5.5
    Medium

    CVE-2019-8656

    Last Modified: 21 Nov 2024

    This was addressed with additional checks by Gatekeeper on files mounted through a network share. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra. Extracting a zip file containing a symbolic link to an endpoint in an NFS mount that is attacker controlled may bypass Gatekeeper.

    Published:27 Oct 2020
    6.1
    Medium

    CVE-2019-8649

    Last Modified: 25 Jul 2019

    A logic issue existed in the handling of synchronous page loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to universal cross site scripting.

    Source:Google Security Research
    Published:29 Aug 2019
    9.8
    Critical

    CVE-2019-8647

    Last Modified: 30 Jul 2019

    A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.4, tvOS 12.4, watchOS 5.3. A remote attacker may be able to cause arbitrary code execution.

    Source:Google Security Research
    Published:18 Dec 2019
    7.5
    High

    CVE-2019-8646

    Last Modified: 30 Jul 2019

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. A remote attacker may be able to leak memory.

    Source:Google Security Research
    Published:18 Dec 2019
    9.8
    Critical

    CVE-2019-8641

    Last Modified: 24 Sept 2019

    An out-of-bounds read was addressed with improved input validation.

    Source:Google Security Research
    Published:18 Dec 2019
    Unknown

    CVE-2019-8627

    https://github.com/maldiohead/CVE-2019-8627

    7.5
    High

    CVE-2019-8624

    Last Modified: 24 Jul 2019

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 5.3. A remote attacker may be able to leak memory.

    Source:Google Security Research
    Published:18 Dec 2019
    8.8
    High

    CVE-2019-8623

    Last Modified: 21 May 2019

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.

    Source:Google Security Research
    Published:20 May 2019
    8.8
    High

    CVE-2019-8622

    Last Modified: 21 May 2019

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.

    Source:Google Security Research
    Published:20 May 2019
    9.8
    Critical

    CVE-2019-8613

    Last Modified: 23 May 2019

    A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, tvOS 12.3, watchOS 5.2.1. A remote attacker may be able to cause arbitrary code execution.

    Source:Google Security Research
    Published:18 Dec 2019
    8.8
    High

    CVE-2019-8611

    Last Modified: 21 May 2019

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.

    Source:Google Security Research
    Published:20 May 2019
    7.8
    High

    CVE-2019-8605

    Last Modified: 18 Jun 2020

    A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to execute arbitrary code with system privileges.

    Source:Umang Raghuvanshi
    Published:18 Dec 2019
    8.8
    High

    CVE-2019-8601

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published:20 May 2019
    7.1
    High

    CVE-2019-8591

    Last Modified: 21 May 2019

    A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. An application may be able to cause unexpected system termination or write kernel memory.

    Source:Google Security Research
    Published:18 Dec 2019
    7
    High

    CVE-2019-8565

    Last Modified: 23 May 2019

    A race condition was addressed with additional validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4. A malicious application may be able to gain root privileges.

    Source:Metasploit
    Published:18 Dec 2019
    7.8
    High

    CVE-2019-8561

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved validation. This issue is fixed in macOS Mojave 10.14.4. A malicious application may be able to elevate privileges.

    Published:18 Dec 2019
    8.8
    High

    CVE-2019-8558

    Last Modified: 3 Apr 2019

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.

    Source:Google Security Research
    Published:10 Apr 2019
    5.5
    Medium

    CVE-2019-8540

    Last Modified: 21 Nov 2024

    A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to determine kernel memory layout.

    Published:18 Dec 2019
    8.8
    High

    CVE-2019-8518

    Last Modified: 3 Apr 2019

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.

    Source:Google Security Research
    Published:10 Apr 2019
    7.8
    High

    CVE-2019-8514

    Last Modified: 3 Apr 2019

    A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. An application may be able to gain elevated privileges.

    Source:Google Security Research
    Published:18 Dec 2019
    7.8
    High

    CVE-2019-8513

    Last Modified: 2 Jul 2019

    This issue was addressed with improved checks. This issue is fixed in macOS Mojave 10.14.4. A local user may be able to execute arbitrary shell commands.

    Source:Metasploit
    Published:18 Dec 2019
    8.8
    High

    CVE-2019-8506

    Last Modified: 3 Apr 2019

    A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.

    Source:Google Security Research
    Published:10 Apr 2019
    7.8
    High

    CVE-2019-8452

    Last Modified: 7 Oct 2019

    A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point Endpoint Security client for Windows before E80.96 to any file on the system will get its permission changed so that all users can access that linked file. Doing this on files with limited access gains the local attacker higher privileges to the file.

    Source:Jakub Palaczynski
    Published:22 Apr 2019
    6.5
    Medium

    CVE-2019-8451

    Last Modified: 21 Nov 2024

    The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class.

    Published:11 Sept 2019
    5.3
    Medium

    CVE-2019-8449

    Last Modified: 3 Feb 2020

    The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability.

    Source:Mufeed VH
    Published:11 Sept 2019
    6.5
    Medium

    CVE-2019-8404

    Last Modified: 18 Feb 2019

    An issue was discovered in Webiness Inventory 2.3. The ProductModel component allows Arbitrary File Upload via a crafted product image during the creation of a new product. Consequently, an attacker can steal information from the site with the help of an installed executable file, or change the contents of pages.

    Source:Mehmet EMIROGLU
    Published:14 May 2019
    7.5
    High

    CVE-2019-8394

    Last Modified: 18 Feb 2019

    Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.

    Source:Dao Duy Hung
    Published:17 Feb 2019
    6.1
    Medium

    CVE-2019-8391

    Last Modified: 18 Feb 2019

    qdPM 9.1 suffers from Cross-site Scripting (XSS) via configuration?type=[XSS] parameter.

