|
1351
|
7.8
4.6
|
HIGH
Local
|
An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 1…
|
CWE-59
Link Following
|
CVE-2020-10003
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
14.2
|
2024-11-21 13:54
2020-12-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1352
|
5.5
2.1
|
MEDIUM
Local
|
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, tvOS 14.2, iTunes 12.11 for Wi…
|
NVD-CWE-noinfo
|
CVE-2020-10002
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
14.2
|
2024-11-21 13:54
2020-12-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1353
|
7.8
6.8
|
HIGH
Local
|
A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. This instance exists in the USDC file format FIELDS section decompression…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-6147
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
14.0
|
2024-11-21 14:35
2020-11-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1354
|
8.8
6.8
|
HIGH
Network
|
Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-787 CWE-416
Out-of-bounds Write Use After Free
|
CVE-2020-15969
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
14.3
|
2024-11-21 14:06
2020-11-3
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1355
|
5.5
2.1
|
MEDIUM
Local
|
A trust issue was addressed by removing a legacy API. This issue is fixed in iOS 14.0 and iPadOS 14.0, tvOS 14.0. An attacker may be able to misuse a trust relationship to download malicious content.
|
NVD-CWE-Other
|
CVE-2020-9979
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
14.0
|
2024-11-21 14:41
2020-10-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1356
|
7.8
9.3
|
HIGH
Local
|
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave, iOS 14.0 and i…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-9973
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
14.0
|
2024-11-21 14:41
2020-10-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1357
|
7.8
6.8
|
HIGH
Local
|
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave. Processing a …
|
CWE-125
Out-of-bounds Read
|
CVE-2020-9961
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
14.0
|
2024-11-21 14:41
2020-10-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1358
|
7.5
5.0
|
HIGH
Network
|
This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave. A remote attacker may be able to u…
|
NVD-CWE-noinfo
|
CVE-2020-9941
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
14.0
|
2024-11-21 14:41
2020-10-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1359
|
8.8
6.8
|
HIGH
Network
|
A memory corruption issue was addressed with improved validation. This issue is fixed in Safari 13.0.1, iOS 13.1 and iPadOS 13.1, tvOS 13. Processing maliciously crafted web content may lead to arbit…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-9932
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
13.1
|
2024-11-21 14:41
2020-10-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1360
|
7.8
9.3
|
HIGH
Local
|
An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 6.1.2, iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, macOS Catalina 10.15.3, Security Update 2020-001 M…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-3880
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
13.3.1
|
2024-11-21 14:31
2020-10-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|