CVE-2023-40437
https://notcve.org/view.php?id=CVE-2023-40437
10 Jan 2024 — A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to read sensitive location information. Se solucionó un problema de privacidad mejorando la redacción de datos privados para las entradas de registro. Este problema se solucionó en iOS 16.6 y iPadOS 16.6, macOS Ventura 13.5. • https://support.apple.com/en-us/HT213841 •
CVE-2022-42839
https://notcve.org/view.php?id=CVE-2022-42839
10 Jan 2024 — This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. An app may be able to read sensitive location information. Este problema se solucionó mejorando la redacción de información confidencial. Este problema se solucionó en iOS 16.2 y iPadOS 16.2, macOS Ventura 13.1. • https://support.apple.com/en-us/HT213530 •
CVE-2023-40529
https://notcve.org/view.php?id=CVE-2023-40529
10 Jan 2024 — This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17 and iPadOS 17. A person with physical access to a device may be able to use VoiceOver to access private calendar information. Este problema se solucionó mejorando la redacción de información confidencial. Este problema se solucionó en iOS 17 y iPadOS 17. • https://support.apple.com/en-us/HT213938 •
CVE-2023-42941
https://notcve.org/view.php?id=CVE-2023-42941
10 Jan 2024 — The issue was addressed with improved checks. This issue is fixed in iOS 17.2 and iPadOS 17.2. An attacker in a privileged network position may be able to perform a denial-of-service attack using crafted Bluetooth packets. El problema se solucionó con controles mejorados. Este problema se solucionó en iOS 17.2 y iPadOS 17.2. • https://support.apple.com/en-us/HT214035 •
CVE-2022-48618 – Apple Multiple Products Memory Corruption Vulnerability
https://notcve.org/view.php?id=CVE-2022-48618
09 Jan 2024 — The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited against versions of iOS released before iOS 15.7.1. El problema se solucionó con controles mejorados. • https://support.apple.com/en-us/HT213530 • CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition •
CVE-2023-40446
https://notcve.org/view.php?id=CVE-2023-40446
12 Dec 2023 — The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1. Processing maliciously crafted input may lead to arbitrary code execution in user-installed apps. El problema se solucionó mejorando el manejo de la memoria. Este problema se solucionó en macOS Monterey 12.7.1, iOS 16.7.2 y iPadOS 16.7.2, iOS 17.1 y iPadOS 17.1. • https://support.apple.com/en-us/HT213981 •
CVE-2023-42890 – webkitgtk: processing malicious web content may lead to arbitrary code execution
https://notcve.org/view.php?id=CVE-2023-42890
12 Dec 2023 — The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, watchOS 10.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2. Processing web content may lead to arbitrary code execution. El problema se solucionó mejorando el manejo de la memoria. Este problema se solucionó en Safari 17.2, macOS Sonoma 14.2, watchOS 10.2, iOS 17.2 y iPadOS 17.2, tvOS 17.2. • http://seclists.org/fulldisclosure/2023/Dec/12 • CWE-20: Improper Input Validation CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2023-42899
https://notcve.org/view.php?id=CVE-2023-42899
12 Dec 2023 — The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, watchOS 10.2, macOS Ventura 13.6.3, tvOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Monterey 12.7.2. Processing an image may lead to arbitrary code execution. El problema se solucionó mejorando el manejo de la memoria. Este problema se solucionó en macOS Sonoma 14.2, iOS 17.2 y iPadOS 17.2, watchOS 10.2, macOS Ventura 13.6.3, tvOS 17.2, iOS 16.7.3 y iPadOS 16.7.3, macOS Monterey 12.7.2. • http://seclists.org/fulldisclosure/2023/Dec/10 •
CVE-2023-42883 – webkitgtk: processing a malicious image may lead to a denial of service
https://notcve.org/view.php?id=CVE-2023-42883
12 Dec 2023 — The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, watchOS 10.2, tvOS 17.2, iOS 16.7.3 and iPadOS 16.7.3. Processing an image may lead to a denial-of-service. El problema se solucionó mejorando el manejo de la memoria. Este problema se solucionó en Safari 17.2, macOS Sonoma 14.2, iOS 17.2 y iPadOS 17.2, watchOS 10.2, tvOS 17.2, iOS 16.7.3 y iPadOS 16.7.3. • http://seclists.org/fulldisclosure/2023/Dec/12 • CWE-20: Improper Input Validation •
CVE-2023-42919
https://notcve.org/view.php?id=CVE-2023-42919
12 Dec 2023 — A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, watchOS 10.2, macOS Ventura 13.6.3, iOS 16.7.3 and iPadOS 16.7.3, macOS Monterey 12.7.2. An app may be able to access sensitive user data. Se solucionó un problema de privacidad mejorando la redacción de datos privados para las entradas de registro. Este problema se solucionó en macOS Sonoma 14.2, iOS 17.2 y iPadOS 17.2, watchOS 10.2, macOS Ventura 13.6.3, i... • http://seclists.org/fulldisclosure/2023/Dec/10 •