Filtered by vendor Apple
Subscribe
Total
11702 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2024-23285 | 1 Apple | 1 Macos | 2024-12-07 | N/A | 5.5 MEDIUM |
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sonoma 14.4. An app may be able to create symlinks to protected regions of the disk. | |||||
CVE-2024-23280 | 4 Apple, Fedoraproject, Webkitgtk and 1 more | 9 Ipad Os, Iphone Os, Macos and 6 more | 2024-12-07 | N/A | 6.5 MEDIUM |
An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, macOS Sonoma 14.4, iOS 17.4 and iPadOS 17.4, watchOS 10.4, tvOS 17.4. A maliciously crafted webpage may be able to fingerprint the user. | |||||
CVE-2024-23281 | 1 Apple | 1 Macos | 2024-12-07 | N/A | 5.5 MEDIUM |
This issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.4. An app may be able to access sensitive user data. | |||||
CVE-2024-23279 | 1 Apple | 1 Macos | 2024-12-07 | N/A | 5.5 MEDIUM |
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.4. An app may be able to access user-sensitive data. | |||||
CVE-2024-23269 | 1 Apple | 1 Macos | 2024-12-07 | N/A | 5.5 MEDIUM |
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.4, macOS Monterey 12.7.4, macOS Ventura 13.6.5. An app may be able to modify protected parts of the file system. | |||||
CVE-2024-23278 | 1 Apple | 5 Ipad Os, Iphone Os, Macos and 2 more | 2024-12-07 | N/A | 8.6 HIGH |
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.5, macOS Sonoma 14.4, iOS 17.4 and iPadOS 17.4, watchOS 10.4, iOS 16.7.6 and iPadOS 16.7.6, tvOS 17.4. An app may be able to break out of its sandbox. | |||||
CVE-2024-44123 | 1 Apple | 3 Ipados, Iphone Os, Macos | 2024-12-06 | N/A | 2.3 LOW |
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15, iOS 18 and iPadOS 18. A malicious app with root privileges may be able to access keyboard input and location information without user consent. | |||||
CVE-2022-42807 | 1 Apple | 1 Macos | 2024-12-06 | N/A | 4.3 MEDIUM |
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. A user may accidentally add a participant to a Shared Album by pressing the Delete key | |||||
CVE-2022-42792 | 1 Apple | 2 Ipados, Iphone Os | 2024-12-06 | N/A | 5.5 MEDIUM |
This issue was addressed with improved data protection. This issue is fixed in iOS 16.1 and iPadOS 16. An app may be able to read sensitive location information | |||||
CVE-2024-44251 | 1 Apple | 2 Ipados, Iphone Os | 2024-12-06 | N/A | 2.4 LOW |
This issue was addressed through improved state management. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to view restricted content from the lock screen. | |||||
CVE-2024-23260 | 1 Apple | 1 Macos | 2024-12-06 | N/A | 5.5 MEDIUM |
This issue was addressed by removing additional entitlements. This issue is fixed in macOS Sonoma 14.4. An app may be able to access user-sensitive data. | |||||
CVE-2024-23239 | 1 Apple | 5 Ipad Os, Iphone Os, Macos and 2 more | 2024-12-06 | N/A | 4.7 MEDIUM |
A race condition was addressed with improved state handling. This issue is fixed in tvOS 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. An app may be able to leak sensitive user information. | |||||
CVE-2024-23258 | 1 Apple | 2 Macos, Visionos | 2024-12-06 | N/A | 7.8 HIGH |
An out-of-bounds read was addressed with improved input validation. This issue is fixed in visionOS 1.1, macOS Sonoma 14.4. Processing an image may lead to arbitrary code execution. | |||||
CVE-2024-44302 | 1 Apple | 6 Ipados, Iphone Os, Macos and 3 more | 2024-12-06 | N/A | 5.5 MEDIUM |
The issue was addressed with improved checks. This issue is fixed in tvOS 18.1, iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, macOS Ventura 13.7.1, macOS Sonoma 14.7.1, watchOS 11.1, visionOS 2.1. Processing a maliciously crafted font may result in the disclosure of process memory. | |||||
CVE-2024-44244 | 1 Apple | 7 Ipados, Iphone Os, Macos and 4 more | 2024-12-06 | N/A | 4.3 MEDIUM |
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 18.1 and iPadOS 18.1, watchOS 11.1, visionOS 2.1, tvOS 18.1, macOS Sequoia 15.1, Safari 18.1. Processing maliciously crafted web content may lead to an unexpected process crash. | |||||
CVE-2024-44194 | 1 Apple | 4 Ipados, Iphone Os, Visionos and 1 more | 2024-12-06 | N/A | 5.5 MEDIUM |
This issue was addressed with improved redaction of sensitive information. This issue is fixed in watchOS 11.1, visionOS 2.1, iOS 18.1 and iPadOS 18.1. An app may be able to access sensitive user data. | |||||
CVE-2024-23257 | 1 Apple | 4 Ipad Os, Iphone Os, Macos and 1 more | 2024-12-06 | N/A | 3.3 LOW |
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.4, macOS Ventura 13.6.5, macOS Sonoma 14.4, visionOS 1.1, iOS 16.7.6 and iPadOS 16.7.6. Processing an image may result in disclosure of process memory. | |||||
CVE-2024-20739 | 3 Adobe, Apple, Microsoft | 3 Audition, Macos, Windows | 2024-12-06 | N/A | 7.8 HIGH |
Audition versions 24.0.3, 23.6.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
CVE-2023-42823 | 1 Apple | 5 Ipados, Iphone Os, Macos and 2 more | 2024-12-06 | N/A | 5.5 MEDIUM |
The issue was resolved by sanitizing logging This issue is fixed in watchOS 10.1, macOS Sonoma 14.1, tvOS 17.1, macOS Monterey 12.7.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, macOS Ventura 13.6.1. An app may be able to access user-sensitive data. | |||||
CVE-2023-42836 | 1 Apple | 3 Ipad Os, Iphone Os, Macos | 2024-12-06 | N/A | 5.3 MEDIUM |
A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, macOS Ventura 13.6.3, macOS Sonoma 14.1, macOS Monterey 12.7.2. An attacker may be able to access connected network volumes mounted in the home directory. |