
CVE-2021-1883 – Apple Security Advisory 2021-05-25-4
https://notcve.org/view.php?id=CVE-2021-1883
28 Apr 2021 — This issue was addressed with improved checks. This issue is fixed in Security Update 2021-004 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, Security Update 2021-003 Catalina, tvOS 14.5, macOS Big Sur 11.3. Processing maliciously crafted server messages may lead to heap corruption. Este problema es abordado con comprobaciones mejoradas. Este problema se corrigió en Security Update 2021-004 Mojave, iOS versión 14.5 e iPadOS versión 14.5, watchOS versión 7.4, Security Update 2021-003 Catalina, tvOS versión 1... • https://github.com/gabe-k/CVE-2021-1883 • CWE-787: Out-of-bounds Write •

CVE-2021-1885 – Apple Security Advisory 2021-04-26-2
https://notcve.org/view.php?id=CVE-2021-1885
28 Apr 2021 — An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing a maliciously crafted image may lead to arbitrary code execution. Se abordó una lectura fuera de límites con una comprobación de límites mejorada. Este problema es corregido en macOS Big Sur versión 11.3, iOS versión 14.5 y iPadOS versión 14.5, watchOS versión 7.4, tvOS versión 14.5. • https://support.apple.com/en-us/HT212317 • CWE-125: Out-of-bounds Read •

CVE-2021-1868 – Apple Security Advisory 2021-04-26-2
https://notcve.org/view.php?id=CVE-2021-1868
28 Apr 2021 — A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A local attacker may be able to elevate their privileges. Se abordó un problema lógico con una administración de estado mejorada. Este problema se corrigió en Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS versión 14.5 e iPadOS versión 14.5, watchOS versión 7.4, tvO... • https://support.apple.com/en-us/HT212317 • CWE-269: Improper Privilege Management •

CVE-2021-1820 – webkitgtk: Memory initialization issue possibly leading to memory disclosure
https://notcve.org/view.php?id=CVE-2021-1820
28 Apr 2021 — A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing maliciously crafted web content may result in the disclosure of process memory. Se abordó un problema de inicialización de la memoria con un manejo de la memoria mejorada. Este problema se corrigió en macOS Big Sur versión 11.3, iOS versión 14.5 e iPadOS versión 14.5, watchOS versión 7.4, tvOS versión 14.5. • https://support.apple.com/en-us/HT212317 • CWE-20: Improper Input Validation CWE-665: Improper Initialization •

CVE-2021-1813 – Apple Security Advisory 2021-04-26-2
https://notcve.org/view.php?id=CVE-2021-1813
28 Apr 2021 — A validation issue was addressed with improved logic. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A malicious application may be able to gain root privileges. Se abordó un problema de comprobación con una lógica mejorada. Este problema se corrigió en Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS versión 14.5 e iPadOS versión 14.5, watchOS versión 7.4, tvOS versión 14... • https://support.apple.com/en-us/HT212317 • CWE-269: Improper Privilege Management •

CVE-2021-1811 – Apple Security Advisory 2021-04-26-2
https://notcve.org/view.php?id=CVE-2021-1811
28 Apr 2021 — A logic issue was addressed with improved state management. This issue is fixed in iTunes 12.11.3 for Windows, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iCloud for Windows 12.3, macOS Big Sur 11.3, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing a maliciously crafted font may result in the disclosure of process memory. Se abordó un problema lógico con una administración de estado mejorada. Este problema se corrigió en iTunes versión 12.11.3 para Windows, Security Updat... • https://support.apple.com/en-us/HT212317 •

CVE-2021-1814 – Apple macOS ImageIO DDS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2021-1814
28 Apr 2021 — This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.3, watchOS 7.4. Processing a maliciously crafted image may lead to arbitrary code execution. Este problema es abordado con comprobaciones mejoradas. Este problema se corrigió en macOS Big Sur versión 11.3, watchOS versión 7.4. • https://support.apple.com/en-us/HT212324 •

CVE-2021-30661 – Apple Multiple Products WebKit Storage Use-After-Free Vulnerability
https://notcve.org/view.php?id=CVE-2021-30661
28 Apr 2021 — A use after free issue was addressed with improved memory management. This issue is fixed in Safari 14.1, iOS 12.5.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.. Se abordó un problema de uso de la memoria previamente liberada con una administración de la memoria mejorada. • https://support.apple.com/en-us/HT212317 • CWE-20: Improper Input Validation CWE-416: Use After Free •

CVE-2021-1884 – Apple Security Advisory 2021-05-25-4
https://notcve.org/view.php?id=CVE-2021-1884
28 Apr 2021 — A race condition was addressed with improved locking. This issue is fixed in Security Update 2021-004 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, Security Update 2021-003 Catalina, tvOS 14.5, macOS Big Sur 11.3. A remote attacker may be able to cause a denial of service. Se abordó una condición de carrera con un bloqueo mejorado. Este problema es corregido en Security Update 2021-004 Mojave, iOS versión 14.5 y iPadOS versión 14.5, watchOS versión 7.4, Security Update 2021-003 Catalina, tvOS versión 14.5,... • https://support.apple.com/en-us/HT212317 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •

CVE-2021-1822 – Apple Security Advisory 2021-04-26-6
https://notcve.org/view.php?id=CVE-2021-1822
28 Apr 2021 — A logic issue was addressed with improved restrictions. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A local user may be able to modify protected parts of the file system. Se abordó un problema lógico con restricciones mejoradas. Este problema se corrigió en iOS versión 14.5 e iPadOS versión 14.5, watchOS versión 7.4, tvOS versión 14.5. • https://support.apple.com/en-us/HT212317 •