FontParser. Multiple memory corruption issues were addressed through improved input validation.
Kernel. A memory corruption issue was addressed through improved memory handling.
Security. A memory corruption issue existed in the parsing of certificates. This issue was addressed through improved input validation.
Kernel. A buffer overflow issue was addressed through improved memory handling.
Kernel. A race condition was addressed through improved locking.
Kernel. A buffer overflow issue was addressed through improved memory handling.
Kernel. A use after free issue was addressed through improved memory management.
Kernel. A memory corruption issue was addressed through improved input validation.
Kernel. An off-by-one issue was addressed through improved bounds checking.
Audio. A memory corruption issue was addressed through improved input validation.
ImageIO. A memory corruption issue was addressed through improved input validation.
CoreText. A resource exhaustion issue was addressed through improved input validation.
Kernel. A race condition was addressed through improved memory handling.
Keyboards. A buffer overflow was addressed through improved bounds checking.
CoreText. An out-of-bounds read was addressed through improved input validation.
Security. A buffer overflow was addressed through improved bounds checking.
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Bluetooth" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.
FontParser. An out-of-bounds read was addressed through improved input validation.
Kernel. An integer overflow was addressed through improved input validation.
libc++abi. A use after free issue was addressed through improved memory management.
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "AppleRAID" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "IOFireWireAVC" component. It allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
Audio. A memory corruption issue was addressed through improved input validation.
CoreText. A memory corruption issue was addressed through improved input validation.
ImageIO. A memory corruption issue was addressed through improved input validation.
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "IOFireWireAVC" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "CoreMedia" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted .mov file.
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "FinderKit" component. It allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging unexpected permission changes during an iCloud Sharing Send Link action.
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Bluetooth" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.