Vulnerabilities > Apple > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-03-26 CVE-2020-7463 Use After Free vulnerability in multiple products
In FreeBSD 12.1-STABLE before r364644, 11.4-STABLE before r364651, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 11.3-RELEASE before p13, improper handling in the kernel causes a use-after-free bug by sending large user messages from multiple threads on the same SCTP socket.
local
low complexity
freebsd apple CWE-416
5.5
2021-02-16 CVE-2021-23841 NULL Pointer Dereference vulnerability in multiple products
The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate.
5.9
2020-12-11 CVE-2020-13520 Out-of-bounds Write vulnerability in multiple products
An out of bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 reconstructs paths from binary USD files.
network
pixar apple CWE-787
6.8
2020-12-08 CVE-2020-27896 Path Traversal vulnerability in Apple mac OS X and Macos
A path handling issue was addressed with improved validation.
local
low complexity
apple CWE-22
5.5
2020-12-08 CVE-2020-27930 Out-of-bounds Write vulnerability in Apple products
A memory corruption issue was addressed with improved input validation.
network
apple CWE-787
6.8
2020-12-08 CVE-2020-27929 Unspecified vulnerability in Apple Iphone OS
A logic issue existed in the handling of Group FaceTime calls.
network
apple
4.3
2020-12-08 CVE-2020-27927 Out-of-bounds Write vulnerability in Apple products
An out-of-bounds write issue was addressed with improved bounds checking.
network
apple CWE-787
6.8
2020-12-08 CVE-2020-27900 Information Exposure vulnerability in Apple Macos 10.15.7/11.0
An issue existed in the handling of snapshots.
network
apple CWE-200
4.3
2020-12-08 CVE-2020-27898 Unchecked Return Value vulnerability in Apple Macos 11.0
A denial of service issue was addressed with improved state handling.
network
apple CWE-252
4.3
2020-12-08 CVE-2020-27895 Information Exposure vulnerability in Apple Itunes
An information disclosure issue existed in the transition of program state.
network
apple CWE-200
4.3