CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2020-3858

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1. An application may be able to execute arbitrary code with kernel privileges.

    Published: 27 Feb 2020
    5.5
    Medium

    CVE-2020-3866

    Last Modified: 21 Nov 2024

    This was addressed with additional checks by Gatekeeper on files mounted through a network share. This issue is fixed in macOS Catalina 10.15.3. Searching for and opening a file from an attacker controlled NFS mount may bypass Gatekeeper.

    Published: 27 Feb 2020
    5.3
    Medium

    CVE-2020-3869

    Last Modified: 21 Nov 2024

    An issue existed in the handling of the local user's self-view. The issue was corrected with improved logic. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1. A remote FaceTime user may be able to cause the local user's camera self-view to display the incorrect camera.

    Published: 27 Feb 2020
    7.8
    High

    CVE-2020-3871

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.3. An application may be able to execute arbitrary code with kernel privileges.

    Published: 27 Feb 2020
    5.5
    Medium

    CVE-2020-3872

    Last Modified: 21 Nov 2024

    A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to read restricted memory.

    Published: 27 Feb 2020
    3.3
    Low

    CVE-2020-3873

    Last Modified: 21 Nov 2024

    This issue was addressed with improved setting propagation. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1. Turning off "Load remote content in messages” may not apply to all mail previews.

    Published: 27 Feb 2020
    7.5
    High

    CVE-2020-3877

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3, watchOS 6.1.2. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.

    Published: 27 Feb 2020
    7.8
    High

    CVE-2020-3878

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing a maliciously crafted image may lead to arbitrary code execution.

    Published: 27 Feb 2020
    8.8
    High

    CVE-2020-3846

    Last Modified: 21 Nov 2024

    A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution.

    Published: 27 Feb 2020
    7.8
    High

    CVE-2020-3853

    Last Modified: 21 Nov 2024

    A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. A malicious application may be able to execute arbitrary code with system privileges.

    Published: 27 Feb 2020
    7.8
    High

    CVE-2020-3857

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with system privileges.

    Published: 27 Feb 2020
    7.8
    High

    CVE-2020-3860

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with kernel privileges.

    Published: 27 Feb 2020
    5.3
    Medium

    CVE-2020-3874

    Last Modified: 21 Nov 2024

    An issued existed in the naming of screenshots. The issue was corrected with improved naming. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1. Screenshots of the Messages app may reveal additional message content.

    Published: 27 Feb 2020
    7.8
    High

    CVE-2020-3842

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with kernel privileges.

    Published: 27 Feb 2020
    7.8
    High

    CVE-2020-3840

    Last Modified: 21 Nov 2024

    An off by one issue existed in the handling of racoon configuration files. This issue was addressed through improved bounds checking. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1. Loading a maliciously crafted racoon configuration file may lead to arbitrary code execution.

    Published: 27 Feb 2020
    8.8
    High

    CVE-2020-3825

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 27 Feb 2020
    7
    High

    CVE-2020-3831

    Last Modified: 21 Nov 2024

    A race condition was addressed with improved locking. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1. An application may be able to execute arbitrary code with kernel privileges.

    Published: 27 Feb 2020
    4.3
    Medium

    CVE-2020-3833

    Last Modified: 21 Nov 2024

    An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 13.0.5. Visiting a malicious website may lead to address bar spoofing.

    Published: 27 Feb 2020
    5.5
    Medium

    CVE-2020-3836

    Last Modified: 21 Nov 2024

    An access issue was addressed with improved memory management. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. A malicious application may be able to determine kernel memory layout.

    Published: 27 Feb 2020
    5.5
    Medium

    CVE-2020-3839

    Last Modified: 21 Nov 2024

    A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.3. An application may be able to read restricted memory.

    Published: 27 Feb 2020
    7.8
    High

    CVE-2020-3845

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.3. An application may be able to execute arbitrary code with system privileges.

    Published: 27 Feb 2020
    7.8
    High

    CVE-2020-3826

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing a maliciously crafted image may lead to arbitrary code execution.

    Published: 27 Feb 2020
    7.8
    High

    CVE-2020-3827

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. Viewing a maliciously crafted JPEG file may lead to arbitrary code execution.

    Published: 27 Feb 2020
    2.4
    Low

    CVE-2020-3828

    Last Modified: 21 Nov 2024

    A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1. A person with physical access to an iOS device may be able to access contacts from the lock screen.

    Published: 27 Feb 2020
    7.8
    High

    CVE-2020-3829

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to gain elevated privileges.

    Published: 27 Feb 2020
    7.8
    High

    CVE-2020-3834

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 6.1.2. An application may be able to execute arbitrary code with kernel privileges.

    Published: 27 Feb 2020
    6.5
    Medium

    CVE-2020-3841

    Last Modified: 21 Nov 2024

    The issue was addressed with improved UI handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, Safari 13.0.5. A local user may unknowingly send a password unencrypted over the network.

    Published: 27 Feb 2020
    8.8
    High

    CVE-2020-3843

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.4.7, watchOS 5.3.7. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.

    Published: 27 Feb 2020
    3.3
    Low

    CVE-2020-3844

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1. Users removed from an iMessage conversation may still be able to alter state.

    Published: 27 Feb 2020
    2.4
    Low

    CVE-2020-3859

    Last Modified: 21 Nov 2024

    An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1. A person with physical access to an iOS device may be able to access contacts from the lock screen.

