Apple Security Update 2021-003 Catalina vulnerabilities
58 known vulnerabilities affecting apple/security_update_2021-003_catalina.
Total CVEs
58
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH33MEDIUM23LOW1
Vulnerabilities
Page 1 of 3
CVE-2021-30678CRITICALCVSS 9.82021-05-24
CVE-2021-30678 [CRITICAL] CVE-2021-30678: Security Update 2021-003 Catalina
Apple Security Update: About the security content of Security Update 2021-003 Catalina
Product: Security Update 2021-003 Catalina
CVE: CVE-2021-30678
Component: AMD
Impact: A remote attacker may be able to cause unexpected application termination or arbitrary code execution
Description: A logic issue was addressed with improved state management.
apple
CVE-2020-36227HIGHCVSS 7.52021-05-24
CVE-2020-36227 [HIGH] CVE-2020-36227: Security Update 2021-003 Catalina
Apple Security Update: About the security content of Security Update 2021-003 Catalina
Product: Security Update 2021-003 Catalina
CVE: CVE-2020-36227
Component: CVE-2020-36227
apple
CVE-2020-36226HIGHCVSS 7.52021-05-24
CVE-2020-36226 [HIGH] CVE-2020-36226: Security Update 2021-003 Catalina
Apple Security Update: About the security content of Security Update 2021-003 Catalina
Product: Security Update 2021-003 Catalina
CVE: CVE-2020-36226
Component: CVE-2020-36226
apple
CVE-2020-36221HIGHCVSS 7.52021-05-24
CVE-2020-36221 [HIGH] CVE-2020-36221: Security Update 2021-003 Catalina
Apple Security Update: About the security content of Security Update 2021-003 Catalina
Product: Security Update 2021-003 Catalina
CVE: CVE-2020-36221
Component: CVE-2020-36221
apple
CVE-2020-36230HIGHCVSS 7.52021-05-24
CVE-2020-36230 [HIGH] CVE-2020-36230: Security Update 2021-003 Catalina
Apple Security Update: About the security content of Security Update 2021-003 Catalina
Product: Security Update 2021-003 Catalina
CVE: CVE-2020-36230
Component: CVE-2020-36230
apple
CVE-2021-30710HIGHCVSS 7.12021-05-24
CVE-2021-30710 [HIGH] CVE-2021-30710: Security Update 2021-003 Catalina
Apple Security Update: About the security content of Security Update 2021-003 Catalina
Product: Security Update 2021-003 Catalina
CVE: CVE-2021-30710
Component: Heimdal
Impact: A malicious application may cause a denial of service or potentially disclose memory contents
Description: A memory corruption issue was addressed with improved state management.
apple
CVE-2021-30743HIGHCVSS 7.82021-05-24
CVE-2021-30743 [HIGH] CVE-2021-30743: Security Update 2021-003 Catalina
Apple Security Update: About the security content of Security Update 2021-003 Catalina
Product: Security Update 2021-003 Catalina
CVE: CVE-2021-30743
Component: ImageIO
Impact: Processing a maliciously crafted image may lead to arbitrary code execution
Description: An out-of-bounds write was addressed with improved input validation.
apple
CVE-2020-36225HIGHCVSS 7.52021-05-24
CVE-2020-36225 [HIGH] CVE-2020-36225: Security Update 2021-003 Catalina
Apple Security Update: About the security content of Security Update 2021-003 Catalina
Product: Security Update 2021-003 Catalina
CVE: CVE-2020-36225
Component: CVE-2020-36225
apple
CVE-2021-30735HIGHCVSS 7.82021-05-24
CVE-2021-30735 [HIGH] CVE-2021-30735: Security Update 2021-003 Catalina
Apple Security Update: About the security content of Security Update 2021-003 Catalina
Product: Security Update 2021-003 Catalina
CVE: CVE-2021-30735
Component: Graphics Drivers
Impact: An out-of-bounds write issue was addressed with improved bounds checking
Description: A malicious application may be able to execute arbitrary code with kernel privileges.
apple
CVE-2020-36224HIGHCVSS 7.52021-05-24
CVE-2020-36224 [HIGH] CVE-2020-36224: Security Update 2021-003 Catalina
Apple Security Update: About the security content of Security Update 2021-003 Catalina
Product: Security Update 2021-003 Catalina
CVE: CVE-2020-36224
Component: CVE-2020-36224
apple
CVE-2021-30681HIGHCVSS 7.82021-05-24
CVE-2021-30681 [HIGH] CVE-2021-30681: Security Update 2021-003 Catalina
Apple Security Update: About the security content of Security Update 2021-003 Catalina
Product: Security Update 2021-003 Catalina
CVE: CVE-2021-30681
Component: Core Services
Impact: A malicious application may be able to gain root privileges
Description: A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks.
