CVE-2023-32403
https://notcve.org/view.php?id=CVE-2023-32403
30 May 2023 — This issue was addressed with improved redaction of sensitive information. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. An app may be able to read sensitive location information. • https://support.apple.com/en-us/HT213757 • CWE-125: Out-of-bounds Read •
CVE-2023-32392
https://notcve.org/view.php?id=CVE-2023-32392
30 May 2023 — A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. An app may be able to read sensitive location information. • https://support.apple.com/en-us/HT213757 • CWE-532: Insertion of Sensitive Information into Log File •
CVE-2023-32386
https://notcve.org/view.php?id=CVE-2023-32386
30 May 2023 — A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An app may be able to observe unprotected user data. • https://support.apple.com/en-us/HT213758 • CWE-125: Out-of-bounds Read •
CVE-2023-32387
https://notcve.org/view.php?id=CVE-2023-32387
30 May 2023 — A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. A remote attacker may be able to cause unexpected app termination or arbitrary code execution. • https://support.apple.com/en-us/HT213758 • CWE-416: Use After Free •
CVE-2023-32388
https://notcve.org/view.php?id=CVE-2023-32388
30 May 2023 — A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in watchOS 9.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. An app may be able to bypass Privacy preferences. • https://support.apple.com/en-us/HT213757 • CWE-281: Improper Preservation of Permissions •
CVE-2023-32375 – Apple macOS Hydra USD Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2023-32375
30 May 2023 — An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.6, macOS Ventura 13.4. Processing a 3D model may result in disclosure of process memory. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Apple macOS. Interaction with the Hydra library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the Hydra framework. • https://support.apple.com/en-us/HT213758 • CWE-125: Out-of-bounds Read •
CVE-2023-32380
https://notcve.org/view.php?id=CVE-2023-32380
30 May 2023 — An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. Processing a 3D model may lead to arbitrary code execution. • https://support.apple.com/en-us/HT213758 • CWE-787: Out-of-bounds Write •
CVE-2023-32382
https://notcve.org/view.php?id=CVE-2023-32382
30 May 2023 — An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. Processing a 3D model may result in disclosure of process memory. • https://support.apple.com/en-us/HT213758 • CWE-125: Out-of-bounds Read •
CVE-2023-32384 – Apple macOS ImageIO EXR File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2023-32384
30 May 2023 — A buffer overflow was addressed with improved bounds checking. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. Processing an image may lead to arbitrary code execution. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. Interaction with the ImageIO library is required to exploit this vulnerability but attack vectors may vary depen... • https://support.apple.com/en-us/HT213757 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •
CVE-2023-32355
https://notcve.org/view.php?id=CVE-2023-32355
30 May 2023 — A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An app may be able to modify protected parts of the file system. • https://support.apple.com/en-us/HT213758 • CWE-281: Improper Preservation of Permissions •