Vulnerabilities > Apple > Macos > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-02-16 CVE-2021-23841 NULL Pointer Dereference vulnerability in multiple products
The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate.
5.9
2020-12-08 CVE-2020-27896 Path Traversal vulnerability in Apple mac OS X and Macos
A path handling issue was addressed with improved validation.
local
low complexity
apple CWE-22
5.5
2020-12-08 CVE-2020-27950 Improper Initialization vulnerability in Apple products
A memory initialization issue was addressed.
local
low complexity
apple CWE-665
5.5
2020-12-08 CVE-2020-27900 Unspecified vulnerability in Apple Macos
An issue existed in the handling of snapshots.
local
low complexity
apple
5.5
2020-12-08 CVE-2020-27898 Unchecked Return Value vulnerability in Apple Macos
A denial of service issue was addressed with improved state handling.
local
low complexity
apple CWE-252
5.5
2020-12-08 CVE-2020-9849 Information Exposure vulnerability in Apple products
An information disclosure issue was addressed with improved state management.
network
low complexity
apple CWE-200
6.5
2020-12-08 CVE-2020-27894 Unspecified vulnerability in Apple Macos 11.0
The issue was addressed with additional user controls.
local
low complexity
apple
5.5
2020-12-08 CVE-2020-10014 Path Traversal vulnerability in Apple mac OS X and Macos
A parsing issue in the handling of directory paths was addressed with improved path validation.
local
low complexity
apple CWE-22
6.3
2020-12-08 CVE-2020-10012 Cross-site Scripting vulnerability in Apple mac OS X and Macos
An access issue was addressed with improved access restrictions.
network
low complexity
apple CWE-79
6.1
2020-12-03 CVE-2020-13524 Out-of-bounds Write vulnerability in multiple products
An out-of-bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 uses SPECS data from binary USD files.
local
low complexity
pixar apple CWE-787
5.5