apple
CVE-2021-30684HIGHCVSS 7.82021-05-24
CVE-2021-30684 [HIGH] CVE-2021-30684: Security Update 2021-003 Catalina
Apple Security Update: About the security content of Security Update 2021-003 Catalina
Product: Security Update 2021-003 Catalina
CVE: CVE-2021-30684
Component: Graphics Drivers
Impact: A remote attacker may cause an unexpected application termination or arbitrary code execution
Description: A logic issue was addressed with improved state management.
apple
CVE-2021-30679HIGHCVSS 7.82021-05-24
CVE-2021-30679 [HIGH] CVE-2021-30679: Security Update 2021-003 Catalina
Apple Security Update: About the security content of Security Update 2021-003 Catalina
Product: Security Update 2021-003 Catalina
CVE: CVE-2021-30679
Component: NSOpenPanel
Impact: An application may be able to gain elevated privileges
Description: This issue was addressed by removing the vulnerable code.
apple
CVE-2021-30688HIGHCVSS 8.82021-05-24
CVE-2021-30688 [HIGH] CVE-2021-30688: Security Update 2021-003 Catalina
Apple Security Update: About the security content of Security Update 2021-003 Catalina
Product: Security Update 2021-003 Catalina
CVE: CVE-2021-30688
Component: App Store
Impact: A path handling issue was addressed with improved validation
Description: A malicious application may be able to break out of its sandbox.
apple
CVE-2021-30717HIGHCVSS 8.12021-05-24
CVE-2021-30717 [HIGH] CVE-2021-30717: Security Update 2021-003 Catalina
Apple Security Update: About the security content of Security Update 2021-003 Catalina
Product: Security Update 2021-003 Catalina
CVE: CVE-2021-30717
Component: Security
Impact: A memory corruption issue in the ASN.1 decoder was addressed by removing the vulnerable code
Description: Processing a maliciously crafted certificate may lead to arbitrary code execution.
apple
CVE-2020-36229HIGHCVSS 7.52021-05-24
CVE-2020-36229 [HIGH] CVE-2020-36229: Security Update 2021-003 Catalina
Apple Security Update: About the security content of Security Update 2021-003 Catalina
Product: Security Update 2021-003 Catalina
CVE: CVE-2020-36229
Component: CVE-2020-36229
apple
CVE-2021-30708HIGHCVSS 7.82021-05-24
CVE-2021-30708 [HIGH] CVE-2021-30708: Security Update 2021-003 Catalina
Apple Security Update: About the security content of Security Update 2021-003 Catalina
Product: Security Update 2021-003 Catalina
CVE: CVE-2021-30708
Component: Model I/O
Impact: Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution
Description: An out-of-bounds read was addressed with improved input validation.
apple
CVE-2021-30725HIGHCVSS 7.82021-05-24
CVE-2021-30725 [HIGH] CVE-2021-30725: Security Update 2021-003 Catalina
Apple Security Update: About the security content of Security Update 2021-003 Catalina
Product: Security Update 2021-003 Catalina
CVE: CVE-2021-30725
Component: Model I/O
Impact: Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution
Description: A memory corruption issue was addressed with improved state management.
apple
CVE-2021-30712HIGHCVSS 7.82021-05-24
CVE-2021-30712 [HIGH] CVE-2021-30712: Security Update 2021-003 Catalina
Apple Security Update: About the security content of Security Update 2021-003 Catalina
Product: Security Update 2021-003 Catalina
CVE: CVE-2021-30712
Component: Security
Impact: A memory corruption issue in the ASN.1 decoder was addressed by removing the vulnerable code
Description: Processing a maliciously crafted certificate may lead to arbitrary code execution.
apple
CVE-2021-30737HIGHCVSS 8.82021-05-24
CVE-2021-30737 [HIGH] CVE-2021-30737: Security Update 2021-003 Catalina
Apple Security Update: About the security content of Security Update 2021-003 Catalina
Product: Security Update 2021-003 Catalina
CVE: CVE-2021-30737
Component: Security
Impact: A memory corruption issue in the ASN.1 decoder was addressed by removing the vulnerable code
Description: Processing a maliciously crafted certificate may lead to arbitrary code execution.
apple
1 / 3Next →