Vulnerabilities > Apple

DATE CVE VULNERABILITY TITLE RISK
2021-12-23 CVE-2020-3886 Use After Free vulnerability in Apple mac OS X
A use after free issue was addressed with improved memory management.
network
apple CWE-416
critical
9.3
2021-12-23 CVE-2020-3896 Unspecified vulnerability in Apple mac OS X
This issue was addressed by removing the vulnerable code.
network
apple
4.3
2021-12-23 CVE-2021-30767 Unspecified vulnerability in Apple products
A logic issue was addressed with improved state management.
local
low complexity
apple
2.1
2021-12-20 CVE-2021-44224 NULL Pointer Dereference vulnerability in multiple products
A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery).
8.2
2021-12-20 CVE-2021-44790 Out-of-bounds Write vulnerability in multiple products
A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts).
network
low complexity
apache fedoraproject debian tenable netapp oracle apple CWE-787
critical
9.8
2021-12-19 CVE-2021-4136 Heap-based Buffer Overflow vulnerability in multiple products
vim is vulnerable to Heap-based Buffer Overflow
local
low complexity
vim fedoraproject apple CWE-122
7.8
2021-12-10 CVE-2021-44228 Deserialization of Untrusted Data vulnerability in multiple products
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints.
10.0
2021-10-28 CVE-2020-10005 Resource Exhaustion vulnerability in Apple Macos
A resource exhaustion issue was addressed with improved input validation.
network
low complexity
apple CWE-400
6.5
2021-10-28 CVE-2020-29629 Out-of-bounds Read vulnerability in Apple Macos
An out-of-bounds read was addressed with improved input validation.
network
apple CWE-125
4.3
2021-10-28 CVE-2020-9897 Out-of-bounds Write vulnerability in Apple Iphone OS
An out-of-bounds write was addressed with improved input validation.
local
low complexity
apple CWE-787
7.8