cbcvebase.
CVE-2020-9952
published 2020-10-16

CVE-2020-9952: An input validation issue was addressed with improved input validation. This issue is fixed in iOS 14.0 and iPadOS 14.0, tvOS 14.0, watchOS 7.0, Safari 14.0…

PriorityP434high7.1CVSS 3.1
AVNACLPRNUIRSCCLILAL
EPSS
1.50%
71.3th percentile
An input validation issue was addressed with improved input validation. This issue is fixed in iOS 14.0 and iPadOS 14.0, tvOS 14.0, watchOS 7.0, Safari 14.0, iCloud for Windows 11.4, iCloud for Windows 7.21. Processing maliciously crafted web content may lead to a cross site scripting attack.

Affected

20 ranges
VendorProductVersion rangeFixed in
appleicloud< 7.217.21
appleicloud>= 11.0 < 11.411.4
appleicloud_for_windows
appleicloud_for_windows
appleicloud_for_windows>= unspecified < iCloud for Windows 11.4iCloud for Windows 11.4
appleicloud_for_windows>= unspecified < iCloud for Windows 7.21iCloud for Windows 7.21
appleios>= unspecified < iOS 14.0 and iPadOS 14.0iOS 14.0 and iPadOS 14.0
appleipados< 14.014.0
appleiphone_os< 14.014.0
applesafari< 14.014.0
applesafari>= unspecified < Safari 14.0Safari 14.0
appletvos< 14.014.0
appletvos
appletvos>= unspecified < tvOS 14.0tvOS 14.0
applewatchos< 7.07.0
applewatchos
applewatchos>= unspecified < watchOS 7.0watchOS 7.0
debianwebkit2gtk< webkit2gtk 2.28.3-1 (bookworm)webkit2gtk 2.28.3-1 (bookworm)
debianwpewebkit< webkit2gtk 2.28.3-1 (bookworm)webkit2gtk 2.28.3-1 (bookworm)
webkitwebkitgtk<= 2.30.3

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.