|
197371
|
5.5 |
MEDIUM
Local
|
apple
|
mac_os_x
|
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.3. An application may be able to read restricted memory.
|
CWE-20
Improper Input Validation
|
CVE-2020-3839
|
2024-11-21 14:31 |
2020-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197372
|
7.8 |
HIGH
Local
|
apple
|
mac_os_x iphone_os ipados tvos watchos
|
The issue was addressed with improved permissions logic. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-3838
|
2024-11-21 14:31 |
2020-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197373
|
5.5 |
MEDIUM
Local
|
apple
|
iphone_os ipados tvos watchos mac_os_x
|
An access issue was addressed with improved memory management. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. A malicious application may be …
|
NVD-CWE-noinfo
|
CVE-2020-3836
|
2024-11-21 14:31 |
2020-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197374
|
4.4 |
MEDIUM
Local
|
apple
|
mac_os_x
|
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Catalina 10.15.3. A malicious application may be ab…
|
CWE-59
Link Following
|
CVE-2020-3835
|
2024-11-21 14:31 |
2020-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197375
|
7.8 |
HIGH
Local
|
apple
|
watchos
|
A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 6.1.2. An application may be able to execute arbitrary code with kernel privileges.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-3834
|
2024-11-21 14:31 |
2020-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197376
|
4.3 |
MEDIUM
Network
|
apple
|
safari
|
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 13.0.5. Visiting a malicious website may lead to address bar spoofing.
|
NVD-CWE-Other
|
CVE-2020-3833
|
2024-11-21 14:31 |
2020-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197377
|
7.0 |
HIGH
Local
|
apple
|
iphone_os ipados
|
A race condition was addressed with improved locking. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1. An application may be able to execute arbitrary code with kernel privileges.
|
CWE-362
Race Condition
|
CVE-2020-3831
|
2024-11-21 14:31 |
2020-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197378
|
3.3 |
LOW
Local
|
apple
|
mac_os_x
|
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Catalina 10.15.3. A malicious application may be ab…
|
CWE-59
Link Following
|
CVE-2020-3830
|
2024-11-21 14:31 |
2020-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197379
|
7.8 |
HIGH
Local
|
apple
|
iphone_os ipados tvos watchos mac_os_x
|
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able …
|
CWE-125
Out-of-bounds Read
|
CVE-2020-3829
|
2024-11-21 14:31 |
2020-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197380
|
2.4 |
LOW
Physics
|
apple
|
iphone_os ipados
|
A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1. A person with physical…
|
NVD-CWE-noinfo
|
CVE-2020-3828
|
2024-11-21 14:31 |
2020-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|