7.8
CVSSv3

CVE-2020-9859

Published: 05/06/2020 Updated: 09/01/2023
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5 Supplemental Update, tvOS 13.4.6, watchOS 6.2.6. An application may be able to execute arbitrary code with kernel privileges.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple tvos

apple mac os x

apple iphone os

apple watchos

apple ipados

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> APPLE-SA-2020-06-01-1 iOS 1351 and iPadOS 1351 <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Apple ...
<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> APPLE-SA-2020-06-01-2 macOS Catalina 10155 Supplemental Update, Security Update 2020-003 High Sierra <!--X-Subject-H ...
<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> APPLE-SA-2020-06-01-3 tvOS 1346 <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Apple Product Security ...

Recent Articles

Tycoon malware rages through US schools, LG's boot problem, and QNAP admins had better get busy
The Register • Shaun Nichols in San Francisco • 08 Jun 2020

Also: Cisco and Apple push out patches

It is time once again for El Reg's weekly security roundup. Here's a look at a few of the more interesting stories making the rounds over the past seven days. A few weeks back, hackers dumped limited information on some 40 million people who used Wishbone, a sort of polling app where users choose between two different items. Now, the lawyers have stepped in and filed a class action suit against Mammoth Media, the company that made the leaky app. Of particular interest is the fact that many of th...