CVE-2023-36191
published 2023-10-25CVE-2023-36191: Apple Security Update: About the security content of macOS Monterey 12.7.1 Product: macOS Monterey Version: 12.7.1 CVE: CVE-2023-40421 Component…
low5.5
Apple Security Update: About the security content of macOS Monterey 12.7.1
Product: macOS Monterey
Version: 12.7.1
CVE: CVE-2023-40421
Component: CVE-2023-36191
Impact: An app may be able to access sensitive user data
Description: A permissions issue was addressed with additional restrictions.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_monterey | — | — |
| apple | macos_sonoma | — | — |
| apple | macos_ventura | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2023-40421: macOS Monterey 12.7.1
vendor_apple·2023-10-25·CVSS 5.5
CVE-2023-40421 [MEDIUM] CVE-2023-40421: macOS Monterey 12.7.1
Apple Security Update: About the security content of macOS Monterey 12.7.1
Product: macOS Monterey
Version: 12.7.1
CVE: CVE-2023-40421
Component: CVE-2023-36191
Impact: An app may be able to access sensitive user data
Description: A permissions issue was addressed with additional restrictions.
Apple
CVE-2023-36191: macOS Ventura 13.6.1
vendor_apple·2023-10-25
CVE-2023-36191 CVE-2023-36191: macOS Ventura 13.6.1
Apple Security Update: About the security content of macOS Ventura 13.6.1
Product: macOS Ventura
Version: 13.6.1
CVE: CVE-2023-36191
Component: CVE-2023-36191
Impact: An app may be able to access sensitive user data
Description: A permissions issue was addressed with additional restrictions.
Apple
CVE-2023-36191: macOS Monterey 12.7.1
vendor_apple·2023-10-25
CVE-2023-36191 CVE-2023-36191: macOS Monterey 12.7.1
Apple Security Update: About the security content of macOS Monterey 12.7.1
Product: macOS Monterey
Version: 12.7.1
CVE: CVE-2023-36191
Component: CVE-2023-36191
Impact: An app may be able to access sensitive user data
Description: A permissions issue was addressed with additional restrictions.
Apple
CVE-2023-40421: macOS Ventura 13.6.1
vendor_apple·2023-10-25·CVSS 5.5
CVE-2023-40421 [MEDIUM] CVE-2023-40421: macOS Ventura 13.6.1
Apple Security Update: About the security content of macOS Ventura 13.6.1
Product: macOS Ventura
Version: 13.6.1
CVE: CVE-2023-40421
Component: CVE-2023-36191
Impact: An app may be able to access sensitive user data
Description: A permissions issue was addressed with additional restrictions.
Apple
CVE-2023-40421: macOS Sonoma 14.1
vendor_apple·2023-10-25·CVSS 5.5
CVE-2023-40421 [MEDIUM] CVE-2023-40421: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-40421
Component: CVE-2023-36191
Impact: An app may be able to access sensitive user data
Description: A permissions issue was addressed with additional restrictions.
Apple
CVE-2023-36191: macOS Sonoma 14.1
vendor_apple·2023-10-25
CVE-2023-36191 CVE-2023-36191: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-36191
Component: CVE-2023-36191
Impact: An app may be able to access sensitive user data
Description: A permissions issue was addressed with additional restrictions.
Red Hat
sqlite: CLI fault on missing -nonce
vendor_redhat·2023-06-23·CVSS 5.5
CVE-2023-36191 [LOW] CWE-119 sqlite: CLI fault on missing -nonce
sqlite: CLI fault on missing -nonce
A segmentation fault was discovered in SQLite. This issue exists due to a boundary error within the /sqlite3_aflpp/shell.c which could allow a local user to send a specially crafted request to the database to trigger memory corruption and perform a denial of service (DoS) attack.
Statement: This vulnerability has been rated as Low security impact because the CLI fault on missing '-nonce', though it could cause a crash in CLI, it doesn't possess a real security risk.
Package: sqlite (Red Hat Enterprise Linux 6) - Not affected
Package: sqlite (Red Hat Enterprise Linux 7) - Not affected
Package: sqlite (Red Hat Enterprise Linux 8) - Not affected
Package: sqlite (Red Hat Enterprise Linux 9) - Not affected
GHSA
GHSA-h9rq-cvxv-r43v: sqlite3 v3
ghsa_unreviewed·2023-06-23
CVE-2023-36191 GHSA-h9rq-cvxv-r43v: sqlite3 v3
sqlite3 v3.40.1 was discovered to contain a segmentation violation at /sqlite3_aflpp/shell.c.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-10-25
Published