
CVE-2021-30799 – webkitgtk: Memory corruptions leading to arbitrary code execution
https://notcve.org/view.php?id=CVE-2021-30799
23 Jul 2021 — Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. Processing maliciously crafted web content may lead to arbitrary code execution. Se abordaron múltiples problemas de corrupción de la memoria con una administración de memoria mejorada. Este problema se corrigió en iOS versión 14.7, macOS Big Sur versión 11.5, Security Update 2021-004 Catalina y Security Updat... • https://packetstorm.news/files/id/163886 • CWE-20: Improper Input Validation CWE-787: Out-of-bounds Write •

CVE-2021-30800 – Apple Security Advisory 2021-07-21-1
https://notcve.org/view.php?id=CVE-2021-30800
23 Jul 2021 — This issue was addressed with improved checks. This issue is fixed in iOS 14.7. Joining a malicious Wi-Fi network may result in a denial of service or arbitrary code execution. Se abordó este problema con comprobaciones mejoradas. Este problema se corrigió en iOS versión 14.7. • https://support.apple.com/en-us/HT212601 •

CVE-2021-30802 – Apple Security Advisory 2021-07-21-1
https://notcve.org/view.php?id=CVE-2021-30802
23 Jul 2021 — A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.7, tvOS 14.7. Processing maliciously crafted web content may lead to arbitrary code execution. Se abordó un problema de uso de memoria previamente liberada con una administración de memoria mejorada. Este problema se corrigió en iOS versión 14.7 y tvOS versión 14.7. • https://support.apple.com/en-us/HT212601 • CWE-416: Use After Free •

CVE-2021-30804 – Apple Security Advisory 2021-07-21-1
https://notcve.org/view.php?id=CVE-2021-30804
23 Jul 2021 — A permissions issue was addressed with improved validation. This issue is fixed in iOS 14.7. A malicious application may be able to access Find My data. Se abordó un problema de permisos con una comprobación mejorada. Este problema se corrigió en iOS versión 14.7. • https://support.apple.com/en-us/HT212601 •

CVE-2021-30662 – Apple macOS ImageIO TIFF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2021-30662
22 Jul 2021 — This issue was addressed with improved checks. This issue is fixed in iOS 14.5 and iPadOS 14.5. Processing a maliciously crafted file may lead to arbitrary code execution. Se abordó este problema con comprobaciones mejoradas. Este problema es corregido en iOS versión 14.5 y iPadOS versión 14.5. • https://support.apple.com/en-us/HT212317 •

CVE-2021-30742 – Apple macOS AudioToolboxCore LOAS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2021-30742
22 Jul 2021 — A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 14.5 and iPadOS 14.5. Processing a maliciously crafted audio file may lead to arbitrary code execution. Se abordó un problema de consumo de memoria con un manejo de la memoria mejorada. Este problema se corrigió en iOS versión 14.5 e iPadOS versión 14.5. • https://support.apple.com/en-us/HT212317 •

CVE-2021-30764 – Apple macOS ImageIO WEBP File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2021-30764
22 Jul 2021 — Processing a maliciously crafted file may lead to arbitrary code execution. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. This issue was addressed with improved checks. El procesamiento de un archivo diseñado maliciosamente puede conllevar a una ejecución de código arbitrario. Este problema se corrigió en iOS versión 14.5 e iPadOS versión 14.5, watchOS versión 7.4, tvOS versión 14.5. • https://support.apple.com/en-us/HT212317 •

CVE-2021-36976 – Apple Security Advisory 2022-03-14-4
https://notcve.org/view.php?id=CVE-2021-36976
20 Jul 2021 — libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block). libarchive versiones 3.4.1 hasta 3.5.1, presenta un uso de memoria previamente liberada en la función copy_string (llamado desde do_uncompress_block y process_block) It was discovered that libarchive incorrectly handled symlinks. If a user or automated system were tricked into processing a specially crafted archive, an attacker could possibly use this issue to change modes, times, ACLs, an... • http://seclists.org/fulldisclosure/2022/Mar/27 • CWE-416: Use After Free •

CVE-2021-32755 – Certificate pinning is not enforced on the web socket connection
https://notcve.org/view.php?id=CVE-2021-32755
13 Jul 2021 — Wire is a collaboration platform. wire-ios-transport handles authentication of requests, network failures, and retries for the iOS implementation of Wire. In the 3.82 version of the iOS application, a new web socket implementation was introduced for users running iOS 13 or higher. This new websocket implementation is not configured to enforce certificate pinning when available. Certificate pinning for the new websocket is enforced in version 3.84 or above. Wire es una plataforma de colaboración. wire-ios-tr... • https://github.com/wireapp/wire-ios-transport/security/advisories/GHSA-v8mx-h3vj-w39v • CWE-295: Improper Certificate Validation •

CVE-2021-1838 – Apple macOS ImageIO PICT File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2021-1838
02 Jun 2021 — This issue was addressed with improved checks. This issue is fixed in iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to arbitrary code execution. Se abordó este problema con comprobaciones mejoradas. Este problema se corrigió en iOS versión 14.4 e iPadOS versión 14.4. • https://support.apple.com/en-us/HT212146 •