
CVE-2020-0409
https://notcve.org/view.php?id=CVE-2020-0409
10 Nov 2020 — In create of FileMap.cpp, there is a possible out of bounds write due to an integer overflow. • https://github.com/nanopathi/system_core_AOSP10_r33_CVE-2020-0409 • CWE-190: Integer Overflow or Wraparound CWE-787: Out-of-bounds Write •

CVE-2020-0452 – libexif: out of bounds write due to an integer overflow in exif-entry.c
https://notcve.org/view.php?id=CVE-2020-0452
10 Nov 2020 — In exif_entry_get_value of exif-entry.c, there is a possible out of bounds write due to an integer overflow. ... A possible out of bounds write, due ot an integer overflow, could lead to a remote code execution if a third party app used this library to process remote image data. ... Issues addressed include integer overflow and out of bounds write vulnerabilities. • https://github.com/ShaikUsaf/external_libexif_AOSP10_CVE-2020-0452 • CWE-190: Integer Overflow or Wraparound CWE-787: Out-of-bounds Write •

CVE-2020-28371
https://notcve.org/view.php?id=CVE-2020-28371
09 Nov 2020 — However, an integer overflow leads to bypassing this check and achieving the out-of-bounds access. • https://github.com/ReadyTalk/avian/commit/0871979b298add320ca63f65060acb7532c8a0dd • CWE-190: Integer Overflow or Wraparound CWE-787: Out-of-bounds Write •

CVE-2020-27932 – Apple Multiple Products Type Confusion Vulnerability
https://notcve.org/view.php?id=CVE-2020-27932
09 Nov 2020 —  Una aplicación maliciosa puede ser capaz de ejecutar código arbitrario con privilegios kernel macOS Big Sur 11.0.1 addresses buffer overflow, bypass, code execution, denial of service, information leakage, integer overflow, out of bounds read, out of bounds write, path sanitization, spoofing, and use-after-free vulnerabilities. • https://packetstorm.news/files/id/161295 • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •

CVE-2020-27902 – Apple Security Advisory 2020-11-05-1
https://notcve.org/view.php?id=CVE-2020-27902
09 Nov 2020 —  Una persona con acceso físico a un dispositivo iOS puede ser capaz de acceder a las contraseñas almacenadas sin autenticación iOS 14.2 and iPadOS 14.2 are now available and addresses code execution, integer overflow, out of bounds read, out of bounds write, path sanitization, and use-after-free vulnerabilities. • https://support.apple.com/en-us/HT211929 • CWE-306: Missing Authentication for Critical Function •

CVE-2020-27905 – Apple Security Advisory 2020-11-05-7
https://notcve.org/view.php?id=CVE-2020-27905
09 Nov 2020 —  Una aplicación maliciosa puede ser capaz de ejecutar código arbitrario con privilegios system iOS 14.2 and iPadOS 14.2 are now available and addresses code execution, integer overflow, out of bounds read, out of bounds write, path sanitization, and use-after-free vulnerabilities. • https://support.apple.com/en-us/HT211928 • CWE-787: Out-of-bounds Write •

CVE-2020-27912 – Apple Security Advisory 2020-12-14-3
https://notcve.org/view.php?id=CVE-2020-27912
09 Nov 2020 —  El procesamiento de una imagen diseñada maliciosamente puede conllevar a una ejecución de código arbitraria macOS Big Sur 11.1, Security Update 2020-001 Catalina, and Security Update 2020-007 Mojave address buffer overflow, bypass, code execution, denial of service, information leakage, integer overflow, out of bounds read, out of bounds write, and use-after-free vulnerabilities. • http://seclists.org/fulldisclosure/2020/Dec/26 • CWE-787: Out-of-bounds Write •

CVE-2020-27950 – Apple Multiple Products Memory Initialization Vulnerability
https://notcve.org/view.php?id=CVE-2020-27950
09 Nov 2020 —  Una aplicación maliciosa puede ser capaz de revelar la memoria del kernel macOS Big Sur 11.0.1 addresses buffer overflow, bypass, code execution, denial of service, information leakage, integer overflow, out of bounds read, out of bounds write, path sanitization, spoofing, and use-after-free vulnerabilities. • https://packetstorm.news/files/id/161296 • CWE-665: Improper Initialization •

CVE-2020-13524 – Apple Security Advisory 2020-12-14-3
https://notcve.org/view.php?id=CVE-2020-13524
09 Nov 2020 — Para activar esta vulnerabilidad, la víctima necesita acceder a un archivo malformado proporcionado por el atacante macOS Big Sur 11.1, Security Update 2020-001 Catalina, and Security Update 2020-007 Mojave address buffer overflow, bypass, code execution, denial of service, information leakage, integer overflow, out of bounds read, out of bounds write, and use-after-free vulnerabilities. • http://seclists.org/fulldisclosure/2020/Dec/26 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-787: Out-of-bounds Write •

CVE-2020-27916 – Apple Security Advisory 2020-12-14-3
https://notcve.org/view.php?id=CVE-2020-27916
09 Nov 2020 —  El procesamiento de un archivo de audio diseñado maliciosamente puede conllevar a una ejecución de código arbitraria macOS Big Sur 11.1, Security Update 2020-001 Catalina, and Security Update 2020-007 Mojave address buffer overflow, bypass, code execution, denial of service, information leakage, integer overflow, out of bounds read, out of bounds write, and use-after-free vulnerabilities. • http://seclists.org/fulldisclosure/2020/Dec/26 • CWE-787: Out-of-bounds Write •