CVE-2019-8686
Summary
| CVE | CVE-2019-8686 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-12-18 18:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution. |
Risk And Classification
Problem Types: CWE-787 | CWE-416
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apple | Icloud | All | All | All | All |
| Application | Apple | Icloud | All | All | All | All |
| Operating System | Apple | Iphone Os | All | All | All | All |
| Operating System | Apple | Iphone Os | All | All | All | All |
| Application | Apple | Itunes | All | All | All | All |
| Application | Apple | Itunes | All | All | All | All |
| Operating System | Apple | Mac Os X | All | All | All | All |
| Operating System | Apple | Mac Os X | All | All | All | All |
| Application | Apple | Safari | All | All | All | All |
| Application | Apple | Safari | All | All | All | All |
| Operating System | Apple | Tvos | All | All | All | All |
| Operating System | Apple | Tvos | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| About the security content of iTunes 12.9.6 for Windows - Apple Support | MISC | support.apple.com | Vendor Advisory |
| Acerca del contenido de seguridad de Safari 12.1.2 - Soporte técnico de Apple | MISC | support.apple.com | Vendor Advisory |
| About the security content of macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra - Apple Support | MISC | support.apple.com | Vendor Advisory |
| About the security content of iOS 12.4 - Apple Support | MISC | support.apple.com | Vendor Advisory |
| About the security content of tvOS 12.4 - Apple Support | MISC | support.apple.com | Vendor Advisory |
| About the security content of iCloud for Windows 10.6 - Apple Support | MISC | support.apple.com | Vendor Advisory |
| About the security content of iCloud for Windows 7.13 - Apple Support | MISC | support.apple.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 296078 Oracle Solaris 11.4 Support Repository Update (SRU) 16.4.0 Missing (CPUOCT2019)
- 377553 Alibaba Cloud Linux Security Update for webkitgtk4 (ALINUX2-SA-2020:0147)
- 501284 Alpine Linux Security Update for webkit2gtk
- 505505 Alpine Linux Security Update for webkit2gtk
- 710127 Gentoo Linux WebkitGTK+ Multiple vulnerabilities (GLSA 201909-05)
- 940366 AlmaLinux Security Update for GNOME (ALSA-2019:3553)
- 960235 Rocky Linux Security Update for GNOME (RLSA-2019:3553)