Support Us — Your donation helps us keep running

Goal: 1000 CNY,Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2020-13524
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
An out-of-bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 uses SPECS data from binary USD files. A specially crafted malformed file can trigger an out-of-bounds memory access and modification which results in memory corruption. To trigger this vulnerability, the victim needs to access an attacker-provided malformed file.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
内存缓冲区边界内操作的限制不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
Apple IO Model 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Apple IO Model是美国苹果(Apple)公司的一个用于处理IO操作的模块。 Apple IO Model 存在缓冲区错误漏洞,该漏洞可造成如果处理恶意制作的USD文件可能会导致应用程序意外终止或任意代码执行。一下设备及版本会受到影响:Apple iPhone 6s 及更高版本, iPod touch 7th generation, iPad Air 2及更高版本, iPad mini 4 及更高版本。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
-Pixar Pixar OpenUSD 20.05 , Apple macOS Catalina 10.15.3 -
II. Public POCs for CVE-2020-13524
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2020-13524
Please Login to view more intelligence information
New Vulnerabilities
V. Comments for CVE-2020-13524

No comments yet


Leave a comment