Heimdal. A memory corruption issue was addressed with improved memory handling.
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
MediaRemote. An access issue was addressed with additional sandbox restrictions.
Kernel. Multiple memory corruption issues were addressed with improved memory handling.
Kernel. Multiple memory corruption issues were addressed with improved memory handling.
Kernel. Multiple memory corruption issues were addressed with improved memory handling.
Kernel. Multiple memory corruption issues were addressed with improved memory handling.
Kernel. Multiple memory corruption issues were addressed with improved memory handling.
Security. A logic issue was addressed with improved restrictions.
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. A malicious application may be able to execute arbitrary code with kernel privileges.
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
apache. Multiple issues in apache were addressed by updating apache to version 2.4.46.
802.1X. A logic issue was addressed with improved state management.
A validation issue existed in Trust Anchor Management. This issue was addressed with improved validation. This issue is fixed in watchOS 5.2, macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, iOS 12.2. An untrusted radius server certificate may be trusted.
In FreeBSD 12.0-STABLE before r350648, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350650, 11.3-RELEASE before 11.3-RELEASE-p2, and 11.2-RELEASE before 11.2-RELEASE-p13, the ICMPv6 input path incorrectly handles cases where an MLDv2 listener query packet is internally fragmented across multiple mbufs. A remote attacker may be able to cause an out-of-bounds read or write that may cause the kernel to attempt to access an unmapped page and subsequently panic.
Kernel. An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation.
fdesetup. A logic issue was addressed with improved state management.
SQLite. A memory corruption issue was addressed with improved input validation.
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
FaceTime. A memory corruption issue was addressed with improved input validation.
Carbon Core. A use after free issue was addressed with improved memory management.
Quick Look. This issue was addressed with improved checks.
DiskArbitration. A permissions issue existed in DiskArbitration. This was addressed with additional ownership checks.
LibreSSL. Multiple issues were addressed by updating to libressl version 2.6.4.
afpserver. An input validation issue was addressed with improved input validation.
Application Firewall. A configuration issue was addressed with additional restrictions.
CoreAudio. A buffer overflow was addressed with improved bounds checking.
This issue was addressed with improved entitlements. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6. A sandboxed process may be able to circumvent sandbox restrictions.
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.