LiveActive security incident?Get immediate response
CVE archive

April 2020

Browse CVE records published in April 2020, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1821 matching CVEs · Page 13 of 37.

Unknown · CVSS Not scored

CVE-2020-29620: This issue was addressed with improved entitlements.

This issue was addressed with improved entitlements. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may be able to elevate privileges.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-29610: An out-of-bounds read was addressed with improved input validation.

An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 7.2, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. Processing a maliciously crafted audio file may disclose restricted memory.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-29608: An out-of-bounds read was addressed with improved bounds checking.

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.3, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, watchOS 7.2. A remote attacker may be able to leak memory.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-29614: This issue was addressed with improved checks.

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. Processing a maliciously crafted file may lead to heap corruption.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-29617: An out-of-bounds read was addressed with improved input validation.

An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 14.3, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, iCloud for Windows 12.0, watchOS 7.2. Processing a maliciously crafted image may lead to heap corruption.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-29592: An issue was discovered in Orchard before 1.10.

An issue was discovered in Orchard before 1.10. A broken access control issue in Orchard components that use the TinyMCE HTML editor's file upload allows an attacker to upload dangerous executables that bypass the file types allowed (regardless of the file types allowed list in Media settings).

Published Apr 14, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-29593: An issue was discovered in Orchard before 1.10.

An issue was discovered in Orchard before 1.10. The Media Settings Allowed File Types list field allows an attacker to add a XSS payload that will execute when users attempt to upload a disallowed file type, causing the error to display.

Published Apr 14, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-28973: The ABUS Secvest wireless alarm system FUAA50000 (v3.01.17) fails to properly authenticate some requests to...

The ABUS Secvest wireless alarm system FUAA50000 (v3.01.17) fails to properly authenticate some requests to its built-in HTTPS interface. Someone can use this vulnerability to obtain sensitive information from the system, such as usernames and passwords. This information can then be used to reconfigure or disable the alarm system.

Published Apr 21, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-27941: A validation issue was addressed with improved logic.

A validation issue was addressed with improved logic. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. An application may be able to execute arbitrary code with kernel privileges.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-27935: Multiple issues were addressed with improved logic.

Multiple issues were addressed with improved logic. This issue is fixed in iOS 14.2 and iPadOS 14.2, macOS Big Sur 11.0.1, watchOS 7.1, tvOS 14.2. A sandboxed process may be able to circumvent sandbox restrictions.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-27914: A memory corruption issue was addressed with improved input validation.

A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1. A malicious application may be able to execute arbitrary code with system privileges.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-27951: This issue was addressed with improved checks.

This issue was addressed with improved checks. This issue is fixed in watchOS 6.3, iOS 12.5, iOS 14.3 and iPadOS 14.3, watchOS 7.2. Unauthorized code execution may lead to an authentication policy violation.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-27922: A logic issue was addressed with improved state management.

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, watchOS 7.1, tvOS 14.2. Processing a maliciously crafted font file may lead to arbitrary code execution.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-27931: A memory corruption issue existed in the processing of font files.

A memory corruption issue existed in the processing of font files. This issue was addressed with improved input validation. This issue is fixed in iOS 14.0 and iPadOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1, watchOS 7.0, tvOS 14.0. Processing a maliciously crafted font file may lead to arbitrary code execution.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-27945: An integer overflow was addressed with improved input validation.

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, macOS Big Sur 11.0.1. Processing maliciously crafted web content may lead to arbitrary code execution.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-27923: An out-of-bounds write was addressed with improved input validation.

An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, watchOS 7.1, tvOS 14.2. Processing a maliciously crafted image may lead to arbitrary code execution.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-27946: An information disclosure issue was addressed with improved state management.

An information disclosure issue was addressed with improved state management. This issue is fixed in watchOS 7.2, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. Processing a maliciously crafted font may result in the disclosure of process memory.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-27948: An out-of-bounds write issue was addressed with improved bounds checking.

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in watchOS 7.2, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. Processing a maliciously crafted audio file may lead to arbitrary code execution.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-27901: A logic issue was addressed with improved restrictions.

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1. A sandboxed process may be able to circumvent sandbox restrictions.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-27936: An out-of-bounds read issue existed that led to the disclosure of kernel memory.

An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A local user may be able to cause unexpected system termination or read kernel memory.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-27939: This issue was addressed with improved checks.

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. Processing a maliciously crafted image may lead to arbitrary code execution.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-27944: A memory corruption issue existed in the processing of font files.

A memory corruption issue existed in the processing of font files. This issue was addressed with improved input validation. This issue is fixed in watchOS 7.2, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. Processing a maliciously crafted font file may lead to arbitrary code execution.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-27952: An out-of-bounds write was addressed with improved input validation.

An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1. Processing a maliciously crafted font file may lead to arbitrary code execution.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-27919: An out-of-bounds write was addressed with improved input validation.

An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1. Processing a maliciously crafted image may lead to arbitrary code execution.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-27933: A memory corruption issue was addressed with improved input validation.

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, iCloud for Windows 7.20, watchOS 6.2.8, tvOS 13.4.8, macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra. Processing a maliciously crafted image may lead to arbitrary code execution.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-27943: A memory corruption issue existed in the processing of font files.

A memory corruption issue existed in the processing of font files. This issue was addressed with improved input validation. This issue is fixed in tvOS 14.3, iOS 14.3 and iPadOS 14.3, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.2. Processing a maliciously crafted font file may lead to arbitrary code execution.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-27937: A logic issue was addressed with improved state management.

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, macOS Big Sur 11.0.1. A malicious application may be able to access private information.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-27908: An out-of-bounds read was addressed with improved input validation.

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, watchOS 7.1, tvOS 14.2. Processing a maliciously crafted audio file may lead to arbitrary code execution.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-27938: A logic issue was addressed with improved state management.

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may be able to elevate privileges.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-27924: An out-of-bounds read was addressed with improved input validation.

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, watchOS 7.1, tvOS 14.2. Processing a maliciously crafted image may lead to arbitrary code execution.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-27915: A memory corruption issue was addressed with improved input validation.

A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1. A malicious application may be able to execute arbitrary code with system privileges.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-27920: A use after free issue was addressed with improved memory management.

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, watchOS 7.1, tvOS 14.2. Processing maliciously crafted web content may lead to code execution.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-27907: A memory corruption issue was addressed with improved memory handling.

A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1. An application may be able to execute arbitrary code with kernel privileges.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-27921: A race condition was addressed with improved state handling.

A race condition was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1. An application may be able to execute arbitrary code with kernel privileges.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-27893: An issue existed in screen sharing.

An issue existed in screen sharing. This issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1. A user with screen sharing access may be able to view another user's screen.

Published Apr 2, 2021 · Updated Aug 4, 2024