Apple Security Advisories · February 2020 — Apple Security Advisories
9 advisories 9 CVEs

Apple-vendor CVEs for 2020-02. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2019-15126

OtherWeaponized exploitHIGH2020-02-05

An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility ...

CVEs:CVE-2019-15126

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
Upstream advisory

CVE-2011-3336

OtherActive exploitation (sightings)HIGH2020-02-12

regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion.

CVEs:CVE-2011-3336

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2020-3864

iPadOSActive exploitation (sightings)HIGH2020-02-17

A logic issue was addressed with improved validation. This issue is fixed in iCloud for Windows 7.17, iTunes 12.10.4 for Windows, iCloud for Windows 10.9.2, tvOS 13.3.1, Safari 13.0.5, iOS 13.3.1 and iPadOS 13.3.1. A DOM object context may not have had...

CVEs:CVE-2020-3864

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2019-8741

OtherEPSS <= 49%HIGH2020-02-28

A denial of service issue was addressed with improved input validation.

CVEs:CVE-2019-8741

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2012-5366

macOSEPSS <= 49%HIGH2020-02-20

The IPv6 implementation in Apple Mac OS X (unknown versions, year 2012 and earlier) allows remote attackers to cause a denial of service via a flood of ICMPv6 Router Advertisement packets containing multiple Routing entries.

CVEs:CVE-2012-5366

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2016-4676

SafariEPSS <= 49%HIGH2020-02-03

A Cross-origin vulnerability exists in WebKit in Apple Safari before 10.0.1 when processing location attributes, which could let a remote malicious user obtain sensitive information.

CVEs:CVE-2016-4676

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
safari affected apple
Upstream advisory

CVE-2019-14868

OtherEPSS <= 49%HIGH2020-02-05

In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and applications that allow remote unaut...

CVEs:CVE-2019-14868

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2019-20044

OtherEPSS <= 49%HIGH2020-02-24

In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option. Zsh fails to overwrite the saved uid, so the original privileges can be restored by executing MODULE_PATH=/dir/with/module zmodload with ...

CVEs:CVE-2019-20044

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2011-0220

OtherEPSS <= 49%HIGH2020-02-05

Apple Bonjour before 2011 allows a crash via a crafted multicast DNS packet.

CVEs:CVE-2011-0220

Affected products

ProductStatusVendorPackageEcosystem
bonjour affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.