CVE-2020-27946 – Apple CoreText libType1Scaler.dylib Memory Disclosure
https://notcve.org/view.php?id=CVE-2020-27946
16 Dec 2020 — An information disclosure issue was addressed with improved state management. This issue is fixed in watchOS 7.2, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. Processing a maliciously crafted font may result in the disclosure of process memory. Se abordó un problema de divulgación de información con una administración de estado mejorada. Este problema es corregido en watchOS versión 7.2, macOS Big Sur versión 11.1, Security... • https://support.apple.com/en-us/HT212003 •
CVE-2020-27948
https://notcve.org/view.php?id=CVE-2020-27948
16 Dec 2020 — An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in watchOS 7.2, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. Processing a maliciously crafted audio file may lead to arbitrary code execution. Se abordó un problema de escritura fuera de límites con una comprobación de límites mejorada. Este problema es corregido en watchOS versión 7.2, macOS Big Sur versión 11.1, Security Update 2... • https://support.apple.com/en-us/HT212003 • CWE-787: Out-of-bounds Write •
CVE-2020-27899 – Apple Security Advisory 2020-12-14-4
https://notcve.org/view.php?id=CVE-2020-27899
16 Dec 2020 — A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.2 and iPadOS 14.2, macOS Big Sur 11.0.1, watchOS 7.1, tvOS 14.2. A local attacker may be able to elevate their privileges. Se abordó un problema de uso de la memoria previamente liberada con una administración de la memoria mejorada. Este problema es corregido en iOS versión 14.2 y iPadOS versión 14.2, macOS Big Sur versión 11.0.1, watchOS versión 7.1, tvOS versión 14.2. • https://support.apple.com/en-us/HT211928 • CWE-416: Use After Free •
CVE-2020-9971 – Apple Security Advisory 2020-12-14-4
https://notcve.org/view.php?id=CVE-2020-9971
16 Dec 2020 — A logic issue was addressed with improved validation. This issue is fixed in watchOS 7.0, tvOS 14.0, iOS 14.0 and iPadOS 14.0, macOS Big Sur 11.0.1. A malicious application may be able to elevate privileges. Se abordó un problema de lógica con una comprobación mejorada. Este problema es corregido en watchOS versión 7.0, tvOS versión 14.0, iOS versión 14.0 y iPadOS versión 14.0, macOS Big Sur versión 11.0.1. • https://support.apple.com/en-us/HT211843 •
CVE-2020-9975 – Apple Security Advisory 2020-12-14-3
https://notcve.org/view.php?id=CVE-2020-9975
16 Dec 2020 — A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.0, iOS 14.0 and iPadOS 14.0. An application may be able to execute arbitrary code with kernel privileges. Se abordó un problema de uso de la memoria previamente liberada con una administración de la memoria mejorada. Este problema es corregido en macOS Big Sur versión 11.0.1, tvOS v... • https://support.apple.com/en-us/HT211843 • CWE-416: Use After Free •
CVE-2020-9960 – Apple Security Advisory 2020-12-14-3
https://notcve.org/view.php?id=CVE-2020-9960
16 Dec 2020 — An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.0, iOS 14.0 and iPadOS 14.0. Processing a maliciously crafted audio file may lead to arbitrary code execution. Se abordó una lectura fuera de límites con una comprobación de la entrada mejorada. Este problema es corregido en macOS Big Sur versión 11.0.1, tvOS versión 14.0, macOS Big S... • https://support.apple.com/en-us/HT211843 • CWE-125: Out-of-bounds Read •
CVE-2020-9962 – Apple Security Advisory 2020-12-14-3
https://notcve.org/view.php?id=CVE-2020-9962
16 Dec 2020 — A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.0, iOS 14.0 and iPadOS 14.0. Processing a maliciously crafted image may lead to arbitrary code execution. Se abordó un desbordamiento del búfer con una comprobación mejorada del tamaño. Este problema es corregido en macOS Big Sur versión 11.0.1, tvOS versión 14.0, macOS Big Sur versión 11.... • https://support.apple.com/en-us/HT211843 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •
CVE-2020-9967 – Apple Security Advisory 2020-12-14-3
https://notcve.org/view.php?id=CVE-2020-9967
16 Dec 2020 — Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.0, iOS 14.0 and iPadOS 14.0. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory. Se abordaron múltiples problemas de corrupción de la memoria con una comprobación de la entrada mejorada. Este problema es corregido en macOS Big Su... • https://packetstorm.news/files/id/163501 • CWE-787: Out-of-bounds Write •
CVE-2020-29611 – Apple Security Advisory 2020-12-14-3
https://notcve.org/view.php?id=CVE-2020-29611
16 Dec 2020 — An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 14.3, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, iCloud for Windows 12.0, watchOS 7.2. Processing a maliciously crafted image may lead to arbitrary code execution. Se abordó un problema de escritura fuera de límites con una comprobación de límites mejorada. Este problema es corregido en tvOS versión 14.3, macOS Big Sur versión 11.1,... • https://packetstorm.news/files/id/160547 • CWE-787: Out-of-bounds Write •
CVE-2020-29617 – Apple Security Advisory 2020-12-14-3
https://notcve.org/view.php?id=CVE-2020-29617
16 Dec 2020 — An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 14.3, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, iCloud for Windows 12.0, watchOS 7.2. Processing a maliciously crafted image may lead to heap corruption. Se abordó una lectura fuera de límites con una comprobación de la entrada mejorada. Este problema es corregido en tvOS versión 14.3, macOS Big Sur versión 11.1, Security Update 2020-001... • https://support.apple.com/en-us/HT212003 • CWE-125: Out-of-bounds Read •