CVE-2019-8617
https://notcve.org/view.php?id=CVE-2019-8617
18 Dec 2019 — An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 12.3. A sandboxed process may be able to circumvent sandbox restrictions. Un problema de acceso fue abordado con restricciones de sandbox adicionales. Este problema es corregido en iOS versión 12.3. • https://support.apple.com/HT210118 •
CVE-2019-8554
https://notcve.org/view.php?id=CVE-2019-8554
18 Dec 2019 — A permissions issue existed in the handling of motion and orientation data. This issue was addressed with improved restrictions. This issue is fixed in iOS 12.2. A website may be able to access sensor information without user consent. Se presentó un problema de permisos en el manejo de datos de movimiento y orientación. • https://support.apple.com/HT209599 •
CVE-2019-8550
https://notcve.org/view.php?id=CVE-2019-8550
18 Dec 2019 — An issue existed in the pausing of FaceTime video. The issue was resolved with improved logic. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, watchOS 5.2. A user’s video may not be paused in a FaceTime call if they exit the FaceTime app while the call is ringing. Hubo un problema en la pausa del video FaceTime. • https://support.apple.com/HT209599 • CWE-459: Incomplete Cleanup •
CVE-2019-8841
https://notcve.org/view.php?id=CVE-2019-8841
14 Dec 2019 — An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.3 and iPadOS 13.3. An application may be able to execute arbitrary code with kernel privileges. Se abordó un problema de divulgación de información al eliminar el código vulnerable. Este problema se corrigió en iOS versión 13.3 y iPadOS versión 13.3. • https://support.apple.com/en-us/HT210785 •
CVE-2019-8857
https://notcve.org/view.php?id=CVE-2019-8857
14 Dec 2019 — The issue was addressed with improved validation when an iCloud Link is created. This issue is fixed in iOS 13.3 and iPadOS 13.3. Live Photo audio and video data may be shared via iCloud links even if Live Photo is disabled in the Share Sheet carousel. El problema se abordó con comprobación mejorada cuando un Enlace de iCloud es creado. Este problema se corrigió en iOS versión 13.3 y iPadOS versión 13.3. • https://support.apple.com/en-us/HT210785 • CWE-20: Improper Input Validation •
CVE-2019-8846 – webkitgtk: Use after free issue may lead to remote code execution
https://notcve.org/view.php?id=CVE-2019-8846
12 Dec 2019 — A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 13.3, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafted web content may lead to arbitrary code execution. Se abordó un problema de uso de la memoria previamente liberada con una administración de la memoria mejorada. Este problema se corrigió en tvOS versión 13.3, iCloud para Windows versión 10.9, iOS versió... • https://support.apple.com/en-us/HT210785 • CWE-416: Use After Free •
CVE-2019-8835 – Apple macOS apfs Use-After-Free Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2019-8835
12 Dec 2019 — Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13.3, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafted web content may lead to arbitrary code execution. Se abordó múltiples problemas de corrupción de memoria con un manejo de la memoria mejorada. Este problema se corrigió en tvOS versión 13.3, iCloud para Windows versión 10.9, iOS versión 13.3 y... • https://support.apple.com/en-us/HT210785 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-787: Out-of-bounds Write •
CVE-2019-8828
https://notcve.org/view.php?id=CVE-2019-8828
12 Dec 2019 — A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, tvOS 13.3. An application may be able to execute arbitrary code with kernel privileges. Se abordó un problema de corrupción de la memoria con un manejo de la memoria mejorada. Este problema se corrigió en iOS versión 13.3 y iPadOS versión 13.3, watchOS versión 6.1.1, macOS... • https://support.apple.com/en-us/HT210785 • CWE-787: Out-of-bounds Write •
CVE-2019-8856
https://notcve.org/view.php?id=CVE-2019-8856
12 Dec 2019 — An API issue existed in the handling of outgoing phone calls initiated with Siri. This issue was addressed with improved state handling. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. Calls made using Siri may be initiated using the wrong cellular plan on devices with two active plans. Se presentó un problema de la API en el manejo de llamadas telefónicas salientes iniciadas con Siri. • https://support.apple.com/en-us/HT210785 •
CVE-2019-8844 – webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution
https://notcve.org/view.php?id=CVE-2019-8844
12 Dec 2019 — Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafted web content may lead to arbitrary code execution. Se abordó múltiples problemas de corrupción de memoria con un manejo de la memoria mejorada. Este problema se corrigió en tvOS versión 13.3, watchOS versión 6.1.1, iCloud para Wi... • https://support.apple.com/en-us/HT210785 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-787: Out-of-bounds Write •