cbcvebase.

Apple Security Update 2021-008 Catalina vulnerabilities

32 known vulnerabilities affecting apple/security_update_2021-008_catalina.

Total CVEs
32
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH17MEDIUM15

Vulnerabilities

Page 1 of 2
CVE-2021-30995HIGHCVSS 7.02021-12-13
CVE-2021-30995 [HIGH] CVE-2021-30995: Security Update 2021-008 Catalina Apple Security Update: About the security content of Security Update 2021-008 Catalina Product: Security Update 2021-008 Catalina CVE: CVE-2021-30995 Component: Preferences Impact: A malicious application may be able to elevate privileges Description: A race condition was addressed with improved state handling.
apple
CVE-2021-30971HIGHCVSS 7.82021-12-13
CVE-2021-30971 [HIGH] CVE-2021-30971: Security Update 2021-008 Catalina Apple Security Update: About the security content of Security Update 2021-008 Catalina Product: Security Update 2021-008 Catalina CVE: CVE-2021-30971 Component: Model I/O Impact: Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution Description: An out-of-bounds write issue was addressed with improved bounds checking.
apple
CVE-2021-30939HIGHCVSS 7.82021-12-13
CVE-2021-30939 [HIGH] CVE-2021-30939: Security Update 2021-008 Catalina Apple Security Update: About the security content of Security Update 2021-008 Catalina Product: Security Update 2021-008 Catalina CVE: CVE-2021-30939 Component: ImageIO Impact: Processing a maliciously crafted image may lead to arbitrary code execution Description: An out-of-bounds read was addressed with improved bounds checking.
apple
CVE-2021-30958HIGHCVSS 7.82021-12-13
CVE-2021-30958 [HIGH] CVE-2021-30958: Security Update 2021-008 Catalina Apple Security Update: About the security content of Security Update 2021-008 Catalina Product: Security Update 2021-008 Catalina CVE: CVE-2021-30958 Component: CoreAudio Impact: Playing a malicious audio file may lead to arbitrary code execution Description: An out-of-bounds read was addressed with improved input validation.
apple
CVE-2021-30935HIGHCVSS 8.82021-12-13
CVE-2021-30935 [HIGH] CVE-2021-30935: Security Update 2021-008 Catalina Apple Security Update: About the security content of Security Update 2021-008 Catalina Product: Security Update 2021-008 Catalina CVE: CVE-2021-30935 Component: Bluetooth Impact: An application may be able to execute arbitrary code with kernel privileges Description: A logic issue was addressed with improved validation.
apple
CVE-2021-30945HIGHCVSS 7.82021-12-13
CVE-2021-30945 [HIGH] CVE-2021-30945: Security Update 2021-008 Catalina Apple Security Update: About the security content of Security Update 2021-008 Catalina Product: Security Update 2021-008 Catalina CVE: CVE-2021-30945 Component: Crash Reporter Impact: A local attacker may be able to elevate their privileges Description: This issue was addressed with improved checks.
apple
CVE-2021-30977HIGHCVSS 7.82021-12-13
CVE-2021-30977 [HIGH] CVE-2021-30977: Security Update 2021-008 Catalina Apple Security Update: About the security content of Security Update 2021-008 Catalina Product: Security Update 2021-008 Catalina CVE: CVE-2021-30977 Component: Graphics Drivers Impact: A malicious application may be able to execute arbitrary code with kernel privileges Description: A buffer overflow was addressed with improved bounds checking.
apple
CVE-2021-30942HIGHCVSS 7.82021-12-13
CVE-2021-30942 [HIGH] CVE-2021-30942: Security Update 2021-008 Catalina Apple Security Update: About the security content of Security Update 2021-008 Catalina Product: Security Update 2021-008 Catalina CVE: CVE-2021-30942 Component: ColorSync Impact: Processing a maliciously crafted image may lead to arbitrary code execution Description: A memory corruption issue in the processing of ICC profiles was addressed with improved input validation.
apple
CVE-2021-30969HIGHCVSS 7.82021-12-13
CVE-2021-30969 [HIGH] CVE-2021-30969: Security Update 2021-008 Catalina Apple Security Update: About the security content of Security Update 2021-008 Catalina Product: Security Update 2021-008 Catalina CVE: CVE-2021-30969 Component: Help Viewer Impact: Processing a maliciously crafted URL may cause unexpected JavaScript execution from a file on disk Description: A path handling issue was addressed with improved validation.
apple
CVE-2021-30979HIGHCVSS 7.82021-12-13
CVE-2021-30979 [HIGH] CVE-2021-30979: Security Update 2021-008 Catalina Apple Security Update: About the security content of Security Update 2021-008 Catalina Product: Security Update 2021-008 Catalina CVE: CVE-2021-30979 Component: Model I/O Impact: Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution Description: A buffer overflow issue was addressed with improved memory handling.
