Vulnerabilities > Apple > High

DATE CVE VULNERABILITY TITLE RISK
2020-12-08 CVE-2020-9947 Use After Free vulnerability in Apple products
A use after free issue was addressed with improved memory management.
network
low complexity
apple CWE-416
8.8
2020-12-08 CVE-2020-10016 Out-of-bounds Write vulnerability in Apple products
A memory corruption issue was addressed with improved state management.
local
low complexity
apple CWE-787
7.8
2020-12-08 CVE-2020-10013 Unspecified vulnerability in Apple products
A logic issue was addressed with improved state management.
local
low complexity
apple
7.8
2020-12-08 CVE-2020-10011 Out-of-bounds Read vulnerability in Apple products
An out-of-bounds read was addressed with improved bounds checking.
local
low complexity
apple CWE-125
7.8
2020-12-08 CVE-2020-10010 Path Traversal vulnerability in Apple products
A path handling issue was addressed with improved validation.
local
low complexity
apple CWE-22
7.8
2020-12-08 CVE-2020-10004 Unspecified vulnerability in Apple products
A logic issue was addressed with improved state management.
local
low complexity
apple
7.8
2020-12-08 CVE-2020-10003 Link Following vulnerability in Apple products
An issue existed within the path validation logic for symlinks.
local
low complexity
apple CWE-59
7.8
2020-11-13 CVE-2020-6147 Out-of-bounds Write vulnerability in multiple products
A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files.
local
low complexity
pixar apple CWE-787
7.8
2020-11-04 CVE-2020-8037 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.
network
low complexity
tcpdump debian fedoraproject apple CWE-770
7.5
2020-11-03 CVE-2020-15969 Use After Free vulnerability in multiple products
Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google debian fedoraproject opensuse apple CWE-416
8.8