Apple Security Advisories · February 2020 — Apple Security Advisories
9 advisories 9 CVEs

Apple-vendor CVEs for 2020-02. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2019-15126

OtherWeaponized exploitHIGH2020-02-05

An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility ...

CVEs:CVE-2019-15126

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2011-3336

OtherActive exploitation (sightings)HIGH2020-02-12

regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion.

CVEs:CVE-2011-3336

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2020-3864

iPadOSActive exploitation (sightings)HIGH2020-02-17

A logic issue was addressed with improved validation. This issue is fixed in iCloud for Windows 7.17, iTunes 12.10.4 for Windows, iCloud for Windows 10.9.2, tvOS 13.3.1, Safari 13.0.5, iOS 13.3.1 and iPadOS 13.3.1. A DOM object context may not have had...

CVEs:CVE-2020-3864

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
ipados affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2019-8741

OtherCoalition ESS < 30%HIGH2020-02-28

A denial of service issue was addressed with improved input validation.

CVEs:CVE-2019-8741

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2019-14868

OtherCoalition ESS < 30%HIGH2020-02-05

In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and applications that allow remote unaut...

CVEs:CVE-2019-14868

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2019-20044

OtherCoalition ESS < 30%HIGH2020-02-24

In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option. Zsh fails to overwrite the saved uid, so the original privileges can be restored by executing MODULE_PATH=/dir/with/module zmodload with ...

CVEs:CVE-2019-20044

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2012-5366

macOSEPSS <= 49%HIGH2020-02-20

The IPv6 implementation in Apple Mac OS X (unknown versions, year 2012 and earlier) allows remote attackers to cause a denial of service via a flood of ICMPv6 Router Advertisement packets containing multiple Routing entries.

CVEs:CVE-2012-5366

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2016-4676

SafariEPSS <= 49%HIGH2020-02-03

A Cross-origin vulnerability exists in WebKit in Apple Safari before 10.0.1 when processing location attributes, which could let a remote malicious user obtain sensitive information.

CVEs:CVE-2016-4676

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
safari affected apple — —
Upstream advisory

CVE-2011-0220

OtherEPSS <= 49%HIGH2020-02-05

Apple Bonjour before 2011 allows a crash via a crafted multicast DNS packet.

CVEs:CVE-2011-0220

Affected products

ProductStatusVendorPackageEcosystem
bonjour affected apple — —
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.