CVE-2020-9952
Summary
| CVE | CVE-2020-9952 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-10-16 17:15:00 UTC |
| Updated | 2023-01-09 16:41:00 UTC |
| Description | An input validation issue was addressed with improved input validation. This issue is fixed in iOS 14.0 and iPadOS 14.0, tvOS 14.0, watchOS 7.0, Safari 14.0, iCloud for Windows 11.4, iCloud for Windows 7.21. Processing maliciously crafted web content may lead to a cross site scripting attack. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| About the security content of iCloud for Windows 7.21 - Apple Support |
MISC |
support.apple.com |
Release Notes, Vendor Advisory |
| About the security content of iOS 14.0 and iPadOS 14.0 - Apple Support |
MISC |
support.apple.com |
Vendor Advisory |
| About the security content of watchOS 7.0 - Apple Support |
MISC |
support.apple.com |
Release Notes, Vendor Advisory |
| Full Disclosure: APPLE-SA-2020-11-13-6 Additional information for APPLE-SA-2020-09-16-4 watchOS 7.0 |
FULLDISC |
seclists.org |
Mailing List, Third Party Advisory |
| oss-security - WebKitGTK and WPE WebKit Security Advisory WSA-2020-0008 |
MLIST |
www.openwall.com |
Mailing List |
| About the security content of tvOS 14.0 - Apple Support |
MISC |
support.apple.com |
Release Notes, Vendor Advisory |
| Full Disclosure: APPLE-SA-2020-11-13-5 Additional information for APPLE-SA-2020-09-16-3 Safari 14.0 |
FULLDISC |
seclists.org |
Mailing List, Third Party Advisory |
| WebkitGTK+: Multiple vulnerabilities (GLSA 202012-10) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| Full Disclosure: APPLE-SA-2020-11-13-4 Additional information for APPLE-SA-2020-09-16-2 tvOS 14.0 |
FULLDISC |
seclists.org |
Mailing List, Third Party Advisory |
| About the security content of Safari 14.0 - Apple Support |
MISC |
support.apple.com |
Release Notes, Vendor Advisory |
| Full Disclosure: APPLE-SA-2020-11-13-3 Additional information for APPLE-SA-2020-09-16-1 iOS 14.0 and iPadOS 14.0 |
FULLDISC |
seclists.org |
Mailing List, Third Party Advisory |
| About the security content of iCloud for Windows 11.4 - Apple Support |
MISC |
support.apple.com |
Release Notes, Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 501707 Alpine Linux Security Update for webkit2gtk
- 505513 Alpine Linux Security Update for webkit2gtk
- 751623 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2022:0142-1)
- 751646 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2022:0183-1)
- 751648 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2022:0182-1)
- 751659 OpenSUSE Security Update for webkit2gtk3 (openSUSE-SU-2022:0182-1)
- 751755 OpenSUSE Security Update for webkit2gtk3 (openSUSE-SU-2022:0182-2)
- 960761 Rocky Linux Security Update for GNOME (RLSA-2020:4451)