Month | Quarter | Year |
---|---|---|
#26 | #18 | #18 |
CVE-ID | CWE-ID | Type | Score |
---|---|---|---|
CVE-2019-6211 | CWE-119 | Buffer Errors | 8.8 |
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3. Processing maliciously crafted web content may lead to arbitrary code execution. |
|||
CVE-2019-6210 | CWE-119 | Buffer Errors | 7.8 |
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to execute arbitrary code with kernel privileges. |
|||
CVE-2019-6209 | CWE-125 | Out-of-bounds Read | 5.5 |
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to determine kernel memory layout. |
|||
CVE-2019-6208 | CWE-399 | Resource Management Errors | 5.5 |
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A malicious application may cause unexpected changes in memory shared between processes. |
|||
CVE-2019-6206 | CWE-255 | Credentials Management | 9.8 |
An issue existed with autofill resuming after it was canceled. The issue was addressed with improved state management. This issue is fixed in iOS 12.1.3. Password autofill may fill in passwords after they were manually cleared. |
|||
CVE-2019-6205 | CWE-119 | Buffer Errors | 7.8 |
A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A malicious application may cause unexpected changes in memory shared between processes. |
|||
CVE-2019-6202 | CWE-125 | Out-of-bounds Read | 7.8 |
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, watchOS 5.1.3. A malicious application may be able to elevate privileges. |
|||
CVE-2019-6200 | CWE-125 | Out-of-bounds Read | 8.8 |
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3. An attacker in a privileged network position may be able to execute arbitrary code. |
|||
CVE-2018-5383 | CWE-310 | Cryptographic Issues | 6.8 |
Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used to generate public keys during a Diffie-Hellman key exchange, which may allow a remote attacker to obtain the encryption key used by the device. |
|||
CVE-2018-4465 | CWE-119 | Buffer Errors | 7.8 |
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2. |