
CVE-2021-1885 – Apple Security Advisory 2021-04-26-2
https://notcve.org/view.php?id=CVE-2021-1885
28 Apr 2021 — An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing a maliciously crafted image may lead to arbitrary code execution. Se abordó una lectura fuera de límites con una comprobación de límites mejorada. Este problema es corregido en macOS Big Sur versión 11.3, iOS versión 14.5 y iPadOS versión 14.5, watchOS versión 7.4, tvOS versión 14.5. • https://support.apple.com/en-us/HT212317 • CWE-125: Out-of-bounds Read •

CVE-2021-1825 – webkitgtk: Input validation issue leading to cross site scripting attack
https://notcve.org/view.php?id=CVE-2021-1825
28 Apr 2021 — An input validation issue was addressed with improved input validation. This issue is fixed in iTunes 12.11.3 for Windows, iCloud for Windows 12.3, macOS Big Sur 11.3, Safari 14.1, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing maliciously crafted web content may lead to a cross site scripting attack. Se abordó un problema de comprobación de entradas con una comprobación de entrada mejorada. Este problema se corrigió en iTunes versión 12.11.3 para Windows, iCloud para Windows versión 12.3, mac... • https://support.apple.com/en-us/HT212317 • CWE-20: Improper Input Validation CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-1851 – Apple Security Advisory 2021-04-26-2
https://notcve.org/view.php?id=CVE-2021-1851
28 Apr 2021 — A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. An application may be able to execute arbitrary code with kernel privileges. Se abordó un problema lógico con una administración de estado mejorada. Este problema se corrigió en Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS versión 14.5 e iPadOS versión 14.5, watch... • https://support.apple.com/en-us/HT212317 • CWE-269: Improper Privilege Management •

CVE-2021-30652 – Apple Security Advisory 2021-04-26-2
https://notcve.org/view.php?id=CVE-2021-30652
28 Apr 2021 — A race condition was addressed with additional validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A malicious application may be able to gain root privileges. Se abordó una condición de carrera con una comprobación adicional. Este problema es corregido en Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS versión 14.5 y iPadOS versión 14.5, watchOS versión 7.4, tvOS ... • https://support.apple.com/en-us/HT212317 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •

CVE-2021-1739 – Apple Security Advisory 2021-04-26-2
https://notcve.org/view.php?id=CVE-2021-1739
28 Apr 2021 — A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A local user may be able to modify protected parts of the file system. Se abordó un problema de análisis en el manejo de las rutas de los directorios con una comprobación de rutas mejorada. Este problema se corrigió en Security Update 2021-002 Catalina, S... • https://support.apple.com/en-us/HT212317 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2021-1816 – Apple Security Advisory 2021-04-26-6
https://notcve.org/view.php?id=CVE-2021-1816
28 Apr 2021 — A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A malicious application may be able to execute arbitrary code with kernel privileges. Se abordó un desbordamiento de búfer con una comprobación de límites mejorada. Este problema se corrigió en iOS versión 14.5 e iPadOS versión 14.5, watchOS versión 7.4, tvOS versión 14.5. • https://support.apple.com/en-us/HT212317 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2021-1868 – Apple Security Advisory 2021-04-26-2
https://notcve.org/view.php?id=CVE-2021-1868
28 Apr 2021 — A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A local attacker may be able to elevate their privileges. Se abordó un problema lógico con una administración de estado mejorada. Este problema se corrigió en Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS versión 14.5 e iPadOS versión 14.5, watchOS versión 7.4, tvO... • https://support.apple.com/en-us/HT212317 • CWE-269: Improper Privilege Management •

CVE-2021-30661 – Apple Multiple Products WebKit Storage Use-After-Free Vulnerability
https://notcve.org/view.php?id=CVE-2021-30661
28 Apr 2021 — A use after free issue was addressed with improved memory management. This issue is fixed in Safari 14.1, iOS 12.5.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.. Se abordó un problema de uso de la memoria previamente liberada con una administración de la memoria mejorada. • https://support.apple.com/en-us/HT212317 • CWE-20: Improper Input Validation CWE-416: Use After Free •

CVE-2020-29615
https://notcve.org/view.php?id=CVE-2020-29615
02 Apr 2021 — An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 7.2, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. Processing a maliciously crafted image may lead to a denial of service. Se abordó una lectura fuera de límites con una comprobación de la entrada mejorada. Este problema es corregido en watchOS versión 7.2, macOS Big Sur versión 11.1, Security Update 2020-001 Catalina, Security... • https://support.apple.com/en-us/HT212003 • CWE-125: Out-of-bounds Read •

CVE-2020-27933
https://notcve.org/view.php?id=CVE-2020-27933
02 Apr 2021 — A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, iCloud for Windows 7.20, watchOS 6.2.8, tvOS 13.4.8, macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra. Processing a maliciously crafted image may lead to arbitrary code execution. Se abordó un problema de corrupción de memoria con una comprobación de la entrada mejorada. Este problema es corregido en iOS versión 13.6 y iPadOS versión 13.6,... • https://support.apple.com/en-us/HT211288 • CWE-787: Out-of-bounds Write •