
CVE-2020-9934 – Apple iOS, iPadOS, and macOS Input Validation Vulnerability
https://notcve.org/view.php?id=CVE-2020-9934
17 Jul 2020 — An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6. A local user may be able to view sensitive user information. Se presentó un problema en el manejo de variables de entorno. • https://github.com/mattshockl/CVE-2020-9934 •

CVE-2020-9864 – Apple Security Advisory 2020-07-15-2
https://notcve.org/view.php?id=CVE-2020-9864
17 Jul 2020 — A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.6. An application may be able to execute arbitrary code with kernel privileges. Se abordó un problema lógico con una restricciones mejoradas. Este problema es corregido en macOS Catalina versión 10.15.6. • https://support.apple.com/HT211289 •

CVE-2020-9888 – Apple Security Advisory 2020-07-15-1
https://notcve.org/view.php?id=CVE-2020-9888
17 Jul 2020 — An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. Processing a maliciously crafted audio file may lead to arbitrary code execution. Se abordó una lectura fuera de límites con una comprobación de límites mejorada. Este problema es corregido en iOS versión 13.6 y iPadOS versión 13.6, macOS Catalina versión 10.15.6, tvOS versión 13.4.8, watchOS versión 6.2.8. • https://support.apple.com/HT211288 • CWE-125: Out-of-bounds Read •

CVE-2020-9885 – Apple Security Advisory 2020-07-15-1
https://notcve.org/view.php?id=CVE-2020-9885
17 Jul 2020 — An issue existed in the handling of iMessage tapbacks. The issue was resolved with additional verification. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A user that is removed from an iMessage group could rejoin the group. Se presentó un problema en el manejo de tapbacks de iMessage. • https://support.apple.com/HT211288 • CWE-345: Insufficient Verification of Data Authenticity •

CVE-2020-9870 – PAC Bypass Due to Unprotected Function Pointer Imports
https://notcve.org/view.php?id=CVE-2020-9870
17 Jul 2020 — A logic issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8. An attacker with memory write capability may be able to bypass pointer authentication codes and run arbitrary code. Se abordó un problema lógico con una comprobación mejorada. Este problema es corregido en iOS versión 13.6 y iPadOS versión 13.6, macOS Catalina versión 10.15.6, tvOS 13.4.8. • https://support.apple.com/HT211288 • CWE-20: Improper Input Validation •

CVE-2020-9859 – Apple Multiple Products Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2020-9859
02 Jun 2020 — A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5 Supplemental Update, tvOS 13.4.6, watchOS 6.2.6. An application may be able to execute arbitrary code with kernel privileges. Se abordó un problema de consumo de memoria con un manejo de memoria mejorado. Este problema esta corregido en iOS versión 13.5.1 y iPadOS versión 13.5.1, Supplemental Update de macOS Catalina versión 10.15.5, tvOS versión 13.4.6, watchOS... • https://support.apple.com/HT211214 • CWE-415: Double Free •

CVE-2020-9824 – Apple Security Advisory 2020-05-26-3
https://notcve.org/view.php?id=CVE-2020-9824
29 May 2020 — A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.5. A non-privileged user may be able to modify restricted network settings. Se abordó un problema lógico con restricciones mejoradas. Este problema es corregido en macOS Catalina versión 10.15.5. • https://support.apple.com/HT211170 •

CVE-2020-9826 – Apple Security Advisory 2020-05-26-3
https://notcve.org/view.php?id=CVE-2020-9826
29 May 2020 — A denial of service issue was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5. A remote attacker may be able to cause a denial of service. Se abordó un problema de denegación de servicio con una comprobación de entrada mejorada. Este problema es corregido en iOS versión 13.5 y iPadOS versión 13.5, macOS Catalina versión 10.15.5. • https://support.apple.com/HT211168 • CWE-20: Improper Input Validation •

CVE-2020-9831 – Apple Security Advisory 2020-05-26-3
https://notcve.org/view.php?id=CVE-2020-9831
29 May 2020 — An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.5. A malicious application may be able to determine kernel memory layout. Se abordó una lectura fuera de límites con una comprobación de límites mejorada. Este problema es corregido en macOS Catalina versión 10.15.5. • https://support.apple.com/HT211170 • CWE-125: Out-of-bounds Read •

CVE-2020-9814 – Apple Security Advisory 2020-05-26-3
https://notcve.org/view.php?id=CVE-2020-9814
29 May 2020 — A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A malicious application may be able to execute arbitrary code with kernel privileges. Se presentó un problema lógico resultando en una corrupción de la memoria. • https://support.apple.com/HT211168 • CWE-787: Out-of-bounds Write •