VDB
CVE-2020-36521
CVE-2020-36521
PUBLISHED
CVSS 7.099999904632568 HIGH
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iCloud for Windows 11.4, iOS 14.0 and iPadOS 14.0, watchOS 7.0, tvOS 14.0, iCloud for Windows 7.21, iTunes for Windows 12.10.9. Processing a maliciously crafted tiff file may lead to a denial-of-service or potentially disclose memory contents.
EPSS 0.41% · 34.0th percentile
Risk Scores
CVSS 3.1
7.099999904632568
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
EPSS Score
0.41%
34.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apple | icloud | 0, 11.0 |
| apple | watchos | 0 |
| Apple | iOS and iPadOS | unspecified |
| Apple | iTunes for Windows | * |
| apple | tvos | 0 |
| apple | iphone_os | 0 |
| apple | macos | 0 |
| apple | itunes | 0 |
| Apple | watchOS | unspecified, unspecified |
| apple | ipados | 0 |
| Apple | iCloud for Windows | unspecified, * |
Timeline
- Sep 23, 2022 CVE Published
- Sep 24, 2022 EPSS Score
- Nov 8, 2022 EPSS Score
- Dec 22, 2022 EPSS Score
- Feb 5, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 22, 2023 EPSS Score
- May 5, 2023 EPSS Score
- Jun 19, 2023 EPSS Score
- Aug 3, 2023 EPSS Score
- Sep 16, 2023 EPSS Score
- Oct 31, 2023 EPSS Score
References
- https://support.apple.com/en-us/HT211843 url
- https://support.apple.com/en-us/HT211850 url
- https://support.apple.com/en-us/HT211844 url
- https://support.apple.com/en-us/HT211952 url
- https://support.apple.com/en-us/HT211847 url
- https://support.apple.com/en-us/HT211846 url
- https://nvd.nist.gov/vuln/detail/CVE-2020-36521 advisory