CVE-2021-30928 – Apple macOS CoreGraphics PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2021-30928
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.6, watchOS 8, tvOS 15, iOS 14.8 and iPadOS 14.8, iOS 15 and iPadOS 15. Processing a maliciously crafted image may lead to arbitrary code execution. Se ha solucionado un problema de corrupción de memoria con una validación de entrada mejorada. Este problema se ha solucionado en macOS Big Sur 11.6, watchOS 8, tvOS 15, iOS 14.8 y iPadOS 14.8, iOS 15 y iPadOS 15. • https://support.apple.com/en-us/HT212804 https://support.apple.com/en-us/HT212807 https://support.apple.com/en-us/HT212814 https://support.apple.com/en-us/HT212815 https://support.apple.com/en-us/HT212819 https://support.apple.com/kb/HT212953 • CWE-787: Out-of-bounds Write •
CVE-2021-30927
https://notcve.org/view.php?id=CVE-2021-30927
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. An application may be able to execute arbitrary code with kernel privileges. Se solucionó un problema de uso de la memoria previamente liberada con una administración de la memoria mejorada. Este problema se solucionó en macOS Big Sur versión 11.6.2, tvOS versión 15.2, macOS Monterey versión 12.1, actualización de seguridad 2021-008 Catalina, iOS versión 15.2 e iPadOS versión 15.2, watchOS versión 8.3. • https://support.apple.com/en-us/HT212975 https://support.apple.com/en-us/HT212976 https://support.apple.com/en-us/HT212978 https://support.apple.com/en-us/HT212979 https://support.apple.com/en-us/HT212980 https://support.apple.com/en-us/HT212981 • CWE-416: Use After Free •
CVE-2021-30925
https://notcve.org/view.php?id=CVE-2021-30925
The issue was addressed with improved permissions logic. This issue is fixed in watchOS 8, macOS Big Sur 11.6, iOS 15 and iPadOS 15. A malicious application may be able to bypass Privacy preferences. El problema se ha solucionado con una lógica de permisos mejorada. Este problema se ha solucionado en watchOS 8, macOS Big Sur 11.6, iOS 15 y iPadOS 15. • https://support.apple.com/en-us/HT212804 https://support.apple.com/en-us/HT212814 https://support.apple.com/en-us/HT212819 • CWE-863: Incorrect Authorization •
CVE-2021-30924
https://notcve.org/view.php?id=CVE-2021-30924
A denial of service issue was addressed with improved state handling. This issue is fixed in macOS Monterey 12.0.1. A remote attacker can cause a device to unexpectedly restart. Se solucionó un problema de denegación de servicio mejorando el manejo estatal. Este problema se solucionó en macOS Monterey versión 12.0.1. • https://support.apple.com/en-us/HT212869 https://support.apple.com/kb/HT212867 https://support.apple.com/kb/HT212874 https://support.apple.com/kb/HT212876 •
CVE-2021-30923
https://notcve.org/view.php?id=CVE-2021-30923
A race condition was addressed with improved locking. This issue is fixed in macOS Monterey 12.0.1. A malicious application may be able to execute arbitrary code with kernel privileges. Se solucionó una condición de carrera con un bloqueo mejorado. Este problema se solucionó en macOS Monterey versión 12.0.1. • https://support.apple.com/en-us/HT212869 https://support.apple.com/kb/HT212867 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •