CVE-2021-1808 – Apple Security Advisory 2021-04-26-2
https://notcve.org/view.php?id=CVE-2021-1808
28 Apr 2021 — A memory corruption issue was addressed with improved validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. An application may be able to read restricted memory. Se abordó un problema de corrupción de la memoria con una comprobación mejorada. Este problema se corrigió en Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS versión 14.5 e iPadOS versión 14.5, watchOS versi... • https://support.apple.com/en-us/HT212317 • CWE-787: Out-of-bounds Write •
CVE-2021-1809 – Apple Security Advisory 2021-04-26-2
https://notcve.org/view.php?id=CVE-2021-1809
28 Apr 2021 — A memory corruption issue was addressed with improved validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A malicious application may be able to read restricted memory. Se abordó un problema de corrupción de la memoria con una comprobación mejorada. Este problema se corrigió en Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS versión 14.5 e iPadOS versión 14.5, watc... • https://support.apple.com/en-us/HT212317 • CWE-787: Out-of-bounds Write •
CVE-2020-29615
https://notcve.org/view.php?id=CVE-2020-29615
02 Apr 2021 — An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 7.2, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. Processing a maliciously crafted image may lead to a denial of service. Se abordó una lectura fuera de límites con una comprobación de la entrada mejorada. Este problema es corregido en watchOS versión 7.2, macOS Big Sur versión 11.1, Security Update 2020-001 Catalina, Security... • https://support.apple.com/en-us/HT212003 • CWE-125: Out-of-bounds Read •
CVE-2020-27933
https://notcve.org/view.php?id=CVE-2020-27933
02 Apr 2021 — A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, iCloud for Windows 7.20, watchOS 6.2.8, tvOS 13.4.8, macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra. Processing a maliciously crafted image may lead to arbitrary code execution. Se abordó un problema de corrupción de memoria con una comprobación de la entrada mejorada. Este problema es corregido en iOS versión 13.6 y iPadOS versión 13.6,... • https://support.apple.com/en-us/HT211288 • CWE-787: Out-of-bounds Write •
CVE-2020-27935
https://notcve.org/view.php?id=CVE-2020-27935
02 Apr 2021 — Multiple issues were addressed with improved logic. This issue is fixed in iOS 14.2 and iPadOS 14.2, macOS Big Sur 11.0.1, watchOS 7.1, tvOS 14.2. A sandboxed process may be able to circumvent sandbox restrictions. Se abordaron múltiples problemas con una lógica mejorada. Este problema es corregido en iOS versión 14.2 y iPadOS versión 14.2, macOS Big Sur versión 11.0.1, watchOS versión 7.1, tvOS versión 14.2. • https://github.com/LIJI32/SnatchBox •
CVE-2020-9926
https://notcve.org/view.php?id=CVE-2020-9926
02 Apr 2021 — A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, iCloud for Windows 7.20, macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra. Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution. Se abordó un problema de uso de la memoria previamente liberada con la mejora la administración de la memoria. Este problema e... • https://support.apple.com/en-us/HT211288 • CWE-416: Use After Free •
CVE-2020-29610 – Apple macOS AudioToolboxCore MP4 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2020-29610
30 Mar 2021 — An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 7.2, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. Processing a maliciously crafted audio file may disclose restricted memory. Se abordó una lectura fuera de límites con una comprobación de la entrada mejorada. Este problema es corregido en watchOS versión 7.2, macOS Big Sur versión 11.1, Security Update 2020-001 Catalina, Secu... • https://support.apple.com/en-us/HT212003 • CWE-125: Out-of-bounds Read •
CVE-2021-1879 – Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability
https://notcve.org/view.php?id=CVE-2021-1879
29 Mar 2021 — This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and iPadOS 14.4.2, watchOS 7.3.3. Processing maliciously crafted web content may lead to universal cross site scripting. Apple is aware of a report that this issue may have been actively exploited.. Este problema es abordado con una administración del tiempo de vida de objetos mejorada. • https://support.apple.com/en-us/HT212256 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-7463 – Apple Security Advisory 2021-04-26-2
https://notcve.org/view.php?id=CVE-2020-7463
26 Mar 2021 — In FreeBSD 12.1-STABLE before r364644, 11.4-STABLE before r364651, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 11.3-RELEASE before p13, improper handling in the kernel causes a use-after-free bug by sending large user messages from multiple threads on the same SCTP socket. The use-after-free situation may result in unintended kernel behaviour including a kernel panic. En FreeBSD versiones 12.1-STABLE anteriores a r364644, 11.4-STABLE anteriores a r364651, 12.1-RELEASE anteriores a p9, 11.4-RELEASE a... • http://seclists.org/fulldisclosure/2021/Apr/49 • CWE-416: Use After Free •
CVE-2021-1844 – webkitgtk: Memory corruption issue leading to arbitrary code execution
https://notcve.org/view.php?id=CVE-2021-1844
09 Mar 2021 — A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 14.4.1 and iPadOS 14.4.1, Safari 14.0.3 (v. 14610.4.3.1.7 and 15610.4.3.1.7), watchOS 7.3.2, macOS Big Sur 11.2.3. Processing maliciously crafted web content may lead to arbitrary code execution. Se abordó un problema de corrupción de memoria con una comprobación mejorada. Este problema es corregido en iOS versión 14.4.1 y iPadOS versión 14.4.1, Safari versión 14.0.3 (versiones v.14610.4.3.1.7 y 15610.4.3.1.7),... • http://seclists.org/fulldisclosure/2021/Apr/55 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-787: Out-of-bounds Write •