
CVE-2022-42860
https://notcve.org/view.php?id=CVE-2022-42860
23 Jun 2023 — This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Monterey 12.6.1, macOS Big Sur 11.7.1, macOS Ventura 13. An app may be able to modify protected parts of the file system • https://support.apple.com/en-us/HT213488 • CWE-346: Origin Validation Error •

CVE-2022-42807
https://notcve.org/view.php?id=CVE-2022-42807
23 Jun 2023 — A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. A user may accidentally add a participant to a Shared Album by pressing the Delete key • https://support.apple.com/en-us/HT213488 • CWE-640: Weak Password Recovery Mechanism for Forgotten Password •

CVE-2022-46718
https://notcve.org/view.php?id=CVE-2022-46718
23 Jun 2023 — A logic issue was addressed with improved restrictions. This issue is fixed in iOS 15.7.2 and iPadOS 15.7.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, macOS Monterey 12.6.2. An app may be able to read sensitive location information • https://github.com/biscuitehh/cve-2022-46718-leaky-location • CWE-346: Origin Validation Error •

CVE-2023-23516
https://notcve.org/view.php?id=CVE-2023-23516
23 Jun 2023 — The issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.7.3, macOS Ventura 13.2, macOS Monterey 12.6.3. An app may be able to execute arbitrary code with kernel privileges. • https://support.apple.com/en-us/HT213603 • CWE-787: Out-of-bounds Write •

CVE-2023-32434 – Apple Multiple Products Integer Overflow Vulnerability
https://notcve.org/view.php?id=CVE-2023-32434
23 Jun 2023 — An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS 15.7.7, macOS Monterey 12.6.7, watchOS 8.8.1, iOS 16.5.1 and iPadOS 16.5.1, macOS Ventura 13.4.1. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7. iOS 15.7.7 and iPadOS 15.7.7 addresses code execution and integer overf... • https://github.com/alfiecg24/Trigon • CWE-190: Integer Overflow or Wraparound •

CVE-2023-34241 – CUPS vulnerable to use-after-free in cupsdAcceptClient()
https://notcve.org/view.php?id=CVE-2023-34241
22 Jun 2023 — OpenPrinting CUPS is a standards-based, open source printing system for Linux and other Unix-like operating systems. Starting in version 2.0.0 and prior to version 2.4.6, CUPS logs data of free memory to the logging service AFTER the connection has been closed, when it should have logged the data right before. This is a use-after-free bug that impacts the entire cupsd process. The exact cause of this issue is the function `httpClose(con->http)` being called in `scheduler/client.c`. The problem is that httpC... • http://www.openwall.com/lists/oss-security/2023/06/23/10 • CWE-416: Use After Free •

CVE-2023-28191 – Apple Security Advisory 2023-05-18-6
https://notcve.org/view.php?id=CVE-2023-28191
30 May 2023 — This issue was addressed with improved redaction of sensitive information. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. An app may be able to bypass Privacy preferences. macOS Monterey 12.6.6 addresses buffer overflow, bypass, code execution, out of bounds read, out of bounds write, and use-after-free vulnerabilities. • https://support.apple.com/en-us/HT213757 • CWE-346: Origin Validation Error •

CVE-2023-2953 – openldap: null pointer dereference in ber_memalloc_x function
https://notcve.org/view.php?id=CVE-2023-2953
30 May 2023 — A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function. A vulnerability was found in OpenLDAP, in ber_memalloc_x() function, leading to a null pointer dereference. This flaw can result in reduced system memory and cause LDAP authentication failures. The impact is primarily a disruption in authentication processes, which may hinder user access or service operations relying on LDAP for authentication. • http://seclists.org/fulldisclosure/2023/Jul/47 • CWE-476: NULL Pointer Dereference •

CVE-2023-32380 – Apple Security Advisory 2023-05-18-3
https://notcve.org/view.php?id=CVE-2023-32380
30 May 2023 — An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. Processing a 3D model may lead to arbitrary code execution. macOS Monterey 12.6.6 addresses buffer overflow, bypass, code execution, out of bounds read, out of bounds write, and use-after-free vulnerabilities. • https://support.apple.com/en-us/HT213758 • CWE-787: Out-of-bounds Write •

CVE-2023-32382 – Apple Security Advisory 2023-05-18-3
https://notcve.org/view.php?id=CVE-2023-32382
30 May 2023 — An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. Processing a 3D model may result in disclosure of process memory. macOS Monterey 12.6.6 addresses buffer overflow, bypass, code execution, out of bounds read, out of bounds write, and use-after-free vulnerabilities. • https://support.apple.com/en-us/HT213758 • CWE-125: Out-of-bounds Read •