Vulnerabilities > Apple > Macos > 11.6

DATE CVE VULNERABILITY TITLE RISK
2021-09-29 CVE-2021-22946 Cleartext Transmission of Sensitive Information vulnerability in multiple products
A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl).
7.5
2021-09-29 CVE-2021-22947 Insufficient Verification of Data Authenticity vulnerability in multiple products
When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches.
5.9
2021-08-24 CVE-2021-31002 Out-of-bounds Read vulnerability in Apple Macos 11.6/11.6.1/12.0.0
An out-of-bounds read was addressed with improved input validation.
local
low complexity
apple CWE-125
7.8
2021-08-24 CVE-2021-31013 Out-of-bounds Read vulnerability in Apple Iphone OS and Macos
An out-of-bounds read was addressed with improved bounds checking.
local
low complexity
apple CWE-125
5.5
2021-08-24 CVE-2021-30962 Improper Initialization vulnerability in Apple Tvos
A memory initialization issue was addressed with improved memory handling.
local
low complexity
apple CWE-665
5.5
2021-08-24 CVE-2021-31007 Incorrect Default Permissions vulnerability in Apple products
Description: A permissions issue was addressed with improved validation.
local
low complexity
apple CWE-276
5.5
2021-08-24 CVE-2021-30922 Out-of-bounds Write vulnerability in Apple mac OS X and Macos
Multiple out-of-bounds write issues were addressed with improved bounds checking.
local
low complexity
apple CWE-787
7.8
2021-08-24 CVE-2021-30972 Incorrect Authorization vulnerability in Apple mac OS X and Macos
This issue was addressed with improved checks.
local
low complexity
apple CWE-863
5.5
2021-08-24 CVE-2021-30897 Unspecified vulnerability in Apple products
An issue existed in the specification for the resource timing API.
network
low complexity
apple
6.5
2021-08-24 CVE-2021-30904 Improper Synchronization vulnerability in Apple Macos
A sync issue was addressed with improved state validation.
network
low complexity
apple CWE-662
5.3