apple
CVE-2021-30938HIGHCVSS 7.72021-12-13
CVE-2021-30938 [HIGH] CVE-2021-30938: Security Update 2021-008 Catalina Apple Security Update: About the security content of Security Update 2021-008 Catalina Product: Security Update 2021-008 Catalina CVE: CVE-2021-30938 Component: Wi-Fi Impact: A local user may be able to cause unexpected system termination or read kernel memory Description: This issue was addressed with improved checks.
apple
CVE-2021-30981HIGHCVSS 7.82021-12-13
CVE-2021-30981 [HIGH] CVE-2021-30981: Security Update 2021-008 Catalina Apple Security Update: About the security content of Security Update 2021-008 Catalina Product: Security Update 2021-008 Catalina CVE: CVE-2021-30981 Component: Intel Graphics Driver Impact: An application may be able to execute arbitrary code with kernel privileges Description: A buffer overflow was addressed with improved bounds checking.
apple
CVE-2021-30927HIGHCVSS 7.82021-12-13
CVE-2021-30927 [HIGH] CVE-2021-30927: Security Update 2021-008 Catalina Apple Security Update: About the security content of Security Update 2021-008 Catalina Product: Security Update 2021-008 Catalina CVE: CVE-2021-30927 Component: Kernel Impact: An application may be able to execute arbitrary code with kernel privileges Description: A use after free issue was addressed with improved memory management.
apple
CVE-2021-30949HIGHCVSS 7.82021-12-13
CVE-2021-30949 [HIGH] CVE-2021-30949: Security Update 2021-008 Catalina Apple Security Update: About the security content of Security Update 2021-008 Catalina Product: Security Update 2021-008 Catalina CVE: CVE-2021-30949 Component: Kernel Impact: A malicious application may be able to execute arbitrary code with kernel privileges Description: A memory corruption issue was addressed with improved state management.
apple
CVE-2021-30975HIGHCVSS 8.62021-12-13
CVE-2021-30975 [HIGH] CVE-2021-30975: Security Update 2021-008 Catalina Apple Security Update: About the security content of Security Update 2021-008 Catalina Product: Security Update 2021-008 Catalina CVE: CVE-2021-30975 Component: Script Editor Impact: A malicious OSAX scripting addition may bypass Gatekeeper checks and circumvent sandbox restrictions Description: This issue was addressed by disabling execution of JavaScript when viewing a scripting dictionary.
apple
CVE-2021-30980HIGHCVSS 7.82021-12-13
CVE-2021-30980 [HIGH] CVE-2021-30980: Security Update 2021-008 Catalina Apple Security Update: About the security content of Security Update 2021-008 Catalina Product: Security Update 2021-008 Catalina CVE: CVE-2021-30980 Component: Kernel Impact: An application may be able to execute arbitrary code with kernel privileges Description: A use after free issue was addressed with improved memory management.
apple
CVE-2021-30937HIGHCVSS 7.82021-12-13
CVE-2021-30937 [HIGH] CVE-2021-30937: Security Update 2021-008 Catalina Apple Security Update: About the security content of Security Update 2021-008 Catalina Product: Security Update 2021-008 Catalina CVE: CVE-2021-30937 Component: Kernel Impact: A malicious application may be able to execute arbitrary code with kernel privileges Description: A memory corruption vulnerability was addressed with improved locking.
apple
CVE-2021-30959MEDIUMCVSS 5.52021-12-13
CVE-2021-30959 [MEDIUM] CVE-2021-30959: Security Update 2021-008 Catalina Apple Security Update: About the security content of Security Update 2021-008 Catalina Product: Security Update 2021-008 Catalina CVE: CVE-2021-30959 Component: CoreAudio Impact: Parsing a maliciously crafted audio file may lead to disclosure of user information Description: A buffer overflow issue was addressed with improved memory handling.
apple
CVE-2021-30963MEDIUMCVSS 5.52021-12-13
CVE-2021-30963 [MEDIUM] CVE-2021-30963: Security Update 2021-008 Catalina Apple Security Update: About the security content of Security Update 2021-008 Catalina Product: Security Update 2021-008 Catalina CVE: CVE-2021-30963 Component: CoreAudio Impact: Parsing a maliciously crafted audio file may lead to disclosure of user information Description: A buffer overflow issue was addressed with improved memory handling.
apple
CVE-2021-30968MEDIUMCVSS 5.52021-12-13
CVE-2021-30968 [MEDIUM] CVE-2021-30968: Security Update 2021-008 Catalina Apple Security Update: About the security content of Security Update 2021-008 Catalina Product: Security Update 2021-008 Catalina CVE: CVE-2021-30968 Component: Sandbox Impact: A malicious application may be able to bypass certain Privacy preferences Description: A validation issue related to hard link behavior was addressed with improved sandbox restrictions.
apple