CVE-2023-32375 – Apple macOS Hydra USD Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2023-32375
Crafted data in a USD file can trigger a read past the end of an allocated data structure. • https://support.apple.com/en-us/HT213758 https://support.apple.com/en-us/HT213759 • CWE-125: Out-of-bounds Read •
CVE-2023-32360 – cups: Information leak through Cups-Get-Document operation
https://notcve.org/view.php?id=CVE-2023-32360
An authentication issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An unauthenticated user may be able to access recently printed documents. A vulnerability was found in OpenPrinting CUPS. Unauthorized users are permitted to fetch documents over local or remote networks, leading to confidentiality breach. • https://lists.debian.org/debian-lts-announce/2023/09/msg00041.html https://support.apple.com/en-us/HT213758 https://support.apple.com/en-us/HT213759 https://support.apple.com/en-us/HT213760 https://access.redhat.com/security/cve/CVE-2023-32360 https://bugzilla.redhat.com/show_bug.cgi?id=2230495 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2023-28204 – Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability
https://notcve.org/view.php?id=CVE-2023-28204
An out of bounds read may be possible when processing malicious web content, which can lead to information disclosure. • https://security.gentoo.org/glsa/202401-04 https://support.apple.com/en-us/HT213757 https://support.apple.com/en-us/HT213758 https://support.apple.com/en-us/HT213761 https://support.apple.com/en-us/HT213762 https://support.apple.com/en-us/HT213764 https://support.apple.com/en-us/HT213765 https://access.redhat.com/security/cve/CVE-2023-28204 https://bugzilla.redhat.com/show_bug.cgi?id=2209208 • CWE-20: Improper Input Validation CWE-125: Out-of-bounds Read •
CVE-2023-32372 – Apple macOS EXR Image Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2023-32372
Crafted data in an EXR image can trigger a read past the end of an allocated buffer. • https://support.apple.com/en-us/HT213757 https://support.apple.com/en-us/HT213758 https://support.apple.com/en-us/HT213761 https://support.apple.com/en-us/HT213764 • CWE-125: Out-of-bounds Read •
CVE-2023-20884
https://notcve.org/view.php?id=CVE-2023-20884
An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure. • https://www.vmware.com/security/advisories/VMSA-2023-0011.html • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •