Apple Security Update 2021-004 Mojave vulnerabilities

49 known vulnerabilities affecting apple/security_update_2021-004_mojave.

Total CVEs
49
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH27MEDIUM20

Vulnerabilities

Page 2 of 3
CVE-2020-36230HIGHCVSS 7.52021-05-24
CVE-2020-36230 [HIGH] CVE-2020-36230: Security Update 2021-004 Mojave Apple Security Update: About the security content of Security Update 2021-004 Mojave Product: Security Update 2021-004 Mojave CVE: CVE-2020-36230 Component: CVE-2020-36230
apple
CVE-2021-30676HIGHCVSS 7.12021-05-24
CVE-2021-30676 [HIGH] CVE-2021-30676: Security Update 2021-004 Mojave Apple Security Update: About the security content of Security Update 2021-004 Mojave Product: Security Update 2021-004 Mojave CVE: CVE-2021-30676 Component: AMD Impact: A local user may be able to cause unexpected system termination or read kernel memory Description: A logic issue was addressed with improved state management.
apple
CVE-2021-30693HIGHCVSS 7.82021-05-24
CVE-2021-30693 [HIGH] CVE-2021-30693: Security Update 2021-004 Mojave Apple Security Update: About the security content of Security Update 2021-004 Mojave Product: Security Update 2021-004 Mojave CVE: CVE-2021-30693 Component: Model I/O Impact: Processing a maliciously crafted image may lead to arbitrary code execution Description: A validation issue was addressed with improved logic.
apple
CVE-2021-30681HIGHCVSS 7.82021-05-24
CVE-2021-30681 [HIGH] CVE-2021-30681: Security Update 2021-004 Mojave Apple Security Update: About the security content of Security Update 2021-004 Mojave Product: Security Update 2021-004 Mojave CVE: CVE-2021-30681 Component: Core Services Impact: A malicious application may be able to gain root privileges Description: A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks.
apple
CVE-2020-36225HIGHCVSS 7.52021-05-24
CVE-2020-36225 [HIGH] CVE-2020-36225: Security Update 2021-004 Mojave Apple Security Update: About the security content of Security Update 2021-004 Mojave Product: Security Update 2021-004 Mojave CVE: CVE-2020-36225 Component: CVE-2020-36225
apple
CVE-2021-30683HIGHCVSS 7.82021-05-24
CVE-2021-30683 [HIGH] CVE-2021-30683: Security Update 2021-004 Mojave Apple Security Update: About the security content of Security Update 2021-004 Mojave Product: Security Update 2021-004 Mojave CVE: CVE-2021-30683 Component: Heimdal Impact: A malicious application could execute arbitrary code leading to compromise of user information Description: A use after free issue was addressed with improved memory management.
apple
CVE-2020-36229HIGHCVSS 7.52021-05-24
CVE-2020-36229 [HIGH] CVE-2020-36229: Security Update 2021-004 Mojave Apple Security Update: About the security content of Security Update 2021-004 Mojave Product: Security Update 2021-004 Mojave CVE: CVE-2020-36229 Component: CVE-2020-36229
apple
CVE-2021-30735HIGHCVSS 7.82021-05-24
CVE-2021-30735 [HIGH] CVE-2021-30735: Security Update 2021-004 Mojave Apple Security Update: About the security content of Security Update 2021-004 Mojave Product: Security Update 2021-004 Mojave CVE: CVE-2021-30735 Component: Graphics Drivers Impact: An out-of-bounds write issue was addressed with improved bounds checking Description: A malicious application may be able to execute arbitrary code with kernel privileges.
apple
CVE-2021-30726HIGHCVSS 7.82021-05-24
CVE-2021-30726 [HIGH] CVE-2021-30726: Security Update 2021-004 Mojave Apple Security Update: About the security content of Security Update 2021-004 Mojave Product: Security Update 2021-004 Mojave CVE: CVE-2021-30726 Component: Intel Graphics Driver Impact: An out-of-bounds write issue was addressed with improved bounds checking Description: A malicious application may be able to execute arbitrary code with kernel privileges.
apple
CVE-2021-30691MEDIUMCVSS 5.52021-05-24
CVE-2021-30691 [MEDIUM] CVE-2021-30691: Security Update 2021-004 Mojave Apple Security Update: About the security content of Security Update 2021-004 Mojave Product: Security Update 2021-004 Mojave CVE: CVE-2021-30691 Component: Model I/O Impact: Processing a maliciously crafted USD file may disclose memory contents Description: An information disclosure issue was addressed with improved state management.
apple
CVE-2021-30819MEDIUMCVSS 5.52021-05-24
CVE-2021-30819 [MEDIUM] CVE-2021-30819: Security Update 2021-004 Mojave Apple Security Update: About the security content of Security Update 2021-004 Mojave Product: Security Update 2021-004 Mojave CVE: CVE-2021-30819 Component: CVE-2021-30819
apple
CVE-2021-30669MEDIUMCVSS 5.52021-05-24
CVE-2021-30669 [MEDIUM] CVE-2021-30669: Security Update 2021-004 Mojave Apple Security Update: About the security content of Security Update 2021-004 Mojave Product: Security Update 2021-004 Mojave CVE: CVE-2021-30669 Component: AppleScript Impact: A malicious application may bypass Gatekeeper checks Description: A logic issue was addressed with improved state management.
apple
CVE-2021-30697MEDIUMCVSS 5.52021-05-24
CVE-2021-30697 [MEDIUM] CVE-2021-30697: Security Update 2021-004 Mojave Apple Security Update: About the security content of Security Update 2021-004 Mojave Product: Security Update 2021-004 Mojave CVE: CVE-2021-30697 Component: Heimdal Impact: A local user may be able to leak sensitive user information Description: A logic issue was addressed with improved state management.
apple
CVE-2021-30723MEDIUMCVSS 5.52021-05-24
CVE-2021-30723 [MEDIUM] CVE-2021-30723: Security Update 2021-004 Mojave Apple Security Update: About the security content of Security Update 2021-004 Mojave Product: Security Update 2021-004 Mojave CVE: CVE-2021-30723 Component: Model I/O Impact: Processing a maliciously crafted USD file may disclose memory contents Description: An information disclosure issue was addressed with improved state management.
apple
CVE-2021-30696MEDIUMCVSS 5.92021-05-24
CVE-2021-30696 [MEDIUM] CVE-2021-30696: Security Update 2021-004 Mojave Apple Security Update: About the security content of Security Update 2021-004 Mojave Product: Security Update 2021-004 Mojave CVE: CVE-2021-30696 Component: Mail Impact: A logic issue was addressed with improved state management Description: An attacker in a privileged network position may be able to misrepresent application state.
apple
CVE-2021-30709MEDIUMCVSS 5.52021-05-24
CVE-2021-30709 [MEDIUM] CVE-2021-30709: Security Update 2021-004 Mojave Apple Security Update: About the security content of Security Update 2021-004 Mojave Product: Security Update 2021-004 Mojave CVE: CVE-2021-30709 Component: Model I/O Impact: Processing a maliciously crafted USD file may disclose memory contents Description: This issue was addressed with improved checks.
apple
CVE-2021-30716MEDIUMCVSS 5.92021-05-24
CVE-2021-30716 [MEDIUM] CVE-2021-30716: Security Update 2021-004 Mojave Apple Security Update: About the security content of Security Update 2021-004 Mojave Product: Security Update 2021-004 Mojave CVE: CVE-2021-30716 Component: Security Impact: A memory corruption issue in the ASN.1 decoder was addressed by removing the vulnerable code Description: Processing a maliciously crafted certificate may lead to arbitrary code execution.
apple
CVE-2021-1884MEDIUMCVSS 5.92021-05-24
CVE-2021-1884 [MEDIUM] CVE-2021-1884: Security Update 2021-004 Mojave Apple Security Update: About the security content of Security Update 2021-004 Mojave Product: Security Update 2021-004 Mojave CVE: CVE-2021-1884 Component: Heimdal Impact: A remote attacker may be able to cause a denial of service Description: A race condition was addressed with improved locking.
apple
CVE-2021-30721MEDIUMCVSS 6.52021-05-24
CVE-2021-30721 [MEDIUM] CVE-2021-30721: Security Update 2021-004 Mojave Apple Security Update: About the security content of Security Update 2021-004 Mojave Product: Security Update 2021-004 Mojave CVE: CVE-2021-30721 Component: Security Impact: A memory corruption issue in the ASN.1 decoder was addressed by removing the vulnerable code Description: Processing a maliciously crafted certificate may lead to arbitrary code execution.
apple
CVE-2021-30738MEDIUMCVSS 5.52021-05-24
CVE-2021-30738 [MEDIUM] CVE-2021-30738: Security Update 2021-004 Mojave Apple Security Update: About the security content of Security Update 2021-004 Mojave Product: Security Update 2021-004 Mojave CVE: CVE-2021-30738 Component: PackageKit Impact: An issue with path validation logic for hardlinks was addressed with improved path sanitization Description: A malicious application may be able to overwrite arbitrary files.
apple