Apple Security Update 2021-008 Catalina vulnerabilities
32 known vulnerabilities affecting apple/security_update_2021-008_catalina.
Total CVEs
32
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH17MEDIUM15
Vulnerabilities
Page 1 of 2
CVE-2021-30995HIGHCVSS 7.02021-12-13
CVE-2021-30995 [HIGH] CVE-2021-30995: Security Update 2021-008 Catalina
Apple Security Update: About the security content of Security Update 2021-008 Catalina
Product: Security Update 2021-008 Catalina
CVE: CVE-2021-30995
Component: Preferences
Impact: A malicious application may be able to elevate privileges
Description: A race condition was addressed with improved state handling.
apple
CVE-2021-30971HIGHCVSS 7.82021-12-13
CVE-2021-30971 [HIGH] CVE-2021-30971: Security Update 2021-008 Catalina
Apple Security Update: About the security content of Security Update 2021-008 Catalina
Product: Security Update 2021-008 Catalina
CVE: CVE-2021-30971
Component: Model I/O
Impact: Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution
Description: An out-of-bounds write issue was addressed with improved bounds checking.
apple
CVE-2021-30939HIGHCVSS 7.82021-12-13
CVE-2021-30939 [HIGH] CVE-2021-30939: Security Update 2021-008 Catalina
Apple Security Update: About the security content of Security Update 2021-008 Catalina
Product: Security Update 2021-008 Catalina
CVE: CVE-2021-30939
Component: ImageIO
Impact: Processing a maliciously crafted image may lead to arbitrary code execution
Description: An out-of-bounds read was addressed with improved bounds checking.
apple
CVE-2021-30958HIGHCVSS 7.82021-12-13
CVE-2021-30958 [HIGH] CVE-2021-30958: Security Update 2021-008 Catalina
Apple Security Update: About the security content of Security Update 2021-008 Catalina
Product: Security Update 2021-008 Catalina
CVE: CVE-2021-30958
Component: CoreAudio
Impact: Playing a malicious audio file may lead to arbitrary code execution
Description: An out-of-bounds read was addressed with improved input validation.
apple
CVE-2021-30935HIGHCVSS 8.82021-12-13
CVE-2021-30935 [HIGH] CVE-2021-30935: Security Update 2021-008 Catalina
Apple Security Update: About the security content of Security Update 2021-008 Catalina
Product: Security Update 2021-008 Catalina
CVE: CVE-2021-30935
Component: Bluetooth
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A logic issue was addressed with improved validation.
apple
CVE-2021-30945HIGHCVSS 7.82021-12-13
CVE-2021-30945 [HIGH] CVE-2021-30945: Security Update 2021-008 Catalina
Apple Security Update: About the security content of Security Update 2021-008 Catalina
Product: Security Update 2021-008 Catalina
CVE: CVE-2021-30945
Component: Crash Reporter
Impact: A local attacker may be able to elevate their privileges
Description: This issue was addressed with improved checks.
apple
CVE-2021-30977HIGHCVSS 7.82021-12-13
CVE-2021-30977 [HIGH] CVE-2021-30977: Security Update 2021-008 Catalina
Apple Security Update: About the security content of Security Update 2021-008 Catalina
Product: Security Update 2021-008 Catalina
CVE: CVE-2021-30977
Component: Graphics Drivers
Impact: A malicious application may be able to execute arbitrary code with kernel privileges
Description: A buffer overflow was addressed with improved bounds checking.
apple
CVE-2021-30942HIGHCVSS 7.82021-12-13
CVE-2021-30942 [HIGH] CVE-2021-30942: Security Update 2021-008 Catalina
Apple Security Update: About the security content of Security Update 2021-008 Catalina
Product: Security Update 2021-008 Catalina
CVE: CVE-2021-30942
Component: ColorSync
Impact: Processing a maliciously crafted image may lead to arbitrary code execution
Description: A memory corruption issue in the processing of ICC profiles was addressed with improved input validation.
apple
CVE-2021-30969HIGHCVSS 7.82021-12-13
CVE-2021-30969 [HIGH] CVE-2021-30969: Security Update 2021-008 Catalina
Apple Security Update: About the security content of Security Update 2021-008 Catalina
Product: Security Update 2021-008 Catalina
CVE: CVE-2021-30969
Component: Help Viewer
Impact: Processing a maliciously crafted URL may cause unexpected JavaScript execution from a file on disk
Description: A path handling issue was addressed with improved validation.
apple
CVE-2021-30979HIGHCVSS 7.82021-12-13
CVE-2021-30979 [HIGH] CVE-2021-30979: Security Update 2021-008 Catalina
Apple Security Update: About the security content of Security Update 2021-008 Catalina
Product: Security Update 2021-008 Catalina
CVE: CVE-2021-30979
Component: Model I/O
Impact: Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution
Description: A buffer overflow issue was addressed with improved memory handling.
