|
211
|
5.5
-
|
MEDIUM
Local
|
This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, Xcode 16, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iPadOS 18, tvOS 18. An app …
|
NVD-CWE-noinfo
|
CVE-2024-44191
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
17.7
|
2024-09-25 22:24
2024-09-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212
|
6.5
-
|
MEDIUM
Network
|
A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue is fixed in Safari 18, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 …
|
CWE-346
Origin Validation Error
|
CVE-2024-44187
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
18.0
|
2024-09-25 22:25
2024-09-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213
|
5.5
-
|
MEDIUM
Local
|
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.7, iOS 17.7 and iPadOS 17.7, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iP…
|
NVD-CWE-noinfo
|
CVE-2024-44176
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
17.7
|
2024-09-25 22:27
2024-09-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214
|
6.5
-
|
MEDIUM
Adjacent
|
This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. A malicious Bluetooth input device may bypass pairing.
|
NVD-CWE-noinfo
|
CVE-2024-44124
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
18.0
|
2024-09-26 00:14
2024-09-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
215
|
5.5
-
|
MEDIUM
Local
|
This issue was addressed with improved data protection. This issue is fixed in iOS 18 and iPadOS 18. An app may be able to leak sensitive user information.
|
NVD-CWE-noinfo
|
CVE-2024-40863
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
18.0
|
2024-09-25 22:40
2024-09-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
216
|
6.1
-
|
MEDIUM
Network
|
This issue was addressed through improved state management. This issue is fixed in Safari 18, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iPadOS 18, tvOS 18. Processing maliciously crafted w…
|
CWE-79
Cross-site Scripting
|
CVE-2024-40857
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
18.0
|
2024-09-25 22:41
2024-09-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
217
|
7.5
-
|
HIGH
Network
|
An integrity issue was addressed with Beacon Protection. This issue is fixed in iOS 18 and iPadOS 18, tvOS 18, macOS Sequoia 15. An attacker may be able to force a device to disconnect from a secure …
|
NVD-CWE-noinfo
|
CVE-2024-40856
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
18.0
|
2024-09-25 22:43
2024-09-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218
|
4.6
-
|
MEDIUM
Physics
|
This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical access may be able to use Siri to access sensitive user data.
|
NVD-CWE-noinfo
|
CVE-2024-40840
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
18.0
|
2024-09-26 04:42
2024-09-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219
|
7.5
-
|
HIGH
Network
|
A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7, iOS 17.7 and iPadOS 17.7, visionOS 2, iOS 18 and iPadOS 18, macOS Sonoma 14.7, macOS Sequoia 15. Network t…
|
NVD-CWE-noinfo
|
CVE-2024-44165
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
17.7
|
2024-09-26 22:53
2024-09-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220
|
7.1
-
|
HIGH
Local
|
This issue was addressed with improved checks. This issue is fixed in iOS 17.7 and iPadOS 17.7, macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to bypass Privacy preferenc…
|
NVD-CWE-noinfo
|
CVE-2024-44164
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
17.7
|
2024-09-26 22:54
2024-09-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|