Latest CVE Feed
-
9.8
CRITICALCVE-2024-54492
This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, visionOS 2.2. An attacker in a privileged network position may be able to alter network ... Read more
- Published: Dec. 12, 2024
- Modified: Dec. 19, 2024
-
5.5
MEDIUMCVE-2024-54491
The issue was resolved by sanitizing logging This issue is fixed in macOS Sequoia 15.2. A malicious application may be able to determine a user's current location.... Read more
Affected Products : macos- Published: Dec. 12, 2024
- Modified: Jan. 08, 2025
-
5.5
MEDIUMCVE-2024-54490
This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Sequoia 15.2. A local attacker may gain access to user's Keychain items.... Read more
Affected Products : macos- Published: Dec. 12, 2024
- Modified: Dec. 19, 2024
-
7.8
HIGHCVE-2024-54489
A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. Running a mount command may unexpectedly execute arbitrary code.... Read more
Affected Products : macos- Published: Dec. 12, 2024
- Modified: Dec. 13, 2024
-
6.5
MEDIUMCVE-2024-54486
The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.3, watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. Processing a maliciously crafted font may r... Read more
- Published: Dec. 12, 2024
- Modified: Dec. 20, 2024
-
5.5
MEDIUMCVE-2024-54485
The issue was addressed by adding additional logic. This issue is fixed in iPadOS 17.7.3, iOS 18.2 and iPadOS 18.2. An attacker with physical access to an iOS device may be able to view notification content from the lock screen.... Read more
- Published: Dec. 12, 2024
- Modified: Dec. 13, 2024
-
5.5
MEDIUMCVE-2024-54484
The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2. An app may be able to access user-sensitive data.... Read more
Affected Products : macos- Published: Dec. 12, 2024
- Modified: Dec. 13, 2024
-
7.5
HIGHCVE-2024-54479
The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.3, watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, Safari 18.2, iOS 18.2 and iPadOS 18.2. Processing maliciously crafted web content may lead to an unexpected proc... Read more
- Published: Dec. 12, 2024
- Modified: Dec. 20, 2024
-
5.5
MEDIUMCVE-2024-54477
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to access user-sensitive data.... Read more
Affected Products : macos- Published: Dec. 12, 2024
- Modified: Dec. 13, 2024
-
5.5
MEDIUMCVE-2024-54476
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to access user-sensitive data.... Read more
Affected Products : macos- Published: Dec. 12, 2024
- Modified: Dec. 19, 2024
-
5.5
MEDIUMCVE-2024-54474
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to access user-sensitive data.... Read more
Affected Products : macos- Published: Dec. 12, 2024
- Modified: Dec. 16, 2024
-
5.5
MEDIUMCVE-2024-54471
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious application may be able to leak a user's credentials.... Read more
Affected Products : macos- Published: Dec. 12, 2024
- Modified: Mar. 20, 2025
-
6.5
MEDIUMCVE-2024-54466
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An encrypted volume may be accessed by a different user without prompting for the password.... Read more
Affected Products : macos- Published: Dec. 12, 2024
- Modified: Dec. 18, 2024
-
9.8
CRITICALCVE-2024-54465
A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.2. An app may be able to elevate privileges.... Read more
Affected Products : macos- Published: Dec. 12, 2024
- Modified: Dec. 16, 2024
-
6.6
MEDIUMCVE-2024-53845
ESPTouch is a connection protocol for internet of things devices. In the ESPTouchV2 protocol, while there is an option to use a custom AES key, there is no option to set the IV (Initialization Vector) prior to versions 5.3.2, 5.2.4, 5.1.6, and 5.0.8. The ... Read more
Affected Products : esp-idf- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024
-
2.0
LOWCVE-2024-53274
Habitica is an open-source habit-building program. Versions prior to 5.28.5 are vulnerable to reflected cross-site scripting. The `register` function in `home.vue` containsa reflected XSS vulnerability due to an incorrect sanitization function. An attacke... Read more
Affected Products :- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024
-
5.0
MEDIUMCVE-2024-53273
Habitica is an open-source habit-building program. Versions prior to 5.28.5 are vulnerable to reflected cross-site scripting. The `register` function in `RegisterLoginReset.vue` contains a reflected XSS vulnerability due to an incorrect sanitization funct... Read more
Affected Products :- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024
-
5.0
MEDIUMCVE-2024-53272
Habitica is an open-source habit-building program. Versions prior to 5.28.5 are vulnerable to reflected cross-site scripting. The `login` and `social media` function in `RegisterLoginReset.vue` contains two reflected XSS vulnerabilities due to an incorrec... Read more
Affected Products :- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024
-
5.5
MEDIUMCVE-2024-44300
A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to access protected user data.... Read more
Affected Products : macos- Published: Dec. 12, 2024
- Modified: Dec. 20, 2024
-
9.8
CRITICALCVE-2024-44299
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP firmware.... Read more
- Published: Dec. 12, 2024
- Modified: Dec. 13, 2024