7456782E-B6CE-42ED-A51E-39907120E28B'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qfw7114:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '637BF4DF-BB40-479F-B696-6AD9D4B35D64'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qfw7124_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'D72C4CE0-AB59-4652-854F-94C9998F2712'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qfw7124:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '98720774-11B8-4B4B-BC73-D4DA84E07F78'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qmp1000_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '5298473D-8B34-42E6-BC32-69A3800972B4'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qmp1000:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '2A1CF44E-FFC2-4DCB-8DC2-46422D912448'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qru1032_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '8ECC6966-23CF-4189-81B3-477A97E38B05'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qru1032:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '01490429-D26C-4F80-83A4-8DC257142B86'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qru1052_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '0EAAB699-BFDA-465B-9B82-5E957C67D52A'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qru1052:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '0D2C3994-110F-40FA-B60F-D2C85A36E256'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qru1062_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '7C81773C-4A1C-4589-A6FD-A85770F3ADFE'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qru1062:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'CABCCB94-8C93-4CF1-9EA1-D410FF6ACD72'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:qsm8350_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '1894F6B9-31DA-44E8-AA28-064F73EBEE8D'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:qsm8350:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '8AA23845-D9F5-4035-8A93-F475D865586F'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:video_collaboration_vc3_platform_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'DD4946C6-778F-4542-AB77-C9B86AF25C05'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:video_collaboration_vc3_platform:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '6F1D604A-4530-42B3-80A0-58A82D658DDD'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:robotics_rb3_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '01264215-1B23-4406-B5A2-2C0A7B4E9937'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:robotics_rb3:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'F67FE29B-D218-4B32-B881-79262BD6BFA1'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sa6145p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'C66671C1-AE1A-44BE-9DB2-0B09FF4417DB'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sa6145p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '74AA3929-3F80-4D54-B13A-9B070D5C03BB'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sa6150p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '054F77D6-FC66-4151-9005-DC7ECDB5C722'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sa6150p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '8ED3F589-16D9-46A7-A539-C9862473EE0D'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sa6155_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '4C40544E-B040-491C-8DF3-50225E70B50C'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sa6155:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'A2DAC85C-CDC9-4784-A69A-147A2CE8A8B2'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sa6155p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '8DC40C14-3B2D-4E00-9E0F-86E6BDBF2D81'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sa6155p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '0514D433-162C-4680-8912-721D19BE6201'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sa7255p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '2B651F0A-34DA-400F-A376-B499BFDF8E86'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sa7255p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '4CFF093D-98C8-470F-8330-E5126E06343A'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sa7775p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '6C32CA38-5D48-4108-9858-FD66E20CAF2F'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sa7775p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'E1997F8B-17B8-4DE3-BCF7-726928720592'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sa8145p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A71D74B0-0963-49FD-8E97-148C8993B263'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sa8145p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '910CBFA4-50F7-4C7A-B9B9-B88C8A919827'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sa8150p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '69C1B02F-8D2D-42E7-B70D-41F4D9844FD1'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sa8150p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '3FEACAA9-C061-4713-9A54-37D8BFC0B00B'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sa8155_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'F33EB594-B0D3-42F2-B1CA-B0E6C9D82C6B'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sa8155:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '50EF47E5-2875-412F-815D-44804BB3A739'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sa8155p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'C8648B38-2597-401A-8F53-D582FA911569'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sa8155p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'A01CD59B-8F21-4CD6-8A1A-7B37547A8715'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sa8195p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '51BC0A66-493B-43BE-B51F-640BDF2FF32E'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sa8195p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'D8DA4D12-7ABF-4A04-B44E-E1D68C8E58AB'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sa8255p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'EC6E268D-C4AF-4950-9223-39EA36D538A8'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sa8255p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '073C1A81-D02B-4F2F-9378-CD1B2DCE0E5B'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sa8295p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '2A19659B-A0C3-44B7-8D54-BA21729873A4'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sa8295p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'F978041A-CE28-4BDF-A7DB-F0360F1A5F14'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sa8530p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '6107034C-E0B0-43BD-963B-2B558B913537'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sa8530p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'FC1839A1-4B68-468E-8155-F0A53A3C9B94'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sa8540p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '8FE8B62D-83B4-4326-8A53-FED5947D5FFE'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sa8540p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '2D6F8899-136A-4A57-9F02-BD428E1663DA'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sa8620p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '6ACE6D64-A498-482F-8270-718F4884CFFD'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sa8620p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'B6E016D6-1B83-4261-A27E-1F9873F81E14'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sa8650p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E0E807AA-5646-48AD-9A5C-B0B13E222AA9'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sa8650p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '45FBB72B-B850-4E3F-ACBB-9392157FF131'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sa8770p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '781CCC31-C08F-499B-BE73-6C7DB70437AF'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sa8770p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '75AFAA21-0589-4C6A-9418-34EE8A61BBAD'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sa8775p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '1C79595B-1259-4431-96F9-C5A24E624305'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sa8775p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '0F2F3431-9CD7-4D4F-833D-DD4D3ACF94C7'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sa9000p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A024AB04-B213-4018-A4C1-FA467C7BA775'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sa9000p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'A2A8AB7C-5D34-4794-8C06-2193075B323F'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sc8380xp_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '14E3FE58-7F1C-4F5C-B62D-0CF124E14AB2'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sc8380xp:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'FFCB0BBA-3F81-4FCA-B3DE-190C46DA50DB'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sd_675_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '3F900C8F-9763-441A-B97E-E5394A68A08A'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sd_675:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '589C1001-E9F6-41A6-BCC8-A94A3C97F2E6'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sd_8_gen1_5g_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '76910884-45D9-4EA2-BA30-44A8C7CC1339'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sd_8_gen1_5g:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '33D393A6-4586-4416-86EB-F9D86DC3DED8'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sd_8cx_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A71D1A7C-537F-458B-BA56-A11F95E36EA9'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sd_8cx:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '716DEC4D-D854-44CD-8A14-AA5AFD96809E'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sd670_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '5B8DA94C-23A0-4C99-9F05-144B9B5224B3'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sd670:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '39E10E22-E7CC-41D6-80F3-030083F45645'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sd675_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '1497D052-884E-496B-BEF8-6904A25125ED'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sd675:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '589F4888-28F6-4ECA-860E-8054C2A8C419'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sd855_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '42B30014-95AB-4F24-A7A5-60A907502609'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sd855:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'F562ED3D-CBE3-4DCC-BFBB-DE0AD2425A9C'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sd865_5g_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '72433485-B229-46A6-BCA4-394AA4EEA683'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sd865_5g:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '04D40EC4-BF31-4BFD-8D0A-8193F541AF02'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sdx55_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E93FB34B-3674-404D-9687-E092E9A246AB'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sdx55:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'F3FF5A9A-A34A-499C-B6E0-D67B496C5454'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sdx57m_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '18431C93-7497-4A2C-9B5A-B9E4C7F88B7D'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sdx57m:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '0BF0FFBA-73EC-4615-98D2-BA62D67353DB'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sdx80m_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '7CAE7C89-05DD-4083-9DCE-68E02F77EA69'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sdx80m:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'BA282402-64E3-40F7-8A26-B0922777510F'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sg8275p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '8509F3A3-A1CA-466B-9031-4146C36B9AF8'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sg8275p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'B1813AB7-44F5-476B-9533-536F5B2F26BB'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sm4635_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'CE676369-CC9C-4A16-A477-188240861747'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sm4635:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'A3BCB636-956F-417D-8858-8BFB3EABD83E'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sm7250p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '76DB5472-DF51-4144-8A69-9B231CF782DA'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sm7250p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '1D395018-251C-45AA-9EE8-A638CAB0B508'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sm8550p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'C4CDD6A2-5A3C-4572-8CE1-2F102333BB79'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sm8550p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '699E5D17-6144-4F0A-8D52-1E8C83990E52'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sm8735_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '167C1CC1-03F8-49B3-B460-FCA38644DA06'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sm8735:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '3D2E820B-1273-4E82-9D45-A4159AF3878C'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sm8750_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '84641A8E-A93C-48C1-86AC-193951BA4D78'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sm8750:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '74169A4C-0247-4719-887E-BBFB36B04F07'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:sm8750p_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '4D8ABDBF-BABC-4219-8A18-BDFC8C826B1F'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:sm8750p:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '685D81D0-7E95-4DBA-A05B-7C708A5DFDF0'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_670_mobile_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '066BEC31-0C11-4816-A76A-D1D4BC516FBA'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_670_mobile:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'A8196A85-1D01-4663-8C6E-043BFACFE25E'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_675_mobile_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '46DCE136-DC16-41A2-92F4-36A859AF833F'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_675_mobile:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '4D1E661D-F412-43D8-98C2-CE371C2FD316'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_678_mobile_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '7C34EE20-69D2-407A-A916-77E79D0C27E8'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_678_mobile:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '568B682C-2B70-4EC0-9E1A-E6A418D53F4C'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_765_5g_mobile_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'B0D23A8E-06DE-4DE2-ADAD-9D9B7CA09F7D'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_765_5g_mobile:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'B00B72F0-6E85-40D6-A162-66908A570F46'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_765g_5g_mobile_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '16B75F00-99B2-4C63-81F0-39257002630A'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_765g_5g_mobile:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'C2D3D004-F706-4D66-993A-B72AB0F9D129'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_768g_5g_mobile_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '5A7E183E-2BD3-4745-81EA-21A357C14E0D'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_768g_5g_mobile:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'D1BF63E3-8673-463E-BF55-3F9B32EF9A29'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_8_gen_1_mobile_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '13AF1A58-3121-4F06-9B13-D7D94A8A10A8'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_8_gen_1_mobile:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '629264C3-8EA3-475F-88D5-4407691499DA'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_8_gen_2_mobile_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '863BA6B8-5F2D-4D97-BBBE-EAD5B35AB3AA'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_8_gen_2_mobile:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '2E0344CF-A15E-4734-852F-9553E780644B'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_8_gen_3_mobile_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'DA40FA0B-F9F1-48D4-B68A-ECD7241A5F39'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_8_gen_3_mobile:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '0B00530E-070B-4832-AFF0-535D4A1A6F85'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_8\\+_gen_2_mobile_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '28D14A7F-F116-416B-A359-32D395F706D4'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_8\\+_gen_2_mobile:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '6B67D19B-E1B0-41A2-B122-FBA6D797F3C8'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_845_mobile_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '14F878B5-7E62-40D5-AD88-D109130F6F57'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_845_mobile:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '3BDDA689-D36D-456B-9AC1-3FA925563F30'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_850_mobile_compute_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '4E5FB95B-D6AA-4E92-A7B3-5C2760D965FE'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_850_mobile_compute:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '800DD4A9-E2DA-4B96-8E8C-C4D7CD26284F'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_855_mobile_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'F83F4E9E-481F-4275-BCB2-0706D52D8DEE'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_855_mobile:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '1B49C835-2316-49CA-B87C-790C19D81688'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_855\\+_mobile_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '0B3A4256-DBA0-4981-A6EE-BEA06AF3C1D8'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_855\\+_mobile:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'C200D712-451B-4748-B0DE-5EBCFB591045'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:qualcomm:snapdragon_860_mobile_firmware:-:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'F9FC371A-F67E-466C-BE01-F867EE587078'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:qualcomm:snapdragon_860_mobile:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '4A2FAB27-2BDF-4FED-872D-9622050992CF'}], 'operator': 'OR'}], 'operator': 'AND'}], 'sourceIdentifier': 'product-security@qualcomm.com'}
CVE-2019-19889
2019-12-18 21:52:52+03:00
2026-06-17 02:27:24.007000+03:00
PUBLISHED
An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. The attacker can discover admin credentials in the backup file, aka backupsettings.conf.
HIGH
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
[{'url': 'https://github.com/V1n1v131r4/HGB10R-2', 'source': 'cve@mitre.org'}, {'url': 'https://github.com/V1n1v131r4/HGB10R-2', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:15.937311+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://github.com/V1n1v131r4/HGB10R-2', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-05T02:32:09.961Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://github.com/V1n1v131r4/HGB10R-2', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. The attacker can discover admin credentials in the backup file, aka backupsettings.conf.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2019-12-18T18:52:52.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://github.com/V1n1v131r4/HGB10R-2', 'name': 'https://github.com/V1n1v131r4/HGB10R-2', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. The attacker can discover admin credentials in the backup file, aka backupsettings.conf.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-19889', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-19889', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-05T02:32:09.961Z', 'dateReserved': '2019-12-18T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2019-12-18T18:52:52.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-19889', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 5.0, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:P/I:N/A:N', 'authentication': 'NONE', 'integrityImpact': 'NONE', 'accessComplexity': 'LOW', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 10.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 3.6, 'exploitabilityScore': 3.9}]}, 'affected': [{'source': 'cve@mitre.org', 'affectedData': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}]}], 'published': '2019-12-18T19:15:12.017', 'references': [{'url': 'https://github.com/V1n1v131r4/HGB10R-2', 'tags': ['Exploit', 'Third Party Advisory'], 'source': 'cve@mitre.org'}, {'url': 'https://github.com/V1n1v131r4/HGB10R-2', 'tags': ['Exploit', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-319'}]}], 'descriptions': [{'lang': 'en', 'value': 'An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. The attacker can discover admin credentials in the backup file, aka backupsettings.conf.'}, {'lang': 'es', 'value': 'Se detectó un problema en los dispositivos Humax Wireless Voice Gateway HGB10R-2 versión 20160817_1855. El atacante puede descubrir las credenciales de administrador en el archivo de copia de seguridad, también se conoce como backupsettings.conf.'}], 'lastModified': '2026-06-17T02:27:24.007', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:humaxdigital:hgb10r-02_firmware:20160817_1855:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A44A8D57-0FB9-45A3-8D7B-3FAF3EBC0532'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:humaxdigital:hgb10r-02:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '08F77F1D-DCAE-47E7-85A6-BBCF783EA033'}], 'operator': 'OR'}], 'operator': 'AND'}], 'sourceIdentifier': 'cve@mitre.org'}
CVE-2019-19890
2019-12-18 21:53:05+03:00
2026-06-17 02:27:24.113000+03:00
PUBLISHED
An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. Admin credentials are sent over cleartext HTTP.
HIGH
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
[{'url': 'https://github.com/V1n1v131r4/HGB10R-2', 'source': 'cve@mitre.org'}, {'url': 'https://github.com/V1n1v131r4/HGB10R-2', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:15.937311+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://github.com/V1n1v131r4/HGB10R-2', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-05T02:32:09.357Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://github.com/V1n1v131r4/HGB10R-2', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. Admin credentials are sent over cleartext HTTP.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2019-12-18T18:53:05.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://github.com/V1n1v131r4/HGB10R-2', 'name': 'https://github.com/V1n1v131r4/HGB10R-2', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. Admin credentials are sent over cleartext HTTP.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-19890', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-19890', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-05T02:32:09.357Z', 'dateReserved': '2019-12-18T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2019-12-18T18:53:05.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-19890', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 5.0, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:P/I:N/A:N', 'authentication': 'NONE', 'integrityImpact': 'NONE', 'accessComplexity': 'LOW', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 10.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 3.6, 'exploitabilityScore': 3.9}]}, 'affected': [{'source': 'cve@mitre.org', 'affectedData': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}]}], 'published': '2019-12-18T19:15:12.093', 'references': [{'url': 'https://github.com/V1n1v131r4/HGB10R-2', 'tags': ['Exploit', 'Third Party Advisory'], 'source': 'cve@mitre.org'}, {'url': 'https://github.com/V1n1v131r4/HGB10R-2', 'tags': ['Exploit', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-319'}, {'lang': 'en', 'value': 'CWE-522'}]}], 'descriptions': [{'lang': 'en', 'value': 'An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. Admin credentials are sent over cleartext HTTP.'}, {'lang': 'es', 'value': 'Se detectó un problema en los dispositivos Humax Wireless Voice Gateway HGB10R-2 versión 20160817_1855. Las credenciales de administrador son enviadas por medio de HTTP en texto sin cifrar.'}], 'lastModified': '2026-06-17T02:27:24.113', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:humaxdigital:hgb10r-02_firmware:20160817_1855:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A44A8D57-0FB9-45A3-8D7B-3FAF3EBC0532'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:humaxdigital:hgb10r-02:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '08F77F1D-DCAE-47E7-85A6-BBCF783EA033'}], 'operator': 'OR'}], 'operator': 'AND'}], 'sourceIdentifier': 'cve@mitre.org'}
CVE-2018-1311
2019-12-18 03:00:00+03:00
2026-06-17 01:50:59.290000+03:00
PUBLISHED
The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library and has no current mitigation other than to disable DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable.
HIGH
8.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
[{'url': 'http://www.openwall.com/lists/oss-security/2024/02/16/1', 'source': 'security@apache.org'}, {'url': 'https://access.redhat.com/errata/RHSA-2020:0702', 'source': 'security@apache.org'}, {'url': 'https://access.redhat.com/errata/RHSA-2020:0704', 'source': 'security@apache.org'}, {'url': 'https://lists.apache.org/thread.html/r48ea463fde218b1e4cc1a1d05770a0cea34de0600b4355315a49226b%40%3Cc-dev.xerces.apache.org%3E', 'source': 'security@apache.org'}, {'url': 'https://lists.apache.org/thread.html/r90ec105571622a7dc3a43b846c12732d2e563561dfb2f72941625f35%40%3Cc-users.xerces.apache.org%3E', 'source': 'security@apache.org'}, {'url': 'https://lists.apache.org/thread.html/rabbcc0249de1dda70cda96fd9bcff78217be7a57d96e7dcc8cd96646%40%3Cc-users.xerces.apache.org%3E', 'source': 'security@apache.org'}, {'url': 'https://lists.apache.org/thread.html/rfeb8abe36bcca91eb603deef49fbbe46870918830a66328a780b8625%40%3Cc-users.xerces.apache.org%3E', 'source': 'security@apache.org'}, {'url': 'https://lists.debian.org/debian-lts-announce/2020/12/msg00025.html', 'source': 'security@apache.org'}, {'url': 'https://lists.debian.org/debian-lts-announce/2023/12/msg00027.html', 'source': 'security@apache.org'}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7A6WWL4SWKAVYK6VK5YN7KZP4MZWC7IY/', 'source': 'security@apache.org'}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AJYZUBGPVWJ7LEHRCMB5XVADQBNGURXD/', 'source': 'security@apache.org'}, {'url': 'https://marc.info/?l=xerces-c-users&m=157653840106914&w=2', 'source': 'security@apache.org'}, {'url': 'https://www.debian.org/security/2020/dsa-4814', 'source': 'security@apache.org'}, {'url': 'https://www.oracle.com/security-alerts/cpujan2022.html', 'source': 'security@apache.org'}, {'url': 'http://www.openwall.com/lists/oss-security/2024/02/16/1', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://access.redhat.com/errata/RHSA-2020:0702', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://access.redhat.com/errata/RHSA-2020:0704', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lists.apache.org/thread.html/r48ea463fde218b1e4cc1a1d05770a0cea34de0600b4355315a49226b%40%3Cc-dev.xerces.apache.org%3E', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lists.apache.org/thread.html/r90ec105571622a7dc3a43b846c12732d2e563561dfb2f72941625f35%40%3Cc-users.xerces.apache.org%3E', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lists.apache.org/thread.html/rabbcc0249de1dda70cda96fd9bcff78217be7a57d96e7dcc8cd96646%40%3Cc-users.xerces.apache.org%3E', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lists.apache.org/thread.html/rfeb8abe36bcca91eb603deef49fbbe46870918830a66328a780b8625%40%3Cc-users.xerces.apache.org%3E', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lists.debian.org/debian-lts-announce/2020/12/msg00025.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lists.debian.org/debian-lts-announce/2023/12/msg00027.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7A6WWL4SWKAVYK6VK5YN7KZP4MZWC7IY/', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AJYZUBGPVWJ7LEHRCMB5XVADQBNGURXD/', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AJYZUBGPVWJ7LEHRCMB5XVADQBNGURXD/', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://marc.info/?l=xerces-c-users&m=157653840106914&w=2', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://www.debian.org/security/2020/dsa-4814', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://www.oracle.com/security-alerts/cpujan2022.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:17:06.676307+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://lists.apache.org/thread.html/r48ea463fde218b1e4cc1a1d05770a0cea34de0600b4355315a49226b%40%3Cc-dev.xerces.apache.org%3E', 'name': '[xerces-c-dev] 20200110 [xerces-c] 06/13: Add CVE-2018-1311 advisory and web site note.', 'tags': ['mailing-list', 'x_transferred']}, {'url': 'https://access.redhat.com/errata/RHSA-2020:0704', 'name': 'RHSA-2020:0704', 'tags': ['vendor-advisory', 'x_transferred']}, {'url': 'https://access.redhat.com/errata/RHSA-2020:0702', 'name': 'RHSA-2020:0702', 'tags': ['vendor-advisory', 'x_transferred']}, {'url': 'https://lists.debian.org/debian-lts-announce/2020/12/msg00025.html', 'name': '[debian-lts-announce] 20201217 [SECURITY] [DLA 2498-1] xerces-c security update', 'tags': ['mailing-list', 'x_transferred']}, {'url': 'https://www.debian.org/security/2020/dsa-4814', 'name': 'DSA-4814', 'tags': ['vendor-advisory', 'x_transferred']}, {'url': 'https://lists.apache.org/thread.html/rabbcc0249de1dda70cda96fd9bcff78217be7a57d96e7dcc8cd96646%40%3Cc-users.xerces.apache.org%3E', 'name': '[xerces-c-users] 20210528 Security vulnerability - CVE-2018-1311', 'tags': ['mailing-list', 'x_transferred']}, {'url': 'https://lists.apache.org/thread.html/rfeb8abe36bcca91eb603deef49fbbe46870918830a66328a780b8625%40%3Cc-users.xerces.apache.org%3E', 'name': '[xerces-c-users] 20210528 RE: Security vulnerability - CVE-2018-1311', 'tags': ['mailing-list', 'x_transferred']}, {'url': 'https://lists.apache.org/thread.html/r90ec105571622a7dc3a43b846c12732d2e563561dfb2f72941625f35%40%3Cc-users.xerces.apache.org%3E', 'name': '[xerces-c-users] 20210528 Re: Security vulnerability - CVE-2018-1311', 'tags': ['mailing-list', 'x_transferred']}, {'url': 'https://www.oracle.com/security-alerts/cpujan2022.html', 'tags': ['x_transferred']}, {'url': 'https://marc.info/?l=xerces-c-users&m=157653840106914&w=2', 'tags': ['x_transferred']}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7A6WWL4SWKAVYK6VK5YN7KZP4MZWC7IY/', 'name': 'FEDORA-2023-52ba628e03', 'tags': ['vendor-advisory', 'x_transferred']}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AJYZUBGPVWJ7LEHRCMB5XVADQBNGURXD/', 'name': 'FEDORA-2023-817ecc703f', 'tags': ['vendor-advisory', 'x_transferred']}, {'url': 'https://lists.debian.org/debian-lts-announce/2023/12/msg00027.html', 'name': '[debian-lts-announce] 20231231 [SECURITY] [DLA 3704-1] xerces-c security update', 'tags': ['mailing-list', 'x_transferred']}, {'url': 'http://www.openwall.com/lists/oss-security/2024/02/16/1', 'name': '[oss-security] 20240216 CVE-2024-23807: Apache Xerces C++: Use-after-free on external DTD scan', 'tags': ['mailing-list', 'x_transferred']}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AJYZUBGPVWJ7LEHRCMB5XVADQBNGURXD/'}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2025-11-04T18:14:14.531Z'}}], 'cna': {'affected': [{'vendor': 'Apache Software Foundation', 'product': 'Apache Xerces-C', 'versions': [{'status': 'affected', 'version': '3.0.0 to 3.2.2'}]}], 'references': [{'url': 'https://lists.apache.org/thread.html/r48ea463fde218b1e4cc1a1d05770a0cea34de0600b4355315a49226b%40%3Cc-dev.xerces.apache.org%3E', 'name': '[xerces-c-dev] 20200110 [xerces-c] 06/13: Add CVE-2018-1311 advisory and web site note.', 'tags': ['mailing-list']}, {'url': 'https://access.redhat.com/errata/RHSA-2020:0704', 'name': 'RHSA-2020:0704', 'tags': ['vendor-advisory']}, {'url': 'https://access.redhat.com/errata/RHSA-2020:0702', 'name': 'RHSA-2020:0702', 'tags': ['vendor-advisory']}, {'url': 'https://lists.debian.org/debian-lts-announce/2020/12/msg00025.html', 'name': '[debian-lts-announce] 20201217 [SECURITY] [DLA 2498-1] xerces-c security update', 'tags': ['mailing-list']}, {'url': 'https://www.debian.org/security/2020/dsa-4814', 'name': 'DSA-4814', 'tags': ['vendor-advisory']}, {'url': 'https://lists.apache.org/thread.html/rabbcc0249de1dda70cda96fd9bcff78217be7a57d96e7dcc8cd96646%40%3Cc-users.xerces.apache.org%3E', 'name': '[xerces-c-users] 20210528 Security vulnerability - CVE-2018-1311', 'tags': ['mailing-list']}, {'url': 'https://lists.apache.org/thread.html/rfeb8abe36bcca91eb603deef49fbbe46870918830a66328a780b8625%40%3Cc-users.xerces.apache.org%3E', 'name': '[xerces-c-users] 20210528 RE: Security vulnerability - CVE-2018-1311', 'tags': ['mailing-list']}, {'url': 'https://lists.apache.org/thread.html/r90ec105571622a7dc3a43b846c12732d2e563561dfb2f72941625f35%40%3Cc-users.xerces.apache.org%3E', 'name': '[xerces-c-users] 20210528 Re: Security vulnerability - CVE-2018-1311', 'tags': ['mailing-list']}, {'url': 'https://www.oracle.com/security-alerts/cpujan2022.html'}, {'url': 'https://marc.info/?l=xerces-c-users&m=157653840106914&w=2'}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7A6WWL4SWKAVYK6VK5YN7KZP4MZWC7IY/', 'name': 'FEDORA-2023-52ba628e03', 'tags': ['vendor-advisory']}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AJYZUBGPVWJ7LEHRCMB5XVADQBNGURXD/', 'name': 'FEDORA-2023-817ecc703f', 'tags': ['vendor-advisory']}, {'url': 'https://lists.debian.org/debian-lts-announce/2023/12/msg00027.html', 'name': '[debian-lts-announce] 20231231 [SECURITY] [DLA 3704-1] xerces-c security update', 'tags': ['mailing-list']}, {'url': 'http://www.openwall.com/lists/oss-security/2024/02/16/1', 'name': '[oss-security] 20240216 CVE-2024-23807: Apache Xerces C++: Use-after-free on external DTD scan', 'tags': ['mailing-list']}], 'descriptions': [{'lang': 'en', 'value': 'The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library and has no current mitigation other than to disable DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Denial of Service and Remote Exploit'}]}], 'providerMetadata': {'orgId': 'f0158376-9dc2-43b6-827c-5f631a4d8d09', 'shortName': 'apache', 'dateUpdated': '2024-02-16T17:05:54.808Z'}}}, 'cveMetadata': {'cveId': 'CVE-2018-1311', 'state': 'PUBLISHED', 'dateUpdated': '2025-11-04T18:14:14.531Z', 'dateReserved': '2017-12-07T00:00:00.000Z', 'assignerOrgId': 'f0158376-9dc2-43b6-827c-5f631a4d8d09', 'datePublished': '2019-12-18T00:00:00.000Z', 'assignerShortName': 'apache'}, 'dataVersion': '5.2'}
{'id': 'CVE-2018-1311', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 6.8, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.1, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 2.2}]}, 'affected': [{'source': 'security@apache.org', 'affectedData': [{'vendor': 'Apache Software Foundation', 'product': 'Apache Xerces-C', 'versions': [{'status': 'affected', 'version': '3.0.0 to 3.2.2'}]}]}], 'published': '2019-12-18T20:15:15.493', 'references': [{'url': 'http://www.openwall.com/lists/oss-security/2024/02/16/1', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'security@apache.org'}, {'url': 'https://access.redhat.com/errata/RHSA-2020:0702', 'tags': ['Third Party Advisory'], 'source': 'security@apache.org'}, {'url': 'https://access.redhat.com/errata/RHSA-2020:0704', 'tags': ['Third Party Advisory'], 'source': 'security@apache.org'}, {'url': 'https://lists.apache.org/thread.html/r48ea463fde218b1e4cc1a1d05770a0cea34de0600b4355315a49226b%40%3Cc-dev.xerces.apache.org%3E', 'tags': ['Vendor Advisory'], 'source': 'security@apache.org'}, {'url': 'https://lists.apache.org/thread.html/r90ec105571622a7dc3a43b846c12732d2e563561dfb2f72941625f35%40%3Cc-users.xerces.apache.org%3E', 'tags': ['Issue Tracking'], 'source': 'security@apache.org'}, {'url': 'https://lists.apache.org/thread.html/rabbcc0249de1dda70cda96fd9bcff78217be7a57d96e7dcc8cd96646%40%3Cc-users.xerces.apache.org%3E', 'tags': ['Issue Tracking'], 'source': 'security@apache.org'}, {'url': 'https://lists.apache.org/thread.html/rfeb8abe36bcca91eb603deef49fbbe46870918830a66328a780b8625%40%3Cc-users.xerces.apache.org%3E', 'tags': ['Issue Tracking'], 'source': 'security@apache.org'}, {'url': 'https://lists.debian.org/debian-lts-announce/2020/12/msg00025.html', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'security@apache.org'}, {'url': 'https://lists.debian.org/debian-lts-announce/2023/12/msg00027.html', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'security@apache.org'}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7A6WWL4SWKAVYK6VK5YN7KZP4MZWC7IY/', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'security@apache.org'}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AJYZUBGPVWJ7LEHRCMB5XVADQBNGURXD/', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'security@apache.org'}, {'url': 'https://marc.info/?l=xerces-c-users&m=157653840106914&w=2', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'security@apache.org'}, {'url': 'https://www.debian.org/security/2020/dsa-4814', 'tags': ['Third Party Advisory'], 'source': 'security@apache.org'}, {'url': 'https://www.oracle.com/security-alerts/cpujan2022.html', 'tags': ['Patch', 'Third Party Advisory'], 'source': 'security@apache.org'}, {'url': 'http://www.openwall.com/lists/oss-security/2024/02/16/1', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://access.redhat.com/errata/RHSA-2020:0702', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://access.redhat.com/errata/RHSA-2020:0704', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lists.apache.org/thread.html/r48ea463fde218b1e4cc1a1d05770a0cea34de0600b4355315a49226b%40%3Cc-dev.xerces.apache.org%3E', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lists.apache.org/thread.html/r90ec105571622a7dc3a43b846c12732d2e563561dfb2f72941625f35%40%3Cc-users.xerces.apache.org%3E', 'tags': ['Issue Tracking'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lists.apache.org/thread.html/rabbcc0249de1dda70cda96fd9bcff78217be7a57d96e7dcc8cd96646%40%3Cc-users.xerces.apache.org%3E', 'tags': ['Issue Tracking'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lists.apache.org/thread.html/rfeb8abe36bcca91eb603deef49fbbe46870918830a66328a780b8625%40%3Cc-users.xerces.apache.org%3E', 'tags': ['Issue Tracking'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lists.debian.org/debian-lts-announce/2020/12/msg00025.html', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lists.debian.org/debian-lts-announce/2023/12/msg00027.html', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7A6WWL4SWKAVYK6VK5YN7KZP4MZWC7IY/', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AJYZUBGPVWJ7LEHRCMB5XVADQBNGURXD/', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AJYZUBGPVWJ7LEHRCMB5XVADQBNGURXD/', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://marc.info/?l=xerces-c-users&m=157653840106914&w=2', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://www.debian.org/security/2020/dsa-4814', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://www.oracle.com/security-alerts/cpujan2022.html', 'tags': ['Patch', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-416'}]}], 'descriptions': [{'lang': 'en', 'value': 'The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library and has no current mitigation other than to disable DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable.'}, {'lang': 'es', 'value': 'El analizador XML de Apache Xerces - versiones C 3.0.0 hasta 3.2.3, contiene un error de uso de la memoria previamente liberada desencadenado durante el escaneo de los DTD externos. Este error no se ha abordado en la versión mantenida de la biblioteca y no tiene una mitigación actual que no sea deshabilitar el procesamiento de DTD. Esto se puede lograr por medio de DOM usando una funcionalidad de analizador estándar, o por medio de SAX usando la variable de entorno XERCES_DISABLE_DTD.'}], 'lastModified': '2026-06-17T01:50:59.290', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:apache:xerces-c\\+\\+:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'B5B190EE-3513-4089-BB60-ECF12A48C31A', 'versionEndExcluding': '3.2.5', 'versionStartIncluding': '3.0.0'}], 'operator': 'OR'}]}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'EE249E1B-A1FD-4E08-AA71-A0E1F10FFE97'}, {'criteria': 'cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '33C068A4-3780-4EAB-A937-6082DF847564'}, {'criteria': 'cpe:2.3:o:redhat:enterprise_linux_eus:7.7:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '83737173-E12E-4641-BC49-0BD84A6B29D0'}, {'criteria': 'cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '9BBCD86A-E6C7-4444-9D74-F861084090F0'}, {'criteria': 'cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '51EF4996-72F4-4FA4-814F-F5991E7A8318'}, {'criteria': 'cpe:2.3:o:redhat:enterprise_linux_server_aus:7.7:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '7431ABC1-9252-419E-8CC1-311B41360078'}, {'criteria': 'cpe:2.3:o:redhat:enterprise_linux_server_tus:7.7:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '17F256A9-D3B9-4C72-B013-4EFD878BFEA8'}, {'criteria': 'cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E5ED5807-55B7-47C5-97A6-03233F4FBC3A'}, {'criteria': 'cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '825ECE2D-E232-46E0-A047-074B34DB1E97'}], 'operator': 'OR'}]}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'DEECE5FC-CACF-4496-A3E7-164736409252'}, {'criteria': 'cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '07B237A9-69A3-4A9C-9DA0-4E06BD37AE73'}], 'operator': 'OR'}]}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:oracle:goldengate:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'D972FB51-4035-42DE-A25E-EE12FF67A28C', 'versionEndExcluding': '21.4.0.0.0'}], 'operator': 'OR'}]}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'CC559B26-5DFC-4B7A-A27C-B77DE755DFF9'}, {'criteria': 'cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'B8EDB836-4E6A-4B71-B9B2-AA3E03E0F646'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'security@apache.org'}
CVE-2019-11995
2019-12-18 22:46:26+03:00
2026-06-17 02:13:58.983000+03:00
PUBLISHED
Security vulnerabilities in HPE UIoT version 1.2.4.2 could allow unauthorized remote access and access to sensitive data. HPE has addressed this issue in HPE UIoT: For customers with release UIoT 1.2.4.2 fixes are made available with 1.2.4.2 RP3 HF1. For customers with release older than 1.2.4.2, such as 1.2.4.1, 1.2.4.0, the resolution will be to upgrade to 1.2.4.2 RP3 HF1 Customers are requested to upgrade to the updated versions or contact HPE support for further assistance.
