Apple Security Update 2021-007 Catalina vulnerabilities
29 known vulnerabilities affecting apple/security_update_2021-007_catalina.
Total CVEs
29
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH21MEDIUM7LOW1
Vulnerabilities
Page 2 of 2
CVE-2021-30906HIGHCVSS 7.82021-10-25
CVE-2021-30906 [HIGH] CVE-2021-30906: Security Update 2021-007 Catalina
Apple Security Update: About the security content of Security Update 2021-007 Catalina
Product: Security Update 2021-007 Catalina
CVE: CVE-2021-30906
Component: FileProvider
Impact: Unpacking a maliciously crafted archive may lead to arbitrary code execution
Description: An input validation issue was addressed with improved memory handling.
apple
CVE-2021-30910MEDIUMCVSS 5.52021-10-25
CVE-2021-30910 [MEDIUM] CVE-2021-30910: Security Update 2021-007 Catalina
Apple Security Update: About the security content of Security Update 2021-007 Catalina
Product: Security Update 2021-007 Catalina
CVE: CVE-2021-30910
Component: Model I/O
Impact: Processing a maliciously crafted file may disclose user information
Description: An out-of-bounds read was addressed with improved bounds checking.
apple
CVE-2021-30911MEDIUMCVSS 5.52021-10-25
CVE-2021-30911 [MEDIUM] CVE-2021-30911: Security Update 2021-007 Catalina
Apple Security Update: About the security content of Security Update 2021-007 Catalina
Product: Security Update 2021-007 Catalina
CVE: CVE-2021-30911
Component: Model I/O
Impact: Processing a maliciously crafted USD file may disclose memory contents
Description: An out-of-bounds read was addressed with improved bounds checking.
apple
CVE-2021-30913MEDIUMCVSS 5.52021-10-25
CVE-2021-30913 [MEDIUM] CVE-2021-30913: Security Update 2021-007 Catalina
Apple Security Update: About the security content of Security Update 2021-007 Catalina
Product: Security Update 2021-007 Catalina
CVE: CVE-2021-30913
Component: SoftwareUpdate
Impact: An unprivileged application may be able to edit NVRAM variables
Description: A logic issue was addressed with improved restrictions.
apple
CVE-2021-30892MEDIUMCVSS 5.52021-10-25
CVE-2021-30892 [MEDIUM] CVE-2021-30892: Security Update 2021-007 Catalina
Apple Security Update: About the security content of Security Update 2021-007 Catalina
Product: Security Update 2021-007 Catalina
CVE: CVE-2021-30892
Component: UIKit
Impact: A person with physical access to a device may be able to determine characteristics of a user's password in a secure text entry field
Description: A logic issue was addressed with improved state management.
apple
CVE-2021-30833MEDIUMCVSS 5.52021-10-25
CVE-2021-30833 [MEDIUM] CVE-2021-30833: Security Update 2021-007 Catalina
Apple Security Update: About the security content of Security Update 2021-007 Catalina
Product: Security Update 2021-007 Catalina
CVE: CVE-2021-30833
Component: UIKit
Impact: A person with physical access to a device may be able to determine characteristics of a user's password in a secure text entry field
Description: A logic issue was addressed with improved state management.
apple
CVE-2021-30912MEDIUMCVSS 5.52021-10-25
CVE-2021-30912 [MEDIUM] CVE-2021-30912: Security Update 2021-007 Catalina
Apple Security Update: About the security content of Security Update 2021-007 Catalina
Product: Security Update 2021-007 Catalina
CVE: CVE-2021-30912
Component: SoftwareUpdate
Impact: A malicious application may gain access to a user's Keychain items
Description: The issue was addressed with improved permissions logic.
apple
CVE-2021-30905MEDIUMCVSS 5.52021-10-25
CVE-2021-30905 [MEDIUM] CVE-2021-30905: Security Update 2021-007 Catalina
Apple Security Update: About the security content of Security Update 2021-007 Catalina
Product: Security Update 2021-007 Catalina
CVE: CVE-2021-30905
Component: CoreAudio
Impact: Processing a maliciously crafted file may disclose user information
Description: An out-of-bounds read was addressed with improved bounds checking.
apple
CVE-2021-30915LOWCVSS 2.42021-10-25
CVE-2021-30915 [LOW] CVE-2021-30915: Security Update 2021-007 Catalina
Apple Security Update: About the security content of Security Update 2021-007 Catalina
Product: Security Update 2021-007 Catalina
CVE: CVE-2021-30915
Component: UIKit
Impact: A person with physical access to a device may be able to determine characteristics of a user's password in a secure text entry field
Description: A logic issue was addressed with improved state management.
apple
← Previous2 / 2