CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2021-1881

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. Processing a maliciously crafted font file may lead to arbitrary code execution.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-30654

    Last Modified: 21 Nov 2024

    This issue was addressed by removing additional entitlements. This issue is fixed in GarageBand 10.4.3. A local attacker may be able to read sensitive information.

    Published: 8 Sept 2021
    9.8
    Critical

    CVE-2021-30655

    Last Modified: 21 Nov 2024

    An application may be able to execute arbitrary code with system privileges. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. The issue was addressed with improved permissions logic.

    Published: 8 Sept 2021
    4.3
    Medium

    CVE-2021-1872

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, macOS Big Sur 11.3. Muting a CallKit call while ringing may not result in mute being enabled.

    Published: 8 Sept 2021
    8.8
    High

    CVE-2021-1874

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in iOS 14.5 and iPadOS 14.5. An application may be able to execute arbitrary code with kernel privileges.

    Published: 8 Sept 2021
    7.3
    High

    CVE-2021-30662

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in iOS 14.5 and iPadOS 14.5. Processing a maliciously crafted file may lead to arbitrary code execution.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-1880

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.3, watchOS 7.4. Processing a maliciously crafted image may lead to arbitrary code execution.

    Published: 8 Sept 2021
    6.5
    Medium

    CVE-2021-1878

    Last Modified: 21 Nov 2024

    An integer overflow was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. An attacker in a privileged network position may be able to leak sensitive user information.

    Published: 8 Sept 2021
    5
    Medium

    CVE-2021-1865

    Last Modified: 21 Nov 2024

    An issue obscuring passwords in screenshots was addressed with improved logic. This issue is fixed in iOS 14.5 and iPadOS 14.5. A user's password may be visible on screen.

    Published: 8 Sept 2021
    6.5
    Medium

    CVE-2021-1873

    Last Modified: 21 Nov 2024

    An API issue in Accessibility TCC permissions was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. A malicious application may be able to unexpectedly leak a user's credentials from secure text fields.

    Published: 8 Sept 2021
    2.4
    Low

    CVE-2021-1863

    Last Modified: 21 Nov 2024

    An issue existed with authenticating the action triggered by an NFC tag. The issue was addressed with improved action authentication. This issue is fixed in iOS 14.5 and iPadOS 14.5. A person with physical access to an iOS device may be able to place phone calls to any phone number.

    Published: 8 Sept 2021
    4.3
    Medium

    CVE-2021-1861

    Last Modified: 21 Nov 2024

    An issue existed in determining cache occupancy. The issue was addressed through improved logic. This issue is fixed in macOS Big Sur 11.3. A malicious website may be able to track users by setting state in a cache.

    Published: 8 Sept 2021
    2.4
    Low

    CVE-2021-1862

    Last Modified: 21 Nov 2024

    Description: A person with physical access may be able to access contacts. This issue is fixed in iOS 14.5 and iPadOS 14.5. Impact: An issue with Siri search access to information was addressed with improved logic.

    Published: 8 Sept 2021
    6.5
    Medium

    CVE-2021-1860

    Last Modified: 21 Nov 2024

    A memory initialization issue was addressed with improved memory handling. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A malicious application may be able to disclose kernel memory.

    Published: 8 Sept 2021
    7.5
    High

    CVE-2021-1859

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3. Locked Notes content may have been unexpectedly unlocked.

    Published: 8 Sept 2021
    6.5
    Medium

    CVE-2021-1855

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3. A malicious website may be able to force unnecessary network connections to fetch its favicon.

    Published: 8 Sept 2021
    4.3
    Medium

    CVE-2021-1854

    Last Modified: 21 Nov 2024

    A call termination issue with was addressed with improved logic. This issue is fixed in iOS 14.5 and iPadOS 14.5. A legacy cellular network can automatically answer an incoming call when an ongoing call ends or drops. .

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-1852

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.5 and iPadOS 14.5. A local user may be able to read kernel memory.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-1858

    Last Modified: 21 Nov 2024

    Processing a maliciously crafted image may lead to arbitrary code execution. This issue is fixed in Security Update 2021-002 Catalina, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. An out-of-bounds write issue was addressed with improved bounds checking.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-1853

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3. A local attacker may be able to elevate their privileges.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-1848

    Last Modified: 21 Nov 2024

    The issue was addressed with improved UI handling. This issue is fixed in iOS 14.5 and iPadOS 14.5. A local user may be able to view sensitive information in the app switcher.