HIGH
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
[{'url': 'https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03954en_us', 'source': 'security-alert@hpe.com'}, {'url': 'https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03954en_us', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:20.781064+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03954en_us', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T23:10:30.027Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'HPE IOT + GCP', 'versions': [{'status': 'affected', 'version': '1.2.4.2'}]}], 'references': [{'url': 'https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03954en_us', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'Security vulnerabilities in HPE UIoT version 1.2.4.2 could allow unauthorized remote access and access to sensitive data. HPE has addressed this issue in HPE UIoT: For customers with release UIoT 1.2.4.2 fixes are made available with 1.2.4.2 RP3 HF1. For customers with release older than 1.2.4.2, such as 1.2.4.1, 1.2.4.0, the resolution will be to upgrade to 1.2.4.2 RP3 HF1 Customers are requested to upgrade to the updated versions or contact HPE support for further assistance.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'remote unauthorized access to sensitive information; remote unauthorized remote access'}]}], 'providerMetadata': {'orgId': 'eb103674-0d28-4225-80f8-39fb86215de0', 'shortName': 'hpe', 'dateUpdated': '2019-12-18T19:46:26.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': '1.2.4.2'}]}, 'product_name': 'HPE IOT + GCP'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03954en_us', 'name': 'https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03954en_us', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Security vulnerabilities in HPE UIoT version 1.2.4.2 could allow unauthorized remote access and access to sensitive data. HPE has addressed this issue in HPE UIoT: For customers with release UIoT 1.2.4.2 fixes are made available with 1.2.4.2 RP3 HF1. For customers with release older than 1.2.4.2, such as 1.2.4.1, 1.2.4.0, the resolution will be to upgrade to 1.2.4.2 RP3 HF1 Customers are requested to upgrade to the updated versions or contact HPE support for further assistance.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'remote unauthorized access to sensitive information; remote unauthorized remote access'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-11995', 'STATE': 'PUBLIC', 'ASSIGNER': 'security-alert@hpe.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-11995', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T23:10:30.027Z', 'dateReserved': '2019-05-13T00:00:00.000Z', 'assignerOrgId': 'eb103674-0d28-4225-80f8-39fb86215de0', 'datePublished': '2019-12-18T19:46:26.000Z', 'assignerShortName': 'hpe'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-11995', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 5.0, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:P/I:N/A:N', 'authentication': 'NONE', 'integrityImpact': 'NONE', 'accessComplexity': 'LOW', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 10.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 3.6, 'exploitabilityScore': 3.9}]}, 'affected': [{'source': 'security-alert@hpe.com', 'affectedData': [{'vendor': 'n/a', 'product': 'HPE IOT + GCP', 'versions': [{'status': 'affected', 'version': '1.2.4.2'}]}]}], 'published': '2019-12-18T20:15:16.103', 'references': [{'url': 'https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03954en_us', 'tags': ['Vendor Advisory'], 'source': 'security-alert@hpe.com'}, {'url': 'https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03954en_us', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'NVD-CWE-noinfo'}]}], 'descriptions': [{'lang': 'en', 'value': 'Security vulnerabilities in HPE UIoT version 1.2.4.2 could allow unauthorized remote access and access to sensitive data. HPE has addressed this issue in HPE UIoT: For customers with release UIoT 1.2.4.2 fixes are made available with 1.2.4.2 RP3 HF1. For customers with release older than 1.2.4.2, such as 1.2.4.1, 1.2.4.0, the resolution will be to upgrade to 1.2.4.2 RP3 HF1 Customers are requested to upgrade to the updated versions or contact HPE support for further assistance.'}, {'lang': 'es', 'value': 'Vulnerabilidades de seguridad en HPE UIoT versión 1.2.4.2, podrían permitir el acceso remoto no autorizado y el acceso a datos confidenciales. HPE ha abordado este problema en HPE UIoT: para los clientes con la versión UIoT 1.2.4.2, las correcciones están disponibles con 1.2.4.2 RP3 HF1. Para los clientes con versiones mas antiguas que 1.2.4.2, como 1.2.4.1, 1.2.4.0, la resolución será actualizar a 1.2.4.2 RP3 HF1. ??Se solicitó a los clientes que actualicen a las versiones actualizadas o se pongan en contacto con el soporte de HPE para más ayuda.'}], 'lastModified': '2026-06-17T02:13:58.983', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:hp:universal_internet_of_things:1.2.4.0:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '523ADE31-F340-4B6C-99A6-8DF21340A42B'}, {'criteria': 'cpe:2.3:a:hp:universal_internet_of_things:1.2.4.1:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '8F127E3D-48B6-47EE-9048-51065872A48D'}, {'criteria': 'cpe:2.3:a:hp:universal_internet_of_things:1.2.4.2:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '9122AE4B-9F75-499D-AAC3-397F8BFD5FC7'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'security-alert@hpe.com'}
CVE-2019-16782
2019-12-18 22:05:14+03:00
2026-06-17 02:22:47.697000+03:00
PUBLISHED
There's a possible information leak / session hijack vulnerability in Rack (RubyGem rack). This vulnerability is patched in versions 1.6.12 and 2.0.8. Attackers may be able to find and hijack sessions by using timing attacks targeting the session id. Session ids are usually stored and indexed in a database that uses some kind of scheme for speeding up lookups of that session id. By carefully measuring the amount of time it takes to look up a session, an attacker may be able to find a valid session id and hijack the session. The session id itself may be generated randomly, but the way the session is indexed by the backing store does not use a secure comparison.
MEDIUM
6.3
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
[{'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00016.html', 'source': 'security-advisories@github.com'}, {'url': 'http://www.openwall.com/lists/oss-security/2019/12/18/2', 'source': 'security-advisories@github.com'}, {'url': 'http://www.openwall.com/lists/oss-security/2019/12/18/3', 'source': 'security-advisories@github.com'}, {'url': 'http://www.openwall.com/lists/oss-security/2019/12/19/3', 'source': 'security-advisories@github.com'}, {'url': 'http://www.openwall.com/lists/oss-security/2020/04/08/1', 'source': 'security-advisories@github.com'}, {'url': 'http://www.openwall.com/lists/oss-security/2020/04/09/2', 'source': 'security-advisories@github.com'}, {'url': 'https://github.com/rack/rack/commit/7fecaee81f59926b6e1913511c90650e76673b38', 'source': 'security-advisories@github.com'}, {'url': 'https://github.com/rack/rack/security/advisories/GHSA-hrqr-hxpp-chr3', 'source': 'security-advisories@github.com'}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HZXMWILCICQLA2BYSP6I2CRMUG53YBLX/', 'source': 'security-advisories@github.com'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00016.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://www.openwall.com/lists/oss-security/2019/12/18/2', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://www.openwall.com/lists/oss-security/2019/12/18/3', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://www.openwall.com/lists/oss-security/2019/12/19/3', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://www.openwall.com/lists/oss-security/2020/04/08/1', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://www.openwall.com/lists/oss-security/2020/04/09/2', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://github.com/rack/rack/commit/7fecaee81f59926b6e1913511c90650e76673b38', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://github.com/rack/rack/security/advisories/GHSA-hrqr-hxpp-chr3', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HZXMWILCICQLA2BYSP6I2CRMUG53YBLX/', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:17.749529+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://github.com/rack/rack/security/advisories/GHSA-hrqr-hxpp-chr3', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'https://github.com/rack/rack/commit/7fecaee81f59926b6e1913511c90650e76673b38', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://www.openwall.com/lists/oss-security/2019/12/18/3', 'name': '[oss-security] 20191219 Re: [CVE-2019-16782] Possible Information Leak / Session Hijack Vulnerability in Rack', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}, {'url': 'http://www.openwall.com/lists/oss-security/2019/12/18/2', 'name': '[oss-security] 20191218 [CVE-2019-16782] Possible Information Leak / Session Hijack Vulnerability in Rack', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}, {'url': 'http://www.openwall.com/lists/oss-security/2019/12/19/3', 'name': '[oss-security] 20191218 Re: [CVE-2019-16782] Possible Information Leak / Session Hijack Vulnerability in Rack', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HZXMWILCICQLA2BYSP6I2CRMUG53YBLX/', 'name': 'FEDORA-2020-57fc0d0156', 'tags': ['vendor-advisory', 'x_refsource_FEDORA', 'x_transferred']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00016.html', 'name': 'openSUSE-SU-2020:0214', 'tags': ['vendor-advisory', 'x_refsource_SUSE', 'x_transferred']}, {'url': 'http://www.openwall.com/lists/oss-security/2020/04/08/1', 'name': '[oss-security] 20200409 Re: [CVE-2019-16782] Possible Information Leak / Session Hijack Vulnerability in Rack', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}, {'url': 'http://www.openwall.com/lists/oss-security/2020/04/09/2', 'name': '[oss-security] 20200408 Re: [CVE-2019-16782] Possible Information Leak / Session Hijack Vulnerability in Rack', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-05T01:24:48.031Z'}}], 'cna': {'title': 'Possible Information Leak / Session Hijack Vulnerability in Rack', 'source': {'advisory': 'GHSA-hrqr-hxpp-chr3', 'discovery': 'UNKNOWN'}, 'metrics': [{'cvssV3_1': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 6.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}}], 'affected': [{'vendor': 'rack', 'product': 'rack', 'versions': [{'status': 'affected', 'version': 'before 1.6.12 or 2.0.8'}]}], 'references': [{'url': 'https://github.com/rack/rack/security/advisories/GHSA-hrqr-hxpp-chr3', 'tags': ['x_refsource_CONFIRM']}, {'url': 'https://github.com/rack/rack/commit/7fecaee81f59926b6e1913511c90650e76673b38', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://www.openwall.com/lists/oss-security/2019/12/18/3', 'name': '[oss-security] 20191219 Re: [CVE-2019-16782] Possible Information Leak / Session Hijack Vulnerability in Rack', 'tags': ['mailing-list', 'x_refsource_MLIST']}, {'url': 'http://www.openwall.com/lists/oss-security/2019/12/18/2', 'name': '[oss-security] 20191218 [CVE-2019-16782] Possible Information Leak / Session Hijack Vulnerability in Rack', 'tags': ['mailing-list', 'x_refsource_MLIST']}, {'url': 'http://www.openwall.com/lists/oss-security/2019/12/19/3', 'name': '[oss-security] 20191218 Re: [CVE-2019-16782] Possible Information Leak / Session Hijack Vulnerability in Rack', 'tags': ['mailing-list', 'x_refsource_MLIST']}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HZXMWILCICQLA2BYSP6I2CRMUG53YBLX/', 'name': 'FEDORA-2020-57fc0d0156', 'tags': ['vendor-advisory', 'x_refsource_FEDORA']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00016.html', 'name': 'openSUSE-SU-2020:0214', 'tags': ['vendor-advisory', 'x_refsource_SUSE']}, {'url': 'http://www.openwall.com/lists/oss-security/2020/04/08/1', 'name': '[oss-security] 20200409 Re: [CVE-2019-16782] Possible Information Leak / Session Hijack Vulnerability in Rack', 'tags': ['mailing-list', 'x_refsource_MLIST']}, {'url': 'http://www.openwall.com/lists/oss-security/2020/04/09/2', 'name': '[oss-security] 20200408 Re: [CVE-2019-16782] Possible Information Leak / Session Hijack Vulnerability in Rack', 'tags': ['mailing-list', 'x_refsource_MLIST']}], 'descriptions': [{'lang': 'en', 'value': "There's a possible information leak / session hijack vulnerability in Rack (RubyGem rack). This vulnerability is patched in versions 1.6.12 and 2.0.8. Attackers may be able to find and hijack sessions by using timing attacks targeting the session id. Session ids are usually stored and indexed in a database that uses some kind of scheme for speeding up lookups of that session id. By carefully measuring the amount of time it takes to look up a session, an attacker may be able to find a valid session id and hijack the session. The session id itself may be generated randomly, but the way the session is indexed by the backing store does not use a secure comparison."}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-208', 'description': 'CWE-208 Information Exposure Through Timing Discrepancy'}]}], 'providerMetadata': {'orgId': 'a0819718-46f1-4df5-94e2-005712e83aaa', 'shortName': 'GitHub_M', 'dateUpdated': '2020-04-09T14:06:01.000Z'}, 'x_legacyV4Record': {'impact': {'cvss': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 6.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}}, 'source': {'advisory': 'GHSA-hrqr-hxpp-chr3', 'discovery': 'UNKNOWN'}, 'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'before 1.6.12 or 2.0.8'}]}, 'product_name': 'rack'}]}, 'vendor_name': 'rack'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://github.com/rack/rack/security/advisories/GHSA-hrqr-hxpp-chr3', 'name': 'https://github.com/rack/rack/security/advisories/GHSA-hrqr-hxpp-chr3', 'refsource': 'CONFIRM'}, {'url': 'https://github.com/rack/rack/commit/7fecaee81f59926b6e1913511c90650e76673b38', 'name': 'https://github.com/rack/rack/commit/7fecaee81f59926b6e1913511c90650e76673b38', 'refsource': 'CONFIRM'}, {'url': 'http://www.openwall.com/lists/oss-security/2019/12/18/3', 'name': '[oss-security] 20191219 Re: [CVE-2019-16782] Possible Information Leak / Session Hijack Vulnerability in Rack', 'refsource': 'MLIST'}, {'url': 'http://www.openwall.com/lists/oss-security/2019/12/18/2', 'name': '[oss-security] 20191218 [CVE-2019-16782] Possible Information Leak / Session Hijack Vulnerability in Rack', 'refsource': 'MLIST'}, {'url': 'http://www.openwall.com/lists/oss-security/2019/12/19/3', 'name': '[oss-security] 20191218 Re: [CVE-2019-16782] Possible Information Leak / Session Hijack Vulnerability in Rack', 'refsource': 'MLIST'}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HZXMWILCICQLA2BYSP6I2CRMUG53YBLX/', 'name': 'FEDORA-2020-57fc0d0156', 'refsource': 'FEDORA'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00016.html', 'name': 'openSUSE-SU-2020:0214', 'refsource': 'SUSE'}, {'url': 'http://www.openwall.com/lists/oss-security/2020/04/08/1', 'name': '[oss-security] 20200409 Re: [CVE-2019-16782] Possible Information Leak / Session Hijack Vulnerability in Rack', 'refsource': 'MLIST'}, {'url': 'http://www.openwall.com/lists/oss-security/2020/04/09/2', 'name': '[oss-security] 20200408 Re: [CVE-2019-16782] Possible Information Leak / Session Hijack Vulnerability in Rack', 'refsource': 'MLIST'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': "There's a possible information leak / session hijack vulnerability in Rack (RubyGem rack). This vulnerability is patched in versions 1.6.12 and 2.0.8. Attackers may be able to find and hijack sessions by using timing attacks targeting the session id. Session ids are usually stored and indexed in a database that uses some kind of scheme for speeding up lookups of that session id. By carefully measuring the amount of time it takes to look up a session, an attacker may be able to find a valid session id and hijack the session. The session id itself may be generated randomly, but the way the session is indexed by the backing store does not use a secure comparison."}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'CWE-208 Information Exposure Through Timing Discrepancy'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-16782', 'STATE': 'PUBLIC', 'TITLE': 'Possible Information Leak / Session Hijack Vulnerability in Rack', 'ASSIGNER': 'security-advisories@github.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-16782', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-05T01:24:48.031Z', 'dateReserved': '2019-09-24T00:00:00.000Z', 'assignerOrgId': 'a0819718-46f1-4df5-94e2-005712e83aaa', 'datePublished': '2019-12-18T19:05:14.000Z', 'assignerShortName': 'GitHub_M'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-16782', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 4.3, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:P/I:N/A:N', 'authentication': 'NONE', 'integrityImpact': 'NONE', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Secondary', 'source': 'security-advisories@github.com', 'cvssData': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 6.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'impactScore': 4.0, 'exploitabilityScore': 1.8}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.9, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 3.6, 'exploitabilityScore': 2.2}]}, 'affected': [{'source': 'security-advisories@github.com', 'affectedData': [{'vendor': 'rack', 'product': 'rack', 'versions': [{'status': 'affected', 'version': 'before 1.6.12 or 2.0.8'}]}]}], 'published': '2019-12-18T20:15:16.180', 'references': [{'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00016.html', 'tags': ['Third Party Advisory'], 'source': 'security-advisories@github.com'}, {'url': 'http://www.openwall.com/lists/oss-security/2019/12/18/2', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'security-advisories@github.com'}, {'url': 'http://www.openwall.com/lists/oss-security/2019/12/18/3', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'security-advisories@github.com'}, {'url': 'http://www.openwall.com/lists/oss-security/2019/12/19/3', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'security-advisories@github.com'}, {'url': 'http://www.openwall.com/lists/oss-security/2020/04/08/1', 'tags': ['Mailing List', 'Patch', 'Third Party Advisory'], 'source': 'security-advisories@github.com'}, {'url': 'http://www.openwall.com/lists/oss-security/2020/04/09/2', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'security-advisories@github.com'}, {'url': 'https://github.com/rack/rack/commit/7fecaee81f59926b6e1913511c90650e76673b38', 'tags': ['Patch', 'Third Party Advisory'], 'source': 'security-advisories@github.com'}, {'url': 'https://github.com/rack/rack/security/advisories/GHSA-hrqr-hxpp-chr3', 'tags': ['Third Party Advisory'], 'source': 'security-advisories@github.com'}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HZXMWILCICQLA2BYSP6I2CRMUG53YBLX/', 'source': 'security-advisories@github.com'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00016.html', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://www.openwall.com/lists/oss-security/2019/12/18/2', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://www.openwall.com/lists/oss-security/2019/12/18/3', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://www.openwall.com/lists/oss-security/2019/12/19/3', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://www.openwall.com/lists/oss-security/2020/04/08/1', 'tags': ['Mailing List', 'Patch', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://www.openwall.com/lists/oss-security/2020/04/09/2', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://github.com/rack/rack/commit/7fecaee81f59926b6e1913511c90650e76673b38', 'tags': ['Patch', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://github.com/rack/rack/security/advisories/GHSA-hrqr-hxpp-chr3', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HZXMWILCICQLA2BYSP6I2CRMUG53YBLX/', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Secondary', 'source': 'security-advisories@github.com', 'description': [{'lang': 'en', 'value': 'CWE-208'}]}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-203'}]}], 'descriptions': [{'lang': 'en', 'value': "There's a possible information leak / session hijack vulnerability in Rack (RubyGem rack). This vulnerability is patched in versions 1.6.12 and 2.0.8. Attackers may be able to find and hijack sessions by using timing attacks targeting the session id. Session ids are usually stored and indexed in a database that uses some kind of scheme for speeding up lookups of that session id. By carefully measuring the amount of time it takes to look up a session, an attacker may be able to find a valid session id and hijack the session. The session id itself may be generated randomly, but the way the session is indexed by the backing store does not use a secure comparison."}, {'lang': 'es', 'value': 'Se presenta una posible vulnerabilidad de fuga de información y secuestro de sesión en Rack (rack RubyGem). Esta vulnerabilidad está parchada en las versiones 1.6.12 y 2.0.8. Los atacantes pueden ser capaces de encontrar y secuestrar sesiones utilizando ataques de sincronización dirigidos al id de sesión. Los id de sesión comúnmente son almacenados e indexados a una base de datos que utiliza algún tipo de esquema para acelerar las búsquedas de ese identificador de sesión. Al medir cuidadosamente la cantidad de tiempo que toma buscar una sesión, un atacante puede encontrar un id de sesión válida y secuestrar la sesión. El id de sesión en sí puede ser generado aleatoriamente, pero la forma en que es indexada la sesión por parte del almacén de respaldo no utiliza una comparación segura.'}], 'lastModified': '2026-06-17T02:22:47.697', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:*', 'vulnerable': True, 'matchCriteriaId': 'D920538B-B12B-4CB6-B04C-4ED0122B1ACE', 'versionEndExcluding': '1.6.12'}, {'criteria': 'cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:*', 'vulnerable': True, 'matchCriteriaId': '75BDB863-165A-4446-855E-25243469A538', 'versionEndExcluding': '2.0.8', 'versionStartIncluding': '2.0.0'}], 'operator': 'OR'}]}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '80F0FA5D-8D3B-4C0E-81E2-87998286AF33'}], 'operator': 'OR'}]}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'B620311B-34A3-48A6-82DF-6F078D7A4493'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'security-advisories@github.com'}
CVE-2019-18267
2019-12-18 22:37:46+03:00
2026-06-17 02:24:43.600000+03:00
PUBLISHED
An issue was found in GE S2020/S2020G Fast Switch 61850, S2020/S2020G Fast Switch 61850 Versions 07A03 and prior. An attacker can inject arbitrary Javascript in a specially crafted HTTP request that may be reflected back in the HTTP response. The device is also vulnerable to a stored cross-site scripting vulnerability that may allow session hijacking, disclosure of sensitive data, cross-site request forgery (CSRF) attacks, and remote code execution.
MEDIUM
5.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
[{'url': 'https://www.us-cert.gov/ics/advisories/icsa-19-351-01', 'source': 'ics-cert@hq.dhs.gov'}, {'url': 'https://www.us-cert.gov/ics/advisories/icsa-19-351-01', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:15.698920+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://www.us-cert.gov/ics/advisories/icsa-19-351-01', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-05T01:47:14.086Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'GE S2020/S2020G Fast Switch 61850', 'versions': [{'status': 'affected', 'version': 'S2020/S2020G Fast Switch 61850 Versions 07A03 and prior'}]}], 'references': [{'url': 'https://www.us-cert.gov/ics/advisories/icsa-19-351-01', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'An issue was found in GE S2020/S2020G Fast Switch 61850, S2020/S2020G Fast Switch 61850 Versions 07A03 and prior. An attacker can inject arbitrary Javascript in a specially crafted HTTP request that may be reflected back in the HTTP response. The device is also vulnerable to a stored cross-site scripting vulnerability that may allow session hijacking, disclosure of sensitive data, cross-site request forgery (CSRF) attacks, and remote code execution.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-79', 'description': "IMPROPER NEUTRALIZATION OF INPUT DURING WEB PAGE GENERATION ('CROSS-SITE SCRIPTING') CWE-79"}]}], 'providerMetadata': {'orgId': '7d14cffa-0d7d-4270-9dc0-52cabd5a23a6', 'shortName': 'icscert', 'dateUpdated': '2019-12-18T19:37:46.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'S2020/S2020G Fast Switch 61850 Versions 07A03 and prior'}]}, 'product_name': 'GE S2020/S2020G Fast Switch 61850'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://www.us-cert.gov/ics/advisories/icsa-19-351-01', 'name': 'https://www.us-cert.gov/ics/advisories/icsa-19-351-01', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'An issue was found in GE S2020/S2020G Fast Switch 61850, S2020/S2020G Fast Switch 61850 Versions 07A03 and prior. An attacker can inject arbitrary Javascript in a specially crafted HTTP request that may be reflected back in the HTTP response. The device is also vulnerable to a stored cross-site scripting vulnerability that may allow session hijacking, disclosure of sensitive data, cross-site request forgery (CSRF) attacks, and remote code execution.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': "IMPROPER NEUTRALIZATION OF INPUT DURING WEB PAGE GENERATION ('CROSS-SITE SCRIPTING') CWE-79"}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-18267', 'STATE': 'PUBLIC', 'ASSIGNER': 'ics-cert@hq.dhs.gov'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-18267', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-05T01:47:14.086Z', 'dateReserved': '2019-10-22T00:00:00.000Z', 'assignerOrgId': '7d14cffa-0d7d-4270-9dc0-52cabd5a23a6', 'datePublished': '2019-12-18T19:37:46.000Z', 'assignerShortName': 'icscert'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-18267', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 3.5, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:S/C:N/I:P/A:N', 'authentication': 'SINGLE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'NONE'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'LOW', 'obtainAllPrivilege': False, 'exploitabilityScore': 6.8, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 5.4, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N', 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'LOW'}, 'impactScore': 2.7, 'exploitabilityScore': 2.3}]}, 'affected': [{'source': 'ics-cert@hq.dhs.gov', 'affectedData': [{'vendor': 'n/a', 'product': 'GE S2020/S2020G Fast Switch 61850', 'versions': [{'status': 'affected', 'version': 'S2020/S2020G Fast Switch 61850 Versions 07A03 and prior'}]}]}], 'published': '2019-12-18T20:15:16.383', 'references': [{'url': 'https://www.us-cert.gov/ics/advisories/icsa-19-351-01', 'tags': ['Third Party Advisory', 'US Government Resource'], 'source': 'ics-cert@hq.dhs.gov'}, {'url': 'https://www.us-cert.gov/ics/advisories/icsa-19-351-01', 'tags': ['Third Party Advisory', 'US Government Resource'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Secondary', 'source': 'ics-cert@hq.dhs.gov', 'description': [{'lang': 'en', 'value': 'CWE-79'}]}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-79'}]}], 'descriptions': [{'lang': 'en', 'value': 'An issue was found in GE S2020/S2020G Fast Switch 61850, S2020/S2020G Fast Switch 61850 Versions 07A03 and prior. An attacker can inject arbitrary Javascript in a specially crafted HTTP request that may be reflected back in the HTTP response. The device is also vulnerable to a stored cross-site scripting vulnerability that may allow session hijacking, disclosure of sensitive data, cross-site request forgery (CSRF) attacks, and remote code execution.'}, {'lang': 'es', 'value': 'Se detectó un problema en GE S2020/S2020G Fast Switch 61850, S2020/S2020G Fast Switch 61850 Versiones 07A03 y anteriores. Un atacante puede inyectar Javascript arbitrario en una petición HTTP especialmente diseñada que puede ser reflejada en la respuesta HTTP. El dispositivo también es susceptible a una vulnerabilidad de tipo cross-site scripting almacenado que puede permitir un secuestro de sesión, una divulgación de datos confidenciales, ataques de tipo cross-site request forgery (CSRF) y una ejecución de código remota.'}], 'lastModified': '2026-06-17T02:24:43.600', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:ge:s2020_firmware:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'C3616651-CFB3-4E75-BDB9-CA7F571A1DA3', 'versionEndIncluding': '07a03'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:ge:s2020:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '246DAD44-F752-4BE4-9475-ADFAA70BEB44'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:ge:s2020g_firmware:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AD846435-648D-447F-93BA-15F83AD792DA', 'versionEndIncluding': '07a03'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:ge:s2020g:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '88390636-707A-4B0D-973E-4EB0495E0B13'}], 'operator': 'OR'}], 'operator': 'AND'}], 'sourceIdentifier': 'ics-cert@hq.dhs.gov'}
CVE-2019-19688
2019-12-18 21:30:15+03:00
2026-06-17 02:27:05.047000+03:00
PUBLISHED
A privilege escalation vulnerability in Trend Micro HouseCall for Home Networks (versions below 5.3.0.1063) could be exploited allowing an attacker to place a malicious DLL file into the application directory and elevate privileges.
