|
1501
|
5.5
4.3
|
MEDIUM
Local
|
An issue existed in the handling of iMessage tapbacks. The issue was resolved with additional verification. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watch…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2020-9885
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
13.6
|
2024-11-21 14:41
2020-10-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1502
|
7.8
6.8
|
HIGH
Local
|
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. Processing a maliciously…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-9884
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
13.6
|
2024-11-21 14:41
2020-10-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1503
|
7.8
6.8
|
HIGH
Local
|
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. Processing a maliciously craf…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-9878
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
13.6
|
2024-11-21 14:41
2020-10-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1504
|
8.8
6.5
|
HIGH
Network
|
A logic issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8. An attacker with memory write capability may be able to byp…
|
CWE-20
Improper Input Validation
|
CVE-2020-9870
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
13.6
|
2024-11-21 14:41
2020-10-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1505
|
8.6
6.8
|
HIGH
Local
|
A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A malicious application m…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-9865
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
13.6
|
2024-11-21 14:41
2020-10-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1506
|
7.8
6.8
|
HIGH
Local
|
A command injection issue existed in Web Inspector. This issue was addressed with improved escaping. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes…
|
CWE-77 CWE-116
Command Injection Improper Encoding or Escaping of Output
|
CVE-2020-9862
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
13.6
|
2024-11-21 14:41
2020-10-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1507
|
5.5
2.1
|
MEDIUM
Local
|
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6. A local user may…
|
NVD-CWE-noinfo
|
CVE-2020-9934
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
13.6
|
2025-02-28 23:44
2020-10-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1508
|
7.8
9.3
|
HIGH
Local
|
A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8. An application may be able to execute arbitrary code with kernel…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-9907
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
13.6
|
2025-02-28 23:44
2020-10-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1509
|
6.5
4.3
|
MEDIUM
Network
|
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.
|
CWE-200
Information Exposure
|
CVE-2020-6514
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
13.6
|
2024-11-21 14:35
2020-07-23
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1510
|
5.5
2.1
|
MEDIUM
Local
|
In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-15358
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
14.0
|
2024-11-21 14:05
2020-06-27
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|