CVE-2020-9947

high

Description

A use after free issue was addressed with improved memory management. This issue is fixed in watchOS 7.0, iOS 14.0 and iPadOS 14.0, iTunes for Windows 12.10.9, iCloud for Windows 11.5, tvOS 14.0, Safari 14.0. Processing maliciously crafted web content may lead to arbitrary code execution.

References

https://support.apple.com/en-us/HT211935

https://support.apple.com/en-us/HT211844

https://support.apple.com/en-us/HT211843

https://support.apple.com/en-us/HT211845

https://support.apple.com/en-us/HT211850

https://support.apple.com/en-us/HT211952

http://www.openwall.com/lists/oss-security/2021/03/22/1

https://security.gentoo.org/glsa/202104-03

Details

Source: MITRE

Published: 2020-12-08

Updated: 2022-06-02

Type: CWE-416

Risk Information

CVSS v2

Base Score: 6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 8.6

Severity: MEDIUM

CVSS v3

Base Score: 8.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 2.8

Severity: HIGH