    Published: 8 Sept 2021
    6.5
    Medium

    CVE-2021-1857

    Last Modified: 21 Nov 2024

    A memory initialization issue was addressed with improved memory handling. This issue is fixed in iTunes 12.11.3 for Windows, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iCloud for Windows 12.3, macOS Big Sur 11.3, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing maliciously crafted web content may disclose sensitive user information.

    Published: 8 Sept 2021
    7.5
    High

    CVE-2021-1849

    Last Modified: 21 Nov 2024

    An issue in code signature validation was addressed with improved checks. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A malicious application may be able to bypass Privacy preferences.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-1847

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution.

    Published: 8 Sept 2021
    8.8
    High

    CVE-2021-1851

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. An application may be able to execute arbitrary code with kernel privileges.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-1841

    Last Modified: 21 Nov 2024

    A malicious application may be able to execute arbitrary code with kernel privileges. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. An out-of-bounds write issue was addressed with improved bounds checking.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-1832

    Last Modified: 21 Nov 2024

    Copied files may not have the expected file permissions. This issue is fixed in Security Update 2021-002 Catalina, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. The issue was addressed with improved permissions logic.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-1846

    Last Modified: 21 Nov 2024

    Processing a maliciously crafted audio file may disclose restricted memory. This issue is fixed in Security Update 2021-002 Catalina, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. An out-of-bounds read was addressed with improved input validation.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-1839

    Last Modified: 21 Nov 2024

    The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. A local attacker may be able to elevate their privileges.

    Published: 8 Sept 2021
    5.3
    Medium

    CVE-2021-1837

    Last Modified: 21 Nov 2024

    A certificate validation issue was addressed. This issue is fixed in iOS 14.5 and iPadOS 14.5. An attacker in a privileged network position may be able to alter network traffic.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-1838

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to arbitrary code execution.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-1840

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. A local attacker may be able to elevate their privileges.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-1843

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. Processing a maliciously crafted image may lead to arbitrary code execution.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-1833

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in iOS 14.5 and iPadOS 14.5. An application may be able to gain elevated privileges.

    Published: 8 Sept 2021
    4.6
    Medium

    CVE-2021-1835

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in iOS 14.5 and iPadOS 14.5. A person with physical access to an iOS device may be able to access notes from the lock screen.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-1831

    Last Modified: 21 Nov 2024

    The issue was addressed with improved permissions logic. This issue is fixed in iOS 14.5 and iPadOS 14.5. An application may allow shortcuts to access restricted files.

    Published: 8 Sept 2021
    9.8
    Critical

    CVE-2021-1834

    Last Modified: 21 Nov 2024

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. A malicious application may be able to execute arbitrary code with kernel privileges.

    Published: 8 Sept 2021
    9.8
    Critical

    CVE-2021-1829

    Last Modified: 21 Nov 2024

    A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.3. An application may be able to execute arbitrary code with kernel privileges.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-1836

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved restrictions. This issue is fixed in iOS 14.5 and iPadOS 14.5, tvOS 14.5. A local user may be able to create or modify privileged files.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-1830

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.5 and iPadOS 14.5. A local user may be able to read kernel memory.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30664

    Last Modified: 21 Nov 2024

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing a maliciously crafted file may lead to arbitrary code execution.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30680

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4. A local user may be able to load unsigned kernel extensions.

    Published: 8 Sept 2021
    7.1
    High

    CVE-2021-30719

    Last Modified: 21 Nov 2024

    A local user may be able to cause unexpected system termination or read kernel memory. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina. An out-of-bounds read issue was addressed by removing the vulnerable code.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30684

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina. A remote attacker may cause an unexpected application termination or arbitrary code execution.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30679

    Last Modified: 21 Nov 2024

    This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. An application may be able to gain elevated privileges.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30681

    Last Modified: 21 Nov 2024

    A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. A malicious application may be able to gain root privileges.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-30685

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. Parsing a maliciously crafted audio file may lead to disclosure of user information.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-30687

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. Processing a maliciously crafted image may lead to disclosure of user information.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30712

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.

    Published: 8 Sept 2021
    4.6
    Medium

    CVE-2021-30702

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A person with physical access to a Mac may be able to bypass Login Window.

    Published: 8 Sept 2021