Selection:
XSS CSRF Privilege Buffer Remote Stack
CVE ID Name Status References
CVE-2020-9997

An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15.6, watchOS 6.2.8. A malicious application may disclose restricted memory.

Assigned (20200302)

MISC:https://support.apple.com/kb/HT211289 | URL:https://support.apple.com/kb/HT211289 | MISC:https://support.apple.com/kb/HT211291 | URL:https://support.apple.com/kb/HT211291

CVE-2020-9994

A path handling issue was addressed with improved validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A malicious application may be able to overwrite arbitrary files.

Assigned (20200302)

MISC:https://support.apple.com/kb/HT211168 | URL:https://support.apple.com/kb/HT211168 | MISC:https://support.apple.com/kb/HT211170 | URL:https://support.apple.com/kb/HT211170 | MISC:https://support.apple.com/kb/HT211171 | URL:https://support.apple.com/kb/HT211171 | MISC:https://support.apple.com/kb/HT211175 | URL:https://support.apple.com/kb/HT211175

CVE-2020-9992

This issue was addressed by encrypting communications over the network to devices running iOS 14, iPadOS 14, tvOS 14, and watchOS 7. This issue is fixed in iOS 14.0 and iPadOS 14.0, Xcode 12.0. An attacker in a privileged network position may be able to execute arbitrary code on a paired device during a debug session over the network.

Assigned (20200302)

FULLDISC:20201115 APPLE-SA-2020-11-13-3 Additional information for APPLE-SA-2020-09-16-1 iOS 14.0 and iPadOS 14.0 | URL:http://seclists.org/fulldisclosure/2020/Nov/20 | MISC:https://support.apple.com/HT211848 | URL:https://support.apple.com/HT211848 | MISC:https://support.apple.com/HT211850 | URL:https://support.apple.com/HT211850

CVE-2020-9990

A race condition was addressed with additional validation. This issue is fixed in macOS Catalina 10.15.6. A malicious application may be able to execute arbitrary code with kernel privileges.

Assigned (20200302)

MISC:https://support.apple.com/kb/HT211289 | URL:https://support.apple.com/kb/HT211289

CVE-2020-9986

A file access issue existed with certain home folder files. This was addressed with improved access restrictions. This issue is fixed in macOS Catalina 10.15.7. A malicious application may be able to read sensitive location information.

Assigned (20200302)

FULLDISC:20201115 APPLE-SA-2020-11-13-7 Additional information for APPLE-SA-2020-09-24-1 macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave | URL:http://seclists.org/fulldisclosure/2020/Nov/21 | MISC:https://support.apple.com/kb/HT211849 | URL:https://support.apple.com/kb/HT211849

CVE-2020-9985

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, watchOS 6.2.8. Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution.

Assigned (20200302)

MISC:https://support.apple.com/kb/HT211288 | URL:https://support.apple.com/kb/HT211288 | MISC:https://support.apple.com/kb/HT211289 | URL:https://support.apple.com/kb/HT211289 | MISC:https://support.apple.com/kb/HT211291 | URL:https://support.apple.com/kb/HT211291

CVE-2020-9984

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing a maliciously crafted image may lead to arbitrary code execution.

Assigned (20200302)

MISC:https://support.apple.com/kb/HT211288 | URL:https://support.apple.com/kb/HT211288 | MISC:https://support.apple.com/kb/HT211289 | URL:https://support.apple.com/kb/HT211289 | MISC:https://support.apple.com/kb/HT211290 | URL:https://support.apple.com/kb/HT211290 | MISC:https://support.apple.com/kb/HT211291 | URL:https://support.apple.com/kb/HT211291 | MISC:https://support.apple.com/kb/HT211293 | URL:https://support.apple.com/kb/HT211293 | MISC:https://support.apple.com/kb/HT211294 | URL:https://support.apple.com/kb/HT211294 | MISC:https://support.apple.com/kb/HT211295 | URL:https://support.apple.com/kb/HT211295

CVE-2020-9983

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Safari 14.0. Processing maliciously crafted web content may lead to code execution.

Assigned (20200302)

CONFIRM:https://support.apple.com/kb/HT211843 | CONFIRM:https://support.apple.com/kb/HT211844 | CONFIRM:https://support.apple.com/kb/HT211850 | CONFIRM:https://support.apple.com/kb/HT211952 | FULLDISC:20201115 APPLE-SA-2020-11-13-3 Additional information for APPLE-SA-2020-09-16-1 iOS 14.0 and iPadOS 14.0 | URL:http://seclists.org/fulldisclosure/2020/Nov/20 | FULLDISC:20201115 APPLE-SA-2020-11-13-4 Additional information for APPLE-SA-2020-09-16-2 tvOS 14.0 | URL:http://seclists.org/fulldisclosure/2020/Nov/19 | FULLDISC:20201115 APPLE-SA-2020-11-13-5 Additional information for APPLE-SA-2020-09-16-3 Safari 14.0 | URL:http://seclists.org/fulldisclosure/2020/Nov/18 | FULLDISC:20201115 APPLE-SA-2020-11-13-6 Additional information for APPLE-SA-2020-09-16-4 watchOS 7.0 | URL:http://seclists.org/fulldisclosure/2020/Nov/22 | MISC:https://support.apple.com/HT211845 | URL:https://support.apple.com/HT211845

CVE-2020-9982

This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Apple Music 3.4.0 for Android. A malicious application may be able to leak a user's credentials.

Assigned (20200302)

MISC:https://support.apple.com/en-us/HT211898 | URL:https://support.apple.com/en-us/HT211898

CVE-2020-9980

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. Processing a maliciously crafted font file may lead to arbitrary code execution.

Assigned (20200302)

MISC:https://support.apple.com/kb/HT211288 | URL:https://support.apple.com/kb/HT211288 | MISC:https://support.apple.com/kb/HT211289 | URL:https://support.apple.com/kb/HT211289 | MISC:https://support.apple.com/kb/HT211290 | URL:https://support.apple.com/kb/HT211290 | MISC:https://support.apple.com/kb/HT211291 | URL:https://support.apple.com/kb/HT211291


Page created:

CVE year by year statistics.

CVE year statistics by common vulnerability domain.

Latest data from: 2020-11-23