CVE-2021-30979 – Apple macOS ModelIO ABC File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2021-30979
24 Aug 2021 — A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.1, iOS 15.2 and iPadOS 15.2, macOS Big Sur 11.6.2, Security Update 2021-008 Catalina. Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution. Se abordó un problema de desbordamiento del búfer con una administración de la memoria mejorada. Este problema es corregido en macOS Monterey versión 12.1, iOS versión 15.2 e iPadOS versión 15.... • https://support.apple.com/en-us/HT212976 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •
CVE-2021-30977
https://notcve.org/view.php?id=CVE-2021-30977
24 Aug 2021 — A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.1, Security Update 2021-008 Catalina, macOS Big Sur 11.6.2. A malicious application may be able to execute arbitrary code with kernel privileges. Se abordó un desbordamiento de búfer con una comprobación de límites mejorada. Este problema es corregido en macOS Monterey versión 12.1, Security Update 2021-008 Catalina, macOS Big Sur versión 11.6.2. • https://support.apple.com/en-us/HT212978 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •
CVE-2021-30976
https://notcve.org/view.php?id=CVE-2021-30976
24 Aug 2021 — A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.1, Security Update 2021-008 Catalina, macOS Big Sur 11.6.2. A malicious application may bypass Gatekeeper checks. Se abordó un problema lógico con una administración de estado mejorada. Este problema es corregido en macOS Monterey versión 12.1, Security Update 2021-008 Catalina, macOS Big Sur versión 11.6.2. • https://support.apple.com/en-us/HT212978 •
CVE-2021-30975
https://notcve.org/view.php?id=CVE-2021-30975
24 Aug 2021 — This issue was addressed by disabling execution of JavaScript when viewing a scripting dictionary. This issue is fixed in macOS Monterey 12.1, Security Update 2021-008 Catalina, macOS Big Sur 11.6.2. A malicious OSAX scripting addition may bypass Gatekeeper checks and circumvent sandbox restrictions. Este problema es corregido al deshabilitar la ejecución de JavaScript al visualizar un diccionario de scripts. Este problema es corregido en macOS Monterey versión 12.1, Security Update 2021-008 Catalina, ... • https://support.apple.com/en-us/HT212978 • CWE-863: Incorrect Authorization •
CVE-2021-30973
https://notcve.org/view.php?id=CVE-2021-30973
24 Aug 2021 — An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Monterey 12.1, iOS 15.2 and iPadOS 15.2, macOS Big Sur 11.6.2, Security Update 2021-008 Catalina. Processing a maliciously crafted file may disclose user information. Se abordó una lectura fuera de límites con una comprobación de entrada mejorada. Este problema es corregido en macOS Monterey versión 12.1, iOS versión 15.2 e iPadOS versión 15.2, macOS Big Sur versión 11.6.2, Security Update 2021-008 Catalina... • https://support.apple.com/en-us/HT212976 • CWE-125: Out-of-bounds Read •
CVE-2021-30972
https://notcve.org/view.php?id=CVE-2021-30972
24 Aug 2021 — This issue was addressed with improved checks. This issue is fixed in Security Update 2022-001 Catalina, macOS Big Sur 11.6.3. A malicious application may be able to bypass certain Privacy preferences. Este problema se ha solucionado con la mejora de las comprobaciones. Este problema se ha solucionado en la actualización de seguridad 2022-001 Catalina, macOS Big Sur 11.6.3. • https://support.apple.com/en-us/HT213055 • CWE-863: Incorrect Authorization •
CVE-2021-30971
https://notcve.org/view.php?id=CVE-2021-30971
24 Aug 2021 — An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.1, iOS 15.2 and iPadOS 15.2, macOS Big Sur 11.6.2, Security Update 2021-008 Catalina. Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution. Se abordó un problema de escritura fuera de límites con una comprobación de límites mejorada. Este problema es corregido en macOS Monterey versión 12.1, iOS versión 15.2 e iPadOS versión 1... • https://support.apple.com/en-us/HT212976 • CWE-787: Out-of-bounds Write •
CVE-2021-30970
https://notcve.org/view.php?id=CVE-2021-30970
24 Aug 2021 — A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.1, macOS Big Sur 11.6.2. A malicious application may be able to bypass Privacy preferences. Se abordó un problema lógico con una administración de estado mejorada. Este problema es corregido en macOS Monterey versión 12.1, macOS Big Sur versión 11.6.2. • https://support.apple.com/en-us/HT212978 •
CVE-2021-30968
https://notcve.org/view.php?id=CVE-2021-30968
24 Aug 2021 — A validation issue related to hard link behavior was addressed with improved sandbox restrictions. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. A malicious application may be able to bypass certain Privacy preferences. Se abordó un problema de comprobación relacionado con el comportamiento de los enlaces físicos con restricciones del sandbox mejoradas. Este problema es corregido en macOS Big Sur ve... • https://support.apple.com/en-us/HT212975 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •
CVE-2021-30966
https://notcve.org/view.php?id=CVE-2021-30966
24 Aug 2021 — A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.1, watchOS 8.3, iOS 15.2 and iPadOS 15.2, tvOS 15.2. User traffic might unexpectedly be leaked to a proxy server despite PAC configurations. Se abordó un problema lógico con una administración de estado mejorada. Este problema es corregido en macOS Monterey versión 12.1, watchOS versión 8.3, iOS versión 15.2 e iPadOS versión 15.2, tvOS versión 15.2. • https://support.apple.com/en-us/HT212975 •