Apple Security Update 2021-004 Mojave vulnerabilities
49 known vulnerabilities affecting apple/security_update_2021-004_mojave.
Total CVEs
49
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH27MEDIUM20
Vulnerabilities
Page 2 of 3
CVE-2020-36230HIGHCVSS 7.52021-05-24
CVE-2020-36230 [HIGH] CVE-2020-36230: Security Update 2021-004 Mojave
Apple Security Update: About the security content of Security Update 2021-004 Mojave
Product: Security Update 2021-004 Mojave
CVE: CVE-2020-36230
Component: CVE-2020-36230
apple
CVE-2021-30676HIGHCVSS 7.12021-05-24
CVE-2021-30676 [HIGH] CVE-2021-30676: Security Update 2021-004 Mojave
Apple Security Update: About the security content of Security Update 2021-004 Mojave
Product: Security Update 2021-004 Mojave
CVE: CVE-2021-30676
Component: AMD
Impact: A local user may be able to cause unexpected system termination or read kernel memory
Description: A logic issue was addressed with improved state management.
apple
CVE-2021-30693HIGHCVSS 7.82021-05-24
CVE-2021-30693 [HIGH] CVE-2021-30693: Security Update 2021-004 Mojave
Apple Security Update: About the security content of Security Update 2021-004 Mojave
Product: Security Update 2021-004 Mojave
CVE: CVE-2021-30693
Component: Model I/O
Impact: Processing a maliciously crafted image may lead to arbitrary code execution
Description: A validation issue was addressed with improved logic.
apple
CVE-2021-30681HIGHCVSS 7.82021-05-24
CVE-2021-30681 [HIGH] CVE-2021-30681: Security Update 2021-004 Mojave
Apple Security Update: About the security content of Security Update 2021-004 Mojave
Product: Security Update 2021-004 Mojave
CVE: CVE-2021-30681
Component: Core Services
Impact: A malicious application may be able to gain root privileges
Description: A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks.
apple
CVE-2020-36225HIGHCVSS 7.52021-05-24
CVE-2020-36225 [HIGH] CVE-2020-36225: Security Update 2021-004 Mojave
Apple Security Update: About the security content of Security Update 2021-004 Mojave
Product: Security Update 2021-004 Mojave
CVE: CVE-2020-36225
Component: CVE-2020-36225
apple
CVE-2021-30683HIGHCVSS 7.82021-05-24
CVE-2021-30683 [HIGH] CVE-2021-30683: Security Update 2021-004 Mojave
Apple Security Update: About the security content of Security Update 2021-004 Mojave
Product: Security Update 2021-004 Mojave
CVE: CVE-2021-30683
Component: Heimdal
Impact: A malicious application could execute arbitrary code leading to compromise of user information
Description: A use after free issue was addressed with improved memory management.
apple
CVE-2020-36229HIGHCVSS 7.52021-05-24
CVE-2020-36229 [HIGH] CVE-2020-36229: Security Update 2021-004 Mojave
Apple Security Update: About the security content of Security Update 2021-004 Mojave
Product: Security Update 2021-004 Mojave
CVE: CVE-2020-36229
Component: CVE-2020-36229
apple
CVE-2021-30735HIGHCVSS 7.82021-05-24
CVE-2021-30735 [HIGH] CVE-2021-30735: Security Update 2021-004 Mojave
Apple Security Update: About the security content of Security Update 2021-004 Mojave
Product: Security Update 2021-004 Mojave
CVE: CVE-2021-30735
Component: Graphics Drivers
Impact: An out-of-bounds write issue was addressed with improved bounds checking
Description: A malicious application may be able to execute arbitrary code with kernel privileges.
apple
CVE-2021-30726HIGHCVSS 7.82021-05-24
CVE-2021-30726 [HIGH] CVE-2021-30726: Security Update 2021-004 Mojave
Apple Security Update: About the security content of Security Update 2021-004 Mojave
Product: Security Update 2021-004 Mojave
CVE: CVE-2021-30726
Component: Intel Graphics Driver
Impact: An out-of-bounds write issue was addressed with improved bounds checking
Description: A malicious application may be able to execute arbitrary code with kernel privileges.
apple
CVE-2021-30691MEDIUMCVSS 5.52021-05-24
CVE-2021-30691 [MEDIUM] CVE-2021-30691: Security Update 2021-004 Mojave
Apple Security Update: About the security content of Security Update 2021-004 Mojave
Product: Security Update 2021-004 Mojave
CVE: CVE-2021-30691
Component: Model I/O
Impact: Processing a maliciously crafted USD file may disclose memory contents
Description: An information disclosure issue was addressed with improved state management.
