Apple Ios 13.6 And Ipados vulnerabilities
71 known vulnerabilities affecting apple/ios_13.6_and_ipados.
Total CVEs
71
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
3
Severity breakdown
CRITICAL6HIGH47MEDIUM17LOW1
Vulnerabilities
Page 3 of 4
CVE-2020-9905P3HIGHCVSS 7.5v13.62020-07-15
CVE-2020-9905 [HIGH] CVE-2020-9905: iOS 13.6 and iPadOS 13.6
Apple Security Update: About the security content of iOS 13.6 and iPadOS 13.6
Product: iOS 13.6 and iPadOS
Version: 13.6
CVE: CVE-2020-9905
Component: Kernel
Impact: A remote attacker may be able to cause a denial of service
Description: A buffer overflow was addressed with improved bounds checking.
apple
CVE-2020-9985P3HIGHCVSS 7.8v13.62020-07-15
CVE-2020-9985 [HIGH] CVE-2020-9985: iOS 13.6 and iPadOS 13.6
Apple Security Update: About the security content of iOS 13.6 and iPadOS 13.6
Product: iOS 13.6 and iPadOS
Version: 13.6
CVE: CVE-2020-9985
Component: Model I/O
Impact: Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution
Description: A buffer overflow issue was addressed with improved memory handling.
apple
CVE-2020-9880P3HIGHCVSS 7.8v13.62020-07-15
CVE-2020-9880 [HIGH] CVE-2020-9880: iOS 13.6 and iPadOS 13.6
Apple Security Update: About the security content of iOS 13.6 and iPadOS 13.6
Product: iOS 13.6 and iPadOS
Version: 13.6
CVE: CVE-2020-9880
Component: Model I/O
Impact: Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution
Description: A buffer overflow was addressed with improved bounds checking.
apple
CVE-2020-9940P3HIGHCVSS 7.8v13.62020-07-15
CVE-2020-9940 [HIGH] CVE-2020-9940: iOS 13.6 and iPadOS 13.6
Apple Security Update: About the security content of iOS 13.6 and iPadOS 13.6
Product: iOS 13.6 and iPadOS
Version: 13.6
CVE: CVE-2020-9940
Component: Model I/O
Impact: Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution
Description: A buffer overflow issue was addressed with improved memory handling.
apple
CVE-2020-9882P3HIGHCVSS 7.8v13.62020-07-15
CVE-2020-9882 [HIGH] CVE-2020-9882: iOS 13.6 and iPadOS 13.6
Apple Security Update: About the security content of iOS 13.6 and iPadOS 13.6
Product: iOS 13.6 and iPadOS
Version: 13.6
CVE: CVE-2020-9882
Component: Model I/O
Impact: Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution
Description: A buffer overflow issue was addressed with improved memory handling.
apple
CVE-2020-9881P3HIGHCVSS 7.8v13.62020-07-15
CVE-2020-9881 [HIGH] CVE-2020-9881: iOS 13.6 and iPadOS 13.6
Apple Security Update: About the security content of iOS 13.6 and iPadOS 13.6
Product: iOS 13.6 and iPadOS
Version: 13.6
CVE: CVE-2020-9881
Component: Model I/O
Impact: Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution
Description: A buffer overflow issue was addressed with improved memory handling.
apple
CVE-2020-9923P3HIGHCVSS 7.8v13.62020-07-15
CVE-2020-9923 [HIGH] CVE-2020-9923: iOS 13.6 and iPadOS 13.6
Apple Security Update: About the security content of iOS 13.6 and iPadOS 13.6
Product: iOS 13.6 and iPadOS
Version: 13.6
CVE: CVE-2020-9923
Component: Kernel
Impact: A malicious application may be able to execute arbitrary code with system privileges
Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2020-9911P3HIGHCVSS 7.5v13.62020-07-15
CVE-2020-9911 [HIGH] CVE-2020-9911: iOS 13.6 and iPadOS 13.6
Apple Security Update: About the security content of iOS 13.6 and iPadOS 13.6
Product: iOS 13.6 and iPadOS
Version: 13.6
CVE: CVE-2020-9911
Component: Safari Reader
Impact: An issue in Safari Reader mode may allow a remote attacker to bypass the Same Origin Policy
Description: A logic issue was addressed with improved restrictions.
apple
CVE-2020-9900P3HIGHCVSS 7.8v13.62020-07-15
CVE-2020-9900 [HIGH] CVE-2020-9900: iOS 13.6 and iPadOS 13.6
Apple Security Update: About the security content of iOS 13.6 and iPadOS 13.6
Product: iOS 13.6 and iPadOS
Version: 13.6
CVE: CVE-2020-9900
Component: Crash Reporter
Impact: A local attacker may be able to elevate their privileges
Description: An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization.
apple
CVE-2020-9901P3HIGHCVSS 7.8v13.62020-07-15
CVE-2020-9901 [HIGH] CVE-2020-9901: iOS 13.6 and iPadOS 13.6
Apple Security Update: About the security content of iOS 13.6 and iPadOS 13.6
Product: iOS 13.6 and iPadOS
Version: 13.6
CVE: CVE-2020-9901
Component: Security
Impact: An attacker may have been able to impersonate a trusted website using shared key material for an administrator added certificate
Description: A certificate validation issue existed when processing administrator added certificates. This issue was addressed with improved c
apple
CVE-2020-9914P3HIGHCVSS 7.5v13.62020-07-15
CVE-2020-9914 [HIGH] CVE-2020-9914: iOS 13.6 and iPadOS 13.6
Apple Security Update: About the security content of iOS 13.6 and iPadOS 13.6
Product: iOS 13.6 and iPadOS
Version: 13.6
CVE: CVE-2020-9914
Component: GeoServices
Impact: A malicious application may be able to read sensitive location information
Description: An authorization issue was addressed with improved state management.
