Apple Garageband vulnerabilities

9 known vulnerabilities affecting apple/garageband.

Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH7MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2024-44142HIGHCVSS 7.8fixed in 10.4.122025-01-30
CVE-2024-44142 [HIGH] CVE-2024-44142: The issue was addressed with improved bounds checks. This issue is fixed in GarageBand 10.4.12. Proc The issue was addressed with improved bounds checks. This issue is fixed in GarageBand 10.4.12. Processing a maliciously crafted image may lead to arbitrary code execution.
cvelistv5nvd
CVE-2023-42867HIGHCVSS 7.8fixed in 10.4.9≥ unspecified, < 10.4.92024-12-20
CVE-2023-42867 [HIGH] CWE-281 CVE-2023-42867: This issue was addressed with improved validation of the process entitlement and Team ID. This issue This issue was addressed with improved validation of the process entitlement and Team ID. This issue is fixed in GarageBand 10.4.9. An app may be able to gain root privileges.
cvelistv5nvd
CVE-2024-23300HIGHCVSS 7.8fixed in 10.4.112024-03-12
CVE-2024-23300 [HIGH] CWE-416 CVE-2024-23300: A use-after-free issue was addressed with improved memory management. This issue is fixed in GarageB A use-after-free issue was addressed with improved memory management. This issue is fixed in GarageBand 10.4.11. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
cvelistv5nvd
CVE-2022-22664HIGHCVSS 7.8fixed in 10.4.62022-03-18
CVE-2022-22664 [HIGH] CWE-125 CVE-2022-22664: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Logic Pro An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Logic Pro 10.7.3, GarageBand 10.4.6, macOS Monterey 12.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution.
nvd
CVE-2022-22657HIGHCVSS 7.8fixed in 10.4.62022-03-18
CVE-2022-22657 [HIGH] CWE-665 CVE-2022-22657: A memory initialization issue was addressed with improved memory handling. This issue is fixed in Lo A memory initialization issue was addressed with improved memory handling. This issue is fixed in Logic Pro 10.7.3, GarageBand 10.4.6, macOS Monterey 12.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution.
nvd
CVE-2021-30654MEDIUMCVSS 5.5fixed in 10.4.3≥ unspecified, < 10.42021-09-08
CVE-2021-30654 [MEDIUM] CVE-2021-30654: This issue was addressed by removing additional entitlements. This issue is fixed in GarageBand 10.4 This issue was addressed by removing additional entitlements. This issue is fixed in GarageBand 10.4.3. A local attacker may be able to read sensitive information.
cvelistv5nvd
CVE-2017-2374HIGHCVSS 7.8≤ 10.1.52017-02-20
CVE-2017-2374 [HIGH] CWE-119 CVE-2017-2374: An issue was discovered in certain Apple products. GarageBand before 10.1.6 is affected. The issue i An issue was discovered in certain Apple products. GarageBand before 10.1.6 is affected. The issue involves the "Projects" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted GarageBand project file.
nvd
CVE-2017-2372HIGHCVSS 8.8≤ 10.1.42017-02-20
CVE-2017-2372 [HIGH] CWE-119 CVE-2017-2372: An issue was discovered in certain Apple products. GarageBand before 10.1.5 is affected. Logic Pro X An issue was discovered in certain Apple products. GarageBand before 10.1.5 is affected. Logic Pro X before 10.3 is affected. The issue involves the "Projects" component, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted GarageBand project file.
nvd
CVE-2009-2198MEDIUMCVSS 4.3≤ 5.0.2v4.1.1+3 more2009-08-04
CVE-2009-2198 [MEDIUM] CWE-264 CVE-2009-2198: Apple GarageBand before 5.1 reconfigures Safari to accept all cookies regardless of domain name, whi Apple GarageBand before 5.1 reconfigures Safari to accept all cookies regardless of domain name, which makes it easier for remote web servers to track users.
nvd