CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2024-27877

    Last Modified: 2 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents.

    Published: 29 Jul 2024
    5.5
    Medium

    CVE-2024-40788

    Last Modified: 2 Apr 2026

    A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, visionOS 1.3, watchOS 10.6. A local attacker may be able to cause unexpected system shutdown.

    Published: 29 Jul 2024
    5.5
    Medium

    CVE-2024-40823

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app may be able to access user-sensitive data.

    Published: 29 Jul 2024
    5.5
    Medium

    CVE-2024-40835

    Last Modified: 2 Apr 2026

    A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, watchOS 10.6. A shortcut may be able to use sensitive data with certain actions without prompting the user.

    Published: 29 Jul 2024
    4.4
    Medium

    CVE-2024-40834

    Last Modified: 2 Apr 2026

    This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A shortcut may be able to bypass sensitive Shortcuts app settings.

    Published: 29 Jul 2024
    2.4
    Low

    CVE-2024-40822

    Last Modified: 2 Apr 2026

    This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, watchOS 10.6. An attacker with physical access to a device may be able to access contacts from the lock screen.

    Published: 29 Jul 2024
    4.6
    Medium

    CVE-2024-40818

    Last Modified: 2 Apr 2026

    This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, watchOS 10.6. An attacker with physical access may be able to use Siri to access sensitive user data.

    Published: 29 Jul 2024
    6.1
    Medium

    CVE-2024-40785

    Last Modified: 2 Apr 2026

    This issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to a cross site scripting attack.

    Published: 29 Jul 2024
    7.8
    High

    CVE-2024-40802

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A local attacker may be able to elevate their privileges.

    Published: 29 Jul 2024
    7.1
    High

    CVE-2024-40814

    Last Modified: 2 Apr 2026

    A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.6, macOS Ventura 13.7. An app may be able to bypass Privacy preferences.

    Published: 29 Jul 2024
    4.4
    Medium

    CVE-2024-27883

    Last Modified: 2 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app may be able to modify protected parts of the file system.

    Published: 29 Jul 2024
    5.5
    Medium

    CVE-2024-40793

    Last Modified: 2 Apr 2026

    This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, watchOS 10.6. An app may be able to access user-sensitive data.

    Published: 29 Jul 2024
    7.5
    High

    CVE-2024-40786

    Last Modified: 2 Apr 2026

    This issue was addressed through improved state management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Ventura 13.6.8. An attacker may be able to view sensitive user information.

    Published: 29 Jul 2024
    6.1
    Medium

    CVE-2024-40817

    Last Modified: 2 Apr 2026

    The issue was addressed with improved UI handling. This issue is fixed in Safari 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. Visiting a website that frames malicious content may lead to UI spoofing.

    Published: 29 Jul 2024
    7.1
    High

    CVE-2024-40821

    Last Modified: 2 Apr 2026

    An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. Third party app extensions may not receive the correct sandbox restrictions.

    Published: 29 Jul 2024
    5.5
    Medium

    CVE-2024-27863

    Last Modified: 2 Apr 2026

    An information disclosure issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. A local attacker may be able to determine kernel memory layout.

    Published: 29 Jul 2024
    2.4
    Low

    CVE-2024-27862

    Last Modified: 2 Apr 2026

    A logic issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.6. Enabling Lockdown Mode while setting up a Mac may cause FileVault to become unexpectedly disabled.

    Published: 29 Jul 2024
    5.9
    Medium

    CVE-2024-27823

    Last Modified: 2 Apr 2026

    A race condition was addressed with improved locking. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.3, watchOS 10.5. An attacker in a privileged network position may be able to spoof network packets.

    Published: 29 Jul 2024
    5.5
    Medium

    CVE-2024-40836

    Last Modified: 2 Apr 2026

    A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, watchOS 10.6. A shortcut may be able to use sensitive data with certain actions without prompting the user.

    Published: 29 Jul 2024
    5.3
    Medium

    CVE-2024-27881

    Last Modified: 2 Apr 2026

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app may be able to access information about a user’s contacts.

    Published: 29 Jul 2024
    5.5
    Medium

    CVE-2024-40816

    Last Modified: 2 Apr 2026

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A local attacker may be able to cause unexpected system shutdown.

    Published: 29 Jul 2024
    6.7
    Medium

    CVE-2024-27878

    Last Modified: 2 Apr 2026

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app may be able to execute arbitrary code with kernel privileges.

    Published: 29 Jul 2024
    5.5
    Medium

    CVE-2024-40800

    Last Modified: 2 Apr 2026

    An input validation issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app may be able to modify protected parts of the file system.

    Published: 29 Jul 2024
    7.1
    High

    CVE-2024-40787

    Last Modified: 2 Apr 2026

    This issue was addressed by adding an additional prompt for user consent. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, watchOS 10.6. A shortcut may be able to bypass Internet permission requirements.

    Published: 29 Jul 2024
    7.5
    High

    CVE-2024-23261

    Last Modified: 2 Apr 2026

    A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.8. An attacker may be able to read information belonging to another user.

    Published: 29 Jul 2024
    5.5
    Medium

    CVE-2024-40827

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app may be able to overwrite arbitrary files.

    Published: 29 Jul 2024
    5.5
    Medium

    CVE-2024-27873

    Last Modified: 2 Apr 2026

    An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. Processing a maliciously crafted video file may lead to unexpected app termination.

