Apple Security Advisories · December 2020 — Apple Security Advisories
25 advisories 25 CVEs

Apple-vendor CVEs for 2020-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2020-8285

OtherPoC exploitCRITICAL2020-12-08

curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.

CVEs:CVE-2020-8285

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
mac_os_x affected apple
Upstream advisory

CVE-2020-8286

OtherPoC exploitHIGH2020-12-08

curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.

CVEs:CVE-2020-8286

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
mac_os_x affected apple
Upstream advisory

CVE-2020-8284

OtherPoC exploitMEDIUM2020-12-08

A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, f...

CVEs:CVE-2020-8284

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
mac_os_x affected apple
Upstream advisory

CVE-2020-13520

OtherEPSS <= 49%HIGH2020-12-11

An out of bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 reconstructs paths from binary USD files. A specially crafted malformed file can trigger an out of bounds memory modification which can result in remote code executi...

CVEs:CVE-2020-13520

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2020-9947

iPadOSEPSS <= 49%CRITICAL2020-12-03

A use after free issue was addressed with improved memory management. This issue is fixed in watchOS 7.0, iOS 14.0 and iPadOS 14.0, iTunes for Windows 12.10.9, iCloud for Windows 11.5, tvOS 14.0, Safari 14.0. Processing maliciously crafted web content ...

CVEs:CVE-2020-9947

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-9950

iPadOSEPSS <= 49%CRITICAL2020-12-08

A use after free issue was addressed with improved memory management. This issue is fixed in watchOS 7.0, tvOS 14.0, Safari 14.0, iOS 14.0 and iPadOS 14.0. Processing maliciously crafted web content may lead to arbitrary code execution.

CVEs:CVE-2020-9950

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-9954

iPadOSEPSS <= 49%CRITICAL2020-12-08

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in watchOS 7.0, tvOS 14.0, macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave, iOS 14.0 and iPadOS 14.0. Playing a malic...

CVEs:CVE-2020-9954

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-9972

iPadOSEPSS <= 49%CRITICAL2020-12-08

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 14.0 and iPadOS 14.0. Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution.

CVEs:CVE-2020-9972

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
Upstream advisory

CVE-2020-9981

iPadOSEPSS <= 49%HIGH2020-12-03

A use after free issue was addressed with improved memory management. This issue is fixed in watchOS 7.0, iOS 14.0 and iPadOS 14.0, iTunes for Windows 12.10.9, iCloud for Windows 11.5, tvOS 14.0, macOS Catalina 10.15.7, Security Update 2020-005 High Si...

CVEs:CVE-2020-9981

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
itunes affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-10013

iPadOSEPSS <= 49%HIGH2020-12-08

A logic issue was addressed with improved state management. This issue is fixed in tvOS 14.0, iOS 14.0 and iPadOS 14.0. An application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2020-10013

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
Upstream advisory

CVE-2020-9993

iPadOSEPSS <= 49%MEDIUM2020-12-08

The issue was addressed with improved UI handling. This issue is fixed in watchOS 7.0, Safari 14.0, iOS 14.0 and iPadOS 14.0. Visiting a malicious website may lead to address bar spoofing.

CVEs:CVE-2020-9993

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
safari affected apple
watchos affected apple
Upstream advisory

CVE-2020-27951

iPadOSEPSS <= 49%CRITICAL2020-12-15

This issue was addressed with improved checks. This issue is fixed in watchOS 6.3, iOS 12.5, iOS 14.3 and iPadOS 14.3, watchOS 7.2. Unauthorized code execution may lead to an authentication policy violation.

CVEs:CVE-2020-27951

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
watchos affected apple
Upstream advisory

CVE-2020-29618

iPadOSEPSS <= 49%CRITICAL2020-12-15

An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 14.3, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, iCloud for Windows 12.0, watchOS 7.2...

CVEs:CVE-2020-29618

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
macos affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-29611

iPadOSEPSS <= 49%CRITICAL2020-12-15

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 14.3, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, iCloud for Windows 12.0, watch...

CVEs:CVE-2020-29611

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
macos affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-27944

watchOSEPSS <= 49%CRITICAL2020-12-15

A memory corruption issue existed in the processing of font files. This issue was addressed with improved input validation. This issue is fixed in watchOS 7.2, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS ...

CVEs:CVE-2020-27944

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-27948

iPadOSEPSS <= 49%CRITICAL2020-12-15

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in watchOS 7.2, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. Processing a mali...

CVEs:CVE-2020-27948

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-27943

iPadOSEPSS <= 49%CRITICAL2020-12-15

A memory corruption issue existed in the processing of font files. This issue was addressed with improved input validation. This issue is fixed in tvOS 14.3, iOS 14.3 and iPadOS 14.3, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Upda...

CVEs:CVE-2020-27943

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-9987

SafariEPSS <= 49%MEDIUM2020-12-08

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 14.0. Visiting a malicious website may lead to address bar spoofing.

CVEs:CVE-2020-9987

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2020-27946

iPadOSEPSS <= 49%HIGH2020-12-15

An information disclosure issue was addressed with improved state management. This issue is fixed in watchOS 7.2, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. Processing a ...

CVEs:CVE-2020-27946

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-29617

iPadOSEPSS <= 49%HIGH2020-12-15

An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 14.3, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, iCloud for Windows 12.0, watchOS 7.2...

CVEs:CVE-2020-29617

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
macos affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-29619

iPadOSEPSS <= 49%HIGH2020-12-15

An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 14.3, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, iCloud for Windows 12.0, watchOS 7.2...

CVEs:CVE-2020-29619

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
macos affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-27895

OtherEPSS <= 49%MEDIUM2020-12-08

An information disclosure issue existed in the transition of program state. This issue was addressed with improved state handling. This issue is fixed in iTunes 12.11 for Windows. A malicious application may be able to access local users Apple IDs.

CVEs:CVE-2020-27895

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
Upstream advisory

CVE-2020-9995

macOSEPSS <= 49%CRITICAL2020-12-15

An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Server 5.11. Processing a maliciously crafted URL may lead to an open redirect or cross site scripting.

CVEs:CVE-2020-9995

Affected products

ProductStatusVendorPackageEcosystem
macos_server affected apple
Upstream advisory

CVE-2020-29613

iPadOSEPSS <= 49%MEDIUM2020-12-15

A logic issue was addressed with improved state management. This issue is fixed in iOS 14.3 and iPadOS 14.3. An enterprise application installation prompt may display the wrong domain.

CVEs:CVE-2020-29613

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2020-27897

macOSEPSS <= 49%CRITICAL2020-12-08

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1. An application may be able to execute arbitra...

CVEs:CVE-2020-27897

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
mac_os_x affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.