CVE-2021-30824
https://notcve.org/view.php?id=CVE-2021-30824
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. A malicious application may be able to execute arbitrary code with kernel privileges. Se abordó un problema de corrupción de memoria con una administración de estado mejorada. Este problema se corrigió en macOS Monterey versión 12.0.1, Security Update 2021-007 Catalina, macOS Big Sur versión 11.6.1. • https://support.apple.com/en-us/HT212869 https://support.apple.com/en-us/HT212871 https://support.apple.com/en-us/HT212872 • CWE-787: Out-of-bounds Write •
CVE-2021-30807 – Apple Multiple Products Memory Corruption Vulnerability
https://notcve.org/view.php?id=CVE-2021-30807
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS 14.7.1 and iPadOS 14.7.1, watchOS 7.6.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited. Se abordó un problema de corrupción de memoria con un manejo de memoria mejorado. • https://support.apple.com/en-us/HT212622 https://support.apple.com/en-us/HT212623 https://support.apple.com/en-us/HT212713 • CWE-787: Out-of-bounds Write •
CVE-2021-39246
https://notcve.org/view.php?id=CVE-2021-39246
Tor Browser through 10.5.6 and 11.x through 11.0a4 allows a correlation attack that can compromise the privacy of visits to v2 onion addresses. Exact timestamps of these onion-service visits are logged locally, and an attacker might be able to compare them to timestamp data collected by the destination server (or collected by a rogue site within the Tor network). Tor Browser hasta la versión 10.5.6 y la versión 11.x hasta la 11.0a4 permite un ataque de correlación que puede comprometer la privacidad de las visitas a las direcciones v2 de la cebolla. Las marcas de tiempo exactas de estas visitas al servicio de cebolla se registran localmente, y un atacante podría ser capaz de compararlas con los datos de las marcas de tiempo recogidas por el servidor de destino (o recogidas por un sitio falso dentro de la red Tor) • https://github.com/sickcodes/security/blob/master/advisories/SICK-2021-111.md https://gitlab.torproject.org/tpo/core/tor/-/commit/80c404c4b79f3bcba3fc4585d4c62a62a04f3ed9 https://gitlab.torproject.org/tpo/core/tor/-/merge_requests/434 https://sick.codes/sick-2021-111 https://www.privacyaffairs.com/cve-2021-39246-tor-vulnerability • CWE-532: Insertion of Sensitive Information into Log File •
CVE-2021-30845
https://notcve.org/view.php?id=CVE-2021-30845
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.6. A local user may be able to read kernel memory. Se abordó una lectura fuera de límites con una comprobación de límites mejorada. Este problema es corregido en macOS Big Sur versión 11.6. • https://support.apple.com/en-us/HT212804 • CWE-125: Out-of-bounds Read •
CVE-2021-30827
https://notcve.org/view.php?id=CVE-2021-30827
A permissions issue existed. This issue was addressed with improved permission validation. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6. A local attacker may be able to elevate their privileges. Se presentaba un problema de permisos. • https://support.apple.com/en-us/HT212804 https://support.apple.com/en-us/HT212805 • CWE-281: Improper Preservation of Permissions •