apple
CVE-2021-30819MEDIUMCVSS 5.52021-05-24
CVE-2021-30819 [MEDIUM] CVE-2021-30819: Security Update 2021-004 Mojave
Apple Security Update: About the security content of Security Update 2021-004 Mojave
Product: Security Update 2021-004 Mojave
CVE: CVE-2021-30819
Component: CVE-2021-30819
apple
CVE-2021-30669MEDIUMCVSS 5.52021-05-24
CVE-2021-30669 [MEDIUM] CVE-2021-30669: Security Update 2021-004 Mojave
Apple Security Update: About the security content of Security Update 2021-004 Mojave
Product: Security Update 2021-004 Mojave
CVE: CVE-2021-30669
Component: AppleScript
Impact: A malicious application may bypass Gatekeeper checks
Description: A logic issue was addressed with improved state management.
apple
CVE-2021-30697MEDIUMCVSS 5.52021-05-24
CVE-2021-30697 [MEDIUM] CVE-2021-30697: Security Update 2021-004 Mojave
Apple Security Update: About the security content of Security Update 2021-004 Mojave
Product: Security Update 2021-004 Mojave
CVE: CVE-2021-30697
Component: Heimdal
Impact: A local user may be able to leak sensitive user information
Description: A logic issue was addressed with improved state management.
apple
CVE-2021-30723MEDIUMCVSS 5.52021-05-24
CVE-2021-30723 [MEDIUM] CVE-2021-30723: Security Update 2021-004 Mojave
Apple Security Update: About the security content of Security Update 2021-004 Mojave
Product: Security Update 2021-004 Mojave
CVE: CVE-2021-30723
Component: Model I/O
Impact: Processing a maliciously crafted USD file may disclose memory contents
Description: An information disclosure issue was addressed with improved state management.
apple
CVE-2021-30696MEDIUMCVSS 5.92021-05-24
CVE-2021-30696 [MEDIUM] CVE-2021-30696: Security Update 2021-004 Mojave
Apple Security Update: About the security content of Security Update 2021-004 Mojave
Product: Security Update 2021-004 Mojave
CVE: CVE-2021-30696
Component: Mail
Impact: A logic issue was addressed with improved state management
Description: An attacker in a privileged network position may be able to misrepresent application state.
apple
CVE-2021-30709MEDIUMCVSS 5.52021-05-24
CVE-2021-30709 [MEDIUM] CVE-2021-30709: Security Update 2021-004 Mojave
Apple Security Update: About the security content of Security Update 2021-004 Mojave
Product: Security Update 2021-004 Mojave
CVE: CVE-2021-30709
Component: Model I/O
Impact: Processing a maliciously crafted USD file may disclose memory contents
Description: This issue was addressed with improved checks.
apple
CVE-2021-30716MEDIUMCVSS 5.92021-05-24
CVE-2021-30716 [MEDIUM] CVE-2021-30716: Security Update 2021-004 Mojave
Apple Security Update: About the security content of Security Update 2021-004 Mojave
Product: Security Update 2021-004 Mojave
CVE: CVE-2021-30716
Component: Security
Impact: A memory corruption issue in the ASN.1 decoder was addressed by removing the vulnerable code
Description: Processing a maliciously crafted certificate may lead to arbitrary code execution.
apple
CVE-2021-1884MEDIUMCVSS 5.92021-05-24
CVE-2021-1884 [MEDIUM] CVE-2021-1884: Security Update 2021-004 Mojave
Apple Security Update: About the security content of Security Update 2021-004 Mojave
Product: Security Update 2021-004 Mojave
CVE: CVE-2021-1884
Component: Heimdal
Impact: A remote attacker may be able to cause a denial of service
Description: A race condition was addressed with improved locking.
apple
CVE-2021-30721MEDIUMCVSS 6.52021-05-24
CVE-2021-30721 [MEDIUM] CVE-2021-30721: Security Update 2021-004 Mojave
Apple Security Update: About the security content of Security Update 2021-004 Mojave
Product: Security Update 2021-004 Mojave
CVE: CVE-2021-30721
Component: Security
Impact: A memory corruption issue in the ASN.1 decoder was addressed by removing the vulnerable code
Description: Processing a maliciously crafted certificate may lead to arbitrary code execution.
apple
CVE-2021-30738MEDIUMCVSS 5.52021-05-24
CVE-2021-30738 [MEDIUM] CVE-2021-30738: Security Update 2021-004 Mojave
Apple Security Update: About the security content of Security Update 2021-004 Mojave
Product: Security Update 2021-004 Mojave
CVE: CVE-2021-30738
Component: PackageKit
Impact: An issue with path validation logic for hardlinks was addressed with improved path sanitization
Description: A malicious application may be able to overwrite arbitrary files.
apple