CVE-2021-1785 – Apple Security Advisory 2021-02-01-3
https://notcve.org/view.php?id=CVE-2021-1785
02 Feb 2021 — An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to arbitrary code execution. Se abordó una lectura fuera de límites con una comprobación de la entrada mejorada. Este problema es corregido en macOS Big Sur versión 11.2, Security Update 2021-001 Catalina, Security Update 2021-001... • https://support.apple.com/en-us/HT212146 • CWE-125: Out-of-bounds Read •
CVE-2021-1786 – Apple Security Advisory 2021-02-01-3
https://notcve.org/view.php?id=CVE-2021-1786
02 Feb 2021 — A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A local user may be able to create or modify system files. Se abordó un problema de lógica con una administración de estado mejorada. Este problema es corregido en macOS Big Sur versión 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS versión 7.3, tvOS ... • https://support.apple.com/en-us/HT212146 •
CVE-2021-1787 – Apple Security Advisory 2021-02-01-3
https://notcve.org/view.php?id=CVE-2021-1787
02 Feb 2021 — Multiple issues were addressed with improved logic. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A local attacker may be able to elevate their privileges. Se abordaron múltiples problemas con una lógica mejorada. Este problema es corregido en macOS Big Sur versión 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS versión 7.3, tvOS versión 14.4, iOS versión ... • https://support.apple.com/en-us/HT212146 • CWE-269: Improper Privilege Management •
CVE-2021-1788 – webkitgtk: Use-after-free leading to arbitrary code execution
https://notcve.org/view.php?id=CVE-2021-1788
02 Feb 2021 — A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4, Safari 14.0.3. Processing maliciously crafted web content may lead to arbitrary code execution. Se abordó un problema de uso de la memoria previamente liberada con una administración de la memoria mejorada. Este problema es corregido en macOS Big Sur versión 11.2, Security Up... • https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L3L6ZZOU5JS7E3RFYGLP7UFLXCG7TNLU • CWE-416: Use After Free •
CVE-2021-1789 – Apple Multiple Products Type Confusion Vulnerability
https://notcve.org/view.php?id=CVE-2021-1789
02 Feb 2021 — A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4, Safari 14.0.3. Processing maliciously crafted web content may lead to arbitrary code execution. Se abordó un problema de confusión de tipos con un manejo del estado mejorado. Este problema es corregido en macOS Big Sur versión 11.2, Security Update 2021-001 Catalina, Security Up... • https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JN6ZOD62CTO54CHTMJTHVEF6R2Y532TJ • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •
CVE-2021-1791 – Apple iOS FairplayIOKit Out-Of-Bounds Read Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2021-1791
02 Feb 2021 — An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application may be able to disclose kernel memory. Se presentó un problema de lectura fuera de límites que conllevó a una divulgación de la memoria del kernel. • https://support.apple.com/en-us/HT212146 • CWE-125: Out-of-bounds Read •
CVE-2021-1792 – Apple macOS CoreText TTF Parsing Out-of-Bounds Read Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2021-1792
02 Feb 2021 — An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Se abordó una lectura fuera de límites con una comprobación de límites mejorada. Este problema es corregido en macOS Big Sur versión 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS... • https://support.apple.com/en-us/HT212146 • CWE-125: Out-of-bounds Read •
CVE-2021-1782 – Apple Multiple Products Race Condition Vulnerability
https://notcve.org/view.php?id=CVE-2021-1782
27 Jan 2021 — A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited.. Se abordó una condición de carrera con un bloqueo mejorado. • https://github.com/synacktiv/CVE-2021-1782 • CWE-667: Improper Locking •
CVE-2020-27943 – Apple CoreText libType1Scaler.dylib Buffer Overflow
https://notcve.org/view.php?id=CVE-2020-27943
16 Dec 2020 — A memory corruption issue existed in the processing of font files. This issue was addressed with improved input validation. This issue is fixed in tvOS 14.3, iOS 14.3 and iPadOS 14.3, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.2. Processing a maliciously crafted font file may lead to arbitrary code execution. Se presentó un problema de corrupción de memoria en un procesamiento de archivos de fuentes. • https://support.apple.com/en-us/HT212003 • CWE-787: Out-of-bounds Write •
CVE-2020-27944 – Apple CoreText libType1Scaler.dylib Out-Of-Bounds Write / Integer Overflow
https://notcve.org/view.php?id=CVE-2020-27944
16 Dec 2020 — A memory corruption issue existed in the processing of font files. This issue was addressed with improved input validation. This issue is fixed in watchOS 7.2, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. Processing a maliciously crafted font file may lead to arbitrary code execution. Se presentó un problema de corrupción de memoria en un procesamiento de archivos de fuentes. • https://support.apple.com/en-us/HT212003 • CWE-787: Out-of-bounds Write •