Latest CVE Feed
-
9.3
HIGHCVE-2021-30672
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. A malicious application may be able to gain root privileges.... Read more
- EPSS Score: %0.35
- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-30671
A validation issue was addressed with improved logic. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina. A malicious application may be able to send unauthorized Apple events to Finder.... Read more
- EPSS Score: %0.14
- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-30669
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A malicious application may bypass Gatekeeper checks.... Read more
- EPSS Score: %0.07
- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
4.6
MEDIUMCVE-2021-30668
This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.4. A person with physical access to a Mac may be able to bypass Login Window during a software update.... Read more
Affected Products : macos- EPSS Score: %0.06
- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-30667
A logic issue was addressed with improved validation. This issue is fixed in iOS 14.6 and iPadOS 14.6. An attacker in WiFi range may be able to force a client to use a less secure authentication mechanism.... Read more
- EPSS Score: %0.06
- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-30664
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing a maliciously crafted file may lead to arbitrary code execution.... Read more
- EPSS Score: %0.46
- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
7.3
HIGHCVE-2021-30662
This issue was addressed with improved checks. This issue is fixed in iOS 14.5 and iPadOS 14.5. Processing a maliciously crafted file may lead to arbitrary code execution.... Read more
- EPSS Score: %0.40
- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-30660
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A malicious application may be able to disclose kernel memory.... Read more
- EPSS Score: %0.60
- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-30659
A validation issue was addressed with improved logic. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, macOS Big Sur 11.3. A malicious application may be able to leak sensitive user information.... Read more
- EPSS Score: %0.41
- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-30658
This issue was addressed with improved handling of file metadata. This issue is fixed in macOS Big Sur 11.3. A malicious application may bypass Gatekeeper checks.... Read more
Affected Products : macos- EPSS Score: %0.06
- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-30656
An access issue was addressed with improved memory management. This issue is fixed in iOS 14.5 and iPadOS 14.5. A malicious application may be able to determine kernel memory layout.... Read more
- EPSS Score: %0.22
- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-30655
An application may be able to execute arbitrary code with system privileges. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. The issue was addressed with improved permissions logic.... Read more
- EPSS Score: %0.62
- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-30654
This issue was addressed by removing additional entitlements. This issue is fixed in GarageBand 10.4.3. A local attacker may be able to read sensitive information.... Read more
Affected Products : garageband- EPSS Score: %0.13
- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-30653
This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing a maliciously crafted image may lead to arbitrary code execution.... Read more
- EPSS Score: %0.46
- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
7.6
HIGHCVE-2021-30652
A race condition was addressed with additional validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A malicious application may be able... Read more
- EPSS Score: %0.22
- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-30651
A malicious authenticated SMG administrator user can obtain passwords for external LDAP/Active Directory servers that they might not otherwise be authorized to access.... Read more
Affected Products : symantec_messaging_gateway- EPSS Score: %0.30
- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-30650
A reflected cross-site scripting (XSS) vulnerability in the Symantec Layer7 API Management OAuth Toolkit (OTK) allows a remote attacker to craft a malicious URL for the OTK web UI and target OTK users with phishing attacks or other social engineering tech... Read more
Affected Products : layer7_api_management_oauth_toolkit- EPSS Score: %0.25
- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-30648
The Symantec Advanced Secure Gateway (ASG) and ProxySG web management consoles are susceptible to an authentication bypass vulnerability. An unauthenticated attacker can execute arbitrary CLI commands, view/modify the appliance configuration and policy, a... Read more
Affected Products : symantec_proxysg symantec_advanced_secure_gateway_s200-30_firmware symantec_advanced_secure_gateway_s200-40_firmware symantec_advanced_secure_gateway_s400-20_firmware symantec_advanced_secure_gateway_s400-30_firmware symantec_advanced_secure_gateway_s400-40_firmware symantec_advanced_secure_gateway_500-10_firmware symantec_advanced_secure_gateway_s500-20_firmware symantec_advanced_secure_gateway_s200-30 symantec_advanced_secure_gateway_s200-40 +5 more products- EPSS Score: %0.49
- Published: Jun. 30, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-30642
An input validation flaw in the Symantec Security Analytics web UI 7.2 prior 7.2.7, 8.1, prior to 8.1.3-NSR3, 8.2, prior to 8.2.1-NSR2 or 8.2.2 allows a remote, unauthenticated attacker to execute arbitrary OS commands on the target with elevated privileg... Read more
Affected Products : security_analytics- EPSS Score: %1.60
- Published: Apr. 27, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-30641
Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF'... Read more
- EPSS Score: %20.87
- Published: Jun. 10, 2021
- Modified: Nov. 21, 2024