Apple Ios And Ipados vulnerabilities

1,463 known vulnerabilities affecting apple/ios_and_ipados.

Total CVEs
1,463
CISA KEV
57
actively exploited
Public exploits
1
Exploited in wild
44
Severity breakdown
CRITICAL73HIGH563MEDIUM708LOW119

Vulnerabilities

Page 64 of 74
CVE-2021-30874HIGHCVSS 7.5≥ unspecified, < 152021-08-24
CVE-2021-30874 [HIGH] CWE-862 CVE-2021-30874: An authorization issue was addressed with improved state management. This issue is fixed in iOS 15 a An authorization issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15. A VPN configuration may be installed by an app without user permission.
nvd
CVE-2021-30914HIGHCVSS 7.8≥ unspecified, < 15.12021-08-24
CVE-2021-30914 [HIGH] CWE-787 CVE-2021-30914: A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 1 A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 15.1 and iPadOS 15.1. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2021-30949HIGHCVSS 7.8≥ unspecified, < 15.22021-08-24
CVE-2021-30949 [HIGH] CWE-787 CVE-2021-30949: A memory corruption issue was addressed with improved state management. This issue is fixed in macOS A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2021-30954HIGHCVSS 7.8≥ unspecified, < 15.22021-08-24
CVE-2021-30954 [HIGH] CWE-843 CVE-2021-30954: A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 15.2 A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2021-30854HIGHCVSS 8.6≥ unspecified, < 152021-08-24
CVE-2021-30854 [HIGH] CVE-2021-30854: A logic issue was addressed with improved state management. This issue is fixed in tvOS 15, watchOS A logic issue was addressed with improved state management. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. A sandboxed process may be able to circumvent sandbox restrictions.
nvd
CVE-2021-30996HIGHCVSS 7.0≥ unspecified, < 15.22021-08-24
CVE-2021-30996 [HIGH] CWE-362 CVE-2021-30996: A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 1 A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 12.1, iOS 15.2 and iPadOS 15.2. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2021-30942HIGHCVSS 7.8≥ unspecified, < 15.22021-08-24
CVE-2021-30942 [HIGH] CWE-787 CVE-2021-30942: Description: A memory corruption issue in the processing of ICC profiles was addressed with improved Description: A memory corruption issue in the processing of ICC profiles was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2021-30884MEDIUMCVSS 4.7≥ unspecified, < 152021-08-24
CVE-2021-30884 [MEDIUM] CVE-2021-30884: The issue was resolved with additional restrictions on CSS compositing. This issue is fixed in tvOS The issue was resolved with additional restrictions on CSS compositing. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Visiting a maliciously crafted website may reveal a user's browsing history.
nvd
CVE-2021-30866MEDIUMCVSS 6.5≥ unspecified, < 152021-08-24
CVE-2021-30866 [MEDIUM] CVE-2021-30866: A user privacy issue was addressed by removing the broadcast MAC address. This issue is fixed in tvO A user privacy issue was addressed by removing the broadcast MAC address. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. A device may be passively tracked by its WiFi MAC address.
nvd
CVE-2021-31001MEDIUMCVSS 6.5≥ unspecified, < 152021-08-24
CVE-2021-31001 [MEDIUM] CVE-2021-31001: An access issue was addressed with improved access restrictions. This issue is fixed in iOS 15 and i An access issue was addressed with improved access restrictions. This issue is fixed in iOS 15 and iPadOS 15. An attacker in a privileged network position may be able to leak sensitive user information.
nvd
CVE-2021-30999MEDIUMCVSS 4.3≥ unspecified, < 14.62021-08-24
CVE-2021-30999 [MEDIUM] CWE-276 CVE-2021-30999: The issue was addressed with improved permissions logic. This issue is fixed in iOS 14.6 and iPadOS The issue was addressed with improved permissions logic. This issue is fixed in iOS 14.6 and iPadOS 14.6. A user may be unable to fully delete browsing history.
nvd
CVE-2021-30947MEDIUMCVSS 5.5≥ unspecified, < 15.22021-08-24
CVE-2021-30947 [MEDIUM] CVE-2021-30947: An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Big An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, iOS 15.2 and iPadOS 15.2, watchOS 8.3. An application may be able to access a user's files.
nvd
CVE-2021-30929MEDIUMCVSS 5.5≥ unspecified, < 15.22021-08-24
CVE-2021-30929 [MEDIUM] CWE-787 CVE-2021-30929: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in mac An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.1, iOS 15.2 and iPadOS 15.2, macOS Big Sur 11.6.2, Security Update 2021-008 Catalina. Processing a maliciously crafted USD file may disclose memory contents.
nvd
CVE-2021-30905MEDIUMCVSS 5.5≥ unspecified, < 15.12021-08-24
CVE-2021-30905 [MEDIUM] CWE-125 CVE-2021-30905: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 15.1 a An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, tvOS 15.1, watchOS 8.1, Security Update 2021-007 Catalina. Processing a maliciously crafted file may disclose user information.
nvd
CVE-2021-30896MEDIUMCVSS 5.5≥ unspecified, < 15.02021-08-24
CVE-2021-30896 [MEDIUM] CVE-2021-30896: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 15.0.2 and iPadOS A logic issue was addressed with improved restrictions. This issue is fixed in iOS 15.0.2 and iPadOS 15.0.2, tvOS 15.1, watchOS 8.1, macOS Monterey 12.0.1. A malicious application may be able to read user's gameplay data.
nvd
CVE-2021-30890MEDIUMCVSS 6.1≥ unspecified, < 15.12021-08-24
CVE-2021-30890 [MEDIUM] CWE-79 CVE-2021-30890: A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12 A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1, iOS 15.1 and iPadOS 15.1, watchOS 8.1, tvOS 15.1. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd
CVE-2021-30911MEDIUMCVSS 5.5≥ unspecified, < 15.12021-08-24
CVE-2021-30911 [MEDIUM] CWE-125 CVE-2021-30911: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Mont An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.0.1, Security Update 2021-007 Catalina, iOS 15.1 and iPadOS 15.1, macOS Big Sur 11.6.1. Processing a maliciously crafted USD file may disclose memory contents.
nvd
CVE-2021-30895MEDIUMCVSS 5.5≥ unspecified, < 15.02021-08-24
CVE-2021-30895 [MEDIUM] CVE-2021-30895: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 15.0.2 and iPadOS A logic issue was addressed with improved restrictions. This issue is fixed in iOS 15.0.2 and iPadOS 15.0.2, tvOS 15.1, watchOS 8.1, macOS Monterey 12.0.1. A malicious application may be able to access information about a user's contacts.
nvd
CVE-2021-30948MEDIUMCVSS 4.6≥ unspecified, < 15.22021-08-24
CVE-2021-30948 [MEDIUM] CWE-522 CVE-2021-30948: An inconsistent user interface issue was addressed with improved state management. This issue is fix An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 15.2 and iPadOS 15.2. A person with physical access to an iOS device may be able to access stored passwords without authentication.
nvd
CVE-2021-30998MEDIUMCVSS 5.3≥ unspecified, < 15.22021-08-24
CVE-2021-30998 [MEDIUM] CVE-2021-30998: A S/MIME issue existed in the handling of encrypted email. This issue was addressed with improved se A S/MIME issue existed in the handling of encrypted email. This issue was addressed with improved selection of the encryption certificate. This issue is fixed in iOS 15.2 and iPadOS 15.2. A sender's email address may be leaked when sending an S/MIME encrypted email using a certificate with more than one email address.
nvd