CVE-2020-3841
https://notcve.org/view.php?id=CVE-2020-3841
The issue was addressed with improved UI handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, Safari 13.0.5. A local user may unknowingly send a password unencrypted over the network. El problema se abordó con un manejo de la Interfaz de Usuario mejorado. Este problema es corregido en iOS versión 13.3.1 y iPadOS versión 13.3.1, Safari 13.0.5. • https://support.apple.com/HT210918 https://support.apple.com/HT210922 • CWE-319: Cleartext Transmission of Sensitive Information CWE-522: Insufficiently Protected Credentials •
CVE-2019-8850 – Apple macOS AudioToolbox MP4 Parsing Integer Overflow Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2019-8850
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15, iOS 13.1 and iPadOS 13.1, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, watchOS 6. Processing a maliciously crafted audio file may disclose restricted memory. Se abordó una lectura fuera de límites con una comprobación de entrada mejorada. Este problema se corrigió en macOS Catalina versión 10.15, iOS versión 13.1 y iPadOS versión 13.1, tvOS versión 13, macOS Catalina versión 10.15.1, Security Update 2019-001 y Security Update 2019-006, watchOS versión 6. • https://support.apple.com/en-us/HT210603 https://support.apple.com/en-us/HT210604 https://support.apple.com/en-us/HT210607 https://support.apple.com/en-us/HT210634 https://support.apple.com/en-us/HT210722 • CWE-125: Out-of-bounds Read •
CVE-2019-8699
https://notcve.org/view.php?id=CVE-2019-8699
A logic issue existed in the handling of answering phone calls. The issue was addressed with improved state management. This issue is fixed in iOS 12.4. The initiator of a phone call may be able to cause the recipient to answer a simultaneous Walkie-Talkie connection. Se presentó un problema lógico en el manejo de respuestas a llamadas telefónicas. • https://support.apple.com/HT210346 •
CVE-2019-8698
https://notcve.org/view.php?id=CVE-2019-8698
A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in iOS 12.4, tvOS 12.4. A malicious application may be able to restrict access to websites. Se presentó un problema de comprobación en la verificación de los derechos. • https://support.apple.com/HT210346 https://support.apple.com/HT210351 • CWE-20: Improper Input Validation •
CVE-2019-8630
https://notcve.org/view.php?id=CVE-2019-8630
The issue was addressed with improved UI handling. This issue is fixed in iOS 12.3. The lock screen may show a locked icon after unlocking. El problema fue abordado con un manejo mejorado de la Interfaz de Usuario. Este problema es corregido en iOS versión 12.3. • https://support.apple.com/HT210118 •