Apple Security Update 2021-003 Catalina vulnerabilities

58 known vulnerabilities affecting apple/security_update_2021-003_catalina.

Total CVEs
58
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH33MEDIUM23LOW1

Vulnerabilities

Page 1 of 3
CVE-2021-30678CRITICALCVSS 9.82021-05-24
CVE-2021-30678 [CRITICAL] CVE-2021-30678: Security Update 2021-003 Catalina Apple Security Update: About the security content of Security Update 2021-003 Catalina Product: Security Update 2021-003 Catalina CVE: CVE-2021-30678 Component: AMD Impact: A remote attacker may be able to cause unexpected application termination or arbitrary code execution Description: A logic issue was addressed with improved state management.
apple
CVE-2020-36227HIGHCVSS 7.52021-05-24
CVE-2020-36227 [HIGH] CVE-2020-36227: Security Update 2021-003 Catalina Apple Security Update: About the security content of Security Update 2021-003 Catalina Product: Security Update 2021-003 Catalina CVE: CVE-2020-36227 Component: CVE-2020-36227
apple
CVE-2020-36226HIGHCVSS 7.52021-05-24
CVE-2020-36226 [HIGH] CVE-2020-36226: Security Update 2021-003 Catalina Apple Security Update: About the security content of Security Update 2021-003 Catalina Product: Security Update 2021-003 Catalina CVE: CVE-2020-36226 Component: CVE-2020-36226
apple
CVE-2020-36221HIGHCVSS 7.52021-05-24
CVE-2020-36221 [HIGH] CVE-2020-36221: Security Update 2021-003 Catalina Apple Security Update: About the security content of Security Update 2021-003 Catalina Product: Security Update 2021-003 Catalina CVE: CVE-2020-36221 Component: CVE-2020-36221
apple
CVE-2020-36230HIGHCVSS 7.52021-05-24
CVE-2020-36230 [HIGH] CVE-2020-36230: Security Update 2021-003 Catalina Apple Security Update: About the security content of Security Update 2021-003 Catalina Product: Security Update 2021-003 Catalina CVE: CVE-2020-36230 Component: CVE-2020-36230
apple
CVE-2021-30710HIGHCVSS 7.12021-05-24
CVE-2021-30710 [HIGH] CVE-2021-30710: Security Update 2021-003 Catalina Apple Security Update: About the security content of Security Update 2021-003 Catalina Product: Security Update 2021-003 Catalina CVE: CVE-2021-30710 Component: Heimdal Impact: A malicious application may cause a denial of service or potentially disclose memory contents Description: A memory corruption issue was addressed with improved state management.
apple
CVE-2021-30743HIGHCVSS 7.82021-05-24
CVE-2021-30743 [HIGH] CVE-2021-30743: Security Update 2021-003 Catalina Apple Security Update: About the security content of Security Update 2021-003 Catalina Product: Security Update 2021-003 Catalina CVE: CVE-2021-30743 Component: ImageIO Impact: Processing a maliciously crafted image may lead to arbitrary code execution Description: An out-of-bounds write was addressed with improved input validation.
apple
CVE-2020-36225HIGHCVSS 7.52021-05-24
CVE-2020-36225 [HIGH] CVE-2020-36225: Security Update 2021-003 Catalina Apple Security Update: About the security content of Security Update 2021-003 Catalina Product: Security Update 2021-003 Catalina CVE: CVE-2020-36225 Component: CVE-2020-36225
apple
CVE-2021-30735HIGHCVSS 7.82021-05-24
CVE-2021-30735 [HIGH] CVE-2021-30735: Security Update 2021-003 Catalina Apple Security Update: About the security content of Security Update 2021-003 Catalina Product: Security Update 2021-003 Catalina CVE: CVE-2021-30735 Component: Graphics Drivers Impact: An out-of-bounds write issue was addressed with improved bounds checking Description: A malicious application may be able to execute arbitrary code with kernel privileges.
apple
CVE-2020-36224HIGHCVSS 7.52021-05-24
CVE-2020-36224 [HIGH] CVE-2020-36224: Security Update 2021-003 Catalina Apple Security Update: About the security content of Security Update 2021-003 Catalina Product: Security Update 2021-003 Catalina CVE: CVE-2020-36224 Component: CVE-2020-36224
apple
CVE-2021-30681HIGHCVSS 7.82021-05-24
CVE-2021-30681 [HIGH] CVE-2021-30681: Security Update 2021-003 Catalina Apple Security Update: About the security content of Security Update 2021-003 Catalina Product: Security Update 2021-003 Catalina CVE: CVE-2021-30681 Component: Core Services Impact: A malicious application may be able to gain root privileges Description: A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks.
