cbcvebase.

Apple Ios 14.2 And Ipados vulnerabilities

32 known vulnerabilities affecting apple/ios_14.2_and_ipados.

Total CVEs
32
CISA KEV
3
actively exploited
Public exploits
2
Exploited in wild
3
Severity breakdown
HIGH25MEDIUM7

Vulnerabilities

Page 2 of 2
CVE-2020-27922P3HIGHCVSS 7.8v14.22020-11-05
CVE-2020-27922 [HIGH] CVE-2020-27922: iOS 14.2 and iPadOS 14.2 Apple Security Update: About the security content of iOS 14.2 and iPadOS 14.2 Product: iOS 14.2 and iPadOS Version: 14.2 CVE: CVE-2020-27922 Component: CoreText Impact: Processing a maliciously crafted font file may lead to arbitrary code execution Description: A logic issue was addressed with improved state management.
apple
CVE-2020-10011P3HIGHCVSS 7.8v14.22020-11-05
CVE-2020-10011 [HIGH] CVE-2020-10011: iOS 14.2 and iPadOS 14.2 Apple Security Update: About the security content of iOS 14.2 and iPadOS 14.2 Product: iOS 14.2 and iPadOS Version: 14.2 CVE: CVE-2020-10011 Component: Model I/O Impact: Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution Description: An out-of-bounds read was addressed with improved bounds checking.
apple
CVE-2020-27926P3HIGHCVSS 7.8v14.22020-11-05
CVE-2020-27926 [HIGH] CVE-2020-27926: iOS 14.2 and iPadOS 14.2 Apple Security Update: About the security content of iOS 14.2 and iPadOS 14.2 Product: iOS 14.2 and iPadOS Version: 14.2 CVE: CVE-2020-27926 Component: Keyboard Impact: A person with physical access to an iOS device may be able to access stored passwords without authentication Description: An authentication issue was addressed with improved state management.
apple
CVE-2020-10010P3HIGHCVSS 7.8v14.22020-11-05
CVE-2020-10010 [HIGH] CVE-2020-10010: iOS 14.2 and iPadOS 14.2 Apple Security Update: About the security content of iOS 14.2 and iPadOS 14.2 Product: iOS 14.2 and iPadOS Version: 14.2 CVE: CVE-2020-10010 Component: Logging Impact: A local attacker may be able to elevate their privileges Description: A path handling issue was addressed with improved validation.
apple
CVE-2020-10003P3HIGHCVSS 7.8v14.22020-11-05
CVE-2020-10003 [HIGH] CVE-2020-10003: iOS 14.2 and iPadOS 14.2 Apple Security Update: About the security content of iOS 14.2 and iPadOS 14.2 Product: iOS 14.2 and iPadOS Version: 14.2 CVE: CVE-2020-10003 Component: Crash Reporter Impact: A local attacker may be able to elevate their privileges Description: An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization.
apple
CVE-2020-27899P3HIGHCVSS 7.8v14.22020-11-05
CVE-2020-27899 [HIGH] CVE-2020-27899: iOS 14.2 and iPadOS 14.2 Apple Security Update: About the security content of iOS 14.2 and iPadOS 14.2 Product: iOS 14.2 and iPadOS Version: 14.2 CVE: CVE-2020-27899 Component: Symptom Framework Impact: A local attacker may be able to elevate their privileges Description: A use after free issue was addressed with improved memory management.
apple
CVE-2020-10002P4MEDIUMCVSS 5.5v14.22020-11-05
CVE-2020-10002 [MEDIUM] CVE-2020-10002: iOS 14.2 and iPadOS 14.2 Apple Security Update: About the security content of iOS 14.2 and iPadOS 14.2 Product: iOS 14.2 and iPadOS Version: 14.2 CVE: CVE-2020-10002 Component: Foundation Impact: A local user may be able to read arbitrary files Description: A logic issue was addressed with improved state management.
apple
CVE-2020-27935P4MEDIUMCVSS 6.3v14.22020-11-05
CVE-2020-27935 [MEDIUM] CVE-2020-27935: iOS 14.2 and iPadOS 14.2 Apple Security Update: About the security content of iOS 14.2 and iPadOS 14.2 Product: iOS 14.2 and iPadOS Version: 14.2 CVE: CVE-2020-27935 Component: XNU Impact: A sandboxed process may be able to circumvent sandbox restrictions Description: Multiple issues were addressed with improved logic.
apple
CVE-2020-9974P4MEDIUMCVSS 5.5v14.22020-11-05
CVE-2020-9974 [MEDIUM] CVE-2020-9974: iOS 14.2 and iPadOS 14.2 Apple Security Update: About the security content of iOS 14.2 and iPadOS 14.2 Product: iOS 14.2 and iPadOS Version: 14.2 CVE: CVE-2020-9974 Component: Kernel Impact: A malicious application may be able to determine kernel memory layout Description: A logic issue was addressed with improved state management.
apple
CVE-2020-13524P4MEDIUMCVSS 5.5v14.22020-11-05
CVE-2020-13524 [MEDIUM] CVE-2020-13524: iOS 14.2 and iPadOS 14.2 Apple Security Update: About the security content of iOS 14.2 and iPadOS 14.2 Product: iOS 14.2 and iPadOS Version: 14.2 CVE: CVE-2020-13524 Component: Model I/O Impact: Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution Description: An out-of-bounds read was addressed with improved input validation.
apple
CVE-2020-27925P4MEDIUMCVSS 5.5v14.22020-11-05
CVE-2020-27925 [MEDIUM] CVE-2020-27925: iOS 14.2 and iPadOS 14.2 Apple Security Update: About the security content of iOS 14.2 and iPadOS 14.2 Product: iOS 14.2 and iPadOS Version: 14.2 CVE: CVE-2020-27925 Component: CallKit Impact: A user may answer two calls simultaneously without indication they have answered a second call Description: An issue existed in the handling of incoming calls. The issue was addressed with additional state checks.
apple
CVE-2020-27902P4MEDIUMCVSS 4.6v14.22020-11-05
CVE-2020-27902 [MEDIUM] CVE-2020-27902: iOS 14.2 and iPadOS 14.2 Apple Security Update: About the security content of iOS 14.2 and iPadOS 14.2 Product: iOS 14.2 and iPadOS Version: 14.2 CVE: CVE-2020-27902 Component: Keyboard Impact: A person with physical access to an iOS device may be able to access stored passwords without authentication Description: An authentication issue was addressed with improved state management.
apple