cbcvebase.

Apple Security Update 2021-007 Catalina vulnerabilities

29 known vulnerabilities affecting apple/security_update_2021-007_catalina.

Total CVEs
29
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH21MEDIUM7LOW1

Vulnerabilities

Page 2 of 2
CVE-2021-30906HIGHCVSS 7.82021-10-25
CVE-2021-30906 [HIGH] CVE-2021-30906: Security Update 2021-007 Catalina Apple Security Update: About the security content of Security Update 2021-007 Catalina Product: Security Update 2021-007 Catalina CVE: CVE-2021-30906 Component: FileProvider Impact: Unpacking a maliciously crafted archive may lead to arbitrary code execution Description: An input validation issue was addressed with improved memory handling.
apple
CVE-2021-30910MEDIUMCVSS 5.52021-10-25
CVE-2021-30910 [MEDIUM] CVE-2021-30910: Security Update 2021-007 Catalina Apple Security Update: About the security content of Security Update 2021-007 Catalina Product: Security Update 2021-007 Catalina CVE: CVE-2021-30910 Component: Model I/O Impact: Processing a maliciously crafted file may disclose user information Description: An out-of-bounds read was addressed with improved bounds checking.
apple
CVE-2021-30911MEDIUMCVSS 5.52021-10-25
CVE-2021-30911 [MEDIUM] CVE-2021-30911: Security Update 2021-007 Catalina Apple Security Update: About the security content of Security Update 2021-007 Catalina Product: Security Update 2021-007 Catalina CVE: CVE-2021-30911 Component: Model I/O Impact: Processing a maliciously crafted USD file may disclose memory contents Description: An out-of-bounds read was addressed with improved bounds checking.
apple
CVE-2021-30913MEDIUMCVSS 5.52021-10-25
CVE-2021-30913 [MEDIUM] CVE-2021-30913: Security Update 2021-007 Catalina Apple Security Update: About the security content of Security Update 2021-007 Catalina Product: Security Update 2021-007 Catalina CVE: CVE-2021-30913 Component: SoftwareUpdate Impact: An unprivileged application may be able to edit NVRAM variables Description: A logic issue was addressed with improved restrictions.
apple
CVE-2021-30892MEDIUMCVSS 5.52021-10-25
CVE-2021-30892 [MEDIUM] CVE-2021-30892: Security Update 2021-007 Catalina Apple Security Update: About the security content of Security Update 2021-007 Catalina Product: Security Update 2021-007 Catalina CVE: CVE-2021-30892 Component: UIKit Impact: A person with physical access to a device may be able to determine characteristics of a user's password in a secure text entry field Description: A logic issue was addressed with improved state management.
apple
CVE-2021-30833MEDIUMCVSS 5.52021-10-25
CVE-2021-30833 [MEDIUM] CVE-2021-30833: Security Update 2021-007 Catalina Apple Security Update: About the security content of Security Update 2021-007 Catalina Product: Security Update 2021-007 Catalina CVE: CVE-2021-30833 Component: UIKit Impact: A person with physical access to a device may be able to determine characteristics of a user's password in a secure text entry field Description: A logic issue was addressed with improved state management.
apple
CVE-2021-30912MEDIUMCVSS 5.52021-10-25
CVE-2021-30912 [MEDIUM] CVE-2021-30912: Security Update 2021-007 Catalina Apple Security Update: About the security content of Security Update 2021-007 Catalina Product: Security Update 2021-007 Catalina CVE: CVE-2021-30912 Component: SoftwareUpdate Impact: A malicious application may gain access to a user's Keychain items Description: The issue was addressed with improved permissions logic.
apple
CVE-2021-30905MEDIUMCVSS 5.52021-10-25
CVE-2021-30905 [MEDIUM] CVE-2021-30905: Security Update 2021-007 Catalina Apple Security Update: About the security content of Security Update 2021-007 Catalina Product: Security Update 2021-007 Catalina CVE: CVE-2021-30905 Component: CoreAudio Impact: Processing a maliciously crafted file may disclose user information Description: An out-of-bounds read was addressed with improved bounds checking.
apple
CVE-2021-30915LOWCVSS 2.42021-10-25
CVE-2021-30915 [LOW] CVE-2021-30915: Security Update 2021-007 Catalina Apple Security Update: About the security content of Security Update 2021-007 Catalina Product: Security Update 2021-007 Catalina CVE: CVE-2021-30915 Component: UIKit Impact: A person with physical access to a device may be able to determine characteristics of a user's password in a secure text entry field Description: A logic issue was addressed with improved state management.
apple