
CVE-2020-9878 – Apple Security Advisory 2020-07-15-1
https://notcve.org/view.php?id=CVE-2020-9878
17 Jul 2020 — A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution. Se abordó un problema de desbordamiento del búfer con un manejo de la memoria mejorado. Este problema es corregido en iOS versión 13.6 y iPadOS versión 13.6, macOS Catalina versión 10.15.6, tvOS versión 13.4.8, watchOS ... • https://support.apple.com/HT211288 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2020-9862 – webkitgtk: Command injection in web inspector
https://notcve.org/view.php?id=CVE-2020-9862
17 Jul 2020 — A command injection issue existed in Web Inspector. This issue was addressed with improved escaping. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Copying a URL from Web Inspector may lead to command injection. Se presentó un problema de inyección de comandos en Web Inspector. • https://support.apple.com/HT211288 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') CWE-116: Improper Encoding or Escaping of Output •

CVE-2020-9917 – Apple Security Advisory 2020-07-15-1
https://notcve.org/view.php?id=CVE-2020-9917
17 Jul 2020 — This issue was addressed with improved checks. This issue is fixed in iOS 13.6 and iPadOS 13.6. A remote attacker may be able to cause a denial of service. Este problema es abordado con unas comprobaciones mejoradas. Este problema es corregido en iOS versión 13.6 y iPadOS versión 13.6. • https://support.apple.com/HT211288 •

CVE-2020-9909 – Apple Security Advisory 2020-07-15-1
https://notcve.org/view.php?id=CVE-2020-9909
17 Jul 2020 — An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8. An attacker that has already achieved kernel code execution may be able to bypass kernel memory mitigations. Se abordó una lectura fuera de límites con una comprobación de límites mejorada. Este problema es corregido en iOS versión 13.6 y iPadOS versión 13.6, tvOS versión 13.4.8, watchOS versión 6.2.8. • https://packetstorm.news/files/id/158698 • CWE-125: Out-of-bounds Read •

CVE-2020-9870 – PAC Bypass Due to Unprotected Function Pointer Imports
https://notcve.org/view.php?id=CVE-2020-9870
17 Jul 2020 — A logic issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8. An attacker with memory write capability may be able to bypass pointer authentication codes and run arbitrary code. Se abordó un problema lógico con una comprobación mejorada. Este problema es corregido en iOS versión 13.6 y iPadOS versión 13.6, macOS Catalina versión 10.15.6, tvOS 13.4.8. • https://support.apple.com/HT211288 • CWE-20: Improper Input Validation •

CVE-2020-9894 – Apple Safari getAnimations Out-Of-Bounds Read Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2020-9894
17 Jul 2020 — An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A remote attacker may be able to cause unexpected application termination or arbitrary code execution. Se abordó una lectura fuera de límites con una comprobación de entrada mejorada. Este problema es corregido en iOS versión 13.6 y iPadOS versión 13.6, tvOS versión 13... • https://support.apple.com/HT211288 • CWE-125: Out-of-bounds Read •

CVE-2020-9888 – Apple Security Advisory 2020-07-15-1
https://notcve.org/view.php?id=CVE-2020-9888
17 Jul 2020 — An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. Processing a maliciously crafted audio file may lead to arbitrary code execution. Se abordó una lectura fuera de límites con una comprobación de límites mejorada. Este problema es corregido en iOS versión 13.6 y iPadOS versión 13.6, macOS Catalina versión 10.15.6, tvOS versión 13.4.8, watchOS versión 6.2.8. • https://support.apple.com/HT211288 • CWE-125: Out-of-bounds Read •

CVE-2020-9895 – webkitgtk: Use-after-free may lead to application termination or arbitrary code execution
https://notcve.org/view.php?id=CVE-2020-9895
17 Jul 2020 — A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A remote attacker may be able to cause unexpected application termination or arbitrary code execution. Se abordó un problema de uso de la memoria previamente liberada con una administración de la memoria mejorada. Este problema es corregido en iOS versión 13.6 y iPad... • https://support.apple.com/HT211288 • CWE-416: Use After Free •

CVE-2020-9890 – Apple Security Advisory 2020-07-15-1
https://notcve.org/view.php?id=CVE-2020-9890
17 Jul 2020 — An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. Processing a maliciously crafted audio file may lead to arbitrary code execution. Se abordó una lectura fuera de límites con una comprobación de límites mejorada. Este problema es corregido en iOS versión 13.6 y iPadOS versión 13.6, macOS Catalina versión 10.15.6, tvOS versión 13.4.8, watchOS versión 6.2.8. • https://support.apple.com/HT211288 • CWE-125: Out-of-bounds Read •

CVE-2020-9893 – Apple Safari RenderWidget Use-After-Free Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2020-9893
17 Jul 2020 — A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A remote attacker may be able to cause unexpected application termination or arbitrary code execution. Se abordó un problema de uso de la memoria previamente liberada con una administración de la memoria mejorada. Este problema es corregido en iOS versión 13.6 y iPad... • https://support.apple.com/HT211288 • CWE-416: Use After Free •