HIGH
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'https://helpcenter.trendmicro.com/en-us/article/TMKA-21674', 'source': 'security@trendmicro.com'}, {'url': 'https://helpcenter.trendmicro.com/en-us/article/TMKA-21674', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:15.937311+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://helpcenter.trendmicro.com/en-us/article/TMKA-21674', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-05T02:25:12.367Z'}}], 'cna': {'affected': [{'vendor': 'Trend Micro', 'product': 'Trend Micro HouseCall for Home Networks', 'versions': [{'status': 'affected', 'version': 'Below 5.3.0.1063'}]}], 'references': [{'url': 'https://helpcenter.trendmicro.com/en-us/article/TMKA-21674', 'tags': ['x_refsource_CONFIRM']}], 'descriptions': [{'lang': 'en', 'value': 'A privilege escalation vulnerability in Trend Micro HouseCall for Home Networks (versions below 5.3.0.1063) could be exploited allowing an attacker to place a malicious DLL file into the application directory and elevate privileges.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Privilege Escalation'}]}], 'providerMetadata': {'orgId': '7f7bd7df-cffe-4fdb-ab6d-859363b89272', 'shortName': 'trendmicro', 'dateUpdated': '2020-10-07T16:01:26.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'Below 5.3.0.1063'}]}, 'product_name': 'Trend Micro HouseCall for Home Networks'}]}, 'vendor_name': 'Trend Micro'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://helpcenter.trendmicro.com/en-us/article/TMKA-21674', 'name': 'https://helpcenter.trendmicro.com/en-us/article/TMKA-21674', 'refsource': 'CONFIRM'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'A privilege escalation vulnerability in Trend Micro HouseCall for Home Networks (versions below 5.3.0.1063) could be exploited allowing an attacker to place a malicious DLL file into the application directory and elevate privileges.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Privilege Escalation'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-19688', 'STATE': 'PUBLIC', 'ASSIGNER': 'security@trendmicro.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-19688', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-05T02:25:12.367Z', 'dateReserved': '2019-12-09T00:00:00.000Z', 'assignerOrgId': '7f7bd7df-cffe-4fdb-ab6d-859363b89272', 'datePublished': '2019-12-18T18:30:15.000Z', 'assignerShortName': 'trendmicro'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-19688', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 4.4, 'accessVector': 'LOCAL', 'vectorString': 'AV:L/AC:M/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 3.4, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 1.8}]}, 'affected': [{'source': 'security@trendmicro.com', 'affectedData': [{'vendor': 'Trend Micro', 'product': 'Trend Micro HouseCall for Home Networks', 'versions': [{'status': 'affected', 'version': 'Below 5.3.0.1063'}]}]}], 'published': '2019-12-18T20:15:16.493', 'references': [{'url': 'https://helpcenter.trendmicro.com/en-us/article/TMKA-21674', 'source': 'security@trendmicro.com'}, {'url': 'https://helpcenter.trendmicro.com/en-us/article/TMKA-21674', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'NVD-CWE-noinfo'}]}], 'descriptions': [{'lang': 'en', 'value': 'A privilege escalation vulnerability in Trend Micro HouseCall for Home Networks (versions below 5.3.0.1063) could be exploited allowing an attacker to place a malicious DLL file into the application directory and elevate privileges.'}, {'lang': 'es', 'value': 'Una vulnerabilidad de escalada de privilegios en Trend Micro HouseCall for Home Networks (versiones por debajo de 5.3.0.1063), podría ser explotada permitiendo a un atacante colocar un archivo DLL malicioso en el directorio de la aplicación y elevar los privilegios.'}], 'lastModified': '2026-06-17T02:27:05.047', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:trendmicro:housecall_for_home_networks:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'BC53A2DD-6C55-4FC0-846F-A07C8BFFA82E', 'versionEndExcluding': '5.3.0.1063'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'security@trendmicro.com'}
CVE-2019-19689
2019-12-18 21:30:16+03:00
2026-06-17 02:27:05.780000+03:00
PUBLISHED
Trend Micro HouseCall for Home Networks (versions below 5.3.0.1063) could be exploited via a DLL Hijack related to a vulnerability on the packer that the program uses.
HIGH
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'https://helpcenter.trendmicro.com/en-us/article/TMKA-21674', 'source': 'security@trendmicro.com'}, {'url': 'https://helpcenter.trendmicro.com/en-us/article/TMKA-21674', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:15.698920+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://helpcenter.trendmicro.com/en-us/article/TMKA-21674', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-05T02:25:12.207Z'}}], 'cna': {'affected': [{'vendor': 'Trend Micro', 'product': 'Trend Micro HouseCall for Home Networks', 'versions': [{'status': 'affected', 'version': 'Below 5.3.0.1063'}]}], 'references': [{'url': 'https://helpcenter.trendmicro.com/en-us/article/TMKA-21674', 'tags': ['x_refsource_CONFIRM']}], 'descriptions': [{'lang': 'en', 'value': 'Trend Micro HouseCall for Home Networks (versions below 5.3.0.1063) could be exploited via a DLL Hijack related to a vulnerability on the packer that the program uses.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'DLL Hijack'}]}], 'providerMetadata': {'orgId': '7f7bd7df-cffe-4fdb-ab6d-859363b89272', 'shortName': 'trendmicro', 'dateUpdated': '2020-10-07T16:00:18.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'Below 5.3.0.1063'}]}, 'product_name': 'Trend Micro HouseCall for Home Networks'}]}, 'vendor_name': 'Trend Micro'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://helpcenter.trendmicro.com/en-us/article/TMKA-21674', 'name': 'https://helpcenter.trendmicro.com/en-us/article/TMKA-21674', 'refsource': 'CONFIRM'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Trend Micro HouseCall for Home Networks (versions below 5.3.0.1063) could be exploited via a DLL Hijack related to a vulnerability on the packer that the program uses.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'DLL Hijack'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-19689', 'STATE': 'PUBLIC', 'ASSIGNER': 'security@trendmicro.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-19689', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-05T02:25:12.207Z', 'dateReserved': '2019-12-09T00:00:00.000Z', 'assignerOrgId': '7f7bd7df-cffe-4fdb-ab6d-859363b89272', 'datePublished': '2019-12-18T18:30:16.000Z', 'assignerShortName': 'trendmicro'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-19689', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 4.4, 'accessVector': 'LOCAL', 'vectorString': 'AV:L/AC:M/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 3.4, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 1.8}]}, 'affected': [{'source': 'security@trendmicro.com', 'affectedData': [{'vendor': 'Trend Micro', 'product': 'Trend Micro HouseCall for Home Networks', 'versions': [{'status': 'affected', 'version': 'Below 5.3.0.1063'}]}]}], 'published': '2019-12-18T20:15:16.540', 'references': [{'url': 'https://helpcenter.trendmicro.com/en-us/article/TMKA-21674', 'tags': ['Vendor Advisory'], 'source': 'security@trendmicro.com'}, {'url': 'https://helpcenter.trendmicro.com/en-us/article/TMKA-21674', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-427'}]}], 'descriptions': [{'lang': 'en', 'value': 'Trend Micro HouseCall for Home Networks (versions below 5.3.0.1063) could be exploited via a DLL Hijack related to a vulnerability on the packer that the program uses.'}, {'lang': 'es', 'value': 'Trend Micro HouseCall for Home Networks (versiones por debajo de 5.3.0.1063), podría ser explotado mediante un secuestro de DLL relacionado con una vulnerabilidad en el empaquetador que el programa utiliza.'}], 'lastModified': '2026-06-17T02:27:05.780', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:trendmicro:housecall_for_home_networks:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'BC53A2DD-6C55-4FC0-846F-A07C8BFFA82E', 'versionEndExcluding': '5.3.0.1063'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'A2572D17-1DE6-457B-99CC-64AFD54487EA'}], 'operator': 'OR'}], 'operator': 'AND'}], 'sourceIdentifier': 'security@trendmicro.com'}
CVE-2019-19690
2019-12-18 21:30:16+03:00
2026-06-17 02:27:05.880000+03:00
PUBLISHED
Trend Micro Mobile Security for Android (Consumer) versions 10.3.1 and below on Android 8.0+ has an issue in which an attacker could bypass the product's App Password Protection feature.
CRITICAL
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
[{'url': 'https://esupport.trendmicro.com/en-us/home/pages/technical-support/1124037.aspx', 'source': 'security@trendmicro.com'}, {'url': 'https://esupport.trendmicro.com/en-us/home/pages/technical-support/1124037.aspx', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:15.937311+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://esupport.trendmicro.com/en-us/home/pages/technical-support/1124037.aspx', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-05T02:25:12.487Z'}}], 'cna': {'affected': [{'vendor': 'Trend Micro', 'product': 'Trend Micro Mobile Security for Android (Consumer)', 'versions': [{'status': 'affected', 'version': '10.3.1 and below'}]}], 'references': [{'url': 'https://esupport.trendmicro.com/en-us/home/pages/technical-support/1124037.aspx', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': "Trend Micro Mobile Security for Android (Consumer) versions 10.3.1 and below on Android 8.0+ has an issue in which an attacker could bypass the product's App Password Protection feature."}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Protection Bypass'}]}], 'providerMetadata': {'orgId': '7f7bd7df-cffe-4fdb-ab6d-859363b89272', 'shortName': 'trendmicro', 'dateUpdated': '2019-12-18T18:30:16.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': '10.3.1 and below'}]}, 'product_name': 'Trend Micro Mobile Security for Android (Consumer)'}]}, 'vendor_name': 'Trend Micro'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://esupport.trendmicro.com/en-us/home/pages/technical-support/1124037.aspx', 'name': 'https://esupport.trendmicro.com/en-us/home/pages/technical-support/1124037.aspx', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': "Trend Micro Mobile Security for Android (Consumer) versions 10.3.1 and below on Android 8.0+ has an issue in which an attacker could bypass the product's App Password Protection feature."}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Protection Bypass'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-19690', 'STATE': 'PUBLIC', 'ASSIGNER': 'security@trendmicro.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-19690', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-05T02:25:12.487Z', 'dateReserved': '2019-12-09T00:00:00.000Z', 'assignerOrgId': '7f7bd7df-cffe-4fdb-ab6d-859363b89272', 'datePublished': '2019-12-18T18:30:16.000Z', 'assignerShortName': 'trendmicro'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-19690', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 7.5, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'LOW', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'HIGH', 'obtainAllPrivilege': False, 'exploitabilityScore': 10.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 3.9}]}, 'affected': [{'source': 'security@trendmicro.com', 'affectedData': [{'vendor': 'Trend Micro', 'product': 'Trend Micro Mobile Security for Android (Consumer)', 'versions': [{'status': 'affected', 'version': '10.3.1 and below'}]}]}], 'published': '2019-12-18T20:15:16.633', 'references': [{'url': 'https://esupport.trendmicro.com/en-us/home/pages/technical-support/1124037.aspx', 'tags': ['Vendor Advisory'], 'source': 'security@trendmicro.com'}, {'url': 'https://esupport.trendmicro.com/en-us/home/pages/technical-support/1124037.aspx', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-521'}]}], 'descriptions': [{'lang': 'en', 'value': "Trend Micro Mobile Security for Android (Consumer) versions 10.3.1 and below on Android 8.0+ has an issue in which an attacker could bypass the product's App Password Protection feature."}, {'lang': 'es', 'value': 'Trend Micro Mobile Security for Android (Consumer) versiones 10.3.1 y por debajo en Android versión 8.0+ presenta un problema donde un atacante podría omitir la funcionalidad App Password Protection del producto.'}], 'lastModified': '2026-06-17T02:27:05.880', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:trendmicro:mobile_security:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A61BD217-2122-4776-95F8-C4DFFE56020E', 'versionEndIncluding': '10.3.1'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:google:android:*:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '92B9CEAC-D863-4C12-9D6C-BA8853D53DFD', 'versionStartIncluding': '8.0'}], 'operator': 'OR'}], 'operator': 'AND'}], 'sourceIdentifier': 'security@trendmicro.com'}
CVE-2019-5074
2019-12-18 22:30:27+03:00
2026-06-17 02:37:05.283000+03:00
PUBLISHED
An exploitable stack buffer overflow vulnerability exists in the iocheckd service ''I/O-Check'' functionality of WAGO PFC200 Firmware version 03.01.07(13), WAGO PFC200 Firmware version 03.00.39(12) and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a stack buffer overflow, resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability.
CRITICAL
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
[{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0863', 'source': 'talos-cna@cisco.com'}, {'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0863', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:12.293545+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0863', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T19:47:55.643Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'WAGO PFC200', 'versions': [{'status': 'affected', 'version': 'Firmware version 03.01.07(13)'}, {'status': 'affected', 'version': 'Firmware version 03.00.39(12)'}]}, {'vendor': 'n/a', 'product': 'WAGO PFC100', 'versions': [{'status': 'affected', 'version': 'Firmware version 03.00.39(12)'}]}], 'references': [{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0863', 'tags': ['x_refsource_CONFIRM']}], 'descriptions': [{'lang': 'en', 'value': "An exploitable stack buffer overflow vulnerability exists in the iocheckd service ''I/O-Check'' functionality of WAGO PFC200 Firmware version 03.01.07(13), WAGO PFC200 Firmware version 03.00.39(12) and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a stack buffer overflow, resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability."}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'remote code execution'}]}], 'providerMetadata': {'orgId': 'b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b', 'shortName': 'talos', 'dateUpdated': '2019-12-18T19:30:27.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'Firmware version 03.01.07(13)'}, {'version_value': 'Firmware version 03.00.39(12)'}]}, 'product_name': 'WAGO PFC200'}, {'version': {'version_data': [{'version_value': 'Firmware version 03.00.39(12)'}]}, 'product_name': 'WAGO PFC100'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0863', 'name': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0863', 'refsource': 'CONFIRM'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': "An exploitable stack buffer overflow vulnerability exists in the iocheckd service ''I/O-Check'' functionality of WAGO PFC200 Firmware version 03.01.07(13), WAGO PFC200 Firmware version 03.00.39(12) and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a stack buffer overflow, resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability."}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'remote code execution'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-5074', 'STATE': 'PUBLIC', 'ASSIGNER': 'talos-cna@cisco.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-5074', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T19:47:55.643Z', 'dateReserved': '2019-01-04T00:00:00.000Z', 'assignerOrgId': 'b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b', 'datePublished': '2019-12-18T19:30:27.000Z', 'assignerShortName': 'talos'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-5074', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 10.0, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:C/I:C/A:C', 'authentication': 'NONE', 'integrityImpact': 'COMPLETE', 'accessComplexity': 'LOW', 'availabilityImpact': 'COMPLETE', 'confidentialityImpact': 'COMPLETE'}, 'acInsufInfo': False, 'impactScore': 10.0, 'baseSeverity': 'HIGH', 'obtainAllPrivilege': False, 'exploitabilityScore': 10.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 3.9}]}, 'affected': [{'source': 'talos-cna@cisco.com', 'affectedData': [{'vendor': 'n/a', 'product': 'WAGO PFC200', 'versions': [{'status': 'affected', 'version': 'Firmware version 03.01.07(13)'}, {'status': 'affected', 'version': 'Firmware version 03.00.39(12)'}]}, {'vendor': 'n/a', 'product': 'WAGO PFC100', 'versions': [{'status': 'affected', 'version': 'Firmware version 03.00.39(12)'}]}]}], 'published': '2019-12-18T20:15:16.760', 'references': [{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0863', 'tags': ['Third Party Advisory'], 'source': 'talos-cna@cisco.com'}, {'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0863', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-787'}]}], 'descriptions': [{'lang': 'en', 'value': "An exploitable stack buffer overflow vulnerability exists in the iocheckd service ''I/O-Check'' functionality of WAGO PFC200 Firmware version 03.01.07(13), WAGO PFC200 Firmware version 03.00.39(12) and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a stack buffer overflow, resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability."}, {'lang': 'es', 'value': "Se presenta una vulnerabilidad de desbordamiento del búfer de la pila explotable en la funcionalidad ''I/O-Check'' del servicio iocheckd de WAGO PFC200 versión de firmware 03.01.07(13), WAGO PFC200 versión de firmware 03.00.39(12) y WAGO PFC100 versión de firmware 03.00. 39(12). Un conjunto de paquetes especialmente diseñado puede causar un desbordamiento del búfer de la pila, resultando en una ejecución de código. Un atacante puede enviar paquetes no autenticados para activar esta vulnerabilidad."}], 'lastModified': '2026-06-17T02:37:05.283', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:wago:pfc_200_firmware:03.01.07\\(13\\):*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '01297381-B7D4-46FB-BFDD-2B5145C5E379'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:wago:pfc_200:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '1A20109A-6CF0-465F-8F97-136DDFB95B2B'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:wago:pfc_100_firmware:03.00.39\\(12\\):*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'C1A0CD98-CC70-4FA2-BFB7-6BC765B05C9B'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:wago:pfc_100:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'CF8E59CE-6A72-49EA-AA44-8714C2411003'}], 'operator': 'OR'}], 'operator': 'AND'}], 'sourceIdentifier': 'talos-cna@cisco.com'}
CVE-2019-5077
2019-12-18 22:53:16+03:00
2026-06-17 02:37:05.593000+03:00
PUBLISHED
An exploitable denial-of-service vulnerability exists in the iocheckd service ‘’I/O-Chec’’ functionality of WAGO PFC 200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC 100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a denial of service, resulting in the device entering an error state where it ceases all network communications. An attacker can send unauthenticated packets to trigger this vulnerability.
CRITICAL
9.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
[{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0869', 'source': 'talos-cna@cisco.com'}, {'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0869', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:12.293545+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0869', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T19:47:55.854Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'WAGO PFC200', 'versions': [{'status': 'affected', 'version': 'Firmware version 03.01.07(13)'}, {'status': 'affected', 'version': 'Firmware version 03.00.39(12)'}]}, {'vendor': 'n/a', 'product': 'WAGO PFC100', 'versions': [{'status': 'affected', 'version': 'Firmware version 03.00.39(12)'}]}], 'references': [{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0869', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'An exploitable denial-of-service vulnerability exists in the iocheckd service ‘’I/O-Chec’’ functionality of WAGO PFC 200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC 100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a denial of service, resulting in the device entering an error state where it ceases all network communications. An attacker can send unauthenticated packets to trigger this vulnerability.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'denial of service'}]}], 'providerMetadata': {'orgId': 'b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b', 'shortName': 'talos', 'dateUpdated': '2019-12-18T19:53:16.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'Firmware version 03.01.07(13)'}, {'version_value': 'Firmware version 03.00.39(12)'}]}, 'product_name': 'WAGO PFC200'}, {'version': {'version_data': [{'version_value': 'Firmware version 03.00.39(12)'}]}, 'product_name': 'WAGO PFC100'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0869', 'name': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0869', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'An exploitable denial-of-service vulnerability exists in the iocheckd service ‘’I/O-Chec’’ functionality of WAGO PFC 200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC 100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a denial of service, resulting in the device entering an error state where it ceases all network communications. An attacker can send unauthenticated packets to trigger this vulnerability.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'denial of service'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-5077', 'STATE': 'PUBLIC', 'ASSIGNER': 'talos-cna@cisco.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-5077', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T19:47:55.854Z', 'dateReserved': '2019-01-04T00:00:00.000Z', 'assignerOrgId': 'b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b', 'datePublished': '2019-12-18T19:53:16.000Z', 'assignerShortName': 'talos'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-5077', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 8.5, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:N/I:P/A:C', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'LOW', 'availabilityImpact': 'COMPLETE', 'confidentialityImpact': 'NONE'}, 'acInsufInfo': False, 'impactScore': 7.8, 'baseSeverity': 'HIGH', 'obtainAllPrivilege': False, 'exploitabilityScore': 10.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.1, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}, 'impactScore': 5.2, 'exploitabilityScore': 3.9}]}, 'affected': [{'source': 'talos-cna@cisco.com', 'affectedData': [{'vendor': 'n/a', 'product': 'WAGO PFC200', 'versions': [{'status': 'affected', 'version': 'Firmware version 03.01.07(13)'}, {'status': 'affected', 'version': 'Firmware version 03.00.39(12)'}]}, {'vendor': 'n/a', 'product': 'WAGO PFC100', 'versions': [{'status': 'affected', 'version': 'Firmware version 03.00.39(12)'}]}]}], 'published': '2019-12-18T20:15:16.837', 'references': [{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0869', 'tags': ['Third Party Advisory'], 'source': 'talos-cna@cisco.com'}, {'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0869', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-306'}]}], 'descriptions': [{'lang': 'en', 'value': 'An exploitable denial-of-service vulnerability exists in the iocheckd service ‘’I/O-Chec’’ functionality of WAGO PFC 200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC 100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a denial of service, resulting in the device entering an error state where it ceases all network communications. An attacker can send unauthenticated packets to trigger this vulnerability.'}, {'lang': 'es', 'value': "Existe una vulnerabilidad de denegación de servicio explotable en la funcionalidad del servicio iocheckd '' I / O-Chec '' de las versiones de firmware WAGO PFC 200 03.01.07 (13) y 03.00.39 (12), y la versión de firmware WAGO PFC 100 03.00 .39 (12). Un conjunto de paquetes especialmente diseñado puede causar una denegación de servicio, lo que da como resultado que el dispositivo entre en un estado de error donde cesa todas las comunicaciones de red. Un atacante puede enviar paquetes no autenticados para activar esta vulnerabilidad."}], 'lastModified': '2026-06-17T02:37:05.593', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:wago:pfc_200_firmware:03.00.39\\(12\\):*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E2381ABB-66E4-492C-8CB2-9FDFE3601A11'}, {'criteria': 'cpe:2.3:o:wago:pfc_200_firmware:03.01.07\\(13\\):*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '01297381-B7D4-46FB-BFDD-2B5145C5E379'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:wago:pfc_200:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '1A20109A-6CF0-465F-8F97-136DDFB95B2B'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:wago:pfc_100_firmware:03.00.39\\(12\\):*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'C1A0CD98-CC70-4FA2-BFB7-6BC765B05C9B'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:wago:pfc_100:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'CF8E59CE-6A72-49EA-AA44-8714C2411003'}], 'operator': 'OR'}], 'operator': 'AND'}], 'sourceIdentifier': 'talos-cna@cisco.com'}
CVE-2022-42290
2023-01-13 05:28:58.208000+03:00
2026-06-17 05:04:39.697000+03:00
PUBLISHED
NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering.
HIGH
7.2
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
[{'url': 'https://nvidia.custhelp.com/app/answers/detail/a_id/5435', 'source': 'psirt@nvidia.com'}, {'url': 'https://nvidia.custhelp.com/app/answers/detail/a_id/5435', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:17:19.859482+03:00
2026-06-27 08:26:40.077172+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://nvidia.custhelp.com/app/answers/detail/a_id/5435', 'tags': ['x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-03T13:03:45.919Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'other': {'type': 'ssvc', 'content': {'id': 'CVE-2022-42290', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-04-07T17:52:21.963434Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-04-07T17:52:31.601Z'}}], 'cna': {'source': {'discovery': 'UNKNOWN'}, 'impacts': [{'descriptions': [{'lang': 'en', 'value': 'Code Execution, Denial of Service, Information Disclosure, Data Tampering'}]}], 'metrics': [{'format': 'CVSS', 'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.2, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'scenarios': [{'lang': 'en', 'value': 'GENERAL'}]}], 'affected': [{'vendor': 'NVIDIA', 'product': 'NVIDIA DGX servers', 'versions': [{'status': 'affected', 'version': 'All BMC firmware versions prior to 00.19.07'}], 'defaultStatus': 'unaffected'}], 'references': [{'url': 'https://nvidia.custhelp.com/app/answers/detail/a_id/5435'}], 'x_generator': {'engine': 'Vulnogram 0.1.0-dev'}, 'descriptions': [{'lang': 'en', 'value': 'NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering.', 'supportingMedia': [{'type': 'text/html', 'value': 'NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering.', 'base64': True}]}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-78', 'description': "CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}]}], 'providerMetadata': {'orgId': '9576f279-3576-44b5-a4af-b9a8644b2de6', 'shortName': 'nvidia', 'dateUpdated': '2023-01-13T02:28:58.208Z'}}}, 'cveMetadata': {'cveId': 'CVE-2022-42290', 'state': 'PUBLISHED', 'dateUpdated': '2025-04-07T17:52:31.601Z', 'dateReserved': '2022-10-03T14:20:26.209Z', 'assignerOrgId': '9576f279-3576-44b5-a4af-b9a8644b2de6', 'datePublished': '2023-01-13T02:28:58.208Z', 'assignerShortName': 'nvidia'}, 'dataVersion': '5.1'}
{'id': 'CVE-2022-42290', 'cveTags': [], 'metrics': {'ssvcV203': [{'source': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'ssvcData': {'id': 'CVE-2022-42290', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-04-07T17:52:21.963434Z'}}], 'cvssMetricV31': [{'type': 'Secondary', 'source': 'psirt@nvidia.com', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.2, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 1.2}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'psirt@nvidia.com', 'affectedData': [{'vendor': 'NVIDIA', 'product': 'NVIDIA DGX servers', 'versions': [{'status': 'affected', 'version': 'All BMC firmware versions prior to 00.19.07'}], 'defaultStatus': 'unaffected'}]}], 'published': '2023-01-13T04:15:08.807', 'references': [{'url': 'https://nvidia.custhelp.com/app/answers/detail/a_id/5435', 'tags': ['Vendor Advisory'], 'source': 'psirt@nvidia.com'}, {'url': 'https://nvidia.custhelp.com/app/answers/detail/a_id/5435', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Secondary', 'source': 'psirt@nvidia.com', 'description': [{'lang': 'en', 'value': 'CWE-78'}]}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-78'}]}], 'descriptions': [{'lang': 'en', 'value': 'NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering.'}, {'lang': 'es', 'value': 'NVIDIA BMC contiene una vulnerabilidad en SPX REST API, donde un atacante autorizado puede inyectar comandos de shell arbitrarios, lo que puede provocar la ejecución de código, denegación de servicio, divulgación de información y manipulación de datos.'}], 'lastModified': '2026-06-17T05:04:39.697', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:nvidia:dgx_a100_firmware:*:*:*:*:bmc:*:*:*', 'vulnerable': True, 'matchCriteriaId': '063DAD57-7DC7-46E6-A5C6-B4D1A3CE7F19', 'versionEndExcluding': '00.19.07'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:nvidia:dgx_a100:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '8807CB65-5F49-42E8-B5D8-36943418ADB9'}], 'operator': 'OR'}], 'operator': 'AND'}], 'sourceIdentifier': 'psirt@nvidia.com'}
CVE-2019-5081
2019-12-18 22:59:36+03:00
2026-06-17 02:37:06+03:00
PUBLISHED
An exploitable heap buffer overflow vulnerability exists in the iocheckd service ''I/O-Chec'' functionality of WAGO PFC 200 Firmware version 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a heap buffer overflow, potentially resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability.
