|
1561
|
5.5
4.3
|
MEDIUM
Local
|
An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and write, as demonstrated by ImfTileOffsets.cpp.
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2020-11763
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
13.6
|
2024-11-21 13:58
2020-04-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1562
|
5.5
4.3
|
MEDIUM
Local
|
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read and write in DwaCompressor::uncompress in ImfDwaCompressor.cpp when handling the UNKNOWN compression case.
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2020-11762
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
13.6
|
2024-11-21 13:58
2020-04-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1563
|
5.5
4.3
|
MEDIUM
Local
|
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncompression, as demonstrated by FastHufDecoder::refill in ImfFastHuf.cpp.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-11761
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
13.6
|
2024-11-21 13:58
2020-04-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1564
|
5.5
4.3
|
MEDIUM
Local
|
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompression in rleUncompress in ImfRle.cpp.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-11760
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
13.6
|
2024-11-21 13:58
2020-04-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1565
|
5.5
4.3
|
MEDIUM
Local
|
An issue was discovered in OpenEXR before 2.4.1. Because of integer overflows in CompositeDeepScanLine::Data::handleDeepFrameBuffer and readSampleCountForLineBlock, an attacker can write to an out-of…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-11759
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
13.6
|
2024-11-21 13:58
2020-04-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1566
|
5.5
4.3
|
MEDIUM
Local
|
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read in ImfOptimizedPixelReading.h.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-11758
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
13.6
|
2024-11-21 13:58
2020-04-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1567
|
7.8
9.3
|
HIGH
Local
|
Multiple memory corruption issues were addressed with improved state management. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. A malicious applicati…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-9785
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
13.4
|
2024-11-21 14:41
2020-04-2
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1568
|
8.8
6.8
|
HIGH
Network
|
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, i…
|
CWE-416
Use After Free
|
CVE-2020-9783
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
13.4
|
2024-11-21 14:41
2020-04-2
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1569
|
5.3
5.0
|
MEDIUM
Network
|
The issue was addressed by clearing website permission prompts after navigation. This issue is fixed in iOS 13.4 and iPadOS 13.4. A user may grant website permissions to a site they didn't intend to.
|
CWE-281
Improper Preservation of Permissions
|
CVE-2020-9781
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
13.4
|
2024-11-21 14:41
2020-04-2
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1570
|
3.3
2.1
|
LOW
Local
|
The issue was resolved by clearing application previews when content is deleted. This issue is fixed in iOS 13.4 and iPadOS 13.4. A local user may be able to view deleted content in the app switcher.
|
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer
|
CVE-2020-9780
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
13.4
|
2024-11-21 14:41
2020-04-2
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|