7.8

CVE-2020-3826

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing a maliciously crafted image may lead to arbitrary code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ iCloud SwPlatform windows Version < 11.0
Apple ≫ iTunes SwPlatform windows Version < 12.10.4
Apple ≫ iPadOS Version < 13.3.1
Apple ≫ iPhone OS Version < 13.3.1
Apple ≫ macOS X Version < 10.15.3
Apple ≫ tvOS Version < 13.3.1
Apple ≫ watchOS Version < 6.1.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.19% 0.643
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

https://support.apple.com/HT210947
Vendor Advisory
Release Notes
https://support.apple.com/HT210948
Vendor Advisory
Release Notes