apple
CVE-2021-30684HIGHCVSS 7.82021-05-24
CVE-2021-30684 [HIGH] CVE-2021-30684: Security Update 2021-003 Catalina Apple Security Update: About the security content of Security Update 2021-003 Catalina Product: Security Update 2021-003 Catalina CVE: CVE-2021-30684 Component: Graphics Drivers Impact: A remote attacker may cause an unexpected application termination or arbitrary code execution Description: A logic issue was addressed with improved state management.
apple
CVE-2021-30679HIGHCVSS 7.82021-05-24
CVE-2021-30679 [HIGH] CVE-2021-30679: Security Update 2021-003 Catalina Apple Security Update: About the security content of Security Update 2021-003 Catalina Product: Security Update 2021-003 Catalina CVE: CVE-2021-30679 Component: NSOpenPanel Impact: An application may be able to gain elevated privileges Description: This issue was addressed by removing the vulnerable code.
apple
CVE-2021-30688HIGHCVSS 8.82021-05-24
CVE-2021-30688 [HIGH] CVE-2021-30688: Security Update 2021-003 Catalina Apple Security Update: About the security content of Security Update 2021-003 Catalina Product: Security Update 2021-003 Catalina CVE: CVE-2021-30688 Component: App Store Impact: A path handling issue was addressed with improved validation Description: A malicious application may be able to break out of its sandbox.
apple
CVE-2021-30717HIGHCVSS 8.12021-05-24
CVE-2021-30717 [HIGH] CVE-2021-30717: Security Update 2021-003 Catalina Apple Security Update: About the security content of Security Update 2021-003 Catalina Product: Security Update 2021-003 Catalina CVE: CVE-2021-30717 Component: Security Impact: A memory corruption issue in the ASN.1 decoder was addressed by removing the vulnerable code Description: Processing a maliciously crafted certificate may lead to arbitrary code execution.
apple
CVE-2020-36229HIGHCVSS 7.52021-05-24
CVE-2020-36229 [HIGH] CVE-2020-36229: Security Update 2021-003 Catalina Apple Security Update: About the security content of Security Update 2021-003 Catalina Product: Security Update 2021-003 Catalina CVE: CVE-2020-36229 Component: CVE-2020-36229
apple
CVE-2021-30708HIGHCVSS 7.82021-05-24
CVE-2021-30708 [HIGH] CVE-2021-30708: Security Update 2021-003 Catalina Apple Security Update: About the security content of Security Update 2021-003 Catalina Product: Security Update 2021-003 Catalina CVE: CVE-2021-30708 Component: Model I/O Impact: Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution Description: An out-of-bounds read was addressed with improved input validation.
apple
CVE-2021-30725HIGHCVSS 7.82021-05-24
CVE-2021-30725 [HIGH] CVE-2021-30725: Security Update 2021-003 Catalina Apple Security Update: About the security content of Security Update 2021-003 Catalina Product: Security Update 2021-003 Catalina CVE: CVE-2021-30725 Component: Model I/O Impact: Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution Description: A memory corruption issue was addressed with improved state management.
apple
CVE-2021-30712HIGHCVSS 7.82021-05-24
CVE-2021-30712 [HIGH] CVE-2021-30712: Security Update 2021-003 Catalina Apple Security Update: About the security content of Security Update 2021-003 Catalina Product: Security Update 2021-003 Catalina CVE: CVE-2021-30712 Component: Security Impact: A memory corruption issue in the ASN.1 decoder was addressed by removing the vulnerable code Description: Processing a maliciously crafted certificate may lead to arbitrary code execution.
apple
CVE-2021-30737HIGHCVSS 8.82021-05-24
CVE-2021-30737 [HIGH] CVE-2021-30737: Security Update 2021-003 Catalina Apple Security Update: About the security content of Security Update 2021-003 Catalina Product: Security Update 2021-003 Catalina CVE: CVE-2021-30737 Component: Security Impact: A memory corruption issue in the ASN.1 decoder was addressed by removing the vulnerable code Description: Processing a maliciously crafted certificate may lead to arbitrary code execution.
apple