cbcvebase.
CVE-2020-9932
published 2020-10-27

CVE-2020-9932: A memory corruption issue was addressed with improved validation. This issue is fixed in Safari 13.0.1, iOS 13.1 and iPadOS 13.1, tvOS 13. Processing…

PriorityP347high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.12%
62.4th percentile
A memory corruption issue was addressed with improved validation. This issue is fixed in Safari 13.0.1, iOS 13.1 and iPadOS 13.1, tvOS 13. Processing maliciously crafted web content may lead to arbitrary code execution.

Affected

10 ranges
VendorProductVersion rangeFixed in
appleios_13.1_and_ipados
appleios_and_ipados>= unspecified < 13.113.1
appleipados< 13.113.1
appleiphone_os< 13.113.1
applesafari< 13.0.113.0.1
applesafari
applesafari>= unspecified < 13.013.0
appletvos< 13.013.0
appletvos
appletvos>= unspecified < 1313

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.