Show filters
246 Total Results
Displaying 141-150 of 246
Sort by:
Attacker Value
Unknown

CVE-2019-8764

Disclosure Date: December 18, 2019 (last updated November 27, 2024)
A logic issue was addressed with improved state management. This issue is fixed in watchOS 6.1. Processing maliciously crafted web content may lead to universal cross site scripting.
Attacker Value
Unknown

CVE-2019-8625

Disclosure Date: December 18, 2019 (last updated November 27, 2024)
A logic issue was addressed with improved state management. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing maliciously crafted web content may lead to universal cross site scripting.
Attacker Value
Unknown

CVE-2019-8719

Disclosure Date: December 18, 2019 (last updated November 27, 2024)
A logic issue was addressed with improved state management. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing maliciously crafted web content may lead to universal cross site scripting.
Attacker Value
Unknown

CVE-2019-8813

Disclosure Date: December 18, 2019 (last updated November 27, 2024)
A logic issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to universal cross site scripting.
Attacker Value
Unknown

CVE-2019-11070

Disclosure Date: April 10, 2019 (last updated November 08, 2023)
WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (HLS, DASH, or Smooth Streaming), an error resulting in deanonymization. This issue was corrected by changing the way livestreams are downloaded.
0
Attacker Value
Unknown

CVE-2019-6234

Disclosure Date: March 05, 2019 (last updated November 27, 2024)
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution.
0
Attacker Value
Unknown

CVE-2019-8375

Disclosure Date: February 24, 2019 (last updated November 27, 2024)
The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script dialog size from exceeding the web view size, which allows remote attackers to cause a denial of service (Buffer Overflow) or possibly have unspecified other impact, related to UIProcess/API/gtk/WebKitScriptDialogGtk.cpp, UIProcess/API/gtk/WebKitScriptDialogImpl.cpp, and UIProcess/API/gtk/WebKitWebViewGtk.cpp, as demonstrated by GNOME Web (aka Epiphany).
0
Attacker Value
Unknown

CVE-2019-6251

Disclosure Date: January 14, 2019 (last updated November 08, 2023)
WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.
0
Attacker Value
Unknown

CVE-2018-4210

Disclosure Date: January 11, 2019 (last updated November 08, 2023)
In iOS before 11.3, Safari before 11.1, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, an array indexing issue existed in the handling of a function in javascript core. This issue was addressed with improved checks.
0
Attacker Value
Unknown

CVE-2018-4213

Disclosure Date: January 11, 2019 (last updated November 08, 2023)
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.
0