4.3

CVE-2020-9819

Warning

A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5, watchOS 5.3.7. Processing a maliciously crafted mail message may lead to heap corruption.

Data is provided by the National Vulnerability Database (NVD)
AppleiPadOS Version < 13.5
AppleiPhone OS Version < 12.4.7
AppleiPhone OS Version >= 13.0 < 13.5
ApplewatchOS Version < 5.3.7
ApplewatchOS Version >= 6.0.0 < 6.2.5

03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog

Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability

Vulnerability

Apple iOS, iPadOS, and watchOS Mail contains a memory corruption vulnerability that may allow heap corruption when processing a maliciously crafted mail message.

Description

Apply updates per vendor instructions.

Required actions
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.45% 0.605
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
134c704f-9b21-4f2e-91b3-4a467353bcc0 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.