CVE-2020-9983: Input Validation
A flaw was found in WebKitGTK. Processing maliciously crafted web content may lead to a cross site scripting attack. Description: An input validation issue was addressed with improved input validation.
Reference: https://webkitgtk.org/security/WSA-2020-0008.html
Other sources
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Safari 14.0. Processing maliciously crafted web content may lead to code execution.
— Launchpad
Apple Safari could allow a remote attacker to execute arbitrary code on the system, caused by an out-of-bounds write in the WebKit component. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to execute arbitrary code on the system.
— IBM
WebKit. An out-of-bounds write issue was addressed with improved bounds checking.
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-9979
- CVE-2020-9943
- CVE-2020-9944
- CVE-2020-9960
- CVE-2020-9954
- CVE-2020-9949
- CVE-2020-9999
- CVE-2020-9965
- CVE-2020-9966
- CVE-2020-29629
- CVE-2020-9956
- CVE-2020-9962
- CVE-2020-27931
- CVE-2020-29639
- CVE-2020-9978
- CVE-2020-36521
- CVE-2020-9961
- CVE-2020-9955
- CVE-2020-9876
- CVE-2020-9967
- CVE-2020-9975
- CVE-2020-9976
- CVE-2020-9981
- CVE-2020-9971
- CVE-2020-9969
- CVE-2020-9968
- CVE-2020-13434
- CVE-2020-13435
- CVE-2020-9991
- CVE-2020-15358
- CVE-2020-13631
- CVE-2020-9849
- CVE-2020-13630
- CVE-2020-9947
- CVE-2020-9950
- CVE-2020-9951
- CVE-2020-9983
- CVE-2020-9952
- CVE-2020-10013
- CVE-2020-9941
- CVE-2020-9989
- CVE-2020-9946
- CVE-2020-9993
- CVE-2020-10002
- CVE-2020-27912
- CVE-2020-27917
- CVE-2020-27911
- CVE-2020-27918
- CVE-2020-9987
- CVE-2020-9948
- CVE-2020-9958
- CVE-2020-9773
- CVE-2020-9992
- CVE-2020-9964
- CVE-2019-14899
- CVE-2020-9988
- CVE-2020-13520
- CVE-2020-6147
- CVE-2020-9972
- CVE-2020-9973
- CVE-2020-9996
- CVE-2020-9963
- CVE-2020-9977
- CVE-2020-9959
Frequently Asked Questions
What is CVE-2020-9983?
CVE-2020-9983 is a vulnerability in WebKit that allows an attacker to perform an out-of-bounds write.
What is the severity of CVE-2020-9983?
The severity of CVE-2020-9983 is not specified in the provided information.
Which software is affected by CVE-2020-9983?
CVE-2020-9983 affects Apple tvOS 14.0, Apple Safari 14.0, Apple iOS 14.0, Apple iPadOS 14.0, Apple watchOS 7.0, Apple iCloud for Windows 11.5, and Apple iTunes for Windows 12.10.9.
How can I fix CVE-2020-9983?
To fix CVE-2020-9983, update your affected software to the recommended versions provided by Apple.
Where can I find more information about CVE-2020-9983?
You can find more information about CVE-2020-9983 on the Apple support page: [https://support.apple.com/en-us/HT211845](https://support.apple.com/en-us/HT211845)