cbcvebase.
CVE-2021-30860
published 2021-08-24

CVE-2021-30860: An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big…

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2021-11-17
Exploited in the wild
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

Affected

15 ranges
VendorProductVersion rangeFixed in
appleios
appleios_14.8_and_ipados
appleipados< 14.814.8
appleiphone_os< 12.5.512.5.5
appleiphone_os>= 13.0 < 14.814.8
applemac_os_x
applemac_os_x>= 10.15 < 10.15.710.15.7
applemacos< 11.611.6
applemacos_big_sur
applesecurity_update_2021-005_catalina
applewatchos< 7.6.27.6.2
applewatchos
freedesktoppoppler< 22.09.022.09.0
xpdfreaderxpdf< 4.044.04
xpdfreaderxpdf

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vulncheck7.8HIGH
cisa7.8HIGH