Vulnerabilities > Apple > Iphone OS > 13.3

DATE CVE VULNERABILITY TITLE RISK
2020-02-24 CVE-2019-20044 Improper Check for Dropped Privileges vulnerability in multiple products
In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option.
local
low complexity
zsh fedoraproject debian apple CWE-273
7.8
2019-12-18 CVE-2019-8742 Information Exposure vulnerability in Apple Iphone OS
The issue was addressed by restricting options offered on a locked device.
local
low complexity
apple CWE-200
2.1
2019-12-18 CVE-2019-8727 Improper Input Validation vulnerability in Apple Iphone OS
A logic issue was addressed with improved state management.
network
apple CWE-20
4.3
2019-12-18 CVE-2019-8711 Information Exposure vulnerability in Apple Iphone OS
A logic issue existed with the display of notification previews.
network
low complexity
apple CWE-200
5.0
2019-12-18 CVE-2019-8674 Cross-site Scripting vulnerability in multiple products
A logic issue was addressed with improved state management.
network
low complexity
apple webkitgtk CWE-79
6.1
2019-12-11 CVE-2019-14899 Man-in-the-Middle vulnerability in multiple products
A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences about the websites they are visiting, and determine the correct sequence and acknowledgement numbers in use, allowing the bad actor to inject data into the TCP stream.
low complexity
freebsd linux openbsd apple CWE-300
7.4
2019-10-03 CVE-2019-15165 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.
5.3