Apple

iPhone OS

4014 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 10.29%
  • Veröffentlicht 17.04.2020 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:46:11

A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2. An attacker in a privileged network position may be able to intercept network traffic.

Exploit
  • EPSS 0.64%
  • Veröffentlicht 14.04.2020 23:15:12
  • Zuletzt bearbeitet 21.11.2024 04:58:32

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read in ImfOptimizedPixelReading.h.

Exploit
  • EPSS 1.06%
  • Veröffentlicht 14.04.2020 23:15:12
  • Zuletzt bearbeitet 21.11.2024 04:58:32

An issue was discovered in OpenEXR before 2.4.1. Because of integer overflows in CompositeDeepScanLine::Data::handleDeepFrameBuffer and readSampleCountForLineBlock, an attacker can write to an out-of-bounds pointer.

Exploit
  • EPSS 0.64%
  • Veröffentlicht 14.04.2020 23:15:12
  • Zuletzt bearbeitet 21.11.2024 04:58:32

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompression in rleUncompress in ImfRle.cpp.

Exploit
  • EPSS 0.58%
  • Veröffentlicht 14.04.2020 23:15:12
  • Zuletzt bearbeitet 21.11.2024 04:58:33

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncompression, as demonstrated by FastHufDecoder::refill in ImfFastHuf.cpp.

Exploit
  • EPSS 0.58%
  • Veröffentlicht 14.04.2020 23:15:12
  • Zuletzt bearbeitet 21.11.2024 04:58:33

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read and write in DwaCompressor::uncompress in ImfDwaCompressor.cpp when handling the UNKNOWN compression case.

Exploit
  • EPSS 0.58%
  • Veröffentlicht 14.04.2020 23:15:12
  • Zuletzt bearbeitet 21.11.2024 04:58:33

An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and write, as demonstrated by ImfTileOffsets.cpp.

Exploit
  • EPSS 0.78%
  • Veröffentlicht 14.04.2020 23:15:12
  • Zuletzt bearbeitet 21.11.2024 04:58:33

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuffer in ImfMisc.cpp.

Exploit
  • EPSS 0.58%
  • Veröffentlicht 14.04.2020 23:15:12
  • Zuletzt bearbeitet 21.11.2024 04:58:33

An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier, leading to an out-of-bounds read.

  • EPSS 0.15%
  • Veröffentlicht 01.04.2020 18:15:18
  • Zuletzt bearbeitet 21.11.2024 05:41:15

The issue was addressed by clearing website permission prompts after navigation. This issue is fixed in iOS 13.4 and iPadOS 13.4. A user may grant website permissions to a site they didn't intend to.