cbcvebase.
CVE-2020-9814
published 2020-06-09

CVE-2020-9814: A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS…

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A malicious application may be able to execute arbitrary code with kernel privileges.

Affected

10 ranges
VendorProductVersion rangeFixed in
appleios>= unspecified < iOS 13.5 and iPadOS 13.5iOS 13.5 and iPadOS 13.5
appleipados< 13.513.5
appleiphone_os< 13.513.5
applemac_os_x< 10.15.510.15.5
applemacos>= unspecified < macOS Catalina 10.15.5macOS Catalina 10.15.5
appletvos< 13.4.513.4.5
appletvos>= unspecified < tvOS 13.4.5tvOS 13.4.5
applewatchos< 6.2.56.2.5
applewatchos>= unspecified < watchOS 6.2.5watchOS 6.2.5
cairographicscairo>= 0 < 1.14.6-1ubuntu0.1~esm11.14.6-1ubuntu0.1~esm1

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv5.5MEDIUM