Page 2 of 12 results (0.013 seconds)

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

An out-of-bounds read was addressed with improved input validation. This issue is fixed in AirPort Base Station Firmware Update 7.8.1, AirPort Base Station Firmware Update 7.9.1. A remote attacker may be able to leak memory. Se abordó una lectura fuera de límites con una comprobación de entrada mejorada. Este problema se corrigió en AirPort Base Station Firmware Update versión 7.8.1, AirPort Base Station Firmware Update versión 7.9.1. • https://support.apple.com/en-us/HT210090 https://support.apple.com/en-us/HT210091 • CWE-125: Out-of-bounds Read •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

A null pointer dereference was addressed with improved input validation. This issue is fixed in AirPort Base Station Firmware Update 7.8.1, AirPort Base Station Firmware Update 7.9.1. A remote attacker may be able to cause a system denial of service. Se abordó una desreferencia de puntero null con una comprobación de entrada mejorada. Este problema se corrigió en AirPort Base Station Firmware Update versión 7.8.1, AirPort Base Station Firmware Update versión 7.9.1. • https://support.apple.com/en-us/HT210090 https://support.apple.com/en-us/HT210091 • CWE-476: NULL Pointer Dereference •

CVSS: 10.0EPSS: 1%CPEs: 3EXPL: 0

Apple AirPort Base Station Firmware before 7.6.7 and 7.7.x before 7.7.7 misparses DNS data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors. Apple AirPort Base Station Firmware en versiones anteriores a 7.6.7 y 7.7.x en versiones anteriores a 7.7.7 no analiza datos DNS, lo que permite a atacantes remotos ejecutar un código arbitrario o provocar una denegación de servicio (corrupción de memoria) a través de vectores no especificados. • http://lists.apple.com/archives/security-announce/2016/Jun/msg00000.html http://www.securitytracker.com/id/1036136 https://support.apple.com/HT206849 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 5.4EPSS: 0%CPEs: 8EXPL: 0

Apple AirPort Base Station Firmware before 7.6.4 does not properly handle incorrect frame lengths, which allows remote attackers to cause a denial of service (device crash) by associating with the access point and then sending a short frame. Apple AirPort Base Station Firmware anterior a 7.6.4 no maneja apropiadamente longitudes de frame incorrectas, lo que permite a atacantes remotos causar una denegación de servicio (cuelgue de dispositivo) asociando con el punto de acceso y más tarde enviando un frame corto. • http://lists.apple.com/archives/security-announce/2013/Sep/msg00000.html http://support.apple.com/kb/HT5920 • CWE-189: Numeric Errors •

CVSS: 2.6EPSS: 0%CPEs: 12EXPL: 0

The Application-Level Gateway (ALG) on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 modifies PORT commands in incoming FTP traffic, which allows remote attackers to use the device's IP address for arbitrary intranet TCP traffic by leveraging write access to an intranet FTP server. Application-Level Gateway (ALG) en Apple Time Capsule, AirPort Extreme Base Station, y AirPort Express Base Station con firmware anterior v7.5.2 modifica los comandos PORT en el tráfico FTP, lo que permite a atacantes remotos usar la dirección IP del dispositivo para tráfico de intranet TCP de su elección aprovechando el acceso de escritura en el servidor FTP de intranet. • http://lists.apple.com/archives/security-announce/2010//Dec/msg00001.html http://support.apple.com/kb/HT4298 http://www.securitytracker.com/id?1024907 • CWE-264: Permissions, Privileges, and Access Controls •