CRITICAL
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
[{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0873', 'source': 'talos-cna@cisco.com'}, {'url': 'https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0874', 'source': 'talos-cna@cisco.com'}, {'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0873', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0874', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:12.540008+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0874', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0873', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T19:47:56.625Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'WAGO PFC200', 'versions': [{'status': 'affected', 'version': 'Firmware version 03.01.07(13)'}, {'status': 'affected', 'version': 'Firmware version 03.00.39(12)'}]}, {'vendor': 'n/a', 'product': 'WAGO PFC100', 'versions': [{'status': 'affected', 'version': 'Firmware version 03.00.39(12)'}]}], 'references': [{'url': 'https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0874', 'tags': ['x_refsource_MISC']}, {'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0873', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': "An exploitable heap buffer overflow vulnerability exists in the iocheckd service ''I/O-Chec'' functionality of WAGO PFC 200 Firmware version 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a heap buffer overflow, potentially resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability."}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'remote code execution'}]}], 'providerMetadata': {'orgId': 'b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b', 'shortName': 'talos', 'dateUpdated': '2019-12-18T19:59:58.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'Firmware version 03.01.07(13)'}, {'version_value': 'Firmware version 03.00.39(12)'}]}, 'product_name': 'WAGO PFC200'}, {'version': {'version_data': [{'version_value': 'Firmware version 03.00.39(12)'}]}, 'product_name': 'WAGO PFC100'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0874', 'name': 'https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0874', 'refsource': 'MISC'}, {'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0873', 'name': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0873', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': "An exploitable heap buffer overflow vulnerability exists in the iocheckd service ''I/O-Chec'' functionality of WAGO PFC 200 Firmware version 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a heap buffer overflow, potentially resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability."}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'remote code execution'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-5081', 'STATE': 'PUBLIC', 'ASSIGNER': 'talos-cna@cisco.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-5081', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T19:47:56.625Z', 'dateReserved': '2019-01-04T00:00:00.000Z', 'assignerOrgId': 'b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b', 'datePublished': '2019-12-18T19:59:36.000Z', 'assignerShortName': 'talos'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-5081', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 10.0, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:C/I:C/A:C', 'authentication': 'NONE', 'integrityImpact': 'COMPLETE', 'accessComplexity': 'LOW', 'availabilityImpact': 'COMPLETE', 'confidentialityImpact': 'COMPLETE'}, 'acInsufInfo': False, 'impactScore': 10.0, 'baseSeverity': 'HIGH', 'obtainAllPrivilege': False, 'exploitabilityScore': 10.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 3.9}]}, 'affected': [{'source': 'talos-cna@cisco.com', 'affectedData': [{'vendor': 'n/a', 'product': 'WAGO PFC200', 'versions': [{'status': 'affected', 'version': 'Firmware version 03.01.07(13)'}, {'status': 'affected', 'version': 'Firmware version 03.00.39(12)'}]}, {'vendor': 'n/a', 'product': 'WAGO PFC100', 'versions': [{'status': 'affected', 'version': 'Firmware version 03.00.39(12)'}]}]}], 'published': '2019-12-18T20:15:16.917', 'references': [{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0873', 'tags': ['Exploit', 'Third Party Advisory'], 'source': 'talos-cna@cisco.com'}, {'url': 'https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0874', 'tags': ['Exploit', 'Third Party Advisory'], 'source': 'talos-cna@cisco.com'}, {'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0873', 'tags': ['Exploit', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0874', 'tags': ['Exploit', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-787'}]}], 'descriptions': [{'lang': 'en', 'value': "An exploitable heap buffer overflow vulnerability exists in the iocheckd service ''I/O-Chec'' functionality of WAGO PFC 200 Firmware version 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a heap buffer overflow, potentially resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability."}, {'lang': 'es', 'value': "Se presenta una vulnerabilidad de desbordamiento del búfer de la pila explotable en la funcionalidad ''I/O-Chec'' del servicio iocheckd de WAGO PFC 200 versión de firmware 03.01.07(13) y 03.00.39(12), y WAGO PFC100 versión de firmware 03.00.39 (12). Un conjunto de paquetes especialmente diseñado puede causar un desbordamiento del búfer de la pila, resultando potencialmente en una ejecución de código. Un atacante puede enviar paquetes no autenticados para activar esta vulnerabilidad."}], 'lastModified': '2026-06-17T02:37:06.000', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:wago:pfc_200_firmware:03.00.39\\(12\\):*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E2381ABB-66E4-492C-8CB2-9FDFE3601A11'}, {'criteria': 'cpe:2.3:o:wago:pfc_200_firmware:03.01.07\\(13\\):*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '01297381-B7D4-46FB-BFDD-2B5145C5E379'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:wago:pfc_200:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '1A20109A-6CF0-465F-8F97-136DDFB95B2B'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:wago:pfc_100_firmware:03.00.39\\(12\\):*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'C1A0CD98-CC70-4FA2-BFB7-6BC765B05C9B'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:wago:pfc_100:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'CF8E59CE-6A72-49EA-AA44-8714C2411003'}], 'operator': 'OR'}], 'operator': 'AND'}], 'sourceIdentifier': 'talos-cna@cisco.com'}
CVE-2019-7621
2019-12-18 22:50:12+03:00
2026-06-17 02:40:46.533000+03:00
PUBLISHED
Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with the ability to create coordinate map visualizations could create a malicious visualization. If another Kibana user views that visualization or a dashboard containing the visualization it could execute JavaScript in the victim�s browser.
MEDIUM
5.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
[{'url': 'https://discuss.elastic.co/t/elastic-stack-6-8-6-and-7-5-1-security-update/212390', 'source': 'security@elastic.co'}, {'url': 'https://www.elastic.co/community/security/', 'source': 'security@elastic.co'}, {'url': 'https://discuss.elastic.co/t/elastic-stack-6-8-6-and-7-5-1-security-update/212390', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://www.elastic.co/community/security/', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:17.487375+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://www.elastic.co/community/security/', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://discuss.elastic.co/t/elastic-stack-6-8-6-and-7-5-1-security-update/212390', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T20:54:28.434Z'}}], 'cna': {'affected': [{'vendor': 'Elastic', 'product': 'Kibana', 'versions': [{'status': 'affected', 'version': 'before 6.8.6 and 7.5.1'}]}], 'references': [{'url': 'https://www.elastic.co/community/security/', 'tags': ['x_refsource_MISC']}, {'url': 'https://discuss.elastic.co/t/elastic-stack-6-8-6-and-7-5-1-security-update/212390', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with the ability to create coordinate map visualizations could create a malicious visualization. If another Kibana user views that visualization or a dashboard containing the visualization it could execute JavaScript in the victim�s browser.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-79', 'description': "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"}]}], 'providerMetadata': {'orgId': '271b6943-45a9-4f3a-ab4e-976f3fa05b5a', 'shortName': 'elastic', 'dateUpdated': '2019-12-18T19:50:12.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'before 6.8.6 and 7.5.1'}]}, 'product_name': 'Kibana'}]}, 'vendor_name': 'Elastic'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://www.elastic.co/community/security/', 'name': 'https://www.elastic.co/community/security/', 'refsource': 'MISC'}, {'url': 'https://discuss.elastic.co/t/elastic-stack-6-8-6-and-7-5-1-security-update/212390', 'name': 'https://discuss.elastic.co/t/elastic-stack-6-8-6-and-7-5-1-security-update/212390', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with the ability to create coordinate map visualizations could create a malicious visualization. If another Kibana user views that visualization or a dashboard containing the visualization it could execute JavaScript in the victim�s browser.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-7621', 'STATE': 'PUBLIC', 'ASSIGNER': 'security@elastic.co'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-7621', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T20:54:28.434Z', 'dateReserved': '2019-02-07T00:00:00.000Z', 'assignerOrgId': '271b6943-45a9-4f3a-ab4e-976f3fa05b5a', 'datePublished': '2019-12-18T19:50:12.000Z', 'assignerShortName': 'elastic'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-7621', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 3.5, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:S/C:N/I:P/A:N', 'authentication': 'SINGLE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'NONE'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'LOW', 'obtainAllPrivilege': False, 'exploitabilityScore': 6.8, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 5.4, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N', 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'LOW'}, 'impactScore': 2.7, 'exploitabilityScore': 2.3}]}, 'affected': [{'source': 'security@elastic.co', 'affectedData': [{'vendor': 'Elastic', 'product': 'Kibana', 'versions': [{'status': 'affected', 'version': 'before 6.8.6 and 7.5.1'}]}]}], 'published': '2019-12-18T20:15:16.977', 'references': [{'url': 'https://discuss.elastic.co/t/elastic-stack-6-8-6-and-7-5-1-security-update/212390', 'tags': ['Vendor Advisory'], 'source': 'security@elastic.co'}, {'url': 'https://www.elastic.co/community/security/', 'tags': ['Vendor Advisory'], 'source': 'security@elastic.co'}, {'url': 'https://discuss.elastic.co/t/elastic-stack-6-8-6-and-7-5-1-security-update/212390', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://www.elastic.co/community/security/', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Secondary', 'source': 'security@elastic.co', 'description': [{'lang': 'en', 'value': 'CWE-79'}]}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-79'}]}], 'descriptions': [{'lang': 'en', 'value': 'Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with the ability to create coordinate map visualizations could create a malicious visualization. If another Kibana user views that visualization or a dashboard containing the visualization it could execute JavaScript in the victim�s browser.'}, {'lang': 'es', 'value': 'Las versiones de Kibana anteriores a 6.8.6 y 7.5.1 contienen un defecto de secuencias de comandos de sitios cruzados (XSS) en las visualizaciones de mapas de coordenadas y regiones. Un atacante con la capacidad de crear visualizaciones de mapas de coordenadas podría crear una visualización maliciosa. Si otro usuario de Kibana ve esa visualización o un tablero que contiene la visualización, podría ejecutar JavaScript en el navegador de la víctima.'}], 'lastModified': '2026-06-17T02:40:46.533', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '6E23D215-5879-406E-B80C-D09B6ABAEF69', 'versionEndExcluding': '6.8.6'}, {'criteria': 'cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A4A18C76-F1F4-40EF-935C-6628F47F182A', 'versionEndExcluding': '7.5.1', 'versionStartIncluding': '7.0.0'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'security@elastic.co'}
CVE-2019-15575
2019-12-19 00:00:16+03:00
2026-06-17 02:20:40.387000+03:00
PUBLISHED
A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.
HIGH
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
[{'url': 'https://hackerone.com/reports/682442', 'source': 'support@hackerone.com'}, {'url': 'https://hackerone.com/reports/682442', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:18.787866+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://hackerone.com/reports/682442', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-05T00:49:13.586Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'GitLab CE/EE', 'versions': [{'status': 'affected', 'version': '12.3.2, 12.2.6, and 12.1.12'}]}], 'references': [{'url': 'https://hackerone.com/reports/682442', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-77', 'description': 'Command Injection - Generic (CWE-77)'}]}], 'providerMetadata': {'orgId': '36234546-b8fa-4601-9d6f-f4e334aa8ea1', 'shortName': 'hackerone', 'dateUpdated': '2019-12-18T21:00:16.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': '12.3.2, 12.2.6, and 12.1.12'}]}, 'product_name': 'GitLab CE/EE'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://hackerone.com/reports/682442', 'name': 'https://hackerone.com/reports/682442', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Command Injection - Generic (CWE-77)'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-15575', 'STATE': 'PUBLIC', 'ASSIGNER': 'support@hackerone.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-15575', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-05T00:49:13.586Z', 'dateReserved': '2019-08-26T00:00:00.000Z', 'assignerOrgId': '36234546-b8fa-4601-9d6f-f4e334aa8ea1', 'datePublished': '2019-12-18T21:00:16.000Z', 'assignerShortName': 'hackerone'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-15575', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 5.0, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:P/I:N/A:N', 'authentication': 'NONE', 'integrityImpact': 'NONE', 'accessComplexity': 'LOW', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 10.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 3.6, 'exploitabilityScore': 3.9}]}, 'affected': [{'source': 'support@hackerone.com', 'affectedData': [{'vendor': 'n/a', 'product': 'GitLab CE/EE', 'versions': [{'status': 'affected', 'version': '12.3.2, 12.2.6, and 12.1.12'}]}]}], 'published': '2019-12-18T21:15:11.600', 'references': [{'url': 'https://hackerone.com/reports/682442', 'tags': ['Exploit', 'Issue Tracking', 'Third Party Advisory'], 'source': 'support@hackerone.com'}, {'url': 'https://hackerone.com/reports/682442', 'tags': ['Exploit', 'Issue Tracking', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Secondary', 'source': 'support@hackerone.com', 'description': [{'lang': 'en', 'value': 'CWE-77'}]}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-77'}]}], 'descriptions': [{'lang': 'en', 'value': 'A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.'}, {'lang': 'es', 'value': 'Se presenta una inyección de comando en GitLab CE/EE versiones anteriores a v12.3.2, versiones anteriores a v12.2.6, versiones anteriores a v12.1.12, que permitió a un atacante inyectar comandos mediante la API por medio del ámbito blobs.'}], 'lastModified': '2026-06-17T02:20:40.387', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E0B15B71-88A5-4565-9F28-FED3637D26E9', 'versionEndExcluding': '12.1.12'}, {'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'EDD47A7D-F6FD-46A5-BE34-882BADBED556', 'versionEndExcluding': '12.1.12'}, {'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'ABCEAA2E-75C8-426B-8EAA-52D3F78FB2A1', 'versionEndExcluding': '12.2.6', 'versionStartIncluding': '12.2.0'}, {'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AF5AC653-CE12-4759-B07A-04C20B9EBA7B', 'versionEndExcluding': '12.2.6', 'versionStartIncluding': '12.2.0'}, {'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*', 'vulnerable': True, 'matchCriteriaId': '5BB337AA-1FBB-4BEF-9652-F462CEC4BE71', 'versionEndExcluding': '12.3.2', 'versionStartIncluding': '12.3.0'}, {'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'DB3CF71C-AD05-4866-9629-0DB7E92775C2', 'versionEndExcluding': '12.3.2', 'versionStartIncluding': '12.3.0'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'support@hackerone.com'}
CVE-2019-15576
2019-12-19 00:00:08+03:00
2026-06-17 02:20:40.507000+03:00
PUBLISHED
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.
HIGH
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
[{'url': 'https://hackerone.com/reports/633001', 'source': 'support@hackerone.com'}, {'url': 'https://hackerone.com/reports/633001', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:18.787866+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://hackerone.com/reports/633001', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-05T00:49:13.643Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'GitLab CE/EE', 'versions': [{'status': 'affected', 'version': '12.3.2, 12.2.6, and 12.1.12'}]}], 'references': [{'url': 'https://hackerone.com/reports/633001', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-200', 'description': 'Information Disclosure (CWE-200)'}]}], 'providerMetadata': {'orgId': '36234546-b8fa-4601-9d6f-f4e334aa8ea1', 'shortName': 'hackerone', 'dateUpdated': '2019-12-18T21:00:08.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': '12.3.2, 12.2.6, and 12.1.12'}]}, 'product_name': 'GitLab CE/EE'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://hackerone.com/reports/633001', 'name': 'https://hackerone.com/reports/633001', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Information Disclosure (CWE-200)'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-15576', 'STATE': 'PUBLIC', 'ASSIGNER': 'support@hackerone.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-15576', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-05T00:49:13.643Z', 'dateReserved': '2019-08-26T00:00:00.000Z', 'assignerOrgId': '36234546-b8fa-4601-9d6f-f4e334aa8ea1', 'datePublished': '2019-12-18T21:00:08.000Z', 'assignerShortName': 'hackerone'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-15576', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 5.0, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:P/I:N/A:N', 'authentication': 'NONE', 'integrityImpact': 'NONE', 'accessComplexity': 'LOW', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 10.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 3.6, 'exploitabilityScore': 3.9}]}, 'affected': [{'source': 'support@hackerone.com', 'affectedData': [{'vendor': 'n/a', 'product': 'GitLab CE/EE', 'versions': [{'status': 'affected', 'version': '12.3.2, 12.2.6, and 12.1.12'}]}]}], 'published': '2019-12-18T21:15:11.770', 'references': [{'url': 'https://hackerone.com/reports/633001', 'tags': ['Exploit', 'Issue Tracking', 'Third Party Advisory'], 'source': 'support@hackerone.com'}, {'url': 'https://hackerone.com/reports/633001', 'tags': ['Exploit', 'Issue Tracking', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Secondary', 'source': 'support@hackerone.com', 'description': [{'lang': 'en', 'value': 'CWE-200'}]}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-862'}]}], 'descriptions': [{'lang': 'en', 'value': 'An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.'}, {'lang': 'es', 'value': 'Se presenta una vulnerabilidad de divulgación de información en GitLab CE/EE versiones anteriores a v12.3.2, versiones anteriores a v12.2.6, versiones anteriores a v12.1.12, que permitió a un atacante visualizar notas privadas del sistema desde un endpoint GraphQL.'}], 'lastModified': '2026-06-17T02:20:40.507', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E0B15B71-88A5-4565-9F28-FED3637D26E9', 'versionEndExcluding': '12.1.12'}, {'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'EDD47A7D-F6FD-46A5-BE34-882BADBED556', 'versionEndExcluding': '12.1.12'}, {'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'ABCEAA2E-75C8-426B-8EAA-52D3F78FB2A1', 'versionEndExcluding': '12.2.6', 'versionStartIncluding': '12.2.0'}, {'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AF5AC653-CE12-4759-B07A-04C20B9EBA7B', 'versionEndExcluding': '12.2.6', 'versionStartIncluding': '12.2.0'}, {'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*', 'vulnerable': True, 'matchCriteriaId': '5BB337AA-1FBB-4BEF-9652-F462CEC4BE71', 'versionEndExcluding': '12.3.2', 'versionStartIncluding': '12.3.0'}, {'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'DB3CF71C-AD05-4866-9629-0DB7E92775C2', 'versionEndExcluding': '12.3.2', 'versionStartIncluding': '12.3.0'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'support@hackerone.com'}
CVE-2020-12416
2020-07-09 17:40:59+03:00
2026-06-17 02:51:47.637000+03:00
PUBLISHED
A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink, resulting in a use-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 78.
HIGH
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html', 'source': 'security@mozilla.org'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html', 'source': 'security@mozilla.org'}, {'url': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1639734', 'source': 'security@mozilla.org'}, {'url': 'https://security.gentoo.org/glsa/202007-10', 'source': 'security@mozilla.org'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'source': 'security@mozilla.org'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1639734', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://security.gentoo.org/glsa/202007-10', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:55.969618+03:00
2026-06-27 08:25:53.850778+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1639734', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html', 'name': 'openSUSE-SU-2020:0983', 'tags': ['vendor-advisory', 'x_refsource_SUSE', 'x_transferred']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html', 'name': 'openSUSE-SU-2020:1017', 'tags': ['vendor-advisory', 'x_refsource_SUSE', 'x_transferred']}, {'url': 'https://security.gentoo.org/glsa/202007-10', 'name': 'GLSA-202007-10', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T11:56:52.058Z'}}], 'cna': {'affected': [{'vendor': 'Mozilla', 'product': 'Firefox', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': '78', 'versionType': 'custom'}]}], 'references': [{'url': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'tags': ['x_refsource_MISC']}, {'url': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1639734', 'tags': ['x_refsource_MISC']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html', 'name': 'openSUSE-SU-2020:0983', 'tags': ['vendor-advisory', 'x_refsource_SUSE']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html', 'name': 'openSUSE-SU-2020:1017', 'tags': ['vendor-advisory', 'x_refsource_SUSE']}, {'url': 'https://security.gentoo.org/glsa/202007-10', 'name': 'GLSA-202007-10', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}], 'descriptions': [{'lang': 'en', 'value': 'A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink, resulting in a use-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 78.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Use-after-free in WebRTC VideoBroadcaster'}]}], 'providerMetadata': {'orgId': 'f16b083a-5664-49f3-a51e-8d479e5ed7fe', 'shortName': 'mozilla', 'dateUpdated': '2020-07-27T01:06:35.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': '78', 'version_affected': '<'}]}, 'product_name': 'Firefox'}]}, 'vendor_name': 'Mozilla'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'name': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'refsource': 'MISC'}, {'url': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1639734', 'name': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1639734', 'refsource': 'MISC'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html', 'name': 'openSUSE-SU-2020:0983', 'refsource': 'SUSE'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html', 'name': 'openSUSE-SU-2020:1017', 'refsource': 'SUSE'}, {'url': 'https://security.gentoo.org/glsa/202007-10', 'name': 'GLSA-202007-10', 'refsource': 'GENTOO'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink, resulting in a use-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 78.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Use-after-free in WebRTC VideoBroadcaster'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2020-12416', 'STATE': 'PUBLIC', 'ASSIGNER': 'security@mozilla.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2020-12416', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T11:56:52.058Z', 'dateReserved': '2020-04-28T00:00:00.000Z', 'assignerOrgId': 'f16b083a-5664-49f3-a51e-8d479e5ed7fe', 'datePublished': '2020-07-09T14:40:59.000Z', 'assignerShortName': 'mozilla'}, 'dataVersion': '5.1'}
{'id': 'CVE-2020-12416', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 9.3, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:C/I:C/A:C', 'authentication': 'NONE', 'integrityImpact': 'COMPLETE', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'COMPLETE', 'confidentialityImpact': 'COMPLETE'}, 'acInsufInfo': False, 'impactScore': 10.0, 'baseSeverity': 'HIGH', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'security@mozilla.org', 'affectedData': [{'vendor': 'Mozilla', 'product': 'Firefox', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': '78', 'versionType': 'custom'}]}]}], 'published': '2020-07-09T15:15:11.677', 'references': [{'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'security@mozilla.org'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'security@mozilla.org'}, {'url': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1639734', 'tags': ['Exploit', 'Issue Tracking', 'Vendor Advisory'], 'source': 'security@mozilla.org'}, {'url': 'https://security.gentoo.org/glsa/202007-10', 'tags': ['Third Party Advisory'], 'source': 'security@mozilla.org'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'tags': ['Vendor Advisory'], 'source': 'security@mozilla.org'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1639734', 'tags': ['Exploit', 'Issue Tracking', 'Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://security.gentoo.org/glsa/202007-10', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-362'}, {'lang': 'en', 'value': 'CWE-416'}]}], 'descriptions': [{'lang': 'en', 'value': 'A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink, resulting in a use-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 78.'}, {'lang': 'es', 'value': 'Un VideoStreamEncoder puede haberse liberado en una condición de carrera con la función VideoBroadcaster::AddOrUpdateSink, resultando en un uso de la memoria previamente liberada, una corrupción de la memoria y un bloqueo potencialmente explotable. Esta vulnerabilidad afecta a Firefox versiones anteriores a 78'}], 'lastModified': '2026-06-17T02:51:47.637', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '09FA5356-4843-47D3-964C-86A6C3859F3C', 'versionEndExcluding': '78.0'}], 'operator': 'OR'}]}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'B620311B-34A3-48A6-82DF-6F078D7A4493'}, {'criteria': 'cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'B009C22E-30A4-4288-BCF6-C3E81DEAF45A'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'security@mozilla.org'}
CVE-2019-15577
2019-12-19 00:00:00+03:00
2026-06-17 02:20:40.623000+03:00
PUBLISHED
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.
MEDIUM
4.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
[{'url': 'https://hackerone.com/reports/636560', 'source': 'support@hackerone.com'}, {'url': 'https://hackerone.com/reports/636560', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.106719+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://hackerone.com/reports/636560', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-05T00:49:13.757Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'GitLab CE/EE', 'versions': [{'status': 'affected', 'version': '12.3.2, 12.2.6, and 12.1.12'}]}], 'references': [{'url': 'https://hackerone.com/reports/636560', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-200', 'description': 'Information Disclosure (CWE-200)'}]}], 'providerMetadata': {'orgId': '36234546-b8fa-4601-9d6f-f4e334aa8ea1', 'shortName': 'hackerone', 'dateUpdated': '2019-12-18T21:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': '12.3.2, 12.2.6, and 12.1.12'}]}, 'product_name': 'GitLab CE/EE'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://hackerone.com/reports/636560', 'name': 'https://hackerone.com/reports/636560', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Information Disclosure (CWE-200)'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-15577', 'STATE': 'PUBLIC', 'ASSIGNER': 'support@hackerone.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-15577', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-05T00:49:13.757Z', 'dateReserved': '2019-08-26T00:00:00.000Z', 'assignerOrgId': '36234546-b8fa-4601-9d6f-f4e334aa8ea1', 'datePublished': '2019-12-18T21:00:00.000Z', 'assignerShortName': 'hackerone'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-15577', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 4.0, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:S/C:P/I:N/A:N', 'authentication': 'SINGLE', 'integrityImpact': 'NONE', 'accessComplexity': 'LOW', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'LOW'}, 'impactScore': 1.4, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'support@hackerone.com', 'affectedData': [{'vendor': 'n/a', 'product': 'GitLab CE/EE', 'versions': [{'status': 'affected', 'version': '12.3.2, 12.2.6, and 12.1.12'}]}]}], 'published': '2019-12-18T21:15:11.867', 'references': [{'url': 'https://hackerone.com/reports/636560', 'tags': ['Exploit', 'Issue Tracking', 'Third Party Advisory'], 'source': 'support@hackerone.com'}, {'url': 'https://hackerone.com/reports/636560', 'tags': ['Exploit', 'Issue Tracking', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Secondary', 'source': 'support@hackerone.com', 'description': [{'lang': 'en', 'value': 'CWE-200'}]}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-307'}]}], 'descriptions': [{'lang': 'en', 'value': 'An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.'}, {'lang': 'es', 'value': 'Se presenta una vulnerabilidad de divulgación de información en GitLab CE/EE versiones anteriores a v12.3.2, versiones anteriores a v12.2.6, versiones anteriores a v12.1.12, que permitió que se revelaran los hitos del proyecto por medio de la exploración de grupos.'}], 'lastModified': '2026-06-17T02:20:40.623', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E0B15B71-88A5-4565-9F28-FED3637D26E9', 'versionEndExcluding': '12.1.12'}, {'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'EDD47A7D-F6FD-46A5-BE34-882BADBED556', 'versionEndExcluding': '12.1.12'}, {'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'ABCEAA2E-75C8-426B-8EAA-52D3F78FB2A1', 'versionEndExcluding': '12.2.6', 'versionStartIncluding': '12.2.0'}, {'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AF5AC653-CE12-4759-B07A-04C20B9EBA7B', 'versionEndExcluding': '12.2.6', 'versionStartIncluding': '12.2.0'}, {'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*', 'vulnerable': True, 'matchCriteriaId': '5BB337AA-1FBB-4BEF-9652-F462CEC4BE71', 'versionEndExcluding': '12.3.2', 'versionStartIncluding': '12.3.0'}, {'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'DB3CF71C-AD05-4866-9629-0DB7E92775C2', 'versionEndExcluding': '12.3.2', 'versionStartIncluding': '12.3.0'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'support@hackerone.com'}
CVE-2019-15580
2019-12-18 23:59:15+03:00
2026-06-17 02:20:40.980000+03:00
PUBLISHED
An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was possible for an unauthenticated user to see the head pipeline data of a public project even though pipeline visibility was restricted.
MEDIUM
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
[{'url': 'https://hackerone.com/reports/667408', 'source': 'support@hackerone.com'}, {'url': 'https://hackerone.com/reports/667408', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.106719+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://hackerone.com/reports/667408', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-05T00:49:13.790Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'gitlab.com', 'versions': [{'status': 'affected', 'version': '12.3.2, 12.2.6, and 12.1.10'}]}], 'references': [{'url': 'https://hackerone.com/reports/667408', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was possible for an unauthenticated user to see the head pipeline data of a public project even though pipeline visibility was restricted.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-201', 'description': 'Information Exposure Through Sent Data (CWE-201)'}]}], 'providerMetadata': {'orgId': '36234546-b8fa-4601-9d6f-f4e334aa8ea1', 'shortName': 'hackerone', 'dateUpdated': '2019-12-18T20:59:15.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': '12.3.2, 12.2.6, and 12.1.10'}]}, 'product_name': 'gitlab.com'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://hackerone.com/reports/667408', 'name': 'https://hackerone.com/reports/667408', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was possible for an unauthenticated user to see the head pipeline data of a public project even though pipeline visibility was restricted.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Information Exposure Through Sent Data (CWE-201)'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-15580', 'STATE': 'PUBLIC', 'ASSIGNER': 'support@hackerone.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-15580', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-05T00:49:13.790Z', 'dateReserved': '2019-08-26T00:00:00.000Z', 'assignerOrgId': '36234546-b8fa-4601-9d6f-f4e334aa8ea1', 'datePublished': '2019-12-18T20:59:15.000Z', 'assignerShortName': 'hackerone'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-15580', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 4.0, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:S/C:P/I:N/A:N', 'authentication': 'SINGLE', 'integrityImpact': 'NONE', 'accessComplexity': 'LOW', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'impactScore': 3.6, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'support@hackerone.com', 'affectedData': [{'vendor': 'n/a', 'product': 'gitlab.com', 'versions': [{'status': 'affected', 'version': '12.3.2, 12.2.6, and 12.1.10'}]}]}], 'published': '2019-12-18T21:15:11.977', 'references': [{'url': 'https://hackerone.com/reports/667408', 'tags': ['Exploit', 'Third Party Advisory'], 'source': 'support@hackerone.com'}, {'url': 'https://hackerone.com/reports/667408', 'tags': ['Exploit', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Secondary', 'source': 'support@hackerone.com', 'description': [{'lang': 'en', 'value': 'CWE-201'}]}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-200'}]}], 'descriptions': [{'lang': 'en', 'value': 'An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was possible for an unauthenticated user to see the head pipeline data of a public project even though pipeline visibility was restricted.'}, {'lang': 'es', 'value': 'Se presenta una vulnerabilidad de exposición de información en gitlab.com versiones anteriores a v12.3.2, versiones anteriores a v12.2.6 y versiones anteriores a v12.1.10, cuando se utiliza el bloqueo de la funcionalidad de petición de fusion, era posible que un usuario no autenticado visualizara los datos de la tubería principal de un proyecto público inclusive aunque la visibilidad de la tubería estaba restringida.'}], 'lastModified': '2026-06-17T02:20:40.980', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AB2637E9-3EAC-4CC2-A614-E6BF2564484B', 'versionEndExcluding': '12.1.10'}, {'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*', 'vulnerable': True, 'matchCriteriaId': '308ED5C4-D836-4541-A789-DD76A8C61EE5', 'versionEndExcluding': '12.1.10'}, {'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'ABCEAA2E-75C8-426B-8EAA-52D3F78FB2A1', 'versionEndExcluding': '12.2.6', 'versionStartIncluding': '12.2.0'}, {'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AF5AC653-CE12-4759-B07A-04C20B9EBA7B', 'versionEndExcluding': '12.2.6', 'versionStartIncluding': '12.2.0'}, {'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*', 'vulnerable': True, 'matchCriteriaId': '5BB337AA-1FBB-4BEF-9652-F462CEC4BE71', 'versionEndExcluding': '12.3.2', 'versionStartIncluding': '12.3.0'}, {'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'DB3CF71C-AD05-4866-9629-0DB7E92775C2', 'versionEndExcluding': '12.3.2', 'versionStartIncluding': '12.3.0'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'support@hackerone.com'}
CVE-2019-15589
2019-12-19 00:00:39+03:00
2026-06-17 02:20:42.043000+03:00
PUBLISHED
An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.