apple
CVE-2020-9931P3HIGHCVSS 7.5v13.62020-07-15
CVE-2020-9931 [HIGH] CVE-2020-9931: iOS 13.6 and iPadOS 13.6
Apple Security Update: About the security content of iOS 13.6 and iPadOS 13.6
Product: iOS 13.6 and iPadOS
Version: 13.6
CVE: CVE-2020-9931
Component: Bluetooth
Impact: A remote attacker may cause an unexpected application termination
Description: A denial of service issue was addressed with improved input validation.
apple
CVE-2019-14899P3HIGHCVSS 7.4v13.62020-07-15
CVE-2019-14899 [HIGH] CVE-2019-14899: iOS 13.6 and iPadOS 13.6
Apple Security Update: About the security content of iOS 13.6 and iPadOS 13.6
Product: iOS 13.6 and iPadOS
Version: 13.6
CVE: CVE-2019-14899
Component: Kernel
Impact: An attacker in a privileged network position may be able to inject into active connections within a VPN tunnel
Description: A routing issue was addressed with improved restrictions.
apple
CVE-2020-9903P3HIGHCVSS 7.5v13.62020-07-15
CVE-2020-9903 [HIGH] CVE-2020-9903: iOS 13.6 and iPadOS 13.6
Apple Security Update: About the security content of iOS 13.6 and iPadOS 13.6
Product: iOS 13.6 and iPadOS
Version: 13.6
CVE: CVE-2020-9903
Component: Safari Login AutoFill
Impact: A malicious attacker may cause Safari to suggest a password for the wrong domain
Description: A logic issue was addressed with improved restrictions.
apple
CVE-2020-9917P3HIGHCVSS 7.5v13.62020-07-15
CVE-2020-9917 [HIGH] CVE-2020-9917: iOS 13.6 and iPadOS 13.6
Apple Security Update: About the security content of iOS 13.6 and iPadOS 13.6
Product: iOS 13.6 and iPadOS
Version: 13.6
CVE: CVE-2020-9917
Component: Wi-Fi
Impact: A remote attacker may be able to cause a denial of service
Description: This issue was addressed with improved checks.
apple
CVE-2020-9915P4MEDIUMCVSS 6.5v13.62020-07-15
CVE-2020-9915 [MEDIUM] CVE-2020-9915: iOS 13.6 and iPadOS 13.6
Apple Security Update: About the security content of iOS 13.6 and iPadOS 13.6
Product: iOS 13.6 and iPadOS
Version: 13.6
CVE: CVE-2020-9915
Component: WebKit
Impact: Processing maliciously crafted web content may prevent Content Security Policy from being enforced
Description: An access issue existed in Content Security Policy. This issue was addressed with improved access restrictions.
apple
CVE-2020-9909P4MEDIUMCVSS 5.9v13.62020-07-15
CVE-2020-9909 [MEDIUM] CVE-2020-9909: iOS 13.6 and iPadOS 13.6
Apple Security Update: About the security content of iOS 13.6 and iPadOS 13.6
Product: iOS 13.6 and iPadOS
Version: 13.6
CVE: CVE-2020-9909
Component: Kernel
Impact: An attacker that has already achieved kernel code execution may be able to bypass kernel memory mitigations
Description: An out-of-bounds read was addressed with improved bounds checking.
apple
CVE-2020-9925P4MEDIUMCVSS 6.1v13.62020-07-15
CVE-2020-9925 [MEDIUM] CVE-2020-9925: iOS 13.6 and iPadOS 13.6
Apple Security Update: About the security content of iOS 13.6 and iPadOS 13.6
Product: iOS 13.6 and iPadOS
Version: 13.6
CVE: CVE-2020-9925
Component: WebKit
Impact: Processing maliciously crafted web content may lead to universal cross site scripting
Description: A logic issue was addressed with improved state management.
apple
CVE-2020-9916P4MEDIUMCVSS 5.3v13.62020-07-15
CVE-2020-9916 [MEDIUM] CVE-2020-9916: iOS 13.6 and iPadOS 13.6
Apple Security Update: About the security content of iOS 13.6 and iPadOS 13.6
Product: iOS 13.6 and iPadOS
Version: 13.6
CVE: CVE-2020-9916
Component: WebKit Page Loading
Impact: A malicious attacker may be able to conceal the destination of a URL
Description: A URL Unicode encoding issue was addressed with improved state management.
apple
CVE-2020-9894P4MEDIUMCVSS 4.3v13.62020-07-15
CVE-2020-9894 [MEDIUM] CVE-2020-9894: iOS 13.6 and iPadOS 13.6
Apple Security Update: About the security content of iOS 13.6 and iPadOS 13.6
Product: iOS 13.6 and iPadOS
Version: 13.6
CVE: CVE-2020-9894
Component: WebKit
Impact: A remote attacker may be able to cause unexpected application termination or arbitrary code execution
Description: An out-of-bounds read was addressed with improved input validation.
apple