Vulnerability Name: | CVE-2019-8746 (CCN-171276) | ||||||||||||
Assigned: | 2019-07-29 | ||||||||||||
Published: | 2019-07-29 | ||||||||||||
Updated: | 2020-10-29 | ||||||||||||
Summary: | An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15, iOS 13, iCloud for Windows 7.14, iCloud for Windows 10.7, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, watchOS 6, iTunes 12.10.1 for Windows. A remote attacker may be able to cause unexpected application termination or arbitrary code execution. | ||||||||||||
CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-125 | ||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-8746 Source: CCN Type: Google Security Research Issue 1918 iMessage: decoding NSSharedKeyDictionary can lead to out-of-bounds reads Source: XF Type: UNKNOWN apple-cve20198746-dos(171276) Source: MISC Type: Vendor Advisory https://support.apple.com/en-us/HT210604 Source: MISC Type: Vendor Advisory https://support.apple.com/en-us/HT210606 Source: MISC Type: Vendor Advisory https://support.apple.com/en-us/HT210607 Source: MISC Type: Vendor Advisory https://support.apple.com/en-us/HT210634 Source: MISC Type: Vendor Advisory https://support.apple.com/en-us/HT210635 Source: MISC Type: Vendor Advisory https://support.apple.com/en-us/HT210636 Source: MISC Type: Vendor Advisory https://support.apple.com/en-us/HT210637 Source: MISC Type: Vendor Advisory https://support.apple.com/en-us/HT210722 Source: CCN Type: Apple Web site Apple | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
BACK |