HIGH
8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
[{'url': 'https://hackerone.com/reports/497047', 'source': 'support@hackerone.com'}, {'url': 'https://hackerone.com/reports/497047', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:18.787866+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://hackerone.com/reports/497047', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-05T00:49:13.715Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'GitLab CE/EE', 'versions': [{'status': 'affected', 'version': '12.3.2, 12.2.6, 12.1.12'}]}], 'references': [{'url': 'https://hackerone.com/reports/497047', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-284', 'description': 'Improper Access Control - Generic (CWE-284)'}]}], 'providerMetadata': {'orgId': '36234546-b8fa-4601-9d6f-f4e334aa8ea1', 'shortName': 'hackerone', 'dateUpdated': '2019-12-18T21:00:39.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': '12.3.2, 12.2.6, 12.1.12'}]}, 'product_name': 'GitLab CE/EE'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://hackerone.com/reports/497047', 'name': 'https://hackerone.com/reports/497047', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Improper Access Control - Generic (CWE-284)'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-15589', 'STATE': 'PUBLIC', 'ASSIGNER': 'support@hackerone.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-15589', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-05T00:49:13.715Z', 'dateReserved': '2019-08-26T00:00:00.000Z', 'assignerOrgId': '36234546-b8fa-4601-9d6f-f4e334aa8ea1', 'datePublished': '2019-12-18T21:00:39.000Z', 'assignerShortName': 'hackerone'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-15589', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 6.5, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:S/C:P/I:P/A:P', 'authentication': 'SINGLE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'LOW', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'support@hackerone.com', 'affectedData': [{'vendor': 'n/a', 'product': 'GitLab CE/EE', 'versions': [{'status': 'affected', 'version': '12.3.2, 12.2.6, 12.1.12'}]}]}], 'published': '2019-12-18T21:15:12.083', 'references': [{'url': 'https://hackerone.com/reports/497047', 'tags': ['Exploit', 'Issue Tracking', 'Third Party Advisory'], 'source': 'support@hackerone.com'}, {'url': 'https://hackerone.com/reports/497047', 'tags': ['Exploit', 'Issue Tracking', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Secondary', 'source': 'support@hackerone.com', 'description': [{'lang': 'en', 'value': 'CWE-284'}]}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'NVD-CWE-Other'}]}], 'descriptions': [{'lang': 'en', 'value': 'An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.'}, {'lang': 'es', 'value': 'Se presenta una vulnerabilidad de control de acceso inapropiado en Gitlab versiones anteriores a v12.3.2, versiones anteriores a v12.2.6, versiones anteriores a v12.1.12, que permitiría que un usuario bloqueado pudiera ser capaz de usar el clon GIT y extraer si hubiera obtenido un token CI/CD antes.'}], 'lastModified': '2026-06-17T02:20:42.043', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E0B15B71-88A5-4565-9F28-FED3637D26E9', 'versionEndExcluding': '12.1.12'}, {'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'EDD47A7D-F6FD-46A5-BE34-882BADBED556', 'versionEndExcluding': '12.1.12'}, {'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'ABCEAA2E-75C8-426B-8EAA-52D3F78FB2A1', 'versionEndExcluding': '12.2.6', 'versionStartIncluding': '12.2.0'}, {'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'AF5AC653-CE12-4759-B07A-04C20B9EBA7B', 'versionEndExcluding': '12.2.6', 'versionStartIncluding': '12.2.0'}, {'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*', 'vulnerable': True, 'matchCriteriaId': '5BB337AA-1FBB-4BEF-9652-F462CEC4BE71', 'versionEndExcluding': '12.3.2', 'versionStartIncluding': '12.3.0'}, {'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'DB3CF71C-AD05-4866-9629-0DB7E92775C2', 'versionEndExcluding': '12.3.2', 'versionStartIncluding': '12.3.0'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'support@hackerone.com'}
CVE-2019-15591
2019-12-18 23:51:27+03:00
2026-06-17 02:20:42.273000+03:00
PUBLISHED
An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.
MEDIUM
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
[{'url': 'https://hackerone.com/reports/676976', 'source': 'support@hackerone.com'}, {'url': 'https://hackerone.com/reports/676976', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:18.787866+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://hackerone.com/reports/676976', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-05T00:49:13.787Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'GitLab', 'versions': [{'status': 'affected', 'version': '12.3.3'}]}], 'references': [{'url': 'https://hackerone.com/reports/676976', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-284', 'description': 'Improper Access Control - Generic (CWE-284)'}]}], 'providerMetadata': {'orgId': '36234546-b8fa-4601-9d6f-f4e334aa8ea1', 'shortName': 'hackerone', 'dateUpdated': '2019-12-18T20:51:27.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': '12.3.3'}]}, 'product_name': 'GitLab'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://hackerone.com/reports/676976', 'name': 'https://hackerone.com/reports/676976', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Improper Access Control - Generic (CWE-284)'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-15591', 'STATE': 'PUBLIC', 'ASSIGNER': 'support@hackerone.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-15591', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-05T00:49:13.787Z', 'dateReserved': '2019-08-26T00:00:00.000Z', 'assignerOrgId': '36234546-b8fa-4601-9d6f-f4e334aa8ea1', 'datePublished': '2019-12-18T20:51:27.000Z', 'assignerShortName': 'hackerone'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-15591', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 4.0, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:S/C:P/I:N/A:N', 'authentication': 'SINGLE', 'integrityImpact': 'NONE', 'accessComplexity': 'LOW', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'impactScore': 3.6, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'support@hackerone.com', 'affectedData': [{'vendor': 'n/a', 'product': 'GitLab', 'versions': [{'status': 'affected', 'version': '12.3.3'}]}]}], 'published': '2019-12-18T21:15:12.193', 'references': [{'url': 'https://hackerone.com/reports/676976', 'tags': ['Exploit', 'Issue Tracking', 'Third Party Advisory'], 'source': 'support@hackerone.com'}, {'url': 'https://hackerone.com/reports/676976', 'tags': ['Exploit', 'Issue Tracking', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Secondary', 'source': 'support@hackerone.com', 'description': [{'lang': 'en', 'value': 'CWE-284'}]}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'NVD-CWE-Other'}]}], 'descriptions': [{'lang': 'en', 'value': 'An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.'}, {'lang': 'es', 'value': 'Se presenta una vulnerabilidad de control de acceso inapropiado en GitLab versiones anteriores a 12.3.3 lo que permite a un atacante obtener informes de escaneo de contenedores y dependencias por medio del widget de petición de fusión a pesar de que las tuberías públicas estaban deshabilitadas.'}], 'lastModified': '2026-06-17T02:20:42.273', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*', 'vulnerable': True, 'matchCriteriaId': '7A0C8FC9-8BEB-4BE3-9570-23A2AAA49416', 'versionEndExcluding': '12.3.3'}, {'criteria': 'cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E74A4499-7F83-47E8-A40C-DF7AE97345DD', 'versionEndExcluding': '12.3.3'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'support@hackerone.com'}
CVE-2019-15596
2019-12-18 23:59:06+03:00
2026-06-17 02:20:42.840000+03:00
PUBLISHED
A path traversal in statics-server exists in all version that allows an attacker to perform a path traversal when a symlink is used within the working directory.
HIGH
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
[{'url': 'https://hackerone.com/reports/695416', 'source': 'support@hackerone.com'}, {'url': 'https://hackerone.com/reports/695416', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.106719+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://hackerone.com/reports/695416', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-05T00:49:13.624Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'statics-server', 'versions': [{'status': 'affected', 'version': 'Not fixed'}]}], 'references': [{'url': 'https://hackerone.com/reports/695416', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'A path traversal in statics-server exists in all version that allows an attacker to perform a path traversal when a symlink is used within the working directory.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-22', 'description': 'Path Traversal (CWE-22)'}]}], 'providerMetadata': {'orgId': '36234546-b8fa-4601-9d6f-f4e334aa8ea1', 'shortName': 'hackerone', 'dateUpdated': '2019-12-18T20:59:06.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'Not fixed'}]}, 'product_name': 'statics-server'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://hackerone.com/reports/695416', 'name': 'https://hackerone.com/reports/695416', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'A path traversal in statics-server exists in all version that allows an attacker to perform a path traversal when a symlink is used within the working directory.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Path Traversal (CWE-22)'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-15596', 'STATE': 'PUBLIC', 'ASSIGNER': 'support@hackerone.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-15596', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-05T00:49:13.624Z', 'dateReserved': '2019-08-26T00:00:00.000Z', 'assignerOrgId': '36234546-b8fa-4601-9d6f-f4e334aa8ea1', 'datePublished': '2019-12-18T20:59:06.000Z', 'assignerShortName': 'hackerone'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-15596', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 5.0, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:P/I:N/A:N', 'authentication': 'NONE', 'integrityImpact': 'NONE', 'accessComplexity': 'LOW', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 10.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 3.6, 'exploitabilityScore': 3.9}]}, 'affected': [{'source': 'support@hackerone.com', 'affectedData': [{'vendor': 'n/a', 'product': 'statics-server', 'versions': [{'status': 'affected', 'version': 'Not fixed'}]}]}], 'published': '2019-12-18T21:15:12.303', 'references': [{'url': 'https://hackerone.com/reports/695416', 'tags': ['Exploit', 'Issue Tracking', 'Third Party Advisory'], 'source': 'support@hackerone.com'}, {'url': 'https://hackerone.com/reports/695416', 'tags': ['Exploit', 'Issue Tracking', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Secondary', 'source': 'support@hackerone.com', 'description': [{'lang': 'en', 'value': 'CWE-22'}]}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-22'}]}], 'descriptions': [{'lang': 'en', 'value': 'A path traversal in statics-server exists in all version that allows an attacker to perform a path traversal when a symlink is used within the working directory.'}, {'lang': 'es', 'value': 'Se presenta un Salto de Ruta en statics-server en todas las versiones lo que permite a un atacante realizar un salto de ruta cuando es usado un enlace simbólico dentro del directorio de trabajo.'}], 'lastModified': '2026-06-17T02:20:42.840', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:statics-server_project:statics-server:*:*:*:*:*:node.js:*:*', 'vulnerable': True, 'matchCriteriaId': '1239B046-1513-4522-8DF4-B302FFB2D34D', 'versionEndIncluding': '0.0.9'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'support@hackerone.com'}
CVE-2020-12417
2020-07-09 17:39:37+03:00
2026-06-17 02:51:47.747000+03:00
PUBLISHED
Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially exploitable crash. *Note: this issue only affects Firefox on ARM64 platforms.* This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
HIGH
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00023.html', 'source': 'security@mozilla.org'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00026.html', 'source': 'security@mozilla.org'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html', 'source': 'security@mozilla.org'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html', 'source': 'security@mozilla.org'}, {'url': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1640737', 'source': 'security@mozilla.org'}, {'url': 'https://security.gentoo.org/glsa/202007-09', 'source': 'security@mozilla.org'}, {'url': 'https://security.gentoo.org/glsa/202007-10', 'source': 'security@mozilla.org'}, {'url': 'https://usn.ubuntu.com/4421-1/', 'source': 'security@mozilla.org'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'source': 'security@mozilla.org'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-25/', 'source': 'security@mozilla.org'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-26/', 'source': 'security@mozilla.org'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00023.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00026.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1640737', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://security.gentoo.org/glsa/202007-09', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://security.gentoo.org/glsa/202007-10', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://usn.ubuntu.com/4421-1/', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-25/', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-26/', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:55.755087+03:00
2026-06-27 08:25:53.850778+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-26/', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-25/', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1640737', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00023.html', 'name': 'openSUSE-SU-2020:0967', 'tags': ['vendor-advisory', 'x_refsource_SUSE', 'x_transferred']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00026.html', 'name': 'openSUSE-SU-2020:0982', 'tags': ['vendor-advisory', 'x_refsource_SUSE', 'x_transferred']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html', 'name': 'openSUSE-SU-2020:0983', 'tags': ['vendor-advisory', 'x_refsource_SUSE', 'x_transferred']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html', 'name': 'openSUSE-SU-2020:1017', 'tags': ['vendor-advisory', 'x_refsource_SUSE', 'x_transferred']}, {'url': 'https://usn.ubuntu.com/4421-1/', 'name': 'USN-4421-1', 'tags': ['vendor-advisory', 'x_refsource_UBUNTU', 'x_transferred']}, {'url': 'https://security.gentoo.org/glsa/202007-09', 'name': 'GLSA-202007-09', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}, {'url': 'https://security.gentoo.org/glsa/202007-10', 'name': 'GLSA-202007-10', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T11:56:51.772Z'}}], 'cna': {'affected': [{'vendor': 'Mozilla', 'product': 'Firefox ESR', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': '68.10', 'versionType': 'custom'}]}, {'vendor': 'Mozilla', 'product': 'Firefox', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': '78', 'versionType': 'custom'}]}, {'vendor': 'Mozilla', 'product': 'Thunderbird', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': '68.10.0', 'versionType': 'custom'}]}], 'references': [{'url': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'tags': ['x_refsource_MISC']}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-26/', 'tags': ['x_refsource_MISC']}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-25/', 'tags': ['x_refsource_MISC']}, {'url': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1640737', 'tags': ['x_refsource_MISC']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00023.html', 'name': 'openSUSE-SU-2020:0967', 'tags': ['vendor-advisory', 'x_refsource_SUSE']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00026.html', 'name': 'openSUSE-SU-2020:0982', 'tags': ['vendor-advisory', 'x_refsource_SUSE']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html', 'name': 'openSUSE-SU-2020:0983', 'tags': ['vendor-advisory', 'x_refsource_SUSE']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html', 'name': 'openSUSE-SU-2020:1017', 'tags': ['vendor-advisory', 'x_refsource_SUSE']}, {'url': 'https://usn.ubuntu.com/4421-1/', 'name': 'USN-4421-1', 'tags': ['vendor-advisory', 'x_refsource_UBUNTU']}, {'url': 'https://security.gentoo.org/glsa/202007-09', 'name': 'GLSA-202007-09', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}, {'url': 'https://security.gentoo.org/glsa/202007-10', 'name': 'GLSA-202007-10', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}], 'descriptions': [{'lang': 'en', 'value': 'Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially exploitable crash. *Note: this issue only affects Firefox on ARM64 platforms.* This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Memory corruption due to missing sign-extension for ValueTags on ARM64'}]}], 'providerMetadata': {'orgId': 'f16b083a-5664-49f3-a51e-8d479e5ed7fe', 'shortName': 'mozilla', 'dateUpdated': '2020-07-27T01:06:39.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': '68.10', 'version_affected': '<'}]}, 'product_name': 'Firefox ESR'}, {'version': {'version_data': [{'version_value': '78', 'version_affected': '<'}]}, 'product_name': 'Firefox'}, {'version': {'version_data': [{'version_value': '68.10.0', 'version_affected': '<'}]}, 'product_name': 'Thunderbird'}]}, 'vendor_name': 'Mozilla'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'name': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'refsource': 'MISC'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-26/', 'name': 'https://www.mozilla.org/security/advisories/mfsa2020-26/', 'refsource': 'MISC'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-25/', 'name': 'https://www.mozilla.org/security/advisories/mfsa2020-25/', 'refsource': 'MISC'}, {'url': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1640737', 'name': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1640737', 'refsource': 'MISC'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00023.html', 'name': 'openSUSE-SU-2020:0967', 'refsource': 'SUSE'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00026.html', 'name': 'openSUSE-SU-2020:0982', 'refsource': 'SUSE'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html', 'name': 'openSUSE-SU-2020:0983', 'refsource': 'SUSE'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html', 'name': 'openSUSE-SU-2020:1017', 'refsource': 'SUSE'}, {'url': 'https://usn.ubuntu.com/4421-1/', 'name': 'USN-4421-1', 'refsource': 'UBUNTU'}, {'url': 'https://security.gentoo.org/glsa/202007-09', 'name': 'GLSA-202007-09', 'refsource': 'GENTOO'}, {'url': 'https://security.gentoo.org/glsa/202007-10', 'name': 'GLSA-202007-10', 'refsource': 'GENTOO'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially exploitable crash. *Note: this issue only affects Firefox on ARM64 platforms.* This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Memory corruption due to missing sign-extension for ValueTags on ARM64'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2020-12417', 'STATE': 'PUBLIC', 'ASSIGNER': 'security@mozilla.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2020-12417', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T11:56:51.772Z', 'dateReserved': '2020-04-28T00:00:00.000Z', 'assignerOrgId': 'f16b083a-5664-49f3-a51e-8d479e5ed7fe', 'datePublished': '2020-07-09T14:39:37.000Z', 'assignerShortName': 'mozilla'}, 'dataVersion': '5.1'}
{'id': 'CVE-2020-12417', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 9.3, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:C/I:C/A:C', 'authentication': 'NONE', 'integrityImpact': 'COMPLETE', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'COMPLETE', 'confidentialityImpact': 'COMPLETE'}, 'acInsufInfo': False, 'impactScore': 10.0, 'baseSeverity': 'HIGH', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'security@mozilla.org', 'affectedData': [{'vendor': 'Mozilla', 'product': 'Firefox ESR', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': '68.10', 'versionType': 'custom'}]}, {'vendor': 'Mozilla', 'product': 'Firefox', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': '78', 'versionType': 'custom'}]}, {'vendor': 'Mozilla', 'product': 'Thunderbird', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': '68.10.0', 'versionType': 'custom'}]}]}], 'published': '2020-07-09T15:15:11.757', 'references': [{'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00023.html', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'security@mozilla.org'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00026.html', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'security@mozilla.org'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'security@mozilla.org'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'security@mozilla.org'}, {'url': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1640737', 'tags': ['Exploit', 'Issue Tracking', 'Vendor Advisory'], 'source': 'security@mozilla.org'}, {'url': 'https://security.gentoo.org/glsa/202007-09', 'tags': ['Third Party Advisory'], 'source': 'security@mozilla.org'}, {'url': 'https://security.gentoo.org/glsa/202007-10', 'tags': ['Third Party Advisory'], 'source': 'security@mozilla.org'}, {'url': 'https://usn.ubuntu.com/4421-1/', 'tags': ['Third Party Advisory'], 'source': 'security@mozilla.org'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'tags': ['Vendor Advisory'], 'source': 'security@mozilla.org'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-25/', 'tags': ['Vendor Advisory'], 'source': 'security@mozilla.org'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-26/', 'tags': ['Vendor Advisory'], 'source': 'security@mozilla.org'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00023.html', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00026.html', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1640737', 'tags': ['Exploit', 'Issue Tracking', 'Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://security.gentoo.org/glsa/202007-09', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://security.gentoo.org/glsa/202007-10', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://usn.ubuntu.com/4421-1/', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-25/', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-26/', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-617'}, {'lang': 'en', 'value': 'CWE-681'}, {'lang': 'en', 'value': 'CWE-787'}]}], 'descriptions': [{'lang': 'en', 'value': 'Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially exploitable crash. *Note: this issue only affects Firefox on ARM64 platforms.* This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.'}, {'lang': 'es', 'value': 'Debido a una confusión acerca de ValueTags en objetos JavaScript, un objeto puede pasar a través de la barrera de tipo, resultando en una corrupción de la memoria y un bloqueo potencialmente explotable. *Nota: este problema solo afecta a Firefox en las plataformas ARM64. * Esta vulnerabilidad afecta a Firefox ESR versiones anteriores a 68.10, Firefox versiones anteriores a 78 y Thunderbird versiones anteriores a 68.10.0'}], 'lastModified': '2026-06-17T02:51:47.747', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '09FA5356-4843-47D3-964C-86A6C3859F3C', 'versionEndExcluding': '78.0'}, {'criteria': 'cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'EFD35B04-283B-4EF1-9D63-6E023A49DDCA', 'versionEndExcluding': '68.10.0'}, {'criteria': 'cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A57C62F6-E2C3-4CDD-8518-EF2DB3DCD4DA', 'versionEndExcluding': '68.10.0'}], 'operator': 'OR'}]}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*', 'vulnerable': True, 'matchCriteriaId': '7A5301BF-1402-4BE0-A0F8-69FBE79BC6D6'}, {'criteria': 'cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*', 'vulnerable': True, 'matchCriteriaId': '23A7C53F-B80F-4E6A-AFA9-58EEA84BE11D'}, {'criteria': 'cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A31C8344-3E02-4EB8-8BD8-4C84B7959624'}, {'criteria': 'cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*', 'vulnerable': True, 'matchCriteriaId': '902B8056-9E37-443B-8905-8AA93E2447FB'}], 'operator': 'OR'}]}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'B620311B-34A3-48A6-82DF-6F078D7A4493'}, {'criteria': 'cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'B009C22E-30A4-4288-BCF6-C3E81DEAF45A'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'security@mozilla.org'}
CVE-2019-15597
2019-12-18 23:58:51+03:00
2026-06-17 02:20:42.957000+03:00
PUBLISHED
A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input.
CRITICAL
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
[{'url': 'https://hackerone.com/reports/703412', 'source': 'support@hackerone.com'}, {'url': 'https://hackerone.com/reports/703412', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.106719+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://hackerone.com/reports/703412', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-05T00:49:13.599Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'node-df', 'versions': [{'status': 'affected', 'version': 'Not fixed'}]}], 'references': [{'url': 'https://hackerone.com/reports/703412', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-94', 'description': 'Code Injection (CWE-94)'}]}], 'providerMetadata': {'orgId': '36234546-b8fa-4601-9d6f-f4e334aa8ea1', 'shortName': 'hackerone', 'dateUpdated': '2019-12-18T20:58:51.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'Not fixed'}]}, 'product_name': 'node-df'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://hackerone.com/reports/703412', 'name': 'https://hackerone.com/reports/703412', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Code Injection (CWE-94)'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-15597', 'STATE': 'PUBLIC', 'ASSIGNER': 'support@hackerone.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-15597', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-05T00:49:13.599Z', 'dateReserved': '2019-08-26T00:00:00.000Z', 'assignerOrgId': '36234546-b8fa-4601-9d6f-f4e334aa8ea1', 'datePublished': '2019-12-18T20:58:51.000Z', 'assignerShortName': 'hackerone'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-15597', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 7.5, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'LOW', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'HIGH', 'obtainAllPrivilege': False, 'exploitabilityScore': 10.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 3.9}]}, 'affected': [{'source': 'support@hackerone.com', 'affectedData': [{'vendor': 'n/a', 'product': 'node-df', 'versions': [{'status': 'affected', 'version': 'Not fixed'}]}]}], 'published': '2019-12-18T21:15:12.413', 'references': [{'url': 'https://hackerone.com/reports/703412', 'tags': ['Permissions Required', 'Third Party Advisory'], 'source': 'support@hackerone.com'}, {'url': 'https://hackerone.com/reports/703412', 'tags': ['Permissions Required', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Secondary', 'source': 'support@hackerone.com', 'description': [{'lang': 'en', 'value': 'CWE-94'}]}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-94'}]}], 'descriptions': [{'lang': 'en', 'value': 'A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input.'}, {'lang': 'es', 'value': 'Se presenta una inyección de código en node-df versión v0.1.4 que puede permitir a un atacante ejecutar código remotamente mediante una entrada no saneada.'}], 'lastModified': '2026-06-17T02:20:42.957', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:node-df_project:node-df:0.1.4:*:*:*:*:node.js:*:*', 'vulnerable': True, 'matchCriteriaId': 'EEFDA726-07F5-4075-BD1B-A5960CE7AA22'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'support@hackerone.com'}
CVE-2019-15598
2019-12-18 23:58:31+03:00
2026-06-17 02:20:43.067000+03:00
PUBLISHED
A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
CRITICAL
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
[{'url': 'https://hackerone.com/reports/703415', 'source': 'support@hackerone.com'}, {'url': 'https://hackerone.com/reports/703415', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.106719+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://hackerone.com/reports/703415', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-05T00:49:13.755Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'treekill', 'versions': [{'status': 'affected', 'version': 'Not fixed'}]}], 'references': [{'url': 'https://hackerone.com/reports/703415', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-94', 'description': 'Code Injection (CWE-94)'}]}], 'providerMetadata': {'orgId': '36234546-b8fa-4601-9d6f-f4e334aa8ea1', 'shortName': 'hackerone', 'dateUpdated': '2019-12-18T20:58:31.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'Not fixed'}]}, 'product_name': 'treekill'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://hackerone.com/reports/703415', 'name': 'https://hackerone.com/reports/703415', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Code Injection (CWE-94)'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-15598', 'STATE': 'PUBLIC', 'ASSIGNER': 'support@hackerone.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-15598', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-05T00:49:13.755Z', 'dateReserved': '2019-08-26T00:00:00.000Z', 'assignerOrgId': '36234546-b8fa-4601-9d6f-f4e334aa8ea1', 'datePublished': '2019-12-18T20:58:31.000Z', 'assignerShortName': 'hackerone'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-15598', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 7.5, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'LOW', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'HIGH', 'obtainAllPrivilege': False, 'exploitabilityScore': 10.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 3.9}]}, 'affected': [{'source': 'support@hackerone.com', 'affectedData': [{'vendor': 'n/a', 'product': 'treekill', 'versions': [{'status': 'affected', 'version': 'Not fixed'}]}]}], 'published': '2019-12-18T21:15:12.523', 'references': [{'url': 'https://hackerone.com/reports/703415', 'tags': ['Permissions Required', 'Third Party Advisory'], 'source': 'support@hackerone.com'}, {'url': 'https://hackerone.com/reports/703415', 'tags': ['Permissions Required', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Secondary', 'source': 'support@hackerone.com', 'description': [{'lang': 'en', 'value': 'CWE-94'}]}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-78'}]}], 'descriptions': [{'lang': 'en', 'value': 'A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command.'}, {'lang': 'es', 'value': 'Se presenta una inyección de código en treekill en Windows lo que permite una ejecución de código remota cuando un atacante es capaz de controlar la entrada en el comando.'}], 'lastModified': '2026-06-17T02:20:43.067', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:treekill_project:treekill:1.0.0:*:*:*:*:node.js:*:*', 'vulnerable': True, 'matchCriteriaId': 'EB0605BE-26D1-4816-A3AF-966EBF37866D'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'support@hackerone.com'}
CVE-2019-15599
2019-12-18 23:56:56+03:00
2026-06-17 02:20:43.177000+03:00
PUBLISHED
A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
CRITICAL
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
[{'url': 'https://hackerone.com/reports/701183', 'source': 'support@hackerone.com'}, {'url': 'https://hackerone.com/reports/701183', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:19.106719+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://hackerone.com/reports/701183', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-05T00:49:13.640Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'tree-kill', 'versions': [{'status': 'affected', 'version': 'Not fixed'}]}], 'references': [{'url': 'https://hackerone.com/reports/701183', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-94', 'description': 'Code Injection (CWE-94)'}]}], 'providerMetadata': {'orgId': '36234546-b8fa-4601-9d6f-f4e334aa8ea1', 'shortName': 'hackerone', 'dateUpdated': '2019-12-18T20:56:56.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'Not fixed'}]}, 'product_name': 'tree-kill'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://hackerone.com/reports/701183', 'name': 'https://hackerone.com/reports/701183', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Code Injection (CWE-94)'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-15599', 'STATE': 'PUBLIC', 'ASSIGNER': 'support@hackerone.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-15599', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-05T00:49:13.640Z', 'dateReserved': '2019-08-26T00:00:00.000Z', 'assignerOrgId': '36234546-b8fa-4601-9d6f-f4e334aa8ea1', 'datePublished': '2019-12-18T20:56:56.000Z', 'assignerShortName': 'hackerone'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-15599', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 7.5, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'LOW', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'HIGH', 'obtainAllPrivilege': False, 'exploitabilityScore': 10.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 3.9}]}, 'affected': [{'source': 'support@hackerone.com', 'affectedData': [{'vendor': 'n/a', 'product': 'tree-kill', 'versions': [{'status': 'affected', 'version': 'Not fixed'}]}]}], 'published': '2019-12-18T21:15:12.617', 'references': [{'url': 'https://hackerone.com/reports/701183', 'tags': ['Permissions Required', 'Third Party Advisory'], 'source': 'support@hackerone.com'}, {'url': 'https://hackerone.com/reports/701183', 'tags': ['Permissions Required', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Secondary', 'source': 'support@hackerone.com', 'description': [{'lang': 'en', 'value': 'CWE-94'}]}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-94'}]}], 'descriptions': [{'lang': 'en', 'value': 'A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command.'}, {'lang': 'es', 'value': 'Se presenta una inyección de código en tree-kill en Windows lo que permite una ejecución de código remota cuando un atacante es capaz de controlar la entrada en el comando.'}], 'lastModified': '2026-06-17T02:20:43.177', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:tree-kill_project:tree-kill:1.2.1:*:*:*:*:node.js:*:*', 'vulnerable': True, 'matchCriteriaId': '03C344DE-5A62-4CC1-96B4-423470C77A57'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'support@hackerone.com'}
CVE-2020-12418
2020-07-09 17:19:50+03:00
2026-06-17 02:51:47.893000+03:00
PUBLISHED
Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
MEDIUM
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
[{'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00023.html', 'source': 'security@mozilla.org'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00026.html', 'source': 'security@mozilla.org'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html', 'source': 'security@mozilla.org'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html', 'source': 'security@mozilla.org'}, {'url': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1641303', 'source': 'security@mozilla.org'}, {'url': 'https://security.gentoo.org/glsa/202007-09', 'source': 'security@mozilla.org'}, {'url': 'https://security.gentoo.org/glsa/202007-10', 'source': 'security@mozilla.org'}, {'url': 'https://usn.ubuntu.com/4421-1/', 'source': 'security@mozilla.org'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'source': 'security@mozilla.org'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-25/', 'source': 'security@mozilla.org'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-26/', 'source': 'security@mozilla.org'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00023.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00026.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1641303', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://security.gentoo.org/glsa/202007-09', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://security.gentoo.org/glsa/202007-10', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://usn.ubuntu.com/4421-1/', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-25/', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-26/', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:55.969618+03:00
2026-06-27 08:25:53.850778+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-26/', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-25/', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1641303', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00023.html', 'name': 'openSUSE-SU-2020:0967', 'tags': ['vendor-advisory', 'x_refsource_SUSE', 'x_transferred']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00026.html', 'name': 'openSUSE-SU-2020:0982', 'tags': ['vendor-advisory', 'x_refsource_SUSE', 'x_transferred']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html', 'name': 'openSUSE-SU-2020:0983', 'tags': ['vendor-advisory', 'x_refsource_SUSE', 'x_transferred']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html', 'name': 'openSUSE-SU-2020:1017', 'tags': ['vendor-advisory', 'x_refsource_SUSE', 'x_transferred']}, {'url': 'https://usn.ubuntu.com/4421-1/', 'name': 'USN-4421-1', 'tags': ['vendor-advisory', 'x_refsource_UBUNTU', 'x_transferred']}, {'url': 'https://security.gentoo.org/glsa/202007-09', 'name': 'GLSA-202007-09', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}, {'url': 'https://security.gentoo.org/glsa/202007-10', 'name': 'GLSA-202007-10', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T11:56:51.647Z'}}], 'cna': {'affected': [{'vendor': 'Mozilla', 'product': 'Firefox ESR', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': '68.10', 'versionType': 'custom'}]}, {'vendor': 'Mozilla', 'product': 'Firefox', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': '78', 'versionType': 'custom'}]}, {'vendor': 'Mozilla', 'product': 'Thunderbird', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': '68.10.0', 'versionType': 'custom'}]}], 'references': [{'url': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'tags': ['x_refsource_MISC']}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-26/', 'tags': ['x_refsource_MISC']}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-25/', 'tags': ['x_refsource_MISC']}, {'url': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1641303', 'tags': ['x_refsource_MISC']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00023.html', 'name': 'openSUSE-SU-2020:0967', 'tags': ['vendor-advisory', 'x_refsource_SUSE']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00026.html', 'name': 'openSUSE-SU-2020:0982', 'tags': ['vendor-advisory', 'x_refsource_SUSE']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html', 'name': 'openSUSE-SU-2020:0983', 'tags': ['vendor-advisory', 'x_refsource_SUSE']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html', 'name': 'openSUSE-SU-2020:1017', 'tags': ['vendor-advisory', 'x_refsource_SUSE']}, {'url': 'https://usn.ubuntu.com/4421-1/', 'name': 'USN-4421-1', 'tags': ['vendor-advisory', 'x_refsource_UBUNTU']}, {'url': 'https://security.gentoo.org/glsa/202007-09', 'name': 'GLSA-202007-09', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}, {'url': 'https://security.gentoo.org/glsa/202007-10', 'name': 'GLSA-202007-10', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}], 'descriptions': [{'lang': 'en', 'value': 'Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Information disclosure due to manipulated URL object'}]}], 'providerMetadata': {'orgId': 'f16b083a-5664-49f3-a51e-8d479e5ed7fe', 'shortName': 'mozilla', 'dateUpdated': '2020-07-27T01:06:39.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': '68.10', 'version_affected': '<'}]}, 'product_name': 'Firefox ESR'}, {'version': {'version_data': [{'version_value': '78', 'version_affected': '<'}]}, 'product_name': 'Firefox'}, {'version': {'version_data': [{'version_value': '68.10.0', 'version_affected': '<'}]}, 'product_name': 'Thunderbird'}]}, 'vendor_name': 'Mozilla'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'name': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'refsource': 'MISC'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-26/', 'name': 'https://www.mozilla.org/security/advisories/mfsa2020-26/', 'refsource': 'MISC'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-25/', 'name': 'https://www.mozilla.org/security/advisories/mfsa2020-25/', 'refsource': 'MISC'}, {'url': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1641303', 'name': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1641303', 'refsource': 'MISC'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00023.html', 'name': 'openSUSE-SU-2020:0967', 'refsource': 'SUSE'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00026.html', 'name': 'openSUSE-SU-2020:0982', 'refsource': 'SUSE'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html', 'name': 'openSUSE-SU-2020:0983', 'refsource': 'SUSE'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html', 'name': 'openSUSE-SU-2020:1017', 'refsource': 'SUSE'}, {'url': 'https://usn.ubuntu.com/4421-1/', 'name': 'USN-4421-1', 'refsource': 'UBUNTU'}, {'url': 'https://security.gentoo.org/glsa/202007-09', 'name': 'GLSA-202007-09', 'refsource': 'GENTOO'}, {'url': 'https://security.gentoo.org/glsa/202007-10', 'name': 'GLSA-202007-10', 'refsource': 'GENTOO'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Information disclosure due to manipulated URL object'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2020-12418', 'STATE': 'PUBLIC', 'ASSIGNER': 'security@mozilla.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2020-12418', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T11:56:51.647Z', 'dateReserved': '2020-04-28T00:00:00.000Z', 'assignerOrgId': 'f16b083a-5664-49f3-a51e-8d479e5ed7fe', 'datePublished': '2020-07-09T14:19:50.000Z', 'assignerShortName': 'mozilla'}, 'dataVersion': '5.1'}
{'id': 'CVE-2020-12418', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 4.3, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:P/I:N/A:N', 'authentication': 'NONE', 'integrityImpact': 'NONE', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 3.6, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'security@mozilla.org', 'affectedData': [{'vendor': 'Mozilla', 'product': 'Firefox ESR', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': '68.10', 'versionType': 'custom'}]}, {'vendor': 'Mozilla', 'product': 'Firefox', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': '78', 'versionType': 'custom'}]}, {'vendor': 'Mozilla', 'product': 'Thunderbird', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': '68.10.0', 'versionType': 'custom'}]}]}], 'published': '2020-07-09T15:15:11.817', 'references': [{'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00023.html', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'security@mozilla.org'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00026.html', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'security@mozilla.org'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'security@mozilla.org'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'security@mozilla.org'}, {'url': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1641303', 'tags': ['Issue Tracking', 'Permissions Required', 'Vendor Advisory'], 'source': 'security@mozilla.org'}, {'url': 'https://security.gentoo.org/glsa/202007-09', 'tags': ['Third Party Advisory'], 'source': 'security@mozilla.org'}, {'url': 'https://security.gentoo.org/glsa/202007-10', 'tags': ['Third Party Advisory'], 'source': 'security@mozilla.org'}, {'url': 'https://usn.ubuntu.com/4421-1/', 'tags': ['Third Party Advisory'], 'source': 'security@mozilla.org'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'tags': ['Vendor Advisory'], 'source': 'security@mozilla.org'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-25/', 'tags': ['Vendor Advisory'], 'source': 'security@mozilla.org'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-26/', 'tags': ['Vendor Advisory'], 'source': 'security@mozilla.org'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00023.html', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00026.html', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1641303', 'tags': ['Issue Tracking', 'Permissions Required', 'Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://security.gentoo.org/glsa/202007-09', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://security.gentoo.org/glsa/202007-10', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://usn.ubuntu.com/4421-1/', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-24/', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-25/', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://www.mozilla.org/security/advisories/mfsa2020-26/', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-125'}]}], 'descriptions': [{'lang': 'en', 'value': 'Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.'}, {'lang': 'es', 'value': 'La manipulación de partes individuales de un objeto URL podría haber causado una lectura fuera de límites, filtrando la memoria de proceso a un JavaScript malicioso. Esta vulnerabilidad afecta a Firefox ESR versiones anteriores a 68.10, Firefox versiones anteriores a 78 y Thunderbird versiones anteriores a 68.10.0'}], 'lastModified': '2026-06-17T02:51:47.893', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '09FA5356-4843-47D3-964C-86A6C3859F3C', 'versionEndExcluding': '78.0'}, {'criteria': 'cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '0C93F92B-A583-4358-A7F5-5BA4493BB819', 'versionEndExcluding': '68.10'}, {'criteria': 'cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A57C62F6-E2C3-4CDD-8518-EF2DB3DCD4DA', 'versionEndExcluding': '68.10.0'}], 'operator': 'OR'}]}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*', 'vulnerable': True, 'matchCriteriaId': '7A5301BF-1402-4BE0-A0F8-69FBE79BC6D6'}, {'criteria': 'cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*', 'vulnerable': True, 'matchCriteriaId': '23A7C53F-B80F-4E6A-AFA9-58EEA84BE11D'}, {'criteria': 'cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A31C8344-3E02-4EB8-8BD8-4C84B7959624'}, {'criteria': 'cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*', 'vulnerable': True, 'matchCriteriaId': '902B8056-9E37-443B-8905-8AA93E2447FB'}], 'operator': 'OR'}]}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'B620311B-34A3-48A6-82DF-6F078D7A4493'}, {'criteria': 'cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'B009C22E-30A4-4288-BCF6-C3E81DEAF45A'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'security@mozilla.org'}
CVE-2019-15600
2019-12-18 23:56:21+03:00
2026-06-17 02:20:43.290000+03:00
PUBLISHED
A Path traversal exists in http_server which allows an attacker to read arbitrary system files.
