CVE-2019-8549
Severity CVSS v4.0: 
            Pending analysis
                                                    Type: 
          
                          CWE-20
                        Input Validation
          
        Publication date: 
                          18/12/2019
                  Last modified: 
                          30/12/2019
                  Description
Multiple input validation issues existed in MIG generated code. These issues were addressed with improved validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to execute arbitrary code with system privileges.
              Impact
Base Score 3.x
          7.80
        Severity 3.x
          HIGH
        Base Score 2.0
          9.30
        Severity 2.0
          HIGH
        Vulnerable products and versions
| CPE | From | Up to | 
|---|---|---|
| cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | 12.2 (excluding) | |
| cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | 10.14.4 (excluding) | |
| cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | 12.2 (excluding) | |
| cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* | 5.2 (excluding) | 
To consult the complete list of CPE names with products and versions, see this page



