CVE-2020-9931 – Apple Security Advisory 2020-07-15-1
https://notcve.org/view.php?id=CVE-2020-9931
17 Jul 2020 — A denial of service issue was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6. A remote attacker may cause an unexpected application termination. Se abordó un problema de denegación de servicio con una comprobación de entrada mejorada. Este problema es corregido en iOS versión 13.6 y iPadOS versión 13.6. • https://support.apple.com/HT211288 • CWE-20: Improper Input Validation •
CVE-2020-9885 – Apple Security Advisory 2020-07-15-1
https://notcve.org/view.php?id=CVE-2020-9885
17 Jul 2020 — An issue existed in the handling of iMessage tapbacks. The issue was resolved with additional verification. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A user that is removed from an iMessage group could rejoin the group. Se presentó un problema en el manejo de tapbacks de iMessage. • https://support.apple.com/HT211288 • CWE-345: Insufficient Verification of Data Authenticity •
CVE-2020-9907 – Apple Multiple Products Memory Corruption Vulnerability
https://notcve.org/view.php?id=CVE-2020-9907
17 Jul 2020 — A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8. An application may be able to execute arbitrary code with kernel privileges. Se abordó un problema de corrupción de la memoria al eliminar el código vulnerable. Este problema es corregido en iOS versión 13.6 y iPadOS versión 13.6, tvOS versión 13.4.8. • https://support.apple.com/HT211288 • CWE-787: Out-of-bounds Write •
CVE-2020-9934 – Apple iOS, iPadOS, and macOS Input Validation Vulnerability
https://notcve.org/view.php?id=CVE-2020-9934
17 Jul 2020 — An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6. A local user may be able to view sensitive user information. Se presentó un problema en el manejo de variables de entorno. • https://github.com/mattshockl/CVE-2020-9934 •
CVE-2020-15358 – sqlite: heap-based buffer overflow in multiSelectOrderBy due to mishandling of query-flattener optimization in select.c
https://notcve.org/view.php?id=CVE-2020-15358
27 Jun 2020 — In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation. En SQLite versiones anteriores a 3.32.3, el archivo select.c maneja inapropiadamente la optimización query-flattener, conllevando a un desbordamiento de la pila de multiSelectOrderBy debido al uso inapropiado de las propiedades transitivas para la propagación constante A heap buffer overflow was found in SQLite in the qu... • http://seclists.org/fulldisclosure/2020/Dec/32 • CWE-122: Heap-based Buffer Overflow CWE-787: Out-of-bounds Write •
CVE-2020-9859 – Apple Multiple Products Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2020-9859
02 Jun 2020 — A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5 Supplemental Update, tvOS 13.4.6, watchOS 6.2.6. An application may be able to execute arbitrary code with kernel privileges. Se abordó un problema de consumo de memoria con un manejo de memoria mejorado. Este problema esta corregido en iOS versión 13.5.1 y iPadOS versión 13.5.1, Supplemental Update de macOS Catalina versión 10.15.5, tvOS versión 13.4.6, watchOS... • https://support.apple.com/HT211214 • CWE-415: Double Free •
CVE-2020-9802 – webkitgtk: Logic issue may lead to arbitrary code execution
https://notcve.org/view.php?id=CVE-2020-9802
29 May 2020 — A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously crafted web content may lead to arbitrary code execution. Se abordó un problema lógico con restricciones mejoradas. Este problema es corregido en iOS versión 13.5 y iPadOS versión 13.5, tvOS versión 13.4.5, watchOS versión 6.2.5, Safari versión 13.1.1, iTunes ver... • https://packetstorm.news/files/id/157926 • CWE-841: Improper Enforcement of Behavioral Workflow •
CVE-2020-9805 – webkitgtk: Logic issue may lead to cross site scripting
https://notcve.org/view.php?id=CVE-2020-9805
29 May 2020 — A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously crafted web content may lead to universal cross site scripting. Se abordó un problema lógico con restricciones mejoradas. Este problema es corregido en iOS versión 13.5 y iPadOS versión 13.5, tvOS versión 13.4.5, watchOS versión 6.2.5, Safari versión 13.1.1, iTun... • https://support.apple.com/HT211168 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-9811 – Apple Security Advisory 2020-05-26-3
https://notcve.org/view.php?id=CVE-2020-9811
29 May 2020 — An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A local user may be able to read kernel memory. Se abordó un problema de divulgación de información con una administración de estado mejorada. Este problema es corregido en iOS versión 13.5 y iPadOS versión 13.5, macOS Catalina versión 10.15.5, tvOS versión 13.4.5, watchOS versión 6.2.5. • https://support.apple.com/HT211168 •
CVE-2020-9823 – Apple Security Advisory 2020-05-26-1
https://notcve.org/view.php?id=CVE-2020-9823
29 May 2020 — This issue was addressed with improved checks. This issue is fixed in iOS 13.5 and iPadOS 13.5. Users removed from an iMessage conversation may still be able to alter state. Este problema se abordó con unas comprobaciones mejoradas. Este problema es corregido en iOS versión 13.5 y iPadOS versión 13.5. • https://support.apple.com/HT211168 •