apple
CVE-2021-30938HIGHCVSS 7.72021-12-13
CVE-2021-30938 [HIGH] CVE-2021-30938: Security Update 2021-008 Catalina
Apple Security Update: About the security content of Security Update 2021-008 Catalina
Product: Security Update 2021-008 Catalina
CVE: CVE-2021-30938
Component: Wi-Fi
Impact: A local user may be able to cause unexpected system termination or read kernel memory
Description: This issue was addressed with improved checks.
apple
CVE-2021-30981HIGHCVSS 7.82021-12-13
CVE-2021-30981 [HIGH] CVE-2021-30981: Security Update 2021-008 Catalina
Apple Security Update: About the security content of Security Update 2021-008 Catalina
Product: Security Update 2021-008 Catalina
CVE: CVE-2021-30981
Component: Intel Graphics Driver
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A buffer overflow was addressed with improved bounds checking.
apple
CVE-2021-30927HIGHCVSS 7.82021-12-13
CVE-2021-30927 [HIGH] CVE-2021-30927: Security Update 2021-008 Catalina
Apple Security Update: About the security content of Security Update 2021-008 Catalina
Product: Security Update 2021-008 Catalina
CVE: CVE-2021-30927
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A use after free issue was addressed with improved memory management.
apple
CVE-2021-30949HIGHCVSS 7.82021-12-13
CVE-2021-30949 [HIGH] CVE-2021-30949: Security Update 2021-008 Catalina
Apple Security Update: About the security content of Security Update 2021-008 Catalina
Product: Security Update 2021-008 Catalina
CVE: CVE-2021-30949
Component: Kernel
Impact: A malicious application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed with improved state management.
apple
CVE-2021-30975HIGHCVSS 8.62021-12-13
CVE-2021-30975 [HIGH] CVE-2021-30975: Security Update 2021-008 Catalina
Apple Security Update: About the security content of Security Update 2021-008 Catalina
Product: Security Update 2021-008 Catalina
CVE: CVE-2021-30975
Component: Script Editor
Impact: A malicious OSAX scripting addition may bypass Gatekeeper checks and circumvent sandbox restrictions
Description: This issue was addressed by disabling execution of JavaScript when viewing a scripting dictionary.
apple
CVE-2021-30980HIGHCVSS 7.82021-12-13
CVE-2021-30980 [HIGH] CVE-2021-30980: Security Update 2021-008 Catalina
Apple Security Update: About the security content of Security Update 2021-008 Catalina
Product: Security Update 2021-008 Catalina
CVE: CVE-2021-30980
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A use after free issue was addressed with improved memory management.
apple
CVE-2021-30937HIGHCVSS 7.82021-12-13
CVE-2021-30937 [HIGH] CVE-2021-30937: Security Update 2021-008 Catalina
Apple Security Update: About the security content of Security Update 2021-008 Catalina
Product: Security Update 2021-008 Catalina
CVE: CVE-2021-30937
Component: Kernel
Impact: A malicious application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption vulnerability was addressed with improved locking.
apple
CVE-2021-30959MEDIUMCVSS 5.52021-12-13
CVE-2021-30959 [MEDIUM] CVE-2021-30959: Security Update 2021-008 Catalina
Apple Security Update: About the security content of Security Update 2021-008 Catalina
Product: Security Update 2021-008 Catalina
CVE: CVE-2021-30959
Component: CoreAudio
Impact: Parsing a maliciously crafted audio file may lead to disclosure of user information
Description: A buffer overflow issue was addressed with improved memory handling.
apple
CVE-2021-30963MEDIUMCVSS 5.52021-12-13
CVE-2021-30963 [MEDIUM] CVE-2021-30963: Security Update 2021-008 Catalina
Apple Security Update: About the security content of Security Update 2021-008 Catalina
Product: Security Update 2021-008 Catalina
CVE: CVE-2021-30963
Component: CoreAudio
Impact: Parsing a maliciously crafted audio file may lead to disclosure of user information
Description: A buffer overflow issue was addressed with improved memory handling.
apple
CVE-2021-30968MEDIUMCVSS 5.52021-12-13
CVE-2021-30968 [MEDIUM] CVE-2021-30968: Security Update 2021-008 Catalina
Apple Security Update: About the security content of Security Update 2021-008 Catalina
Product: Security Update 2021-008 Catalina
CVE: CVE-2021-30968
Component: Sandbox
Impact: A malicious application may be able to bypass certain Privacy preferences
Description: A validation issue related to hard link behavior was addressed with improved sandbox restrictions.
apple
1 / 2Next →