Vulnerabilities > Apple > Macos > 11.1

DATE CVE VULNERABILITY TITLE RISK
2021-04-02 CVE-2020-29616 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple mac OS X and Macos
A memory corruption issue was addressed with improved input validation.
network
apple CWE-119
6.8
2021-04-02 CVE-2020-29614 Unspecified vulnerability in Apple products
This issue was addressed with improved checks.
network
apple
6.8
2021-04-02 CVE-2020-27947 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple mac OS X and Macos
A memory corruption issue was addressed with improved input validation.
network
apple CWE-119
critical
9.3
2021-04-02 CVE-2020-27946 Information Exposure vulnerability in Apple products
An information disclosure issue was addressed with improved state management.
network
apple CWE-200
4.3
2021-04-02 CVE-2020-27944 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple products
A memory corruption issue existed in the processing of font files.
network
apple CWE-119
6.8
2021-04-02 CVE-2020-27943 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple products
A memory corruption issue existed in the processing of font files.
network
apple CWE-119
6.8
2021-04-02 CVE-2020-27907 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple Macos
A memory corruption issue was addressed with improved memory handling.
network
apple CWE-119
critical
9.3
2021-03-26 CVE-2020-7463 Use After Free vulnerability in multiple products
In FreeBSD 12.1-STABLE before r364644, 11.4-STABLE before r364651, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 11.3-RELEASE before p13, improper handling in the kernel causes a use-after-free bug by sending large user messages from multiple threads on the same SCTP socket.
local
low complexity
freebsd apple CWE-416
5.5
2021-02-16 CVE-2021-23841 NULL Pointer Dereference vulnerability in multiple products
The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate.
5.9
2021-01-26 CVE-2020-36230 Reachable Assertion vulnerability in multiple products
A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, resulting in denial of service.
network
low complexity
openldap debian apple apache CWE-617
7.5