CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2021-30782

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. A malicious application may be able to access restricted files.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30785

    Last Modified: 21 Nov 2024

    A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-004 Catalina. Processing a maliciously crafted image may lead to arbitrary code execution.

    Published: 8 Sept 2021
    6.5
    Medium

    CVE-2021-30783

    Last Modified: 21 Nov 2024

    An access issue was addressed with improved access restrictions. This issue is fixed in macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. A sandboxed process may be able to circumvent sandbox restrictions.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30780

    Last Modified: 21 Nov 2024

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-005 Mojave, Security Update 2021-004 Catalina. A malicious application may be able to gain root privileges.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-30778

    Last Modified: 21 Nov 2024

    This issue was addressed with improved entitlements. This issue is fixed in macOS Big Sur 11.5. A malicious application may be able to bypass Privacy preferences.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30781

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-005 Mojave, Security Update 2021-004 Catalina. A local attacker may be able to cause unexpected application termination or arbitrary code execution.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-30776

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-004 Catalina. Playing a malicious audio file may lead to an unexpected application termination.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30779

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. Processing a maliciously crafted image may lead to arbitrary code execution.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-30773

    Last Modified: 21 Nov 2024

    An issue in code signature validation was addressed with improved checks. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. A malicious application may be able to bypass code signing checks.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30772

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.5. A malicious application may be able to gain root privileges.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30774

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. A malicious application may be able to gain root privileges.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30777

    Last Modified: 21 Nov 2024

    An injection issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. A malicious application may be able to gain root privileges.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-30769

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30775

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-004 Catalina. Processing a maliciously crafted audio file may lead to arbitrary code execution.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30766

    Last Modified: 21 Nov 2024

    An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. An application may be able to execute arbitrary code with kernel privileges.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-30770

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. An attacker that has already achieved kernel code execution may be able to bypass kernel memory mitigations.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30764

    Last Modified: 21 Nov 2024

    Processing a maliciously crafted file may lead to arbitrary code execution. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. This issue was addressed with improved checks.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30765

    Last Modified: 21 Nov 2024

    An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. An application may be able to execute arbitrary code with kernel privileges.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-30768

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-004 Catalina. A sandboxed process may be able to circumvent sandbox restrictions.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30760

    Last Modified: 21 Nov 2024

    An integer overflow was addressed through improved input validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-005 Mojave, Security Update 2021-004 Catalina. Processing a maliciously crafted font file may lead to arbitrary code execution.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-30763

    Last Modified: 21 Nov 2024

    An input validation issue was addressed with improved input validation. This issue is fixed in iOS 14.7, watchOS 7.6. A shortcut may be able to bypass Internet permission requirements.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-30756

    Last Modified: 21 Nov 2024

    A local attacker may be able to view Now Playing information from the lock screen. This issue is fixed in macOS Big Sur 11.4, iOS 14.6 and iPadOS 14.6. A privacy issue in Now Playing was addressed with improved permissions.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-30751

    Last Modified: 21 Nov 2024

    This issue was addressed with improved data protection. This issue is fixed in macOS Big Sur 11.4. A malicious application may be able to bypass certain Privacy preferences.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-30757

    Last Modified: 21 Nov 2024

    This issue was addressed by enabling hardened runtime. This issue is fixed in iMovie 10.2.4. Entitlements and privacy permissions granted to this app may be used by a malicious app.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30759

    Last Modified: 21 Nov 2024

    A stack overflow was addressed with improved input validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-005 Mojave, Security Update 2021-004 Catalina. Processing a maliciously crafted font file may lead to arbitrary code execution.

    Published: 8 Sept 2021
    6.5
    Medium

    CVE-2021-30755

    Last Modified: 21 Nov 2024

    Processing a maliciously crafted font may result in the disclosure of process memory. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5. An out-of-bounds read was addressed with improved input validation.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-30753

    Last Modified: 21 Nov 2024

    Processing a maliciously crafted font may result in the disclosure of process memory. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. An out-of-bounds read was addressed with improved input validation.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30743

    Last Modified: 21 Nov 2024

    An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, Security Update 2021-003 Catalina, tvOS 14.5, macOS Big Sur 11.3. Processing a maliciously crafted image may lead to arbitrary code execution.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-30746

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted USD file may disclose memory contents.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30752

    Last Modified: 21 Nov 2024

    Processing a maliciously crafted image may lead to arbitrary code execution. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. An out-of-bounds read was addressed with improved input validation.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-30750

    Last Modified: 21 Nov 2024

    The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.3. A malicious application may be able to access the user's recent contacts.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30748

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 14.7, macOS Big Sur 11.5. An application may be able to execute arbitrary code with kernel privileges.

    Published: 8 Sept 2021
    7.1
    High

    CVE-2021-30741

    Last Modified: 21 Nov 2024

    A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted mail message may lead to unexpected memory modification or application termination.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30739

    Last Modified: 21 Nov 2024

    A local attacker may be able to elevate their privileges. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A memory corruption issue was addressed with improved validation.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30735

    Last Modified: 21 Nov 2024

    A malicious application may be able to execute arbitrary code with kernel privileges. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. An out-of-bounds write issue was addressed with improved bounds checking.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30742

    Last Modified: 21 Nov 2024

    A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 14.5 and iPadOS 14.5. Processing a maliciously crafted audio file may lead to arbitrary code execution.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30740

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. A malicious application may be able to execute arbitrary code with kernel privileges.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-30738

    Last Modified: 21 Nov 2024

    A malicious application may be able to overwrite arbitrary files. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-004 Mojave. An issue with path validation logic for hardlinks was addressed with improved path sanitization.

    Published: 8 Sept 2021
    8.8
    High

    CVE-2021-30737

    Last Modified: 21 Nov 2024

    A memory corruption issue in the ASN.1 decoder was addressed by removing the vulnerable code. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, iOS 12.5.4, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. Processing a maliciously crafted certificate may lead to arbitrary code execution.

    Published: 8 Sept 2021
    7.5
    High

    CVE-2021-30729

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved restrictions. This issue is fixed in iOS 14.6 and iPadOS 14.6. A device may accept invalid activation results.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-30733

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave, macOS Big Sur 11.4, watchOS 7.5. Processing a maliciously crafted font may result in the disclosure of process memory.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30736

    Last Modified: 21 Nov 2024

    A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. An application may be able to execute arbitrary code with kernel privileges.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-30731

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-004 Catalina. An unprivileged application may be able to capture USB devices.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-30727

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. A malicious application may be able to modify protected parts of the file system.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30725

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-30723

    Last Modified: 21 Nov 2024

    An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted USD file may disclose memory contents.

    Published: 8 Sept 2021
    6.5
    Medium

    CVE-2021-30721

    Last Modified: 21 Nov 2024

    A path handling issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. An attacker in a privileged network position may be able to leak sensitive user information.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30728

    Last Modified: 21 Nov 2024

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A malicious application may be able to execute arbitrary code with kernel privileges.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30726

    Last Modified: 21 Nov 2024

    A malicious application may be able to execute arbitrary code with kernel privileges. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. An out-of-bounds write issue was addressed with improved bounds checking.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30724

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. A local attacker may be able to elevate their privileges.

    Published: 8 Sept 2021