CVE-2020-27900
- EPSS 0.23%
- Published 08.12.2020 21:15:12
- Last modified 21.11.2024 05:22:00
An issue existed in the handling of snapshots. The issue was resolved with improved permissions logic. This issue is fixed in macOS Big Sur 11.0.1. A malicious application may be able to preview files it does not have access to.
CVE-2020-9965
- EPSS 0.63%
- Published 08.12.2020 20:15:17
- Last modified 21.11.2024 05:41:36
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, tvOS 14.0, iOS 14.0 and iPadOS 14.0. An application may be able to execute arbitrary code with kernel privileges.
CVE-2020-9972
- EPSS 2.32%
- Published 08.12.2020 20:15:17
- Last modified 21.11.2024 05:41:37
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 14.0 and iPadOS 14.0. Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution.
CVE-2020-9849
- EPSS 1.07%
- Published 08.12.2020 20:15:16
- Last modified 21.11.2024 05:41:24
An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, iOS 14.0 and iPadOS 14.0, iTunes for Windows 12.10.9, iCloud for Windows 11.5, tvOS 14.0. A remote attacker may be...
CVE-2020-27894
- EPSS 0.33%
- Published 08.12.2020 20:15:15
- Last modified 21.11.2024 05:22:00
The issue was addressed with additional user controls. This issue is fixed in macOS Big Sur 11.0.1. Users may be unable to remove metadata indicating where files were downloaded from.
CVE-2020-10014
- EPSS 0.79%
- Published 08.12.2020 20:15:14
- Last modified 21.11.2024 04:54:39
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Big Sur 11.0.1. A malicious application may be able to break out of its sandbox.
CVE-2020-10016
- EPSS 0.56%
- Published 08.12.2020 20:15:14
- Last modified 21.11.2024 04:54:39
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. An application may be able to execute arbitrary code with kernel privileges.
CVE-2020-10012
- EPSS 0.9%
- Published 08.12.2020 20:15:13
- Last modified 21.11.2024 04:54:39
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Big Sur 11.0.1. Processing a maliciously crafted document may lead to a cross site scripting attack.
CVE-2020-13524
- EPSS 0.41%
- Published 03.12.2020 18:15:10
- Last modified 21.11.2024 05:01:25
An out-of-bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 uses SPECS data from binary USD files. A specially crafted malformed file can trigger an out-of-bounds memory access and modification which results in memory corru...
CVE-2020-8037
- EPSS 0.22%
- Published 04.11.2020 18:15:20
- Last modified 21.11.2024 05:38:16
The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.