CVE-2020-9983Out-of-bounds Write in Apple Safari

CWE-787Out-of-bounds Write10 documents8 sources
Severity
8.8HIGHNVD
EPSS
1.3%
top 20.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16
Latest updateMay 24

Description

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Safari 14.0. Processing maliciously crafted web content may lead to code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages8 packages

CVEListV5apple/safariunspecifiedSafari 14.0
NVDapple/safari< 14.0
NVDapple/ipados< 14.0
NVDapple/iphone_os< 14.0
NVDapple/tvos14.0

Also affects: Fedora 32, 33

🔴Vulnerability Details

3
GHSA
GHSA-6c43-4qm7-f3r6: An out-of-bounds write issue was addressed with improved bounds checking2022-05-24
CVEList
CVE-2020-9983: An out-of-bounds write issue was addressed with improved bounds checking2020-10-16
OSV
CVE-2020-9983: An out-of-bounds write issue was addressed with improved bounds checking2020-10-16

📋Vendor Advisories

6
Ubuntu
WebKitGTK vulnerabilities2020-11-26
Red Hat
webkitgtk: out-of-bounds write may lead to code execution2020-11-23
Apple
CVE-2020-9983: watchOS 7.02020-09-16
Apple
CVE-2020-9983: tvOS 14.02020-09-16
Apple
CVE-2020-9983: iTunes 12.10.9 for Windows2020-09-16
CVE-2020-9983 — Out-of-bounds Write in Apple Safari | cvebase