Where
AND
-Infinity
0
Severity
6.8
EPSS
10.06%
Input Validation, Double Free, Use After Free
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.

1 / 35
Source: Launchpad
First published (updated )
Severity
6.8
Use After Free, Input Validation, Null Pointer Dereference
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H

Accessibility. A logging issue was addressed with improved data redaction.

1 / 16
Source: Apple
First published (updated )
Severity
6.7
EPSS
0.04%
Buffer Overflow, Race Condition, Input Validation, Null Pointer Dereference, Use After Free
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3. An app with root privileges may be able to execute arbitrary code with kernel privileges.

1 / 51
Source: MITRE
First published (updated )
Severity
6.6
EPSS
0.24%
Use After Free, Input Validation, Race Condition
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Impact

The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;).

This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. Note that Ruby 3.1 will reach EOL on 2025-03.

Patches

The REXML gem 3.3.9 or later include the patch to fix the vulnerability.

Workarounds

Use Ruby 3.2 or later instead of Ruby 3.1.

References

https://www.ruby-lang.org/en/news/2024/10/28/redos-rexml-cve-2024-49761/: An announce on www.ruby-lang.org

1 / 72
Source: GitHub
First published (updated )
Severity
6.6
EPSS
0.02%
Integer Overflow, Input Validation
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L

A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.

1 / 32
Source: NVD
First published (updated )
Severity
6.5
EPSS
0.06%
Input Validation
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

App Store. A permissions issue was addressed with additional restrictions.

1 / 23
Source: Apple
First published (updated )
Severity
6.5
Input Validation, Integer Overflow, Race Condition, Buffer Overflow
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. A malicious website may exfiltrate data cross-origin.

1 / 103
Source: MITRE
First published (updated )
Severity
6.5
Input Validation, Race Condition, Buffer Overflow, Integer Overflow
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in Safari 18, iOS 17.7.1 and iPadOS 17.7.1, iOS 18 and iPadOS 18, macOS Sequoia 15, watchOS 11. Maliciously crafted web content may violate iframe sandboxing policy.

1 / 80
Source: MITRE
First published (updated )
Severity
6.5
Input Validation, Use After Free, Race Condition
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

A path deletion vulnerability was addressed by preventing vulnerable code from running with privileges. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An attacker with root privileges may be able to delete protected system files.

1 / 41
Source: MITRE
First published (updated )
Severity
6.5
Input Validation, Use After Free, Race Condition, Buffer Overflow
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. Parsing a maliciously crafted file may lead to an unexpected app termination.

1 / 59
Source: MITRE
First published (updated )
Severity
6.5
Input Validation
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Accessibility. The issue was addressed with improved authentication.

1 / 19
Source: Apple
First published (updated )
Severity
6.5
Input Validation
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Accessibility. The issue was addressed with improved authentication.

1 / 23
Source: Apple
First published (updated )
Severity
6.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Accessibility. The issue was addressed with improved authentication.

1 / 14
Source: Apple
First published (updated )
Severity
6.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Accessibility. The issue was addressed with improved authentication.

1 / 5
Source: Apple
First published (updated )
Severity
6.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Accessibility. The issue was addressed with improved authentication.

1 / 5
Source: Apple
First published (updated )
Severity
6.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Accessibility. The issue was addressed with improved authentication.

1 / 5
Source: Apple
First published (updated )
Severity
6.5
EPSS
0.05%
Buffer Overflow, Input Validation, Null Pointer Dereference, Integer Overflow, Use After Free
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L

Accessibility. A logging issue was addressed with improved data redaction.

1 / 49
Source: Apple
First published (updated )
Severity
6.5
Input Validation
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Accounts. A logic issue was addressed with improved file handling.

1 / 23
Source: Apple
First published (updated )
Severity
6.5
Use After Free, Race Condition, Input Validation, Buffer Overflow, Null Pointer Dereference, Integer Overflow
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Accounts. A logic issue was addressed with improved file handling.

1 / 111
Source: Apple
First published (updated )
Severity
6.5
Malicious File Upload
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Accounts. A logic issue was addressed with improved file handling.

1 / 6
Source: Apple
First published (updated )
Severity
6.5
Input Validation
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Accounts. A logic issue was addressed with improved file handling.

1 / 17
Source: Apple
First published (updated )
Severity
6.5
Use After Free, Race Condition, Input Validation
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Accounts. A logic issue was addressed with improved file handling.

1 / 76
Source: Apple
First published (updated )
Severity
6.5
Input Validation
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Accounts. A logic issue was addressed with improved file handling.

1 / 31
Source: Apple
First published (updated )
Severity
6.5
EPSS
0.04%
Input Validation, Null Pointer Dereference
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

AirPlay. A null pointer dereference was addressed with improved input validation.

1 / 15
Source: Apple
First published (updated )
Severity
6.5
EPSS
0.04%
Input Validation, XSS, Use After Free, Null Pointer Dereference, Race Condition, Buffer Overflow
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Accessibility. An authentication issue was addressed with improved state management.

1 / 70
Source: Apple
First published (updated )
Severity
6.5
EPSS
0.04%
Input Validation, Null Pointer Dereference
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Accessibility. An authentication issue was addressed with improved state management.

1 / 19
Source: Apple
First published (updated )
Severity
6.5
EPSS
0.04%
Input Validation, Use After Free, Null Pointer Dereference, Race Condition, Buffer Overflow
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Accessibility. An authentication issue was addressed with improved state management.

1 / 72
Source: Apple
First published (updated )
Severity
6.5
EPSS
0.07%
Input Validation, Null Pointer Dereference
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Accessibility. An authentication issue was addressed with improved state management.

1 / 13
Source: Apple
First published (updated )
Severity
6.5
EPSS
0.06%
Input Validation, Use After Free, Race Condition, Buffer Overflow, Null Pointer Dereference
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Accessibility. An authentication issue was addressed with improved state management.

1 / 70
Source: Apple
First published (updated )
Severity
6.5
Input Validation, Buffer Overflow, Integer Overflow, Race Condition, Infoleak
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. A malicious website may exfiltrate data cross-origin.

1 / 97
Source: MITRE
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203