    Source:Mehmet EMIROGLU
    Published:14 May 2019
    6.1
    Medium

    CVE-2019-8390

    Last Modified: 18 Feb 2019

    qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter.

    Source:Mehmet EMIROGLU
    Published:14 May 2019
    8.1
    High

    CVE-2019-8389

    Last Modified: 21 Nov 2024

    A file-read vulnerability was identified in the Wi-Fi transfer feature of Musicloud 1.6. By default, the application runs a transfer service on port 8080, accessible by everyone on the same Wi-Fi network. An attacker can send the POST parameters downfiles and cur-folder (with a crafted ../ payload) to the download.script endpoint. This will create a MusicPlayerArchive.zip archive that is publicly accessible and includes the content of any requested file (such as the /etc/passwd file).

    Published:17 Feb 2019
    9.8
    Critical

    CVE-2019-8387

    Last Modified: 18 Feb 2019

    MASTER IPCAMERA01 3.3.4.2103 devices allow Remote Command Execution, related to the thttpd component.

    Source:Raffaele Sabato
    Published:8 May 2019
    9.8
    Critical

    CVE-2019-8385

    Last Modified: 28 Mar 2019

    An issue was discovered in Thomson Reuters Desktop Extensions 1.9.0.358. An unauthenticated directory traversal and local file inclusion vulnerability in the ThomsonReuters.Desktop.Service.exe and ThomsonReuters.Desktop.exe allows a remote attacker to list or enumerate sensitive contents of files via a \.. to port 6677. Additionally, this could allow for privilege escalation by dumping the affected machine's SAM and SYSTEM database files, as well as remote code execution.

    Source:0v3rride
    Published:5 Jun 2019
    9.8
    Critical

    CVE-2019-8375

    Last Modified: 28 Feb 2019

    The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script dialog size from exceeding the web view size, which allows remote attackers to cause a denial of service (Buffer Overflow) or possibly have unspecified other impact, related to UIProcess/API/gtk/WebKitScriptDialogGtk.cpp, UIProcess/API/gtk/WebKitScriptDialogImpl.cpp, and UIProcess/API/gtk/WebKitWebViewGtk.cpp, as demonstrated by GNOME Web (aka Epiphany).

    Source:Dhiraj Mishra
    Published:24 Feb 2019
    9.8
    Critical

    CVE-2019-8352

    Last Modified: 7 Jun 2019

    By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network to managed PATROL Agent services. If an attacker were able to capture this network traffic, they could decrypt these credentials and use them to execute code or escalate privileges on the network.

    Source:Metasploit
    Published:20 May 2019
    9.8
    Critical

    CVE-2019-8341

    Last Modified: 15 Feb 2019

    An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" parameter as a template object, renders it, and then returns it. The attacker can exploit it with {{INJECTION COMMANDS}} in a URI. NOTE: The maintainer and multiple third parties believe that this vulnerability isn't valid because users shouldn't use untrusted templates without sandboxing

    Source:JameelNabbo
    Published:14 Feb 2019
    6.1
    Medium

    CVE-2019-8331

    Last Modified: 21 Nov 2024

    In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.

    Published:11 Feb 2019
    9.8
    Critical

    CVE-2019-8197

    Last Modified: 21 Oct 2019

    Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .

    Source:Google Security Research
    Published:17 Oct 2019
    9.8
    Critical

    CVE-2019-8196

    Last Modified: 11 Nov 2019

    Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution .

    Source:Google Security Research
    Published:17 Oct 2019
    9.8
    Critical

    CVE-2019-8195

    Last Modified: 11 Nov 2019

    Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution .

    Source:Google Security Research
    Published:17 Oct 2019
    9.8
    Critical

    CVE-2019-8050

    Last Modified: 15 Aug 2019

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .

    Source:Google Security Research
    Published:20 Aug 2019
    9.8
    Critical

    CVE-2019-8049

    Last Modified: 15 Aug 2019

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .

    Source:Google Security Research
    Published:20 Aug 2019
    9.8
    Critical

    CVE-2019-8048

    Last Modified: 15 Aug 2019

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution .

    Source:Google Security Research
    Published:20 Aug 2019
    9.8
    Critical

    CVE-2019-8046

    Last Modified: 15 Aug 2019

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .

    Source:Google Security Research
    Published:20 Aug 2019
    9.8
    Critical

    CVE-2019-8045

    Last Modified: 15 Aug 2019

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution .

    Source:Google Security Research
    Published:20 Aug 2019
    9.8
    Critical

    CVE-2019-8044

    Last Modified: 15 Aug 2019

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a double free vulnerability. Successful exploitation could lead to arbitrary code execution .

    Source:Google Security Research
    Published:20 Aug 2019
    7.5
    High

    CVE-2019-8043

    Last Modified: 15 Aug 2019

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

    Source:Google Security Research
    Published:20 Aug 2019
    9.8
    Critical

    CVE-2019-8042

    Last Modified: 15 Aug 2019

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .

    Source:Google Security Research
    Published:20 Aug 2019
    9.8
    Critical

    CVE-2019-8041

    Last Modified: 15 Aug 2019

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .

    Source:Google Security Research
    Published:20 Aug 2019
    9.8
    Critical

    CVE-2019-8024

    Last Modified: 15 Aug 2019

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

    Source:Google Security Research
    Published:20 Aug 2019
    9.8
    Critical

    CVE-2019-8017

    Last Modified: 15 Aug 2019

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution .

    Source:Google Security Research
    Published:20 Aug 2019