Vulnerabilities
Vulnerable Software
Apple:  >> Watchos  >> 5.2.1  Security Vulnerabilities
A denial of service issue was addressed with improved validation. This issue is fixed in iOS 12.4, watchOS 5.3. A remote attacker may cause an unexpected application termination.
CVSS Score
7.5
EPSS Score
0.017
Published
2019-12-18
An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 5.3. A remote attacker may be able to leak memory.
CVSS Score
7.5
EPSS Score
0.069
Published
2019-12-18
An out-of-bounds read was addressed with improved input validation.
CVSS Score
9.8
EPSS Score
0.17
Published
2019-12-18
expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed, and each affected application would need its own CVE.
CVSS Score
6.8
EPSS Score
0.194
Published
2014-01-21


Contact Us

Shodan ® - All rights reserved