Vulnerabilities > Apple > Macos > 9

DATE CVE VULNERABILITY TITLE RISK
2021-04-02 CVE-2020-27899 Use After Free vulnerability in Apple products
A use after free issue was addressed with improved memory management.
local
low complexity
apple CWE-416
7.8
2020-12-11 CVE-2020-13520 Out-of-bounds Write vulnerability in multiple products
An out of bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 reconstructs paths from binary USD files.
network
pixar apple CWE-787
6.8
2020-12-08 CVE-2020-27918 Use After Free vulnerability in multiple products
A use after free issue was addressed with improved memory management.
local
low complexity
apple fedoraproject debian webkitgtk CWE-416
7.8
2020-12-08 CVE-2020-27909 Out-of-bounds Read vulnerability in Apple products
An out-of-bounds read was addressed with improved input validation.
local
low complexity
apple CWE-125
7.8
2020-12-08 CVE-2020-9972 Classic Buffer Overflow vulnerability in Apple products
A buffer overflow issue was addressed with improved memory handling.
network
apple CWE-120
6.8
2020-12-08 CVE-2020-9849 Information Exposure vulnerability in Apple products
An information disclosure issue was addressed with improved state management.
network
low complexity
apple CWE-200
6.5
2020-12-08 CVE-2020-10014 Path Traversal vulnerability in Apple mac OS X and Macos
A parsing issue in the handling of directory paths was addressed with improved path validation.
local
low complexity
apple CWE-22
6.3
2020-12-08 CVE-2020-10012 Cross-site Scripting vulnerability in Apple mac OS X and Macos
An access issue was addressed with improved access restrictions.
network
low complexity
apple CWE-79
6.1
2020-11-03 CVE-2020-15969 Use After Free vulnerability in multiple products
Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google debian fedoraproject opensuse apple CWE-416
8.8
2020-06-27 CVE-2020-15358 Out-of-bounds Write vulnerability in multiple products
In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.
local
low complexity
sqlite canonical apple oracle siemens CWE-787
2.1