7.8

CVE-2020-9919

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing a maliciously crafted image may lead to arbitrary code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ iCloud SwPlatform windows Version < 7.20
Apple ≫ iCloud SwPlatform windows Version >= 11.0 < 11.3
Apple ≫ iTunes SwPlatform windows Version < 12.10.8
Apple ≫ iPadOS Version < 13.6
Apple ≫ iPhone OS Version < 13.6
Apple ≫ macOS X Version < 10.15.6
Apple ≫ tvOS Version < 13.4.8
Apple ≫ watchOS Version < 6.2.8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.51% 0.716
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://support.apple.com/kb/HT211289
Vendor Advisory
https://support.apple.com/kb/HT211288
Vendor Advisory
https://support.apple.com/kb/HT211290
Vendor Advisory
https://support.apple.com/kb/HT211291
Vendor Advisory
https://support.apple.com/kb/HT211293
Vendor Advisory
https://support.apple.com/kb/HT211294
Vendor Advisory
https://support.apple.com/kb/HT211295
Vendor Advisory