CVE-2019-10038 describes a critical vulnerability in Evernote 7.9 on macOS, allowing attackers to execute arbitrary local programs through path traversal by embedding references to executable files. This vulnerability carries a CVSS score of 7.8 (High), indicating a high impact on confidentiality, integrity, and availability, with user interaction required for exploitation. While not listed on the KEV catalog, an ExploitDB entry (EDB-46724) confirms exploit code availability, and the vulnerability has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.9CPE matchmatch criteria | cpe:2.3:a:evernote:evernote:7.9:*:*:*:*:macos:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.