CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2020-9785

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved state management. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. A malicious application may be able to execute arbitrary code with kernel privileges.

    Published: 1 Apr 2020
    8.8
    High

    CVE-2020-9783

    Last Modified: 21 Nov 2024

    A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Processing maliciously crafted web content may lead to code execution.

    Published: 1 Apr 2020
    3.3
    Low

    CVE-2020-9780

    Last Modified: 21 Nov 2024

    The issue was resolved by clearing application previews when content is deleted. This issue is fixed in iOS 13.4 and iPadOS 13.4. A local user may be able to view deleted content in the app switcher.

    Published: 1 Apr 2020
    4.3
    Medium

    CVE-2020-9784

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved restrictions. This issue is fixed in Safari 13.1. A malicious iframe may use another website’s download settings.

    Published: 1 Apr 2020
    5.3
    Medium

    CVE-2020-9781

    Last Modified: 21 Nov 2024

    The issue was addressed by clearing website permission prompts after navigation. This issue is fixed in iOS 13.4 and iPadOS 13.4. A user may grant website permissions to a site they didn't intend to.

    Published: 1 Apr 2020
    3.3
    Low

    CVE-2020-9773

    Last Modified: 21 Nov 2024

    The issue was addressed with improved handling of icon caches. This issue is fixed in iOS 14.0 and iPadOS 14.0. A malicious application may be able to identify what other applications a user has installed.

    Published: 1 Apr 2020
    6.5
    Medium

    CVE-2020-9770

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in iOS 13.4 and iPadOS 13.4. An attacker in a privileged network position may be able to intercept Bluetooth traffic.

    Published: 1 Apr 2020
    5.3
    Medium

    CVE-2020-9777

    Last Modified: 21 Nov 2024

    An issue existed in the selection of video file by Mail. The issue was fixed by selecting the latest version of a video. This issue is fixed in iOS 13.4 and iPadOS 13.4. Cropped videos may not be shared properly via Mail.

    Published: 1 Apr 2020
    5.3
    Medium

    CVE-2020-9775

    Last Modified: 21 Nov 2024

    An issue existed in the handling of tabs displaying picture in picture video. The issue was corrected with improved state handling. This issue is fixed in iOS 13.4 and iPadOS 13.4. A user's private browsing activity may be unexpectedly saved in Screen Time.

    Published: 1 Apr 2020
    3.3
    Low

    CVE-2020-9776

    Last Modified: 21 Nov 2024

    This issue was addressed with a new entitlement. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be able to access a user's call history.

    Published: 1 Apr 2020
    7.8
    High

    CVE-2020-9768

    Last Modified: 21 Nov 2024

    A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, watchOS 6.2. An application may be able to execute arbitrary code with system privileges.

    Published: 1 Apr 2020
    9.8
    Critical

    CVE-2020-9769

    Last Modified: 21 Nov 2024

    Multiple issues were addressed by updating to version 8.1.1850. This issue is fixed in macOS Catalina 10.15.4. Multiple issues in Vim.

    Published: 1 Apr 2020
    7.8
    High

    CVE-2020-3919

    Last Modified: 21 Nov 2024

    A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. A malicious application may be able to execute arbitrary code with kernel privileges.

    Published: 1 Apr 2020
    9.8
    Critical

    CVE-2020-3910

    Last Modified: 21 Nov 2024

    A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Multiple issues in libxml2.

    Published: 1 Apr 2020
    5.5
    Medium

    CVE-2020-3917

    Last Modified: 21 Nov 2024

    This issue was addressed with a new entitlement. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, watchOS 6.2. An application may be able to use an SSH client provided by private frameworks.

    Published: 1 Apr 2020
    5.5
    Medium

    CVE-2020-3914

    Last Modified: 21 Nov 2024

    A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. An application may be able to read restricted memory.

    Published: 1 Apr 2020
    9.8
    Critical

    CVE-2020-3911

    Last Modified: 21 Nov 2024

    A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Multiple issues in libxml2.

    Published: 1 Apr 2020
    5.3
    Medium

    CVE-2020-3916

    Last Modified: 21 Nov 2024

    An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, watchOS 6.2. Setting an alternate app icon may disclose a photo without needing permission to access photos.

    Published: 1 Apr 2020
    7.8
    High

    CVE-2020-3913

    Last Modified: 21 Nov 2024

    A permissions issue existed. This issue was addressed with improved permission validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, watchOS 6.2. A malicious application may be able to elevate privileges.

    Published: 1 Apr 2020
    7.1
    High

    CVE-2020-3912

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A local user may be able to cause unexpected system termination or read kernel memory.

    Published: 1 Apr 2020
    9.8
    Critical

    CVE-2020-3909

    Last Modified: 21 Nov 2024

    A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Multiple issues in libxml2.

    Published: 1 Apr 2020
    7.1
    High

    CVE-2020-3908

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A local user may be able to cause unexpected system termination or read kernel memory.

