CVE-2020-9819
medium · 4.3Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2021-11-03Remediation due 2022-05-03
A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5, watchOS 5.3.7. Processing a maliciously crafted mail message may lead to heap corruption.
4.3
CVSS
2.2%
EPSS (exploit prob.)
82nd
EPSS percentile
2020-06-09
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Weaknesses
CWE-787
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apple | ipados | < 13.5 |
| apple | iphone_os | < 12.4.7 |
| apple | iphone_os | >= 13.0, < 13.5 |
| apple | watchos | < 5.3.7 |
| apple | watchos | >= 6.0.0, < 6.2.5 |
Check a specific version with /api/v1/cve/match.
References
- https://support.apple.com/HT211168
- https://support.apple.com/HT211169
- https://support.apple.com/HT211175
- https://support.apple.com/HT211176
- https://support.apple.com/HT211168
- https://support.apple.com/HT211169
- https://support.apple.com/HT211175
- https://support.apple.com/HT211176
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-9819
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2020-9819