CVE-2021-30884 – webkitgtk: CSS compositing issue leading to revealing of the browsing history
https://notcve.org/view.php?id=CVE-2021-30884
24 Aug 2021 — The issue was resolved with additional restrictions on CSS compositing. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Visiting a maliciously crafted website may reveal a user's browsing history. El problema se resolvió con restricciones adicionales en la composición de CSS. Este problema se corrigió en tvOS versión 15, watchOS versión 8, iOS versión 15 y iPadOS versión 15. • http://www.openwall.com/lists/oss-security/2021/12/20/6 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2021-30883 – Apple Multiple Products Memory Corruption Vulnerability
https://notcve.org/view.php?id=CVE-2021-30883
24 Aug 2021 — A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 15.0.2 and iPadOS 15.0.2, macOS Monterey 12.0.1, iOS 14.8.1 and iPadOS 14.8.1, tvOS 15.1, watchOS 8.1, macOS Big Sur 11.6.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.. Se abordó un problema de corrupción de memoria con un manejo de memoria mejorada. • https://support.apple.com/en-us/HT212846 • CWE-787: Out-of-bounds Write •
CVE-2021-30882 – Apple Security Advisory 2021-10-26-9
https://notcve.org/view.php?id=CVE-2021-30882
24 Aug 2021 — A logic issue was addressed with improved validation. This issue is fixed in watchOS 8, iOS 15 and iPadOS 15. An application with microphone permission may unexpectedly access microphone input during a FaceTime call. Se abordó un problema lógico con una comprobación mejorada. Este problema se corrigió en watchOS versión 8, iOS versión 15 y iPadOS versión 15. • https://support.apple.com/en-us/HT212814 •
CVE-2021-30881 – Apple Security Advisory 2021-10-26-4
https://notcve.org/view.php?id=CVE-2021-30881
24 Aug 2021 — An input validation issue was addressed with improved memory handling. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, tvOS 15.1, watchOS 8.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. Unpacking a maliciously crafted archive may lead to arbitrary code execution. Se abordó un problema de comprobación de entradas con una administración de la memoria mejorada. Este problema se corrigió en iOS versión 15.1 y iPadOS versión 15.1, macOS Monterey versión 12.0.1, tvOS versión ... • https://support.apple.com/en-us/HT212867 • CWE-20: Improper Input Validation •
CVE-2021-30875 – Apple Security Advisory 2021-10-26-1
https://notcve.org/view.php?id=CVE-2021-30875
24 Aug 2021 — A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. This issue is fixed in iOS 15.1 and iPadOS 15.1. A local attacker may be able to view contacts from the lock screen. Un problema con la pantalla de bloqueo permitía acceder a los contactos de un dispositivo bloqueado. • https://support.apple.com/en-us/HT212867 •
CVE-2021-30874 – Apple Security Advisory 2021-10-26-9
https://notcve.org/view.php?id=CVE-2021-30874
24 Aug 2021 — An authorization issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15. A VPN configuration may be installed by an app without user permission. Se abordó un problema de autorización con una administración de estado mejorada. Este problema se corrigió en iOS versión 15 y iPadOS versión 15. • https://support.apple.com/en-us/HT212814 • CWE-862: Missing Authorization •
CVE-2021-30871
https://notcve.org/view.php?id=CVE-2021-30871
24 Aug 2021 — This issue was addressed with a new entitlement. This issue is fixed in iOS 14.7, watchOS 7.6, macOS Big Sur 11.5. A local attacker may be able to access analytics data. Este problema se abordó con un nuevo derecho. Este problema se corrigió en iOS versión 14.7, watchOS versión 7.6 y macOS Big Sur versión 11.5. • https://support.apple.com/en-us/HT212601 •
CVE-2021-30870 – Apple Security Advisory 2021-10-26-9
https://notcve.org/view.php?id=CVE-2021-30870
24 Aug 2021 — A logic issue existed in the handling of document loads. This issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15. Previewing an html file attached to a note may unexpectedly contact remote servers. Se presentó un problema lógico en el manejo de las cargas de documentos. • https://support.apple.com/en-us/HT212814 •
CVE-2021-30867 – Apple Security Advisory 2021-10-26-9
https://notcve.org/view.php?id=CVE-2021-30867
24 Aug 2021 — The issue was addressed with improved authentication. This issue is fixed in iOS 15 and iPadOS 15. A malicious application may be able to access photo metadata without needing permission to access photos. El problema se abordó con una autenticación mejorada. Este problema se corrigió en iOS versión 15 y iPadOS versión 15. • https://support.apple.com/en-us/HT212814 • CWE-287: Improper Authentication •
CVE-2021-30866 – Apple Security Advisory 2021-10-26-11
https://notcve.org/view.php?id=CVE-2021-30866
24 Aug 2021 — A user privacy issue was addressed by removing the broadcast MAC address. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. A device may be passively tracked by its WiFi MAC address. Se abordó un problema de privacidad del usuario al remover la dirección MAC de difusión. Este problema se corrigió en tvOS versión 15, watchOS versión 8, iOS versión 15 y iPadOS versión 15. • https://support.apple.com/en-us/HT212814 •