CVE-2021-30881 – Apple Security Advisory 2021-10-26-4
https://notcve.org/view.php?id=CVE-2021-30881
24 Aug 2021 — An input validation issue was addressed with improved memory handling. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, tvOS 15.1, watchOS 8.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. Unpacking a maliciously crafted archive may lead to arbitrary code execution. Se abordó un problema de comprobación de entradas con una administración de la memoria mejorada. Este problema se corrigió en iOS versión 15.1 y iPadOS versión 15.1, macOS Monterey versión 12.0.1, tvOS versión ... • https://support.apple.com/en-us/HT212867 • CWE-20: Improper Input Validation •
CVE-2021-30865 – Apple Security Advisory 2021-09-20-8
https://notcve.org/view.php?id=CVE-2021-30865
24 Aug 2021 — An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.6, Security Update 2021-005 Catalina. A malicious application may be able to execute arbitrary code with kernel privileges. Se abordó una lectura fuera de límites con una comprobación de entradas mejorada. Este problema se corrigió en macOS Big Sur versión 11.6, Security Update 2021-005 Catalina. • https://support.apple.com/en-us/HT212804 • CWE-125: Out-of-bounds Read •
CVE-2021-30859 – Apple Security Advisory 2021-09-20-8
https://notcve.org/view.php?id=CVE-2021-30859
24 Aug 2021 — A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina. A malicious application may be able to execute arbitrary code with kernel privileges. Se abordó un problema de confusión de tipos con una administración de estado mejorada. Este problema se corrigió en iOS versión 14.8 y iPadOS versión 14.8, macOS Big Sur versión 11.6, Security Update 2021-005 Catalina. • https://support.apple.com/en-us/HT212804 • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •
CVE-2021-30857 – Apple Security Advisory 2021-10-26-11
https://notcve.org/view.php?id=CVE-2021-30857
24 Aug 2021 — A race condition was addressed with improved locking. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, tvOS 15, iOS 15 and iPadOS 15, watchOS 8, macOS Big Sur 11.6. A malicious application may be able to execute arbitrary code with kernel privileges. Se abordó una condición de carrera con un bloqueo mejorado. Este problema se corrigió en Security Update 2021-005 Catalina, iOS versión 14.8 y iPadOS versión 14.8, tvOS versión 15, iOS versión 15 y iPadOS versión 15, watchOS v... • https://support.apple.com/en-us/HT212804 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •
CVE-2021-30855 – Apple Security Advisory 2021-10-26-9
https://notcve.org/view.php?id=CVE-2021-30855
24 Aug 2021 — A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, iOS 15 and iPadOS 15, watchOS 8, macOS Big Sur 11.6. An application may be able to access restricted files. Se presentó un problema de comprobación en el manejo de los enlaces simbólicos. • https://support.apple.com/en-us/HT212804 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •
CVE-2020-27936
https://notcve.org/view.php?id=CVE-2020-27936
02 Apr 2021 — An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A local user may be able to cause unexpected system termination or read kernel memory. Se presentó un problema de lectura fuera de límites que conllevó a una divulgación de la memoria del Kernel. • https://support.apple.com/en-us/HT212011 • CWE-125: Out-of-bounds Read •
CVE-2020-27923
https://notcve.org/view.php?id=CVE-2020-27923
02 Apr 2021 — An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, watchOS 7.1, tvOS 14.2. Processing a maliciously crafted image may lead to arbitrary code execution. Se abordó una escritura fuera de límites con una comprobación de la entrada mejorada. Este problema es corregido en macOS Big Sur versión 11.1, Security Update 2020-001 Catalina,... • https://support.apple.com/en-us/HT211928 • CWE-787: Out-of-bounds Write •
CVE-2020-27924
https://notcve.org/view.php?id=CVE-2020-27924
02 Apr 2021 — An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, watchOS 7.1, tvOS 14.2. Processing a maliciously crafted image may lead to arbitrary code execution. Se abordó una lectura fuera de límites con una comprobación de la entrada mejorada. Este problema es corregido en macOS Big Sur versión 11.1, Security Update 2020-001 Catalina, Se... • https://support.apple.com/en-us/HT211928 • CWE-125: Out-of-bounds Read •
CVE-2020-27935
https://notcve.org/view.php?id=CVE-2020-27935
02 Apr 2021 — Multiple issues were addressed with improved logic. This issue is fixed in iOS 14.2 and iPadOS 14.2, macOS Big Sur 11.0.1, watchOS 7.1, tvOS 14.2. A sandboxed process may be able to circumvent sandbox restrictions. Se abordaron múltiples problemas con una lógica mejorada. Este problema es corregido en iOS versión 14.2 y iPadOS versión 14.2, macOS Big Sur versión 11.0.1, watchOS versión 7.1, tvOS versión 14.2. • https://github.com/LIJI32/SnatchBox •
CVE-2020-10001 – cups: access to uninitialized buffer in ipp.c
https://notcve.org/view.php?id=CVE-2020-10001
02 Apr 2021 — An input validation issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may be able to read restricted memory. Se abordó un problema de comprobación de la entrada con un manejo de la memoria mejorada. Este problema es corregido en macOS Big Sur versión 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. • https://lists.debian.org/debian-lts-announce/2021/10/msg00027.html • CWE-20: Improper Input Validation CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •