|
1551
|
8.8
6.8
|
HIGH
Network
|
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5. Processing a maliciously crafted mail message may…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-9818
|
cpe:2.3:o:apple:iphone_os:*:*
|
13.0
|
|
|
12.4.7 13.5
|
2025-02-28 23:44
2020-06-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1552
|
4.6
2.1
|
MEDIUM
Physics
|
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5. A USB device may be able to cause a denial of service.
|
CWE-20
Improper Input Validation
|
CVE-2020-9792
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
13.5
|
2024-11-21 14:41
2020-06-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1553
|
7.8
7.2
|
HIGH
Local
|
A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5 Supplemental Update, tvOS 13.4.6, watchOS 6.2.6. An…
|
CWE-415
Double Free
|
CVE-2020-9859
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
13.5.1
|
2025-02-28 23:44
2020-06-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1554
|
5.5
2.1
|
MEDIUM
Local
|
SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.
|
NVD-CWE-noinfo
|
CVE-2020-13631
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
14.0
|
2024-11-21 14:01
2020-05-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1555
|
7.0
4.4
|
HIGH
Local
|
ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.
|
CWE-416
Use After Free
|
CVE-2020-13630
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
14.0
|
2024-11-21 14:01
2020-05-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1556
|
5.5
2.1
|
MEDIUM
Local
|
SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-13434
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
14.0
|
2024-11-21 14:01
2020-05-25
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1557
|
6.5
3.3
|
MEDIUM
Adjacent
|
Some Broadcom chips mishandle Bluetooth random-number generation because a low-entropy Pseudo Random Number Generator (PRNG) is used in situations where a Hardware Random Number Generator (HRNG) shou…
|
NVD-CWE-noinfo
|
CVE-2020-6616
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
13.5
|
2024-11-21 14:36
2020-05-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1558
|
9.8
7.5
|
CRITICAL
Network
|
A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2. An attacker in a privileged network position may be able to intercept net…
|
NVD-CWE-noinfo
|
CVE-2019-6203
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
12.2
|
2024-11-21 13:46
2020-04-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1559
|
5.5
4.3
|
MEDIUM
Local
|
An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier, leading to an out-of-bounds read.
|
CWE-125 CWE-193
Out-of-bounds Read Off-by-one Error
|
CVE-2020-11765
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
13.6
|
2024-11-21 13:58
2020-04-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1560
|
5.5
4.3
|
MEDIUM
Local
|
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuffer in ImfMisc.cpp.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-11764
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
13.6
|
2024-11-21 13:58
2020-04-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|