CVE-2023-28180
https://notcve.org/view.php?id=CVE-2023-28180
08 May 2023 — A denial-of-service issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. A user in a privileged network position may be able to cause a denial-of-service. • https://support.apple.com/en-us/HT213670 •
CVE-2023-28182
https://notcve.org/view.php?id=CVE-2023-28182
08 May 2023 — The issue was addressed with improved authentication. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A user in a privileged network position may be able to spoof a VPN server that is configured with EAP-only authentication on a device. • https://support.apple.com/en-us/HT213670 • CWE-287: Improper Authentication •
CVE-2023-28189
https://notcve.org/view.php?id=CVE-2023-28189
08 May 2023 — The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An app may be able to view sensitive information. • https://support.apple.com/en-us/HT213670 •
CVE-2023-28190
https://notcve.org/view.php?id=CVE-2023-28190
08 May 2023 — A privacy issue was addressed by moving sensitive data to a more secure location. This issue is fixed in macOS Ventura 13.3. An app may be able to access user-sensitive data. • https://support.apple.com/en-us/HT213670 •
CVE-2023-28192
https://notcve.org/view.php?id=CVE-2023-28192
08 May 2023 — A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An app may be able to read sensitive location information. • https://support.apple.com/en-us/HT213670 • CWE-276: Incorrect Default Permissions •
CVE-2023-28200
https://notcve.org/view.php?id=CVE-2023-28200
08 May 2023 — A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An app may be able to disclose kernel memory. • https://support.apple.com/en-us/HT213670 • CWE-20: Improper Input Validation •
CVE-2023-27934
https://notcve.org/view.php?id=CVE-2023-27934
08 May 2023 — A memory initialization issue was addressed. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4. A remote attacker may be able to cause unexpected app termination or arbitrary code execution. • https://support.apple.com/en-us/HT213670 • CWE-665: Improper Initialization •
CVE-2023-27943
https://notcve.org/view.php?id=CVE-2023-27943
08 May 2023 — This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4. Files downloaded from the internet may not have the quarantine flag applied. • https://support.apple.com/en-us/HT213670 •
CVE-2023-27951
https://notcve.org/view.php?id=CVE-2023-27951
08 May 2023 — The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An archive may be able to bypass Gatekeeper. • https://support.apple.com/en-us/HT213670 •
CVE-2023-27952
https://notcve.org/view.php?id=CVE-2023-27952
08 May 2023 — A race condition was addressed with improved locking. This issue is fixed in macOS Ventura 13.3. An app may bypass Gatekeeper checks. • https://support.apple.com/en-us/HT213670 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •