CVE-2019-8587
Vulnerability Summary
Timeline
Description
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.
CVSS Metrics
- v3.1•HIGH•Score: 8.8CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- v2.0•MEDIUM•Score: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS Trends
Current EPSS score: 0.81%• Percentile: 74%
Techniques & Countermeasures
- CWE-129•Improper Validation of Array Index
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
- CWE-787•Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Affected Systems
- apple•icloud
< 7.12 | ≥ 10.0, < 10.4
- apple•icloud for windows
≥ unspecified, < iCloud for Windows 7.12
- Unknown•iOS
≥ unspecified, < iOS 12.3
- apple•iphone_os
< 12.3
- apple•itunes
< 12.9.5
- apple•itunes for windows
≥ unspecified, < iTunes for Windows 12.9.5
- apple•mac_os_x
< 10.14.5
- apple•macos
≥ unspecified, < macOS Mojave 10.14.5
- apple•safari
< 12.1.1 | ≥ unspecified, < Safari 12.1.1
- apple•tvos
< 12.3 | ≥ unspecified, < tvOS 12.3