Vulnerabilities > Apple > Ipados > 14.2

DATE CVE VULNERABILITY TITLE RISK
2021-04-02 CVE-2020-29613 Unspecified vulnerability in Apple Ipados and Iphone OS
A logic issue was addressed with improved state management.
local
low complexity
apple
5.5
2021-04-02 CVE-2020-29611 Out-of-bounds Write vulnerability in Apple products
An out-of-bounds write issue was addressed with improved bounds checking.
local
low complexity
apple CWE-787
7.8
2021-04-02 CVE-2020-29610 Out-of-bounds Read vulnerability in Apple products
An out-of-bounds read was addressed with improved input validation.
local
low complexity
apple CWE-125
5.5
2021-04-02 CVE-2020-29608 Out-of-bounds Read vulnerability in Apple products
An out-of-bounds read was addressed with improved bounds checking.
local
low complexity
apple CWE-125
5.5
2021-04-02 CVE-2020-27951 Unspecified vulnerability in Apple Ipados, Iphone OS and Watchos
This issue was addressed with improved checks.
local
low complexity
apple
7.8
2021-04-02 CVE-2020-27948 Out-of-bounds Write vulnerability in Apple products
An out-of-bounds write issue was addressed with improved bounds checking.
local
low complexity
apple CWE-787
7.8
2021-04-02 CVE-2020-27946 Unspecified vulnerability in Apple products
An information disclosure issue was addressed with improved state management.
local
low complexity
apple
5.5
2021-03-26 CVE-2020-7463 Use After Free vulnerability in multiple products
In FreeBSD 12.1-STABLE before r364644, 11.4-STABLE before r364651, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 11.3-RELEASE before p13, improper handling in the kernel causes a use-after-free bug by sending large user messages from multiple threads on the same SCTP socket.
local
low complexity
freebsd apple CWE-416
5.5
2021-02-16 CVE-2021-23841 NULL Pointer Dereference vulnerability in multiple products
The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate.
5.9
2020-11-03 CVE-2020-15969 Use After Free vulnerability in multiple products
Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google debian fedoraproject opensuse apple CWE-416
8.8