|
193651
|
5.5 |
MEDIUM
Local
|
apple
|
ipados iphone_os macos
|
The issue was addressed with improved authentication. This issue is fixed in iOS 15 and iPadOS 15. A malicious application may be able to access photo metadata without needing permission to access ph…
|
CWE-287
Improper Authentication
|
CVE-2021-30867
|
2024-11-21 15:04 |
2021-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193652
|
6.5 |
MEDIUM
Adjacent
|
apple
|
watchos tvos ipados iphone_os macos
|
A user privacy issue was addressed by removing the broadcast MAC address. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. A device may be passively tracked by its WiFi MAC address.
|
NVD-CWE-noinfo
|
CVE-2021-30866
|
2024-11-21 15:04 |
2021-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193653
|
7.8 |
HIGH
Local
|
apple
|
mac_os_x macos
|
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.6, Security Update 2021-005 Catalina. A malicious application may be able to execute arbitr…
|
CWE-125
Out-of-bounds Read
|
CVE-2021-30865
|
2024-11-21 15:04 |
2021-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193654
|
8.6 |
HIGH
Network
|
apple
|
macos
|
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1. A sandboxed process may be able to circumvent sandbox restrictions.
|
NVD-CWE-noinfo
|
CVE-2021-30864
|
2024-11-21 15:04 |
2021-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193655
|
6.8 |
MEDIUM
Physics
|
apple
|
ipados iphone_os
|
This issue was addressed by improving Face ID anti-spoofing models. This issue is fixed in iOS 15 and iPadOS 15. A 3D model constructed to look like the enrolled user may be able to authenticate via …
|
NVD-CWE-noinfo
|
CVE-2021-30863
|
2024-11-21 15:04 |
2021-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193656
|
6.1 |
MEDIUM
Network
|
apple
|
itunes_u
|
A validation issue was addressed with improved input sanitization. This issue is fixed in iTunes U 3.8.3. Processing a maliciously crafted URL may lead to arbitrary javascript code execution.
|
CWE-20
Improper Input Validation
|
CVE-2021-30862
|
2024-11-21 15:04 |
2021-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193657
|
5.5 |
MEDIUM
Local
|
apple
|
safari macos
|
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1. A malicious application may bypass Gatekeeper checks.
|
NVD-CWE-noinfo
|
CVE-2021-30861
|
2024-11-21 15:04 |
2021-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193658
|
7.8 |
HIGH
Local
|
apple xpdfreader freedesktop
|
mac_os_x ipados watchos macos iphone_os xpdf poppler
|
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a m…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2021-30860
|
2024-11-21 15:04 |
2021-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193659
|
7.8 |
HIGH
Local
|
apple
|
mac_os_x ipados iphone_os macos
|
A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina. A malicious application may …
|
CWE-843
Type Confusion
|
CVE-2021-30859
|
2024-11-21 15:04 |
2021-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193660
|
8.8 |
HIGH
Network
|
apple fedoraproject debian
|
macos iphone_os ipados fedora debian_linux
|
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing maliciously crafted web content may lead to arbit…
|
CWE-416
Use After Free
|
CVE-2021-30858
|
2024-11-21 15:04 |
2021-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|