HIGH
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
[{'url': 'https://hackerone.com/reports/692262', 'source': 'support@hackerone.com'}, {'url': 'https://hackerone.com/reports/692262', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:18.787866+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://hackerone.com/reports/692262', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-05T00:49:13.746Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'http_server', 'versions': [{'status': 'affected', 'version': 'Not fixed'}]}], 'references': [{'url': 'https://hackerone.com/reports/692262', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'A Path traversal exists in http_server which allows an attacker to read arbitrary system files.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-22', 'description': 'Path Traversal (CWE-22)'}]}], 'providerMetadata': {'orgId': '36234546-b8fa-4601-9d6f-f4e334aa8ea1', 'shortName': 'hackerone', 'dateUpdated': '2019-12-18T20:56:21.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'Not fixed'}]}, 'product_name': 'http_server'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://hackerone.com/reports/692262', 'name': 'https://hackerone.com/reports/692262', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'A Path traversal exists in http_server which allows an attacker to read arbitrary system files.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'Path Traversal (CWE-22)'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-15600', 'STATE': 'PUBLIC', 'ASSIGNER': 'support@hackerone.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-15600', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-05T00:49:13.746Z', 'dateReserved': '2019-08-26T00:00:00.000Z', 'assignerOrgId': '36234546-b8fa-4601-9d6f-f4e334aa8ea1', 'datePublished': '2019-12-18T20:56:21.000Z', 'assignerShortName': 'hackerone'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-15600', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 5.0, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:P/I:N/A:N', 'authentication': 'NONE', 'integrityImpact': 'NONE', 'accessComplexity': 'LOW', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 10.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 3.6, 'exploitabilityScore': 3.9}]}, 'affected': [{'source': 'support@hackerone.com', 'affectedData': [{'vendor': 'n/a', 'product': 'http_server', 'versions': [{'status': 'affected', 'version': 'Not fixed'}]}]}], 'published': '2019-12-18T21:15:12.740', 'references': [{'url': 'https://hackerone.com/reports/692262', 'tags': ['Issue Tracking', 'Third Party Advisory'], 'source': 'support@hackerone.com'}, {'url': 'https://hackerone.com/reports/692262', 'tags': ['Issue Tracking', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Secondary', 'source': 'support@hackerone.com', 'description': [{'lang': 'en', 'value': 'CWE-22'}]}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-22'}]}], 'descriptions': [{'lang': 'en', 'value': 'A Path traversal exists in http_server which allows an attacker to read arbitrary system files.'}, {'lang': 'es', 'value': 'Se presenta un Salto de Ruta en http_server que permite a un atacante leer archivos arbitrarios del sistema.'}], 'lastModified': '2026-06-17T02:20:43.290', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:http_server_project:http_server:1.0.12:*:*:*:*:node.js:*:*', 'vulnerable': True, 'matchCriteriaId': 'AE99C39A-1E89-4378-9C9B-B8AA97EF471D'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'support@hackerone.com'}
CVE-2019-18571
2019-12-18 23:50:13.968000+03:00
2026-06-17 02:25:06.767000+03:00
PUBLISHED
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a reflected cross-site scripting vulnerability in the My Access Live module [MAL]. An authenticated malicious local user could potentially exploit this vulnerability by sending crafted URL with scripts. When victim users access the module through their browsers, the malicious code gets injected and executed by the web browser in the context of the vulnerable web application.
MEDIUM
5.4
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
[{'url': 'https://community.rsa.com/docs/DOC-109310', 'source': 'security_alert@emc.com'}, {'url': 'https://community.rsa.com/docs/DOC-109310', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:15.698920+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://community.rsa.com/docs/DOC-109310', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-05T01:54:14.492Z'}}], 'cna': {'metrics': [{'cvssV3_0': {'scope': 'CHANGED', 'version': '3.0', 'baseScore': 5.4, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N', 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'LOW'}}], 'affected': [{'vendor': 'Dell', 'product': 'RSA Identity Governance & Lifecycle', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': '7.1.0 P09, 7.1.1 P3', 'versionType': 'custom'}]}], 'datePublic': '2019-11-26T00:00:00.000Z', 'references': [{'url': 'https://community.rsa.com/docs/DOC-109310', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a reflected cross-site scripting vulnerability in the My Access Live module [MAL]. An authenticated malicious local user could potentially exploit this vulnerability by sending crafted URL with scripts. When victim users access the module through their browsers, the malicious code gets injected and executed by the web browser in the context of the vulnerable web application.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-79', 'description': "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"}]}], 'providerMetadata': {'orgId': 'c550e75a-17ff-4988-97f0-544cde3820fe', 'shortName': 'dell', 'dateUpdated': '2020-08-31T15:12:35.000Z'}, 'x_legacyV4Record': {'impact': {'cvss': {'version': '3.0', 'baseScore': 5.4, 'baseSeverity': 'Medium', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}}, 'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': '7.1.0 P09, 7.1.1 P3', 'version_affected': '<'}]}, 'product_name': 'RSA Identity Governance & Lifecycle'}]}, 'vendor_name': 'Dell'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://community.rsa.com/docs/DOC-109310', 'name': 'https://community.rsa.com/docs/DOC-109310', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a reflected cross-site scripting vulnerability in the My Access Live module [MAL]. An authenticated malicious local user could potentially exploit this vulnerability by sending crafted URL with scripts. When victim users access the module through their browsers, the malicious code gets injected and executed by the web browser in the context of the vulnerable web application.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-18571', 'STATE': 'PUBLIC', 'ASSIGNER': 'secure@dell.com', 'DATE_PUBLIC': '2019-11-26'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-18571', 'state': 'PUBLISHED', 'dateUpdated': '2024-09-16T19:10:42.619Z', 'dateReserved': '2019-10-29T00:00:00.000Z', 'assignerOrgId': 'c550e75a-17ff-4988-97f0-544cde3820fe', 'datePublished': '2019-12-18T20:50:13.968Z', 'assignerShortName': 'dell'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-18571', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 3.5, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:S/C:N/I:P/A:N', 'authentication': 'SINGLE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'NONE'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'LOW', 'obtainAllPrivilege': False, 'exploitabilityScore': 6.8, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV30': [{'type': 'Secondary', 'source': 'security_alert@emc.com', 'cvssData': {'scope': 'CHANGED', 'version': '3.0', 'baseScore': 5.4, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N', 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'LOW'}, 'impactScore': 2.7, 'exploitabilityScore': 2.3}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 5.4, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N', 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'LOW'}, 'impactScore': 2.7, 'exploitabilityScore': 2.3}]}, 'affected': [{'source': 'security_alert@emc.com', 'affectedData': [{'vendor': 'Dell', 'product': 'RSA Identity Governance & Lifecycle', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': '7.1.0 P09, 7.1.1 P3', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T21:15:12.833', 'references': [{'url': 'https://community.rsa.com/docs/DOC-109310', 'source': 'security_alert@emc.com'}, {'url': 'https://community.rsa.com/docs/DOC-109310', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Secondary', 'source': 'security_alert@emc.com', 'description': [{'lang': 'en', 'value': 'CWE-79'}]}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-79'}]}], 'descriptions': [{'lang': 'en', 'value': 'The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a reflected cross-site scripting vulnerability in the My Access Live module [MAL]. An authenticated malicious local user could potentially exploit this vulnerability by sending crafted URL with scripts. When victim users access the module through their browsers, the malicious code gets injected and executed by the web browser in the context of the vulnerable web application.'}, {'lang': 'es', 'value': 'Los productos RSA Identity Governance and Lifecycle y RSA Via Lifecycle and Governance versiones anteriores a 7.1.1 P03, contienen una vulnerabilidad de tipo cross-site scripting reflejado en el módulo My Access Live [MAL]. Un usuario local malicioso autenticado podría explotar potencialmente esta vulnerabilidad mediante el envío de una URL diseñada con scripts. Cuando los usuarios víctimas acceden al módulo por medio de sus navegadores, el código malicioso es insertado y ejecutado mediante el navegador web en el contexto de la aplicación web vulnerable.'}], 'lastModified': '2026-06-17T02:25:06.767', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.0:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '54F243EB-5F06-4728-8815-93BDB5502F74'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.0.1:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'DD518D4A-157A-42D8-B958-8C4661CE6224'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.0.2:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E2715882-4E9F-4E4C-A648-30B5D8B36C63'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:-:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'BC3F7997-46CC-4345-981A-4CA38A73BA8C'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p01:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'DD36DED8-5591-4A76-AD40-7DAED6EF1954'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p02:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '6CF203FD-8A59-4237-820A-FDBE4F28E4B9'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p03:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '08FC40D4-433A-4EDE-87B1-422D0473D6D8'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p04:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '5CF1C39E-D12B-44E4-8172-CD91F17E871B'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p05:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '31DCF79D-E1EA-4F65-B355-C821B0D78E73'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p06:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '82CFC850-4C98-42B5-AE77-592FD64E78E1'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p07:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '9DE35E51-0C69-41A8-9332-A9E411CE0B92'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p08:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A8989E78-229D-47B1-A60F-50394D8DF244'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.1:-:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '6E9E1900-FE59-440A-87D6-35DE7233EAB3'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.1:p01:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '15371ECD-CACD-4E1F-854B-D5EA6D1BBC54'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.1:p02:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'ACD868A6-05CC-4BCF-BC53-EA4418DE5F45'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'security_alert@emc.com'}
CVE-2019-18572
2019-12-18 23:50:14.414000+03:00
2026-06-17 02:25:07.023000+03:00
PUBLISHED
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain an Improper Authentication vulnerability. A Java JMX agent running on the remote host is configured with plain text password authentication. An unauthenticated remote attacker can connect to the JMX agent and monitor and manage the Java application.
HIGH
8.3
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
[{'url': 'https://community.rsa.com/docs/DOC-109310', 'source': 'security_alert@emc.com'}, {'url': 'https://community.rsa.com/docs/DOC-109310', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:15.489173+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://community.rsa.com/docs/DOC-109310', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-05T01:54:14.426Z'}}], 'cna': {'metrics': [{'cvssV3_0': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 8.3, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}], 'affected': [{'vendor': 'Dell', 'product': 'RSA Identity Governance & Lifecycle', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': '7.1.0 P09, 7.1.1 P03', 'versionType': 'custom'}]}], 'datePublic': '2019-11-26T00:00:00.000Z', 'references': [{'url': 'https://community.rsa.com/docs/DOC-109310', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain an Improper Authentication vulnerability. A Java JMX agent running on the remote host is configured with plain text password authentication. An unauthenticated remote attacker can connect to the JMX agent and monitor and manage the Java application.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-306', 'description': 'CWE-306: Missing Authentication for Critical Function'}]}], 'providerMetadata': {'orgId': 'c550e75a-17ff-4988-97f0-544cde3820fe', 'shortName': 'dell', 'dateUpdated': '2020-08-31T15:12:36.000Z'}, 'x_legacyV4Record': {'impact': {'cvss': {'version': '3.0', 'baseScore': 8.3, 'baseSeverity': 'High', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L'}}, 'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': '7.1.0 P09, 7.1.1 P03', 'version_affected': '<'}]}, 'product_name': 'RSA Identity Governance & Lifecycle'}]}, 'vendor_name': 'Dell'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://community.rsa.com/docs/DOC-109310', 'name': 'https://community.rsa.com/docs/DOC-109310', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain an Improper Authentication vulnerability. A Java JMX agent running on the remote host is configured with plain text password authentication. An unauthenticated remote attacker can connect to the JMX agent and monitor and manage the Java application.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'CWE-306: Missing Authentication for Critical Function'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-18572', 'STATE': 'PUBLIC', 'ASSIGNER': 'secure@dell.com', 'DATE_PUBLIC': '2019-11-26'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-18572', 'state': 'PUBLISHED', 'dateUpdated': '2024-09-16T22:19:43.694Z', 'dateReserved': '2019-10-29T00:00:00.000Z', 'assignerOrgId': 'c550e75a-17ff-4988-97f0-544cde3820fe', 'datePublished': '2019-12-18T20:50:14.414Z', 'assignerShortName': 'dell'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-18572', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 7.5, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'LOW', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'HIGH', 'obtainAllPrivilege': False, 'exploitabilityScore': 10.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV30': [{'type': 'Secondary', 'source': 'security_alert@emc.com', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 8.3, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.5, 'exploitabilityScore': 2.8}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 3.9}]}, 'affected': [{'source': 'security_alert@emc.com', 'affectedData': [{'vendor': 'Dell', 'product': 'RSA Identity Governance & Lifecycle', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': '7.1.0 P09, 7.1.1 P03', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T21:15:12.943', 'references': [{'url': 'https://community.rsa.com/docs/DOC-109310', 'tags': ['Vendor Advisory'], 'source': 'security_alert@emc.com'}, {'url': 'https://community.rsa.com/docs/DOC-109310', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Secondary', 'source': 'security_alert@emc.com', 'description': [{'lang': 'en', 'value': 'CWE-306'}]}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-522'}]}], 'descriptions': [{'lang': 'en', 'value': 'The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain an Improper Authentication vulnerability. A Java JMX agent running on the remote host is configured with plain text password authentication. An unauthenticated remote attacker can connect to the JMX agent and monitor and manage the Java application.'}, {'lang': 'es', 'value': 'Los productos RSA Identity Governance and Lifecycle y RSA Via Lifecycle and Governance versiones anteriores a 7.1.1 P03, contienen una vulnerabilidad de Autenticación Inapropiada. Un agente Java JMX que se ejecuta en el host remoto está configurado con autenticación de contraseña de texto plano. Un atacante remoto no autenticado puede conectarse al agente JMX y monitorear y administrar la aplicación Java.'}], 'lastModified': '2026-06-17T02:25:07.023', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.0:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '54F243EB-5F06-4728-8815-93BDB5502F74'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.0.1:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'DD518D4A-157A-42D8-B958-8C4661CE6224'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.0.2:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E2715882-4E9F-4E4C-A648-30B5D8B36C63'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:-:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'BC3F7997-46CC-4345-981A-4CA38A73BA8C'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p01:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'DD36DED8-5591-4A76-AD40-7DAED6EF1954'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p02:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '6CF203FD-8A59-4237-820A-FDBE4F28E4B9'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p03:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '08FC40D4-433A-4EDE-87B1-422D0473D6D8'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p04:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '5CF1C39E-D12B-44E4-8172-CD91F17E871B'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p05:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '31DCF79D-E1EA-4F65-B355-C821B0D78E73'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p06:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '82CFC850-4C98-42B5-AE77-592FD64E78E1'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p07:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '9DE35E51-0C69-41A8-9332-A9E411CE0B92'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p08:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A8989E78-229D-47B1-A60F-50394D8DF244'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.1:-:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '6E9E1900-FE59-440A-87D6-35DE7233EAB3'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.1:p01:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '15371ECD-CACD-4E1F-854B-D5EA6D1BBC54'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.1:p02:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'ACD868A6-05CC-4BCF-BC53-EA4418DE5F45'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'security_alert@emc.com'}
CVE-2019-18573
2019-12-18 23:50:14.868000+03:00
2026-06-17 02:25:07.180000+03:00
PUBLISHED
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Session Fixation vulnerability. An authenticated malicious local user could potentially exploit this vulnerability as the session token is exposed as part of the URL. A remote attacker can gain access to victim’s session and perform arbitrary actions with privileges of the user within the compromised session.
HIGH
8.7
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
[{'url': 'https://community.rsa.com/docs/DOC-109310', 'source': 'security_alert@emc.com'}, {'url': 'https://community.rsa.com/docs/DOC-109310', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:15.698920+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://community.rsa.com/docs/DOC-109310', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-05T01:54:14.362Z'}}], 'cna': {'metrics': [{'cvssV3_0': {'scope': 'CHANGED', 'version': '3.0', 'baseScore': 8.7, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}}], 'affected': [{'vendor': 'Dell', 'product': 'RSA Identity Governance & Lifecycle', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': '7.1.0 P09, 7.1.1 P03', 'versionType': 'custom'}]}], 'datePublic': '2019-11-26T00:00:00.000Z', 'references': [{'url': 'https://community.rsa.com/docs/DOC-109310', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Session Fixation vulnerability. An authenticated malicious local user could potentially exploit this vulnerability as the session token is exposed as part of the URL. A remote attacker can gain access to victim’s session and perform arbitrary actions with privileges of the user within the compromised session.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-598', 'description': 'CWE-598: Information Exposure Through Query Strings in GET Request'}]}], 'providerMetadata': {'orgId': 'c550e75a-17ff-4988-97f0-544cde3820fe', 'shortName': 'dell', 'dateUpdated': '2020-08-31T15:12:36.000Z'}, 'x_legacyV4Record': {'impact': {'cvss': {'version': '3.0', 'baseScore': 8.7, 'baseSeverity': 'High', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}}, 'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': '7.1.0 P09, 7.1.1 P03', 'version_affected': '<'}]}, 'product_name': 'RSA Identity Governance & Lifecycle'}]}, 'vendor_name': 'Dell'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://community.rsa.com/docs/DOC-109310', 'name': 'https://community.rsa.com/docs/DOC-109310', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Session Fixation vulnerability. An authenticated malicious local user could potentially exploit this vulnerability as the session token is exposed as part of the URL. A remote attacker can gain access to victim’s session and perform arbitrary actions with privileges of the user within the compromised session.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'CWE-598: Information Exposure Through Query Strings in GET Request'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-18573', 'STATE': 'PUBLIC', 'ASSIGNER': 'secure@dell.com', 'DATE_PUBLIC': '2019-11-26'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-18573', 'state': 'PUBLISHED', 'dateUpdated': '2024-09-16T16:28:49.370Z', 'dateReserved': '2019-10-29T00:00:00.000Z', 'assignerOrgId': 'c550e75a-17ff-4988-97f0-544cde3820fe', 'datePublished': '2019-12-18T20:50:14.868Z', 'assignerShortName': 'dell'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-18573', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 6.8, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV30': [{'type': 'Secondary', 'source': 'security_alert@emc.com', 'cvssData': {'scope': 'CHANGED', 'version': '3.0', 'baseScore': 8.7, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.8, 'exploitabilityScore': 2.3}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'security_alert@emc.com', 'affectedData': [{'vendor': 'Dell', 'product': 'RSA Identity Governance & Lifecycle', 'versions': [{'status': 'affected', 'version': 'unspecified', 'lessThan': '7.1.0 P09, 7.1.1 P03', 'versionType': 'custom'}]}]}], 'published': '2019-12-18T21:15:13.083', 'references': [{'url': 'https://community.rsa.com/docs/DOC-109310', 'source': 'security_alert@emc.com'}, {'url': 'https://community.rsa.com/docs/DOC-109310', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Secondary', 'source': 'security_alert@emc.com', 'description': [{'lang': 'en', 'value': 'CWE-598'}]}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-384'}]}], 'descriptions': [{'lang': 'en', 'value': 'The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Session Fixation vulnerability. An authenticated malicious local user could potentially exploit this vulnerability as the session token is exposed as part of the URL. A remote attacker can gain access to victim’s session and perform arbitrary actions with privileges of the user within the compromised session.'}, {'lang': 'es', 'value': 'Los productos RSA Identity Governance and Lifecycle y RSA Via Lifecycle and Governance anteriores a 7.1.1 P03 contienen una vulnerabilidad de fijación de sesión. Un usuario local malintencionado autenticado podría aprovechar esta vulnerabilidad ya que el token de sesión se expone como parte de la URL. Un atacante remoto puede obtener acceso a la sesión de la víctima y realizar acciones arbitrarias con privilegios del usuario dentro de la sesión comprometida.'}], 'lastModified': '2026-06-17T02:25:07.180', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.0:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '54F243EB-5F06-4728-8815-93BDB5502F74'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.0.1:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'DD518D4A-157A-42D8-B958-8C4661CE6224'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.0.2:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E2715882-4E9F-4E4C-A648-30B5D8B36C63'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:-:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'BC3F7997-46CC-4345-981A-4CA38A73BA8C'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p01:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'DD36DED8-5591-4A76-AD40-7DAED6EF1954'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p02:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '6CF203FD-8A59-4237-820A-FDBE4F28E4B9'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p03:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '08FC40D4-433A-4EDE-87B1-422D0473D6D8'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p04:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '5CF1C39E-D12B-44E4-8172-CD91F17E871B'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p05:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '31DCF79D-E1EA-4F65-B355-C821B0D78E73'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p06:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '82CFC850-4C98-42B5-AE77-592FD64E78E1'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p07:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '9DE35E51-0C69-41A8-9332-A9E411CE0B92'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.0:p08:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A8989E78-229D-47B1-A60F-50394D8DF244'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.1:-:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '6E9E1900-FE59-440A-87D6-35DE7233EAB3'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.1:p01:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '15371ECD-CACD-4E1F-854B-D5EA6D1BBC54'}, {'criteria': 'cpe:2.3:a:dell:rsa_identity_governance_and_lifecycle:7.1.1:p02:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'ACD868A6-05CC-4BCF-BC53-EA4418DE5F45'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'security_alert@emc.com'}
CVE-2019-18994
2019-12-18 23:20:57+03:00
2026-06-17 02:25:48.230000+03:00
PUBLISHED
Due to a lack of file length check, the HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier crashes when trying to load an empty *.JPR application file. An attacker with access to the file system might be able to cause application malfunction such as denial of service.
