Vulnerabilities > Apple > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-12-03 CVE-2020-13524 Out-of-bounds Write vulnerability in multiple products
An out-of-bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 uses SPECS data from binary USD files.
local
low complexity
pixar apple CWE-787
5.5
2020-10-27 CVE-2020-9982 Unspecified vulnerability in Apple Music 3.4.0
This issue was addressed with improved checks to prevent unauthorized actions.
local
low complexity
apple
5.5
2020-10-27 CVE-2020-9979 Unspecified vulnerability in Apple Iphone OS
A trust issue was addressed by removing a legacy API.
local
low complexity
apple
5.5
2020-10-27 CVE-2020-9860 Unspecified vulnerability in Apple Safari
A custom URL scheme handling issue was addressed with improved input validation.
network
low complexity
apple
5.4
2020-10-27 CVE-2020-9857 Unspecified vulnerability in Apple mac OS X
An issue existed in the parsing of URLs.
network
low complexity
apple
4.3
2020-10-27 CVE-2020-3852 Incorrect Authorization vulnerability in Apple Safari
A logic issue was addressed with improved validation.
network
low complexity
apple CWE-863
5.3
2020-10-27 CVE-2019-8901 Improper Verification of Cryptographic Signature vulnerability in Apple Ipados and Iphone OS
This issue was addressed by verifying host keys when connecting to a previously-known SSH server.
network
low complexity
apple CWE-347
6.5
2020-10-27 CVE-2019-8898 Unspecified vulnerability in Apple products
An information disclosure issue existed in the handling of the Storage Access API.
network
low complexity
apple
4.3
2020-10-27 CVE-2019-8858 Unspecified vulnerability in Apple mac OS X
A logic issue was addressed with improved state management.
network
low complexity
apple
5.3
2020-10-27 CVE-2019-8855 Unspecified vulnerability in Apple mac OS X
An access issue was addressed with additional sandbox restrictions.
local
low complexity
apple
6.3