    Published: 27 Feb 2020
    7.8
    High

    CVE-2020-3837

    Last Modified: 23 Oct 2025

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with kernel privileges.

    Published: 27 Feb 2020
    3.3
    Low

    CVE-2020-3830

    Last Modified: 21 Nov 2024

    A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Catalina 10.15.3. A malicious application may be able to overwrite arbitrary files.

    Published: 27 Feb 2020
    4.4
    Medium

    CVE-2020-3835

    Last Modified: 21 Nov 2024

    A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Catalina 10.15.3. A malicious application may be able to access restricted files.

    Published: 27 Feb 2020
    7.8
    High

    CVE-2020-3838

    Last Modified: 21 Nov 2024

    The issue was addressed with improved permissions logic. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with system privileges.

    Published: 27 Feb 2020
    8.8
    High

    CVE-2020-5402

    Last Modified: 21 Nov 2024

    In Cloud Foundry UAA, versions prior to 74.14.0, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function when authenticating with external identity providers.

    Published: 27 Feb 2020
    5.3
    Medium

    CVE-2020-5401

    Last Modified: 21 Nov 2024

    Cloud Foundry Routing Release, versions prior to 0.197.0, contains GoRouter, which allows malicious clients to send invalid headers, causing caching layers to reject subsequent legitimate clients trying to access the app.

    Published: 27 Feb 2020
    6.5
    Medium

    CVE-2020-5400

    Last Modified: 21 Nov 2024

    Cloud Foundry Cloud Controller (CAPI), versions prior to 1.91.0, logs properties of background jobs when they are run, which may include sensitive information such as credentials if provided to the job. A malicious user with access to those logs may gain unauthorized access to resources protected by such credentials.

    Published: 27 Feb 2020
    5.5
    Medium

    CVE-2017-16900

    Last Modified: 21 Nov 2024

    Incorrect Access Control in Hunesion i-oneNet 3.0.6042.1200 allows the local user to access other user's information which is unauthorized via brute force.

    Published: 27 Feb 2020
    9.1
    Critical

    CVE-2020-7043

    Last Modified: 21 Nov 2024

    An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' characters, as demonstrated by a good.example.com\x00evil.example.com attack.

    Published: 27 Feb 2020
    5.3
    Medium

    CVE-2020-7042

    Last Modified: 21 Nov 2024

    An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outcome is that a valid certificate is never accepted (only a malformed certificate may be accepted).

    Published: 27 Feb 2020
    5.3
    Medium

    CVE-2020-7041

    Last Modified: 21 Nov 2024

    An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because an X509_check_host negative error code is interpreted as a successful return value.

    Published: 27 Feb 2020
    6.5
    Medium

    CVE-2020-6864

    Last Modified: 21 Nov 2024

    ZTE E8820V3 router product is impacted by an information leak vulnerability. Attackers could use this vulnerability to to gain wireless passwords. After obtaining the wireless password, the attacker could collect information and attack the router.

    Published: 27 Feb 2020
    6.5
    Medium

    CVE-2020-6863

    Last Modified: 21 Nov 2024

    ZTE E8820V3 router product is impacted by a permission and access control vulnerability. Attackers could use this vulnerability to tamper with DDNS parameters and send DoS attacks on the specified URL.

    Published: 27 Feb 2020
    7.2
    High

    CVE-2019-5326

    Last Modified: 21 Nov 2024

    An administrative application user of or application user with write access to Aruba Airwave VisualRF is able to obtain code execution on the AMP platform. This is possible due to the ability to overwrite a file on disk which is subsequently deserialized by the Java application component.

    Published: 27 Feb 2020
    7.2
    High

    CVE-2019-5323

    Last Modified: 21 Nov 2024

    There are command injection vulnerabilities present in the AirWave application. Certain input fields controlled by an administrative user are not properly sanitized before being parsed by AirWave. If conditions are met, an attacker can obtain command execution on the host.

    Published: 27 Feb 2020
    6.3
    Medium

    CVE-2019-4669

    Last Modified: 21 Nov 2024

    IBM Business Process Manager 8.5.7.0 through 8.5.7.0 2017.06, 8.6.0.0 through 8.6.0.0 CF2018.03, and IBM Business Automation Workflow 18.0.0.1 through 19.0.0.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 171254.

    Published: 27 Feb 2020
    —
    Unknown

    CVE-2019-12882

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 27 Feb 2020
    —
    Unknown

    CVE-2018-19668

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-17963. Reason: This candidate is a reservation duplicate of CVE-2018-17963. Notes: All CVE users should reference CVE-2018-17963 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 27 Feb 2020
    7.5
    High

    CVE-2017-6371

    Last Modified: 21 Nov 2024

    Synchronet BBS 3.16c for Windows allows remote attackers to cause a denial of service (service crash) via a long string in the HTTP Referer header.

    Published: 27 Feb 2020
    8.1
    High

    CVE-2017-6363

    Last Modified: 21 Nov 2024

    In the GD Graphics Library (aka LibGD) through 2.2.5, there is a heap-based buffer over-read in tiffWriter in gd_tiff.c. NOTE: the vendor says "In my opinion this issue should not have a CVE, since the GD and GD2 formats are documented to be 'obsolete, and should only be used for development and testing purposes.'

    Published: 27 Feb 2020