LOW
3.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
[{'url': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'source': 'cybersecurity@ch.abb.com'}, {'url': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:15.489173+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-05T02:02:39.901Z'}}], 'cna': {'title': 'ABB PB610 HMIStudio crashes after launching an empty *.JPR application file', 'source': {'defect': ['ABBVU-RAMF-1908001'], 'advisory': '3ADR010466', 'discovery': 'UNKNOWN'}, 'credits': [{'lang': 'en', 'value': 'NSFOCUS for providing vulnerability details and proof of concept.'}], 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 3.9, 'attackVector': 'LOCAL', 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}}], 'affected': [{'vendor': 'ABB', 'product': 'ABB PB610 Panel Builder 600', 'versions': [{'status': 'affected', 'version': 'unspecified', 'versionType': 'custom', 'lessThanOrEqual': '2.8.0.424'}]}], 'references': [{'url': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'tags': ['x_refsource_MISC']}], 'x_generator': {'engine': 'Vulnogram 0.0.9'}, 'descriptions': [{'lang': 'en', 'value': 'Due to a lack of file length check, the HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier crashes when trying to load an empty *.JPR application file. An attacker with access to the file system might be able to cause application malfunction such as denial of service.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-20', 'description': 'CWE-20 Improper Input Validation'}]}], 'providerMetadata': {'orgId': '2b718523-d88f-4f37-9bbd-300c20644bf9', 'shortName': 'ABB', 'dateUpdated': '2019-12-18T20:20:57.000Z'}, 'x_legacyV4Record': {'credit': [{'lang': 'eng', 'value': 'NSFOCUS for providing vulnerability details and proof of concept.'}], 'impact': {'cvss': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 3.9, 'attackVector': 'LOCAL', 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}}, 'source': {'defect': ['ABBVU-RAMF-1908001'], 'advisory': '3ADR010466', 'discovery': 'UNKNOWN'}, 'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': '2.8.0.424', 'version_affected': '<='}]}, 'product_name': 'ABB PB610 Panel Builder 600'}]}, 'vendor_name': 'ABB'}]}}, 'data_type': 'CVE', 'generator': {'engine': 'Vulnogram 0.0.9'}, 'references': {'reference_data': [{'url': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'name': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Due to a lack of file length check, the HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier crashes when trying to load an empty *.JPR application file. An attacker with access to the file system might be able to cause application malfunction such as denial of service.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'CWE-20 Improper Input Validation'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-18994', 'STATE': 'PUBLIC', 'TITLE': 'ABB PB610 HMIStudio crashes after launching an empty *.JPR application file', 'ASSIGNER': 'cybersecurity@ch.abb.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-18994', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-05T02:02:39.901Z', 'dateReserved': '2019-11-15T00:00:00.000Z', 'assignerOrgId': '2b718523-d88f-4f37-9bbd-300c20644bf9', 'datePublished': '2019-12-18T20:20:57.000Z', 'assignerShortName': 'ABB'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-18994', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 3.5, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:S/C:N/I:N/A:P', 'authentication': 'SINGLE', 'integrityImpact': 'NONE', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'NONE'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'LOW', 'obtainAllPrivilege': False, 'exploitabilityScore': 6.8, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Secondary', 'source': 'cybersecurity@ch.abb.com', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 3.9, 'attackVector': 'LOCAL', 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'impactScore': 2.5, 'exploitabilityScore': 1.3}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}, 'impactScore': 3.6, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'cybersecurity@ch.abb.com', 'affectedData': [{'vendor': 'ABB', 'product': 'ABB PB610 Panel Builder 600', 'versions': [{'status': 'affected', 'version': 'unspecified', 'versionType': 'custom', 'lessThanOrEqual': '2.8.0.424'}]}]}], 'published': '2019-12-18T21:15:13.240', 'references': [{'url': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'tags': ['Third Party Advisory'], 'source': 'cybersecurity@ch.abb.com'}, {'url': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Secondary', 'source': 'cybersecurity@ch.abb.com', 'description': [{'lang': 'en', 'value': 'CWE-20'}]}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-20'}]}], 'descriptions': [{'lang': 'en', 'value': 'Due to a lack of file length check, the HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier crashes when trying to load an empty *.JPR application file. An attacker with access to the file system might be able to cause application malfunction such as denial of service.'}, {'lang': 'es', 'value': 'Debido a la falta de comprobación de la longitud del archivo, el componente HMIStudio de ABB PB610 Panel Builder 600 versiones 2.8.0.424 y anteriores, se bloquea al intentar cargar un archivo de aplicación *.JPR vacío. Un atacante con acceso al sistema de archivos podría ser capaz de causar un mal funcionamiento de la aplicación, tal y como una denegación de servicio.'}], 'lastModified': '2026-06-17T02:25:48.230', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:abb:pb610_panel_builder_600:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '2A9714CC-B58C-4D3E-A618-8C8146032D6B', 'versionEndIncluding': '2.8.0.424'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'cybersecurity@ch.abb.com'}
CVE-2019-18995
2019-12-18 23:19:34+03:00
2026-06-17 02:25:56.483000+03:00
PUBLISHED
The HMISimulator component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier fails to validate the content-length field for HTTP requests, exposing HMISimulator to denial of service via crafted HTTP requests manipulating the content-length setting.
MEDIUM
4.3
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
[{'url': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'source': 'cybersecurity@ch.abb.com'}, {'url': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:15.489173+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-05T02:02:40.045Z'}}], 'cna': {'title': 'ABB PB610 HMISimulator does not check content-length of the HTTP request', 'source': {'defect': ['ABBVU-RAMF-1908002'], 'discovery': 'UNKNOWN'}, 'credits': [{'lang': 'en', 'value': 'NSFOCUS for providing vulnerability details and proof of concept.'}], 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.3, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}], 'affected': [{'vendor': 'ABB', 'product': 'PB610 Panel Builder 600', 'versions': [{'status': 'affected', 'version': 'unspecified', 'versionType': 'custom', 'lessThanOrEqual': '2.8.0.424'}]}], 'references': [{'url': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'tags': ['x_refsource_MISC']}], 'x_generator': {'engine': 'Vulnogram 0.0.9'}, 'descriptions': [{'lang': 'en', 'value': 'The HMISimulator component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier fails to validate the content-length field for HTTP requests, exposing HMISimulator to denial of service via crafted HTTP requests manipulating the content-length setting.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-20', 'description': 'CWE-20 Improper Input Validation'}]}], 'providerMetadata': {'orgId': '2b718523-d88f-4f37-9bbd-300c20644bf9', 'shortName': 'ABB', 'dateUpdated': '2019-12-18T20:19:34.000Z'}, 'x_legacyV4Record': {'credit': [{'lang': 'eng', 'value': 'NSFOCUS for providing vulnerability details and proof of concept.'}], 'impact': {'cvss': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.3, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, 'source': {'defect': ['ABBVU-RAMF-1908002'], 'discovery': 'UNKNOWN'}, 'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': '2.8.0.424', 'version_affected': '<='}]}, 'product_name': 'PB610 Panel Builder 600'}]}, 'vendor_name': 'ABB'}]}}, 'data_type': 'CVE', 'generator': {'engine': 'Vulnogram 0.0.9'}, 'references': {'reference_data': [{'url': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'name': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'The HMISimulator component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier fails to validate the content-length field for HTTP requests, exposing HMISimulator to denial of service via crafted HTTP requests manipulating the content-length setting.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'CWE-20 Improper Input Validation'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-18995', 'STATE': 'PUBLIC', 'TITLE': 'ABB PB610 HMISimulator does not check content-length of the HTTP request', 'ASSIGNER': 'cybersecurity@ch.abb.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-18995', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-05T02:02:40.045Z', 'dateReserved': '2019-11-15T00:00:00.000Z', 'assignerOrgId': '2b718523-d88f-4f37-9bbd-300c20644bf9', 'datePublished': '2019-12-18T20:19:34.000Z', 'assignerShortName': 'ABB'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-18995', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 5.0, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:N/I:N/A:P', 'authentication': 'NONE', 'integrityImpact': 'NONE', 'accessComplexity': 'LOW', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'NONE'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 10.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Secondary', 'source': 'cybersecurity@ch.abb.com', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.3, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}, 'impactScore': 1.4, 'exploitabilityScore': 2.8}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}, 'impactScore': 1.4, 'exploitabilityScore': 3.9}]}, 'affected': [{'source': 'cybersecurity@ch.abb.com', 'affectedData': [{'vendor': 'ABB', 'product': 'PB610 Panel Builder 600', 'versions': [{'status': 'affected', 'version': 'unspecified', 'versionType': 'custom', 'lessThanOrEqual': '2.8.0.424'}]}]}], 'published': '2019-12-18T21:15:13.397', 'references': [{'url': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'tags': ['Third Party Advisory'], 'source': 'cybersecurity@ch.abb.com'}, {'url': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Secondary', 'source': 'cybersecurity@ch.abb.com', 'description': [{'lang': 'en', 'value': 'CWE-20'}]}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-20'}]}], 'descriptions': [{'lang': 'en', 'value': 'The HMISimulator component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier fails to validate the content-length field for HTTP requests, exposing HMISimulator to denial of service via crafted HTTP requests manipulating the content-length setting.'}, {'lang': 'es', 'value': 'El componente HMISimulator de ABB PB610 Panel Builder 600 versiones 2.8.0.424 y anteriores, no comprueba el campo de longitud de contenido para peticiones HTTP, exponiendo HMISimulator a una denegación de servicio por medio de peticiones HTTP diseñadas que manipulan la configuración de longitud de contenido.'}], 'lastModified': '2026-06-17T02:25:56.483', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:abb:pb610_panel_builder_600:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '2A9714CC-B58C-4D3E-A618-8C8146032D6B', 'versionEndIncluding': '2.8.0.424'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'cybersecurity@ch.abb.com'}
CVE-2019-18996
2019-12-18 23:24:44+03:00
2026-06-17 02:25:57.130000+03:00
PUBLISHED
Path settings in HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier accept DLLs outside of the program directory, potentially allowing an attacker with access to the local file system the execution of code in the application’s context.
HIGH
7.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:L
[{'url': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'source': 'cybersecurity@ch.abb.com'}, {'url': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:15.489173+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-05T02:02:39.897Z'}}], 'cna': {'title': 'ABB PB610 HMIStudio accepts malicious DLL file in an application', 'source': {'defect': ['ABBVU-RAMF-1908003'], 'discovery': 'UNKNOWN'}, 'credits': [{'lang': 'en', 'value': 'NSFOCUS for providing vulnerability details and proof of concept.'}], 'metrics': [{'cvssV3_1': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.1, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:L', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}], 'affected': [{'vendor': 'ABB', 'product': 'PB610 Panel Builder 600', 'versions': [{'status': 'affected', 'version': 'unspecified', 'versionType': 'custom', 'lessThanOrEqual': '2.8.0.424'}]}], 'references': [{'url': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'tags': ['x_refsource_MISC']}], 'x_generator': {'engine': 'Vulnogram 0.0.9'}, 'descriptions': [{'lang': 'en', 'value': 'Path settings in HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier accept DLLs outside of the program directory, potentially allowing an attacker with access to the local file system the execution of code in the application’s context.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-424', 'description': 'CWE-424 Improper Protection of Alternate Path'}]}], 'providerMetadata': {'orgId': '2b718523-d88f-4f37-9bbd-300c20644bf9', 'shortName': 'ABB', 'dateUpdated': '2019-12-18T20:24:44.000Z'}, 'x_legacyV4Record': {'credit': [{'lang': 'eng', 'value': 'NSFOCUS for providing vulnerability details and proof of concept.'}], 'impact': {'cvss': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.1, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:L', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, 'source': {'defect': ['ABBVU-RAMF-1908003'], 'discovery': 'UNKNOWN'}, 'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': '2.8.0.424', 'version_affected': '<='}]}, 'product_name': 'PB610 Panel Builder 600'}]}, 'vendor_name': 'ABB'}]}}, 'data_type': 'CVE', 'generator': {'engine': 'Vulnogram 0.0.9'}, 'references': {'reference_data': [{'url': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'name': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Path settings in HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier accept DLLs outside of the program directory, potentially allowing an attacker with access to the local file system the execution of code in the application’s context.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'CWE-424 Improper Protection of Alternate Path'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-18996', 'STATE': 'PUBLIC', 'TITLE': 'ABB PB610 HMIStudio accepts malicious DLL file in an application', 'ASSIGNER': 'cybersecurity@ch.abb.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-18996', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-05T02:02:39.897Z', 'dateReserved': '2019-11-15T00:00:00.000Z', 'assignerOrgId': '2b718523-d88f-4f37-9bbd-300c20644bf9', 'datePublished': '2019-12-18T20:24:44.000Z', 'assignerShortName': 'ABB'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-18996', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 4.4, 'accessVector': 'LOCAL', 'vectorString': 'AV:L/AC:M/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 3.4, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Secondary', 'source': 'cybersecurity@ch.abb.com', 'cvssData': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.1, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:L', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}, 'impactScore': 4.7, 'exploitabilityScore': 1.8}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 1.8}]}, 'affected': [{'source': 'cybersecurity@ch.abb.com', 'affectedData': [{'vendor': 'ABB', 'product': 'PB610 Panel Builder 600', 'versions': [{'status': 'affected', 'version': 'unspecified', 'versionType': 'custom', 'lessThanOrEqual': '2.8.0.424'}]}]}], 'published': '2019-12-18T21:15:13.507', 'references': [{'url': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'tags': ['Third Party Advisory'], 'source': 'cybersecurity@ch.abb.com'}, {'url': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Secondary', 'source': 'cybersecurity@ch.abb.com', 'description': [{'lang': 'en', 'value': 'CWE-424'}]}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-426'}]}], 'descriptions': [{'lang': 'en', 'value': 'Path settings in HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier accept DLLs outside of the program directory, potentially allowing an attacker with access to the local file system the execution of code in the application’s context.'}, {'lang': 'es', 'value': 'La configuración de ruta en el componente HMIStudio de ABB PB610 Panel Builder 600 versiones 2.8.0.424 y anteriores acepta archivos DLL fuera del directorio del programa, lo que potencialmente permite a un atacante con acceso al sistema de archivos local la ejecución de código en el contexto de la aplicación.'}], 'lastModified': '2026-06-17T02:25:57.130', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:abb:pb610_panel_builder_600:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '2A9714CC-B58C-4D3E-A618-8C8146032D6B', 'versionEndIncluding': '2.8.0.424'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'cybersecurity@ch.abb.com'}
CVE-2019-18997
2019-12-18 23:22:47+03:00
2026-06-17 02:25:57.240000+03:00
PUBLISHED
The HMISimulator component of ABB PB610 Panel Builder 600 uses the readFile/writeFile interface to manipulate the work file. Path configuration in PB610 HMISimulator versions 2.8.0.424 and earlier potentially allows access to files outside of the working directory, thus potentially supporting unauthorized file access.
MEDIUM
4.3
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
[{'url': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'source': 'cybersecurity@ch.abb.com'}, {'url': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:15.489173+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-05T02:02:39.800Z'}}], 'cna': {'title': 'PB610 HMISimulator provides interface with access to arbitrary files', 'source': {'defect': ['ABBVU-RAMF-1908004'], 'discovery': 'UNKNOWN'}, 'credits': [{'lang': 'en', 'value': 'NSFOCUS for providing vulnerability details and proof of concept.'}], 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.3, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}], 'affected': [{'vendor': 'ABB', 'product': 'PB610 Panel Builder 600', 'versions': [{'status': 'affected', 'version': 'unspecified', 'versionType': 'custom', 'lessThanOrEqual': '2.8.0.424'}]}], 'references': [{'url': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'tags': ['x_refsource_MISC']}], 'x_generator': {'engine': 'Vulnogram 0.0.9'}, 'descriptions': [{'lang': 'en', 'value': 'The HMISimulator component of ABB PB610 Panel Builder 600 uses the readFile/writeFile interface to manipulate the work file. Path configuration in PB610 HMISimulator versions 2.8.0.424 and earlier potentially allows access to files outside of the working directory, thus potentially supporting unauthorized file access.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-424', 'description': 'CWE-424 Improper Protection of Alternate Path'}]}], 'providerMetadata': {'orgId': '2b718523-d88f-4f37-9bbd-300c20644bf9', 'shortName': 'ABB', 'dateUpdated': '2019-12-18T20:22:47.000Z'}, 'x_legacyV4Record': {'credit': [{'lang': 'eng', 'value': 'NSFOCUS for providing vulnerability details and proof of concept.'}], 'impact': {'cvss': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.3, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, 'source': {'defect': ['ABBVU-RAMF-1908004'], 'discovery': 'UNKNOWN'}, 'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': '2.8.0.424', 'version_affected': '<='}]}, 'product_name': 'PB610 Panel Builder 600'}]}, 'vendor_name': 'ABB'}]}}, 'data_type': 'CVE', 'generator': {'engine': 'Vulnogram 0.0.9'}, 'references': {'reference_data': [{'url': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'name': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'The HMISimulator component of ABB PB610 Panel Builder 600 uses the readFile/writeFile interface to manipulate the work file. Path configuration in PB610 HMISimulator versions 2.8.0.424 and earlier potentially allows access to files outside of the working directory, thus potentially supporting unauthorized file access.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'CWE-424 Improper Protection of Alternate Path'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-18997', 'STATE': 'PUBLIC', 'TITLE': 'PB610 HMISimulator provides interface with access to arbitrary files', 'ASSIGNER': 'cybersecurity@ch.abb.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-18997', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-05T02:02:39.800Z', 'dateReserved': '2019-11-15T00:00:00.000Z', 'assignerOrgId': '2b718523-d88f-4f37-9bbd-300c20644bf9', 'datePublished': '2019-12-18T20:22:47.000Z', 'assignerShortName': 'ABB'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-18997', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 5.0, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:P/I:N/A:N', 'authentication': 'NONE', 'integrityImpact': 'NONE', 'accessComplexity': 'LOW', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 10.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Secondary', 'source': 'cybersecurity@ch.abb.com', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.3, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}, 'impactScore': 1.4, 'exploitabilityScore': 2.8}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 3.6, 'exploitabilityScore': 3.9}]}, 'affected': [{'source': 'cybersecurity@ch.abb.com', 'affectedData': [{'vendor': 'ABB', 'product': 'PB610 Panel Builder 600', 'versions': [{'status': 'affected', 'version': 'unspecified', 'versionType': 'custom', 'lessThanOrEqual': '2.8.0.424'}]}]}], 'published': '2019-12-18T21:15:13.630', 'references': [{'url': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'tags': ['Exploit', 'Vendor Advisory'], 'source': 'cybersecurity@ch.abb.com'}, {'url': 'http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch', 'tags': ['Exploit', 'Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Secondary', 'source': 'cybersecurity@ch.abb.com', 'description': [{'lang': 'en', 'value': 'CWE-424'}]}, {'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'NVD-CWE-noinfo'}]}], 'descriptions': [{'lang': 'en', 'value': 'The HMISimulator component of ABB PB610 Panel Builder 600 uses the readFile/writeFile interface to manipulate the work file. Path configuration in PB610 HMISimulator versions 2.8.0.424 and earlier potentially allows access to files outside of the working directory, thus potentially supporting unauthorized file access.'}, {'lang': 'es', 'value': 'El componente HMISimulator de ABB PB610 Panel Builder 600 utiliza la interfaz readFile/writeFile para manipular el archivo de trabajo. La configuración de ruta en PB610 HMISimulator versiones 2.8.0.424 y anteriores, permite potencialmente el acceso a archivos fuera del directorio de trabajo, lo que potencialmente admite el acceso a archivos no autorizados.'}], 'lastModified': '2026-06-17T02:25:57.240', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:abb:pb610_panel_builder_600:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '2A9714CC-B58C-4D3E-A618-8C8146032D6B', 'versionEndIncluding': '2.8.0.424'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'cybersecurity@ch.abb.com'}
CVE-2019-19724
2019-12-18 23:52:24+03:00
2026-06-17 02:27:08.630000+03:00
PUBLISHED
Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an information leak, and malicious redirection of operations performed against Sylabs cloud services.
HIGH
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
[{'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00025.html', 'source': 'cve@mitre.org'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00059.html', 'source': 'cve@mitre.org'}, {'url': 'https://github.com/sylabs/singularity/releases/tag/v3.5.2', 'source': 'cve@mitre.org'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00025.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00059.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://github.com/sylabs/singularity/releases/tag/v3.5.2', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:15.937311+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://github.com/sylabs/singularity/releases/tag/v3.5.2', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00025.html', 'name': 'openSUSE-SU-2020:0057', 'tags': ['vendor-advisory', 'x_refsource_SUSE', 'x_transferred']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00059.html', 'name': 'openSUSE-SU-2020:1037', 'tags': ['vendor-advisory', 'x_refsource_SUSE', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-05T02:25:12.399Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://github.com/sylabs/singularity/releases/tag/v3.5.2', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00025.html', 'name': 'openSUSE-SU-2020:0057', 'tags': ['vendor-advisory', 'x_refsource_SUSE']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00059.html', 'name': 'openSUSE-SU-2020:1037', 'tags': ['vendor-advisory', 'x_refsource_SUSE']}], 'descriptions': [{'lang': 'en', 'value': 'Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an information leak, and malicious redirection of operations performed against Sylabs cloud services.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2020-07-23T11:06:19.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://github.com/sylabs/singularity/releases/tag/v3.5.2', 'name': 'https://github.com/sylabs/singularity/releases/tag/v3.5.2', 'refsource': 'CONFIRM'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00025.html', 'name': 'openSUSE-SU-2020:0057', 'refsource': 'SUSE'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00059.html', 'name': 'openSUSE-SU-2020:1037', 'refsource': 'SUSE'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an information leak, and malicious redirection of operations performed against Sylabs cloud services.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-19724', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-19724', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-05T02:25:12.399Z', 'dateReserved': '2019-12-11T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2019-12-18T20:52:24.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-19724', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 5.0, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:P/I:N/A:N', 'authentication': 'NONE', 'integrityImpact': 'NONE', 'accessComplexity': 'LOW', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 10.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 3.6, 'exploitabilityScore': 3.9}]}, 'affected': [{'source': 'cve@mitre.org', 'affectedData': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}]}], 'published': '2019-12-18T21:15:13.757', 'references': [{'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00025.html', 'source': 'cve@mitre.org'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00059.html', 'source': 'cve@mitre.org'}, {'url': 'https://github.com/sylabs/singularity/releases/tag/v3.5.2', 'tags': ['Release Notes', 'Third Party Advisory'], 'source': 'cve@mitre.org'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00025.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00059.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://github.com/sylabs/singularity/releases/tag/v3.5.2', 'tags': ['Release Notes', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-276'}]}], 'descriptions': [{'lang': 'en', 'value': 'Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an information leak, and malicious redirection of operations performed against Sylabs cloud services.'}, {'lang': 'es', 'value': 'Los permisos no seguros (777) se establecen en $HOME/.singularity cuando son creados nuevamente por Singularity (versiones 3.3.0 hasta 3.5.1), lo que podría conllevar a un filtrado de información y un redireccionamiento malicioso de las operaciones realizadas contra los servicios en la nube de Sylabs.'}], 'lastModified': '2026-06-17T02:27:08.630', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:sylabs:singularity:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '84407079-F1DF-4DB0-8FFD-5A29B91A4505', 'versionEndIncluding': '3.5.1', 'versionStartIncluding': '3.3.0'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'cve@mitre.org'}
CVE-2019-1387
2019-12-18 23:11:53+03:00
2026-06-17 02:28:30.630000+03:00
PUBLISHED
An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are currently affected by a vulnerability that is caused by too-lax validation of submodule names, allowing very targeted attacks via remote code execution in recursive clones.