    Published: 29 Jul 2024
    5.5
    Medium

    CVE-2024-40775

    Last Modified: 2 Apr 2026

    A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app may be able to leak sensitive user information.

    Published: 29 Jul 2024
    4.4
    Medium

    CVE-2024-27853

    Last Modified: 2 Apr 2026

    This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4. A maliciously crafted ZIP archive may bypass Gatekeeper checks.

    Published: 29 Jul 2024
    5.5
    Medium

    CVE-2024-40807

    Last Modified: 2 Apr 2026

    A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A shortcut may be able to use sensitive data with certain actions without prompting the user.

    Published: 29 Jul 2024
    5.5
    Medium

    CVE-2024-40811

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. An app may be able to modify protected parts of the file system.

    Published: 29 Jul 2024
    5.5
    Medium

    CVE-2024-27886

    Last Modified: 2 Apr 2026

    A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sonoma 14.4, macOS Ventura 13.7. An unprivileged app may be able to log keystrokes in other apps including those using secure input mode.

    Published: 29 Jul 2024
    5.3
    Medium

    CVE-2024-40796

    Last Modified: 2 Apr 2026

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. Private browsing may leak some browsing history.

    Published: 29 Jul 2024
    3.3
    Low

    CVE-2024-40778

    Last Modified: 2 Apr 2026

    An authentication issue was addressed with improved state management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. Photos in the Hidden Photos Album may be viewed without authentication.

    Published: 29 Jul 2024
    5.5
    Medium

    CVE-2024-27887

    Last Modified: 2 Apr 2026

    A path handling issue was addressed with improved validation. This issue is fixed in macOS Sonoma 14.4. An app may be able to access user-sensitive data.

    Published: 29 Jul 2024
    5.5
    Medium

    CVE-2024-40806

    Last Modified: 2 Apr 2026

    An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing a maliciously crafted file may lead to unexpected app termination.

    Published: 29 Jul 2024
    7.8
    High

    CVE-2024-40781

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A local attacker may be able to elevate their privileges.

    Published: 29 Jul 2024
    7.1
    High

    CVE-2024-40774

    Last Modified: 2 Apr 2026

    A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, watchOS 10.6. An app may be able to bypass Privacy preferences.

    Published: 29 Jul 2024
    5.5
    Medium

    CVE-2024-27872

    Last Modified: 2 Apr 2026

    This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sonoma 14.6. An app may be able to access protected user data.

    Published: 29 Jul 2024
    5.5
    Medium

    CVE-2024-27809

    Last Modified: 2 Apr 2026

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.4. An app may be able to access user-sensitive data.

    Published: 29 Jul 2024
    5.1
    Medium

    CVE-2024-3219

    Last Modified: 15 Apr 2026

    The “socket” module provides a pure-Python fallback to the socket.socketpair() function for platforms that don’t support AF_UNIX, such as Windows. This pure-Python implementation uses AF_INET or AF_INET6 to create a local connected pair of sockets. The connection between the two sockets was not verified before passing the two sockets back to the user, which leaves the server socket vulnerable to a connection race from a malicious local peer. Platforms that support AF_UNIX such as Linux and macOS are not affected by this vulnerability. Versions prior to CPython 3.5 are not affected due to the vulnerable API not being included.

    Published: 29 Jul 2024
    7.8
    High

    CVE-2024-7252

    Last Modified: 21 Nov 2024

    Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the cmdagent executable. By creating a symbolic link, an attacker can abuse the agent to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22831.

    Published: 29 Jul 2024
    7.8
    High

    CVE-2024-7251

    Last Modified: 21 Nov 2024

    Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the cmdagent executable. By creating a symbolic link, an attacker can abuse the agent to create a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22832.

    Published: 29 Jul 2024
    7.8
    High

    CVE-2024-7250

    Last Modified: 21 Nov 2024

    Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the cmdagent executable. By creating a symbolic link, an attacker can abuse the agent to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22829.

    Published: 29 Jul 2024
    7.8
    High

    CVE-2024-7249

    Last Modified: 21 Nov 2024

    Comodo Firewall Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Firewall. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the cmdagent executable. By creating a symbolic link, an attacker can abuse the application to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-21794.

    Published: 29 Jul 2024
    7.8
    High

    CVE-2024-7248

    Last Modified: 21 Nov 2024

    Comodo Internet Security Pro Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the update mechanism. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-19055.

    Published: 29 Jul 2024
    8.8
    High

    CVE-2023-40398

    Last Modified: 13 Mar 2025

    This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.4, macOS Big Sur 11.7.5, macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4. A sandboxed process may be able to circumvent sandbox restrictions.

    Published: 29 Jul 2024
    3.3
    Low

    CVE-2023-42957

    Last Modified: 19 Mar 2025

    A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10. An app may be able to read sensitive location information.

    Published: 29 Jul 2024
    3.3
    Low

    CVE-2023-42948

    Last Modified: 17 Mar 2025

    This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14. A Wi-Fi password may not be deleted when activating a Mac in macOS Recovery.

    Published: 29 Jul 2024
    3.3
    Low

    CVE-2023-42925

    Last Modified: 20 Mar 2025

    The issue was addressed with improved restriction of data container access. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to access Notes attachments.

    Published: 29 Jul 2024