peter bassill · operator
$ cve CVE-2020-3909 JSON

CVE-2020-3909

9.8
CRITICAL · CVSS 3.1 · EPSS 3% (pctl 87)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Multiple issues in libxml2.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.04% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-120
On CISA KEVno
Public exploitnone known
Published2020-04-01
Last modified2026-06-17

Affected (8)

VendorProduct
appleicloud
appleipados
appleiphone os
appleitunes
applemac os x
appletvos
applewatchos
oraclesun zfs storage appliance kit software

References

→ the Explorer  ·  watch your stack  ·  NVD