HIGH
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
[{'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00056.html', 'source': 'secure@microsoft.com'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00003.html', 'source': 'secure@microsoft.com'}, {'url': 'https://access.redhat.com/errata/RHSA-2019:4356', 'source': 'secure@microsoft.com'}, {'url': 'https://access.redhat.com/errata/RHSA-2020:0002', 'source': 'secure@microsoft.com'}, {'url': 'https://access.redhat.com/errata/RHSA-2020:0124', 'source': 'secure@microsoft.com'}, {'url': 'https://access.redhat.com/errata/RHSA-2020:0228', 'source': 'secure@microsoft.com'}, {'url': 'https://lists.debian.org/debian-lts-announce/2020/01/msg00019.html', 'source': 'secure@microsoft.com'}, {'url': 'https://lists.debian.org/debian-lts-announce/2024/06/msg00018.html', 'source': 'secure@microsoft.com'}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N6UGTEOXWIYSM5KDZL74QD2GK6YQNQCP/', 'source': 'secure@microsoft.com'}, {'url': 'https://lore.kernel.org/git/xmqqr21cqcn9.fsf%40gitster-ct.c.googlers.com/T/#u', 'source': 'secure@microsoft.com'}, {'url': 'https://public-inbox.org/git/xmqqr21cqcn9.fsf%40gitster-ct.c.googlers.com/', 'source': 'secure@microsoft.com'}, {'url': 'https://security.gentoo.org/glsa/202003-30', 'source': 'secure@microsoft.com'}, {'url': 'https://security.gentoo.org/glsa/202003-42', 'source': 'secure@microsoft.com'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00056.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00003.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://access.redhat.com/errata/RHSA-2019:4356', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://access.redhat.com/errata/RHSA-2020:0002', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://access.redhat.com/errata/RHSA-2020:0124', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://access.redhat.com/errata/RHSA-2020:0228', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lists.debian.org/debian-lts-announce/2020/01/msg00019.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lists.debian.org/debian-lts-announce/2024/06/msg00018.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lists.debian.org/debian-lts-announce/2024/09/msg00009.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N6UGTEOXWIYSM5KDZL74QD2GK6YQNQCP/', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lore.kernel.org/git/xmqqr21cqcn9.fsf%40gitster-ct.c.googlers.com/T/#u', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://public-inbox.org/git/xmqqr21cqcn9.fsf%40gitster-ct.c.googlers.com/', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://security.gentoo.org/glsa/202003-30', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://security.gentoo.org/glsa/202003-42', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:13.082995+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CISA ADP Vulnrichment', 'metrics': [{'other': {'type': 'ssvc', 'content': {'id': 'CVE-2019-1387', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-07-19T18:49:36.663475Z'}}}], 'affected': [{'cpes': ['cpe:2.3:a:git:git:*:*:*:*:*:*:*:*'], 'vendor': 'git', 'product': 'git', 'versions': [{'status': 'affected', 'version': '0', 'lessThan': '2,24.1', 'versionType': 'custom'}, {'status': 'affected', 'version': '0', 'lessThan': '2.23.1', 'versionType': 'custom'}, {'status': 'affected', 'version': '0', 'lessThan': '2.22.2', 'versionType': 'custom'}, {'status': 'affected', 'version': '0', 'lessThan': '2.21.1', 'versionType': 'custom'}, {'status': 'affected', 'version': '0', 'lessThan': '2.20.2', 'versionType': 'custom'}, {'status': 'affected', 'version': '0', 'lessThan': '2.19.3', 'versionType': 'custom'}, {'status': 'affected', 'version': '0', 'lessThan': '2.18.2', 'versionType': 'custom'}, {'status': 'affected', 'version': '0', 'lessThan': '2.17.3', 'versionType': 'custom'}, {'status': 'affected', 'version': '0', 'lessThan': '2.16.6', 'versionType': 'custom'}, {'status': 'affected', 'version': '0', 'lessThan': '2.15.4', 'versionType': 'custom'}, {'status': 'affected', 'version': '0', 'lessThan': '2.14.6', 'versionType': 'custom'}], 'defaultStatus': 'unknown'}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-07-19T19:03:52.040Z'}}, {'title': 'CVE Program Container', 'references': [{'url': 'https://lore.kernel.org/git/xmqqr21cqcn9.fsf%40gitster-ct.c.googlers.com/T/#u', 'tags': ['x_transferred']}, {'url': 'https://access.redhat.com/errata/RHSA-2019:4356', 'name': 'RHSA-2019:4356', 'tags': ['vendor-advisory', 'x_transferred']}, {'url': 'https://access.redhat.com/errata/RHSA-2020:0002', 'name': 'RHSA-2020:0002', 'tags': ['vendor-advisory', 'x_transferred']}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N6UGTEOXWIYSM5KDZL74QD2GK6YQNQCP/', 'name': 'FEDORA-2019-1cec196e20', 'tags': ['vendor-advisory', 'x_transferred']}, {'url': 'https://access.redhat.com/errata/RHSA-2020:0124', 'name': 'RHSA-2020:0124', 'tags': ['vendor-advisory', 'x_transferred']}, {'url': 'https://lists.debian.org/debian-lts-announce/2020/01/msg00019.html', 'name': '[debian-lts-announce] 20200123 [SECURITY] [DLA 2059-1] git security update', 'tags': ['mailing-list', 'x_transferred']}, {'url': 'https://public-inbox.org/git/xmqqr21cqcn9.fsf%40gitster-ct.c.googlers.com/', 'tags': ['x_transferred']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00056.html', 'name': 'openSUSE-SU-2020:0123', 'tags': ['vendor-advisory', 'x_transferred']}, {'url': 'https://access.redhat.com/errata/RHSA-2020:0228', 'name': 'RHSA-2020:0228', 'tags': ['vendor-advisory', 'x_transferred']}, {'url': 'https://security.gentoo.org/glsa/202003-30', 'name': 'GLSA-202003-30', 'tags': ['vendor-advisory', 'x_transferred']}, {'url': 'https://security.gentoo.org/glsa/202003-42', 'name': 'GLSA-202003-42', 'tags': ['vendor-advisory', 'x_transferred']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00003.html', 'name': 'openSUSE-SU-2020:0598', 'tags': ['vendor-advisory', 'x_transferred']}, {'url': 'https://lists.debian.org/debian-lts-announce/2024/06/msg00018.html', 'name': '[debian-lts-announce] 20240626 [SECURITY] [DLA 3844-1] git security update', 'tags': ['mailing-list', 'x_transferred']}, {'url': 'https://lists.debian.org/debian-lts-announce/2024/09/msg00009.html'}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2025-11-04T16:09:13.231Z'}}], 'cna': {'affected': [{'vendor': 'Microsoft Corporation', 'product': 'Git', 'versions': [{'status': 'affected', 'version': 'Before v2.24.1'}, {'status': 'affected', 'version': 'Before v2.23.1'}, {'status': 'affected', 'version': 'Before v2.22.2'}, {'status': 'affected', 'version': 'Before v2.21.1'}, {'status': 'affected', 'version': 'Before v2.20.2'}, {'status': 'affected', 'version': 'Before v2.19.3'}, {'status': 'affected', 'version': 'Before v2.18.2'}, {'status': 'affected', 'version': 'Before v2.17.3'}, {'status': 'affected', 'version': 'Before v2.16.6'}, {'status': 'affected', 'version': 'Before v2.15.4'}, {'status': 'affected', 'version': 'Before v2.14.6'}]}], 'references': [{'url': 'https://lore.kernel.org/git/xmqqr21cqcn9.fsf%40gitster-ct.c.googlers.com/T/#u'}, {'url': 'https://access.redhat.com/errata/RHSA-2019:4356', 'name': 'RHSA-2019:4356', 'tags': ['vendor-advisory']}, {'url': 'https://access.redhat.com/errata/RHSA-2020:0002', 'name': 'RHSA-2020:0002', 'tags': ['vendor-advisory']}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N6UGTEOXWIYSM5KDZL74QD2GK6YQNQCP/', 'name': 'FEDORA-2019-1cec196e20', 'tags': ['vendor-advisory']}, {'url': 'https://access.redhat.com/errata/RHSA-2020:0124', 'name': 'RHSA-2020:0124', 'tags': ['vendor-advisory']}, {'url': 'https://lists.debian.org/debian-lts-announce/2020/01/msg00019.html', 'name': '[debian-lts-announce] 20200123 [SECURITY] [DLA 2059-1] git security update', 'tags': ['mailing-list']}, {'url': 'https://public-inbox.org/git/xmqqr21cqcn9.fsf%40gitster-ct.c.googlers.com/'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00056.html', 'name': 'openSUSE-SU-2020:0123', 'tags': ['vendor-advisory']}, {'url': 'https://access.redhat.com/errata/RHSA-2020:0228', 'name': 'RHSA-2020:0228', 'tags': ['vendor-advisory']}, {'url': 'https://security.gentoo.org/glsa/202003-30', 'name': 'GLSA-202003-30', 'tags': ['vendor-advisory']}, {'url': 'https://security.gentoo.org/glsa/202003-42', 'name': 'GLSA-202003-42', 'tags': ['vendor-advisory']}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00003.html', 'name': 'openSUSE-SU-2020:0598', 'tags': ['vendor-advisory']}, {'url': 'https://lists.debian.org/debian-lts-announce/2024/06/msg00018.html', 'name': '[debian-lts-announce] 20240626 [SECURITY] [DLA 3844-1] git security update', 'tags': ['mailing-list']}], 'descriptions': [{'lang': 'en', 'value': 'An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are currently affected by a vulnerability that is caused by too-lax validation of submodule names, allowing very targeted attacks via remote code execution in recursive clones.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'Remote Code Execution'}]}], 'providerMetadata': {'orgId': 'f38d906d-7342-40ea-92c1-6c4a2c6478c8', 'shortName': 'microsoft', 'dateUpdated': '2024-06-26T10:06:04.659Z'}}}, 'cveMetadata': {'cveId': 'CVE-2019-1387', 'state': 'PUBLISHED', 'dateUpdated': '2025-11-04T16:09:13.231Z', 'dateReserved': '2018-11-26T00:00:00.000Z', 'assignerOrgId': 'f38d906d-7342-40ea-92c1-6c4a2c6478c8', 'datePublished': '2019-12-18T20:11:53.000Z', 'assignerShortName': 'microsoft'}, 'dataVersion': '5.2'}
{'id': 'CVE-2019-1387', 'cveTags': [], 'metrics': {'ssvcV203': [{'source': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'ssvcData': {'id': 'CVE-2019-1387', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-07-19T18:49:36.663475Z'}}], 'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 6.8, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 8.6, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': True}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 2.8}]}, 'affected': [{'source': 'secure@microsoft.com', 'affectedData': [{'vendor': 'Microsoft Corporation', 'product': 'Git', 'versions': [{'status': 'affected', 'version': 'Before v2.24.1'}, {'status': 'affected', 'version': 'Before v2.23.1'}, {'status': 'affected', 'version': 'Before v2.22.2'}, {'status': 'affected', 'version': 'Before v2.21.1'}, {'status': 'affected', 'version': 'Before v2.20.2'}, {'status': 'affected', 'version': 'Before v2.19.3'}, {'status': 'affected', 'version': 'Before v2.18.2'}, {'status': 'affected', 'version': 'Before v2.17.3'}, {'status': 'affected', 'version': 'Before v2.16.6'}, {'status': 'affected', 'version': 'Before v2.15.4'}, {'status': 'affected', 'version': 'Before v2.14.6'}]}]}, {'source': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'affectedData': [{'cpes': ['cpe:2.3:a:git:git:*:*:*:*:*:*:*:*'], 'vendor': 'git', 'product': 'git', 'versions': [{'status': 'affected', 'version': '0', 'lessThan': '2,24.1', 'versionType': 'custom'}, {'status': 'affected', 'version': '0', 'lessThan': '2.23.1', 'versionType': 'custom'}, {'status': 'affected', 'version': '0', 'lessThan': '2.22.2', 'versionType': 'custom'}, {'status': 'affected', 'version': '0', 'lessThan': '2.21.1', 'versionType': 'custom'}, {'status': 'affected', 'version': '0', 'lessThan': '2.20.2', 'versionType': 'custom'}, {'status': 'affected', 'version': '0', 'lessThan': '2.19.3', 'versionType': 'custom'}, {'status': 'affected', 'version': '0', 'lessThan': '2.18.2', 'versionType': 'custom'}, {'status': 'affected', 'version': '0', 'lessThan': '2.17.3', 'versionType': 'custom'}, {'status': 'affected', 'version': '0', 'lessThan': '2.16.6', 'versionType': 'custom'}, {'status': 'affected', 'version': '0', 'lessThan': '2.15.4', 'versionType': 'custom'}, {'status': 'affected', 'version': '0', 'lessThan': '2.14.6', 'versionType': 'custom'}], 'defaultStatus': 'unknown'}]}], 'published': '2019-12-18T21:15:13.820', 'references': [{'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00056.html', 'source': 'secure@microsoft.com'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00003.html', 'source': 'secure@microsoft.com'}, {'url': 'https://access.redhat.com/errata/RHSA-2019:4356', 'tags': ['Third Party Advisory'], 'source': 'secure@microsoft.com'}, {'url': 'https://access.redhat.com/errata/RHSA-2020:0002', 'source': 'secure@microsoft.com'}, {'url': 'https://access.redhat.com/errata/RHSA-2020:0124', 'source': 'secure@microsoft.com'}, {'url': 'https://access.redhat.com/errata/RHSA-2020:0228', 'source': 'secure@microsoft.com'}, {'url': 'https://lists.debian.org/debian-lts-announce/2020/01/msg00019.html', 'source': 'secure@microsoft.com'}, {'url': 'https://lists.debian.org/debian-lts-announce/2024/06/msg00018.html', 'source': 'secure@microsoft.com'}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N6UGTEOXWIYSM5KDZL74QD2GK6YQNQCP/', 'source': 'secure@microsoft.com'}, {'url': 'https://lore.kernel.org/git/xmqqr21cqcn9.fsf%40gitster-ct.c.googlers.com/T/#u', 'source': 'secure@microsoft.com'}, {'url': 'https://public-inbox.org/git/xmqqr21cqcn9.fsf%40gitster-ct.c.googlers.com/', 'source': 'secure@microsoft.com'}, {'url': 'https://security.gentoo.org/glsa/202003-30', 'source': 'secure@microsoft.com'}, {'url': 'https://security.gentoo.org/glsa/202003-42', 'source': 'secure@microsoft.com'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00056.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00003.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://access.redhat.com/errata/RHSA-2019:4356', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://access.redhat.com/errata/RHSA-2020:0002', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://access.redhat.com/errata/RHSA-2020:0124', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://access.redhat.com/errata/RHSA-2020:0228', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lists.debian.org/debian-lts-announce/2020/01/msg00019.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lists.debian.org/debian-lts-announce/2024/06/msg00018.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lists.debian.org/debian-lts-announce/2024/09/msg00009.html', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N6UGTEOXWIYSM5KDZL74QD2GK6YQNQCP/', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://lore.kernel.org/git/xmqqr21cqcn9.fsf%40gitster-ct.c.googlers.com/T/#u', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://public-inbox.org/git/xmqqr21cqcn9.fsf%40gitster-ct.c.googlers.com/', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://security.gentoo.org/glsa/202003-30', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}, {'url': 'https://security.gentoo.org/glsa/202003-42', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'NVD-CWE-noinfo'}]}], 'descriptions': [{'lang': 'en', 'value': 'An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are currently affected by a vulnerability that is caused by too-lax validation of submodule names, allowing very targeted attacks via remote code execution in recursive clones.'}, {'lang': 'es', 'value': 'Se encontró un problema en Git versiones anteriores a v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4 y v2. 14.6. Los clones recursivos están actualmente afectados por una vulnerabilidad causada por una comprobación too-lax de los nombres de submódulos, permitiendo ataques muy específicos por medio de una ejecución de código remota en clones recursivos.'}], 'lastModified': '2026-06-17T02:28:30.630', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'CD0FE176-63B7-4176-8319-80CD3D7C524E', 'versionEndExcluding': '2.14.6', 'versionStartIncluding': '2.14.0'}, {'criteria': 'cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '7FA79B4D-1A29-4520-ACF7-BBD5B2696ABA', 'versionEndExcluding': '2.15.4', 'versionStartIncluding': '2.15.0'}, {'criteria': 'cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'DB018182-B15F-47BC-85FA-6847BB37844A', 'versionEndExcluding': '2.16.6', 'versionStartIncluding': '2.16.0'}, {'criteria': 'cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '19CF821B-9ECC-4F6C-B0BC-7361370776C5', 'versionEndExcluding': '2.17.3', 'versionStartIncluding': '2.17.0'}, {'criteria': 'cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '84278A89-0D1B-4CFD-9B31-68D8D7327E65', 'versionEndExcluding': '2.18.2', 'versionStartIncluding': '2.18.0'}, {'criteria': 'cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '7B4FA857-692C-4C00-A170-1F31E6D9563E', 'versionEndExcluding': '2.19.3', 'versionStartIncluding': '2.19.0'}, {'criteria': 'cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'BD4C8899-C9E7-4DFC-BE17-D5D67B9B5FFB', 'versionEndExcluding': '2.20.2', 'versionStartIncluding': '2.20.0'}, {'criteria': 'cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '025C10E9-40A6-408C-AE2C-5FC55E788775', 'versionEndExcluding': '2.22.2', 'versionStartIncluding': '2.22.0'}, {'criteria': 'cpe:2.3:a:git-scm:git:2.21.0:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'A2FDF378-11FC-414D-8F4B-04BE6269C49A'}, {'criteria': 'cpe:2.3:a:git-scm:git:2.23.0:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '018467BF-01DC-40EE-99F4-0E8375A615DC'}, {'criteria': 'cpe:2.3:a:git-scm:git:2.24.0:*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'B977B43D-A0F8-4367-8BA4-96C12CF10002'}], 'operator': 'OR'}]}], 'sourceIdentifier': 'secure@microsoft.com'}
CVE-2019-5073
2019-12-18 23:51:48+03:00
2026-06-17 02:37:05.177000+03:00
PUBLISHED
An exploitable information exposure vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause an external tool to fail, resulting in uninitialized stack data to be copied to the response packet buffer. An attacker can send unauthenticated packets to trigger this vulnerability.
MEDIUM
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
[{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0862', 'source': 'talos-cna@cisco.com'}, {'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0862', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:12.293545+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0862', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T19:47:55.738Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'WAGO PFC200', 'versions': [{'status': 'affected', 'version': 'Firmware version 03.01.07(13)'}, {'status': 'affected', 'version': 'Firmware version 03.00.39(12)'}]}, {'vendor': 'n/a', 'product': 'WAGO PFC100', 'versions': [{'status': 'affected', 'version': 'Firmware version 03.00.39(12)'}]}], 'references': [{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0862', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'An exploitable information exposure vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause an external tool to fail, resulting in uninitialized stack data to be copied to the response packet buffer. An attacker can send unauthenticated packets to trigger this vulnerability.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'information exposure'}]}], 'providerMetadata': {'orgId': 'b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b', 'shortName': 'talos', 'dateUpdated': '2019-12-18T20:51:48.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'Firmware version 03.01.07(13)'}, {'version_value': 'Firmware version 03.00.39(12)'}]}, 'product_name': 'WAGO PFC200'}, {'version': {'version_data': [{'version_value': 'Firmware version 03.00.39(12)'}]}, 'product_name': 'WAGO PFC100'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0862', 'name': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0862', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'An exploitable information exposure vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause an external tool to fail, resulting in uninitialized stack data to be copied to the response packet buffer. An attacker can send unauthenticated packets to trigger this vulnerability.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'information exposure'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-5073', 'STATE': 'PUBLIC', 'ASSIGNER': 'talos-cna@cisco.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-5073', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T19:47:55.738Z', 'dateReserved': '2019-01-04T00:00:00.000Z', 'assignerOrgId': 'b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b', 'datePublished': '2019-12-18T20:51:48.000Z', 'assignerShortName': 'talos'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-5073', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 5.0, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:P/I:N/A:N', 'authentication': 'NONE', 'integrityImpact': 'NONE', 'accessComplexity': 'LOW', 'availabilityImpact': 'NONE', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 2.9, 'baseSeverity': 'MEDIUM', 'obtainAllPrivilege': False, 'exploitabilityScore': 10.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}, 'impactScore': 1.4, 'exploitabilityScore': 3.9}]}, 'affected': [{'source': 'talos-cna@cisco.com', 'affectedData': [{'vendor': 'n/a', 'product': 'WAGO PFC200', 'versions': [{'status': 'affected', 'version': 'Firmware version 03.01.07(13)'}, {'status': 'affected', 'version': 'Firmware version 03.00.39(12)'}]}, {'vendor': 'n/a', 'product': 'WAGO PFC100', 'versions': [{'status': 'affected', 'version': 'Firmware version 03.00.39(12)'}]}]}], 'published': '2019-12-18T21:15:13.897', 'references': [{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0862', 'tags': ['Exploit', 'Third Party Advisory'], 'source': 'talos-cna@cisco.com'}, {'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0862', 'tags': ['Exploit', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-200'}]}], 'descriptions': [{'lang': 'en', 'value': 'An exploitable information exposure vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause an external tool to fail, resulting in uninitialized stack data to be copied to the response packet buffer. An attacker can send unauthenticated packets to trigger this vulnerability.'}, {'lang': 'es', 'value': 'Se presenta una vulnerabilidad de exposición a la información explotable en la funcionalidad "I/O-Check" del servicio iocheckd de WAGO PFC 200 versiones de firmware 03.01.07(13) y 03.00.39(12), y WAGO PFC100 versión de firmware 03.00.39(12). Un conjunto de paquetes especialmente diseñado puede causar fallo de una herramienta externa, resultando en que los datos de la pila no inicializados sean copiados en el búfer de paquetes de respuesta. Un atacante puede enviar paquetes no autenticados para activar esta vulnerabilidad.'}], 'lastModified': '2026-06-17T02:37:05.177', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:wago:pfc_200_firmware:03.00.39\\(12\\):*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E2381ABB-66E4-492C-8CB2-9FDFE3601A11'}, {'criteria': 'cpe:2.3:o:wago:pfc_200_firmware:03.01.07\\(13\\):*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '01297381-B7D4-46FB-BFDD-2B5145C5E379'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:wago:pfc_200:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '1A20109A-6CF0-465F-8F97-136DDFB95B2B'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:wago:pfc_100_firmware:03.00.39\\(12\\):*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'C1A0CD98-CC70-4FA2-BFB7-6BC765B05C9B'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:wago:pfc_100:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'CF8E59CE-6A72-49EA-AA44-8714C2411003'}], 'operator': 'OR'}], 'operator': 'AND'}], 'sourceIdentifier': 'talos-cna@cisco.com'}
CVE-2019-5075
2019-12-18 23:51:51+03:00
2026-06-17 02:37:05.383000+03:00
PUBLISHED
An exploitable stack buffer overflow vulnerability exists in the command line utility getcouplerdetails of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets sent to the iocheckd service "I/O-Check" can cause a stack buffer overflow in the sub-process getcouplerdetails, resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability.
CRITICAL
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
[{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0864', 'source': 'talos-cna@cisco.com'}, {'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0864', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:12.785414+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0864', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T19:47:56.306Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'WAGO PFC200', 'versions': [{'status': 'affected', 'version': 'Firmware version 03.01.07(13)'}, {'status': 'affected', 'version': 'Firmware version 03.00.39(12)'}]}, {'vendor': 'n/a', 'product': 'WAGO PFC100', 'versions': [{'status': 'affected', 'version': 'Firmware version 03.00.39(12)'}]}], 'references': [{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0864', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'An exploitable stack buffer overflow vulnerability exists in the command line utility getcouplerdetails of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets sent to the iocheckd service "I/O-Check" can cause a stack buffer overflow in the sub-process getcouplerdetails, resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'stack buffer overflow'}]}], 'providerMetadata': {'orgId': 'b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b', 'shortName': 'talos', 'dateUpdated': '2019-12-18T20:51:51.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'Firmware version 03.01.07(13)'}, {'version_value': 'Firmware version 03.00.39(12)'}]}, 'product_name': 'WAGO PFC200'}, {'version': {'version_data': [{'version_value': 'Firmware version 03.00.39(12)'}]}, 'product_name': 'WAGO PFC100'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0864', 'name': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0864', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'An exploitable stack buffer overflow vulnerability exists in the command line utility getcouplerdetails of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets sent to the iocheckd service "I/O-Check" can cause a stack buffer overflow in the sub-process getcouplerdetails, resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'stack buffer overflow'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-5075', 'STATE': 'PUBLIC', 'ASSIGNER': 'talos-cna@cisco.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-5075', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T19:47:56.306Z', 'dateReserved': '2019-01-04T00:00:00.000Z', 'assignerOrgId': 'b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b', 'datePublished': '2019-12-18T20:51:51.000Z', 'assignerShortName': 'talos'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-5075', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 10.0, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:C/I:C/A:C', 'authentication': 'NONE', 'integrityImpact': 'COMPLETE', 'accessComplexity': 'LOW', 'availabilityImpact': 'COMPLETE', 'confidentialityImpact': 'COMPLETE'}, 'acInsufInfo': False, 'impactScore': 10.0, 'baseSeverity': 'HIGH', 'obtainAllPrivilege': False, 'exploitabilityScore': 10.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 3.9}]}, 'affected': [{'source': 'talos-cna@cisco.com', 'affectedData': [{'vendor': 'n/a', 'product': 'WAGO PFC200', 'versions': [{'status': 'affected', 'version': 'Firmware version 03.01.07(13)'}, {'status': 'affected', 'version': 'Firmware version 03.00.39(12)'}]}, {'vendor': 'n/a', 'product': 'WAGO PFC100', 'versions': [{'status': 'affected', 'version': 'Firmware version 03.00.39(12)'}]}]}], 'published': '2019-12-18T21:15:14.007', 'references': [{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0864', 'tags': ['Exploit', 'Third Party Advisory'], 'source': 'talos-cna@cisco.com'}, {'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0864', 'tags': ['Exploit', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-787'}]}], 'descriptions': [{'lang': 'en', 'value': 'An exploitable stack buffer overflow vulnerability exists in the command line utility getcouplerdetails of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets sent to the iocheckd service "I/O-Check" can cause a stack buffer overflow in the sub-process getcouplerdetails, resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability.'}, {'lang': 'es', 'value': 'Se presenta una vulnerabilidad de desbordamiento del búfer de la pila explotable en la utilidad getcouplerdetails de la línea de comandos de WAGO PFC 200 versiones de firmware 03.01.07(13) y 03.00.39(12), y WAGO PFC100 versión de firmware 03.00.39(12). Un conjunto de paquetes especialmente diseñado enviados a "I/O-Check" del servicio iocheckd puede causar un desbordamiento del búfer de pila en el subproceso getcouplerdetails, resultando en una ejecución de código. Un atacante puede enviar paquetes no autenticados para activar esta vulnerabilidad.'}], 'lastModified': '2026-06-17T02:37:05.383', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:wago:pfc_200_firmware:03.00.39\\(12\\):*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E2381ABB-66E4-492C-8CB2-9FDFE3601A11'}, {'criteria': 'cpe:2.3:o:wago:pfc_200_firmware:03.01.07\\(13\\):*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '01297381-B7D4-46FB-BFDD-2B5145C5E379'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:wago:pfc_200:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '1A20109A-6CF0-465F-8F97-136DDFB95B2B'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:wago:pfc_100_firmware:03.00.39\\(12\\):*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'C1A0CD98-CC70-4FA2-BFB7-6BC765B05C9B'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:wago:pfc_100:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'CF8E59CE-6A72-49EA-AA44-8714C2411003'}], 'operator': 'OR'}], 'operator': 'AND'}], 'sourceIdentifier': 'talos-cna@cisco.com'}
CVE-2019-5078
2019-12-18 23:51:53+03:00
2026-06-17 02:37:05.700000+03:00
PUBLISHED
An exploitable denial of service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a denial of service, resulting in the device entering an error state where it ceases all network communications. An attacker can send unauthenticated packets to trigger this vulnerability.
CRITICAL
9.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
[{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0870', 'source': 'talos-cna@cisco.com'}, {'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0870', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:12.540008+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0870', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T19:47:56.805Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'WAGO PFC200', 'versions': [{'status': 'affected', 'version': 'Firmware version 03.01.07(13)'}, {'status': 'affected', 'version': 'Firmware version 03.00.39(12)'}]}, {'vendor': 'n/a', 'product': 'WAGO PFC100', 'versions': [{'status': 'affected', 'version': 'Firmware version 03.00.39(12)'}]}], 'references': [{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0870', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'An exploitable denial of service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a denial of service, resulting in the device entering an error state where it ceases all network communications. An attacker can send unauthenticated packets to trigger this vulnerability.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'denial of service'}]}], 'providerMetadata': {'orgId': 'b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b', 'shortName': 'talos', 'dateUpdated': '2019-12-18T20:51:53.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'Firmware version 03.01.07(13)'}, {'version_value': 'Firmware version 03.00.39(12)'}]}, 'product_name': 'WAGO PFC200'}, {'version': {'version_data': [{'version_value': 'Firmware version 03.00.39(12)'}]}, 'product_name': 'WAGO PFC100'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0870', 'name': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0870', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'An exploitable denial of service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a denial of service, resulting in the device entering an error state where it ceases all network communications. An attacker can send unauthenticated packets to trigger this vulnerability.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'denial of service'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-5078', 'STATE': 'PUBLIC', 'ASSIGNER': 'talos-cna@cisco.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-5078', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T19:47:56.805Z', 'dateReserved': '2019-01-04T00:00:00.000Z', 'assignerOrgId': 'b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b', 'datePublished': '2019-12-18T20:51:53.000Z', 'assignerShortName': 'talos'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-5078', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 9.4, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:N/I:C/A:C', 'authentication': 'NONE', 'integrityImpact': 'COMPLETE', 'accessComplexity': 'LOW', 'availabilityImpact': 'COMPLETE', 'confidentialityImpact': 'NONE'}, 'acInsufInfo': False, 'impactScore': 9.2, 'baseSeverity': 'HIGH', 'obtainAllPrivilege': False, 'exploitabilityScore': 10.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.1, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}, 'impactScore': 5.2, 'exploitabilityScore': 3.9}]}, 'affected': [{'source': 'talos-cna@cisco.com', 'affectedData': [{'vendor': 'n/a', 'product': 'WAGO PFC200', 'versions': [{'status': 'affected', 'version': 'Firmware version 03.01.07(13)'}, {'status': 'affected', 'version': 'Firmware version 03.00.39(12)'}]}, {'vendor': 'n/a', 'product': 'WAGO PFC100', 'versions': [{'status': 'affected', 'version': 'Firmware version 03.00.39(12)'}]}]}], 'published': '2019-12-18T21:15:14.083', 'references': [{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0870', 'tags': ['Third Party Advisory'], 'source': 'talos-cna@cisco.com'}, {'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0870', 'tags': ['Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-306'}]}], 'descriptions': [{'lang': 'en', 'value': 'An exploitable denial of service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a denial of service, resulting in the device entering an error state where it ceases all network communications. An attacker can send unauthenticated packets to trigger this vulnerability.'}, {'lang': 'es', 'value': 'Se presenta una vulnerabilidad de denegación de servicio explotable en la funcionalidad "I/O-Check" del servicio iocheckd de WAGO PFC 200 versiones de firmware 03.01.07(13) y 03.00.39(12), y WAGO PFC100 versión de firmware 03.00.39(12). Un conjunto de paquetes especialmente diseñado puede causar una denegación de servicio, resultando en que el dispositivo entre en un estado de error donde cesa todas las comunicaciones de red. Un atacante puede enviar paquetes no autenticados para activar esta vulnerabilidad.'}], 'lastModified': '2026-06-17T02:37:05.700', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:wago:pfc_200_firmware:03.00.39\\(12\\):*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E2381ABB-66E4-492C-8CB2-9FDFE3601A11'}, {'criteria': 'cpe:2.3:o:wago:pfc_200_firmware:03.01.07\\(13\\):*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '01297381-B7D4-46FB-BFDD-2B5145C5E379'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:wago:pfc_200:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '1A20109A-6CF0-465F-8F97-136DDFB95B2B'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:wago:pfc_100_firmware:03.00.39\\(12\\):*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'C1A0CD98-CC70-4FA2-BFB7-6BC765B05C9B'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:wago:pfc_100:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'CF8E59CE-6A72-49EA-AA44-8714C2411003'}], 'operator': 'OR'}], 'operator': 'AND'}], 'sourceIdentifier': 'talos-cna@cisco.com'}
CVE-2019-5079
2019-12-18 23:33:07+03:00
2026-06-17 02:37:05.800000+03:00
PUBLISHED
An exploitable heap buffer overflow vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a heap buffer overflow, potentially resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability.
CRITICAL
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
[{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0871', 'source': 'talos-cna@cisco.com'}, {'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0871', 'source': 'af854a3a-2127-422b-91ae-364da2661108'}]
cve.org
2026-05-27 22:18:12.540008+03:00
2026-06-27 08:25:45.686028+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0871', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-04T19:47:56.879Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'WAGO PFC200', 'versions': [{'status': 'affected', 'version': 'Firmware version 03.01.07(13)'}, {'status': 'affected', 'version': 'Firmware version 03.00.39(12)'}]}, {'vendor': 'n/a', 'product': 'WAGO PFC100', 'versions': [{'status': 'affected', 'version': 'Firmware version 03.00.39(12)'}]}], 'references': [{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0871', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'An exploitable heap buffer overflow vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a heap buffer overflow, potentially resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'remote code execution'}]}], 'providerMetadata': {'orgId': 'b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b', 'shortName': 'talos', 'dateUpdated': '2019-12-18T20:33:07.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'Firmware version 03.01.07(13)'}, {'version_value': 'Firmware version 03.00.39(12)'}]}, 'product_name': 'WAGO PFC200'}, {'version': {'version_data': [{'version_value': 'Firmware version 03.00.39(12)'}]}, 'product_name': 'WAGO PFC100'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0871', 'name': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0871', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'An exploitable heap buffer overflow vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a heap buffer overflow, potentially resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'remote code execution'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2019-5079', 'STATE': 'PUBLIC', 'ASSIGNER': 'talos-cna@cisco.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2019-5079', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-04T19:47:56.879Z', 'dateReserved': '2019-01-04T00:00:00.000Z', 'assignerOrgId': 'b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b', 'datePublished': '2019-12-18T20:33:07.000Z', 'assignerShortName': 'talos'}, 'dataVersion': '5.1'}
{'id': 'CVE-2019-5079', 'cveTags': [], 'metrics': {'cvssMetricV2': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'version': '2.0', 'baseScore': 7.5, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:P/I:P/A:P', 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'LOW', 'availabilityImpact': 'PARTIAL', 'confidentialityImpact': 'PARTIAL'}, 'acInsufInfo': False, 'impactScore': 6.4, 'baseSeverity': 'HIGH', 'obtainAllPrivilege': False, 'exploitabilityScore': 10.0, 'obtainUserPrivilege': False, 'obtainOtherPrivilege': False, 'userInteractionRequired': False}], 'cvssMetricV31': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'cvssData': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'impactScore': 5.9, 'exploitabilityScore': 3.9}]}, 'affected': [{'source': 'talos-cna@cisco.com', 'affectedData': [{'vendor': 'n/a', 'product': 'WAGO PFC200', 'versions': [{'status': 'affected', 'version': 'Firmware version 03.01.07(13)'}, {'status': 'affected', 'version': 'Firmware version 03.00.39(12)'}]}, {'vendor': 'n/a', 'product': 'WAGO PFC100', 'versions': [{'status': 'affected', 'version': 'Firmware version 03.00.39(12)'}]}]}], 'published': '2019-12-18T21:15:14.163', 'references': [{'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0871', 'tags': ['Exploit', 'Third Party Advisory'], 'source': 'talos-cna@cisco.com'}, {'url': 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0871', 'tags': ['Exploit', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}], 'vulnStatus': 'Modified', 'weaknesses': [{'type': 'Primary', 'source': 'nvd@nist.gov', 'description': [{'lang': 'en', 'value': 'CWE-787'}]}], 'descriptions': [{'lang': 'en', 'value': 'An exploitable heap buffer overflow vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a heap buffer overflow, potentially resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability.'}, {'lang': 'es', 'value': 'Se presenta una vulnerabilidad de desbordamiento del búfer de la pila explotable en la funcionalidad "I/O-Check" del servicio iocheckd de WAGO PFC 200 versiones de firmware 03.01.07(13) y 03.00.39(12), y WAGO PFC100 versión de firmware 03.00.39(12). Un conjunto de paquetes especialmente diseñado puede causar un desbordamiento del búfer de la pila, resultando potencialmente en una ejecución de código. Un atacante puede enviar paquetes no autenticados para activar esta vulnerabilidad.'}], 'lastModified': '2026-06-17T02:37:05.800', 'configurations': [{'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:wago:pfc_200_firmware:03.00.39\\(12\\):*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'E2381ABB-66E4-492C-8CB2-9FDFE3601A11'}, {'criteria': 'cpe:2.3:o:wago:pfc_200_firmware:03.01.07\\(13\\):*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': '01297381-B7D4-46FB-BFDD-2B5145C5E379'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:wago:pfc_200:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': '1A20109A-6CF0-465F-8F97-136DDFB95B2B'}], 'operator': 'OR'}], 'operator': 'AND'}, {'nodes': [{'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:o:wago:pfc_100_firmware:03.00.39\\(12\\):*:*:*:*:*:*:*', 'vulnerable': True, 'matchCriteriaId': 'C1A0CD98-CC70-4FA2-BFB7-6BC765B05C9B'}], 'operator': 'OR'}, {'negate': False, 'cpeMatch': [{'criteria': 'cpe:2.3:h:wago:pfc_100:-:*:*:*:*:*:*:*', 'vulnerable': False, 'matchCriteriaId': 'CF8E59CE-6A72-49EA-AA44-8714C2411003'}], 'operator': 'OR'}], 'operator': 'AND'}], 'sourceIdentifier': 'talos-cna@cisco.com'}