CVE-2020-3910

HIGH

Description

A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Multiple issues in libxml2.

References

https://support.apple.com/HT211100

https://support.apple.com/HT211101

https://support.apple.com/HT211102

https://support.apple.com/HT211103

https://support.apple.com/HT211105

https://support.apple.com/HT211106

https://support.apple.com/HT211107

Details

Source: MITRE

Published: 2020-04-01

Updated: 2020-04-02

Type: CWE-120

Risk Information

CVSS v2.0

Base Score: 7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 10

Severity: HIGH

CVSS v3.0

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 3.9

Severity: CRITICAL