CVE-2020-9947
Published on: 12/08/2020 12:00:00 AM UTC
Last Modified on: 06/02/2022 06:56:00 PM UTC
Certain versions of Icloud from Apple contain the following vulnerability:
A use after free issue was addressed with improved memory management. This issue is fixed in watchOS 7.0, iOS 14.0 and iPadOS 14.0, iTunes for Windows 12.10.9, iCloud for Windows 11.5, tvOS 14.0, Safari 14.0. Processing maliciously crafted web content may lead to arbitrary code execution.
- CVE-2020-9947 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 8.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 6.8 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
About the security content of iTunes 12.10.9 for Windows - Apple Support | Release Notes Vendor Advisory support.apple.com text/html |
![]() |
About the security content of iOS 14.0 and iPadOS 14.0 - Apple Support | Release Notes Vendor Advisory support.apple.com text/html |
![]() |
WebkitGTK+: Multiple vulnerabilities (GLSA 202104-03) — Gentoo security | security.gentoo.org text/html |
![]() |
About the security content of Safari 14.0 - Apple Support | Release Notes Vendor Advisory support.apple.com text/html |
![]() |
About the security content of watchOS 7.0 - Apple Support | Release Notes Vendor Advisory support.apple.com text/html |
![]() |
About the security content of tvOS 14.0 - Apple Support | Release Notes Vendor Advisory support.apple.com text/html |
![]() |
About the security content of iCloud for Windows 11.5 - Apple Support | Release Notes Vendor Advisory support.apple.com text/html |
![]() |
oss-security - WebKitGTK and WPE WebKit Security Advisory WSA-2021-0002 | www.openwall.com text/html |
![]() |
Related QID Numbers
- 296067 Oracle Solaris 11.4 Support Repository Update (SRU) 33.94.0 Missing (CPUAPR2021)
- 501710 Alpine Linux Security Update for webkit2gtk
- 710013 Gentoo Linux WebkitGTK+ Multiple Vulnerabilities (GLSA 202104-03)
- 750655 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2021:1990-1)
- 751623 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2022:0142-1)
- 751646 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2022:0183-1)
- 751648 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2022:0182-1)
- 751659 OpenSUSE Security Update for webkit2gtk3 (openSUSE-SU-2022:0182-1)
- 751755 OpenSUSE Security Update for webkit2gtk3 (openSUSE-SU-2022:0182-2)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Apple | Icloud | All | All | All | All |
Application | Apple | Icloud | All | All | All | All |
Operating System | Apple | Ipados | All | All | All | All |
Operating System | Apple | Ipados | All | All | All | All |
Operating System | Apple | Iphone Os | All | All | All | All |
Operating System | Apple | Iphone Os | All | All | All | All |
Application | Apple | Itunes | All | All | All | All |
Application | Apple | Itunes | All | All | All | All |
Application | Apple | Safari | All | All | All | All |
Operating System | Apple | Tvos | All | All | All | All |
Operating System | Apple | Tvos | All | All | All | All |
Operating System | Apple | Watchos | All | All | All | All |
Operating System | Apple | Watchos | All | All | All | All |
- cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*:
- cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*:
- cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*:
- cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*:
- cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*:
- cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
Severity: ?? | A use after free issue was addressed wit... | CVE-2020-9947 | Link for more: alerts.remotelyrmm.com/CVE-2020-9947 | 2022-06-02 20:29:33 |