    Published: 1 Apr 2020
    7.8
    High

    CVE-2020-3905

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be able to execute arbitrary code with kernel privileges.

    Published: 1 Apr 2020
    7.1
    High

    CVE-2020-3907

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A local user may be able to cause unexpected system termination or read kernel memory.

    Published: 1 Apr 2020
    7.8
    High

    CVE-2020-3904

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved state management. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be able to execute arbitrary code with kernel privileges.

    Published: 1 Apr 2020
    6.1
    Medium

    CVE-2020-3902

    Last Modified: 21 Nov 2024

    An input validation issue was addressed with improved input validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Processing maliciously crafted web content may lead to a cross site scripting attack.

    Published: 1 Apr 2020
    7.8
    High

    CVE-2020-3906

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.4. A maliciously crafted application may be able to bypass code signing enforcement.

    Published: 1 Apr 2020
    8.8
    High

    CVE-2020-3901

    Last Modified: 21 Nov 2024

    A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, watchOS 6.2, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 1 Apr 2020
    7.8
    High

    CVE-2020-3903

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.4. An application may be able to execute arbitrary code with system privileges.

    Published: 1 Apr 2020
    8.8
    High

    CVE-2020-3900

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, watchOS 6.2, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 1 Apr 2020
    8.8
    High

    CVE-2020-3895

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, watchOS 6.2, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 1 Apr 2020
    8.8
    High

    CVE-2020-3899

    Last Modified: 21 Nov 2024

    A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, watchOS 6.2, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. A remote attacker may be able to cause arbitrary code execution.

    Published: 1 Apr 2020
    3.1
    Low

    CVE-2020-3894

    Last Modified: 21 Nov 2024

    A race condition was addressed with additional validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. An application may be able to read restricted memory.

    Published: 1 Apr 2020
    8.8
    High

    CVE-2020-3897

    Last Modified: 21 Nov 2024

    A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, watchOS 6.2, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. A remote attacker may be able to cause arbitrary code execution.

    Published: 1 Apr 2020
    7.8
    High

    CVE-2020-3892

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be able to execute arbitrary code with kernel privileges.

    Published: 1 Apr 2020
    7.8
    High

    CVE-2020-3893

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be able to execute arbitrary code with kernel privileges.

    Published: 1 Apr 2020
    2.4
    Low

    CVE-2020-3891

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in iOS 13.4 and iPadOS 13.4, watchOS 6.2. A person with physical access to a locked iOS device may be able to respond to messages even when replies are disabled.

    Published: 1 Apr 2020
    4.3
    Medium

    CVE-2020-3885

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. A file URL may be incorrectly processed.

    Published: 1 Apr 2020
    4.3
    Medium

    CVE-2020-3887

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. A download's origin may be incorrectly associated.

    Published: 1 Apr 2020
    5.3
    Medium

    CVE-2020-3890

    Last Modified: 21 Nov 2024

    The issue was addressed with improved deletion. This issue is fixed in iOS 13.4 and iPadOS 13.4. Deleted messages groups may still be suggested as an autocompletion.

    Published: 1 Apr 2020
    4.3
    Medium

    CVE-2020-3888

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4. A maliciously crafted page may interfere with other web contexts.

    Published: 1 Apr 2020
    8.8
    High

    CVE-2020-3883

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. An application may be able to use arbitrary entitlements.

    Published: 1 Apr 2020
    5.5
    Medium

    CVE-2020-3889

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15.4. A local user may be able to read arbitrary files.

    Published: 1 Apr 2020
    6.1
    Medium

    CVE-2020-3884

    Last Modified: 21 Nov 2024

    An injection issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. A remote attacker may be able to cause arbitrary javascript code execution.

    Published: 1 Apr 2020
    5.5
    Medium

    CVE-2020-3881

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15.4. A local user may be able to view sensitive user information.

    Published: 1 Apr 2020
    7.5
    High

    CVE-2020-10868

    Last Modified: 21 Nov 2024

    An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to launch the Repair App RPC call from a Low Integrity process.

    Published: 1 Apr 2020
    9.8
    Critical

    CVE-2020-10867

    Last Modified: 21 Nov 2024

    An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to bypass intended access restrictions on tasks from an untrusted process, when Self Defense is enabled.

    Published: 1 Apr 2020
    7.5
    High

    CVE-2020-10866

    Last Modified: 21 Nov 2024

    An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to enumerate the network interfaces and access points from a Low Integrity process via RPC.

    Published: 1 Apr 2020
    7.5
    High

    CVE-2020-10865

    Last Modified: 21 Nov 2024

    An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to make arbitrary changes to the Components section of the Stats.ini file via RPC from a Low Integrity process.

    Published: 1 Apr 2020
    6.5
    Medium

    CVE-2020-10864

    Last Modified: 21 Nov 2024

    An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to trigger a reboot via RPC from a Low Integrity process.

    Published: 1 Apr 2020