macOS
macOS 14.6
Advisory officielmacOS 14.6, publié le 2024-07-29, corrige 80 CVE. Les versions antérieures restent exposées à ces vulnérabilités.
- Date de sortie
- 2024-07-29
- Fin de support
- 2026-09-14 · EOL
- CVE corrigées
- 80
- KEV CISA
- 0
2 critique · 23 élevé
CVE corrigées
| CVE |
|---|
|
CVE-2024-4558
CRITICAL 9.6
Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chr… |
|
CVE-2024-44206
CRITICAL 9.3
An issue in the handling of URL protocols was addressed with improved logic. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, t… |
|
CVE-2024-2398
HIGH 8.6
Microsoft Security Update Guide entry — NVD enrichira. |
|
CVE-2024-6387
Exploit
HIGH 8.1
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an uns… |
|
CVE-2024-44305
HIGH 7.8
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.6. An app may be able to gain root privileges. |
|
CVE-2024-44307
HIGH 7.8
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app may be able to execute arbitrary code wit… |
|
CVE-2024-44306
HIGH 7.8
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app may be able to execute arbitrary code wit… |
|
CVE-2024-40828
HIGH 7.8
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A malicious app may be abl… |
|
CVE-2024-40809
HIGH 7.8
A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS S… |
|
CVE-2024-40812
HIGH 7.8
A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS S… |
|
CVE-2024-40802
HIGH 7.8
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A local attacker may be ab… |
|
CVE-2024-40781
HIGH 7.8
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A local attacker may be ab… |
|
CVE-2024-54551
HIGH 7.5
The issue was addressed with improved memory handling. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3… |
|
CVE-2024-40815
HIGH 7.5
A race condition was addressed with additional validation. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6,… |
|
CVE-2024-40803
HIGH 7.5
A type confusion issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An attacker m… |
|
CVE-2024-27316
HIGH 7.5
Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames |
|
CVE-2023-52356
HIGH 7.5
A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw allows a re… |
|
CVE-2023-38709
HIGH 7.3
Microsoft Security Update Guide entry — NVD enrichira. |
|
CVE-2024-44199
HIGH 7.1
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.6. An app may be able to cause unexpected system ter… |
|
CVE-2024-40805
HIGH 7.1
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, watchOS 10.6. An… |
|
CVE-2024-40814
HIGH 7.1
A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.6, macOS Ventura 13.7. An app may be able to … |
|
CVE-2024-40821
HIGH 7.1
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. Thir… |
|
CVE-2024-40787
HIGH 7.1
This issue was addressed by adding an additional prompt for user consent. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma … |
|
CVE-2024-40799
HIGH 7.1
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS … |
|
CVE-2024-40774
HIGH 7.1
A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma… |
|
CVE-2024-44141
MEDIUM 6.8
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. A person with physical access to an unlocked Mac may be able to gain ro… |
|
CVE-2024-27878
MEDIUM 6.7
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app may be able to execute arbitrary code wit… |
|
CVE-2024-54564
MEDIUM 6.5
This issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, visionOS 1.3. A file received f… |
|
CVE-2023-6277
MEDIUM 6.5
Microsoft Security Update Guide entry — NVD enrichira. |
|
CVE-2024-2466
MEDIUM 6.5
Microsoft Security Update Guide entry — NVD enrichira. |
|
CVE-2024-40789
MEDIUM 6.5
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadO… |
|
CVE-2024-40782
MEDIUM 6.5
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.… |
|
CVE-2024-2379
MEDIUM 6.3
Microsoft Security Update Guide entry — NVD enrichira. |
|
CVE-2024-24795
MEDIUM 6.3
Microsoft Security Update Guide entry — NVD enrichira. |
|
CVE-2024-40817
MEDIUM 6.1
The issue was addressed with improved UI handling. This issue is fixed in Safari 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. Visiting… |
|
CVE-2024-40785
MEDIUM 6.1
This issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, t… |
|
CVE-2024-27877
MEDIUM 6.1
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. Processing a mali… |
|
CVE-2024-40810
MEDIUM 5.5
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.6. An app may be able to cause a coprocessor … |
|
CVE-2024-44185
MEDIUM 5.5
The issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS… |
|
CVE-2024-44205
MEDIUM 5.5
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17… |
|
CVE-2024-40827
MEDIUM 5.5
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app may be able to over… |
|
CVE-2024-40833
MEDIUM 5.5
A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura … |
|
CVE-2024-40835
MEDIUM 5.5
A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS S… |
|
CVE-2024-40836
MEDIUM 5.5
A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, watchOS 10.… |
|
CVE-2024-40806
MEDIUM 5.5
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS … |
|
CVE-2024-40807
MEDIUM 5.5
A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A shortcut may be able… |
|
CVE-2024-40811
MEDIUM 5.5
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. An app may be able to modify protected parts of the file system. |
|
CVE-2024-40816
MEDIUM 5.5
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A lo… |
|
CVE-2024-40823
MEDIUM 5.5
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app may be able to acce… |
|
CVE-2024-40824
MEDIUM 5.5
This issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, watchOS 10.6. An app… |
|
CVE-2024-40788
MEDIUM 5.5
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monter… |
|
CVE-2024-40793
MEDIUM 5.5
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6,… |
|
CVE-2024-40800
MEDIUM 5.5
An input validation issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. … |
|
CVE-2024-40804
MEDIUM 5.5
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. A malicious application may be able to access private information. |
|
CVE-2024-40775
MEDIUM 5.5
A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.… |
|
CVE-2024-40777
MEDIUM 5.5
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visio… |
|
CVE-2024-40779
MEDIUM 5.5
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, … |
|
CVE-2024-40780
MEDIUM 5.5
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, … |
|
CVE-2024-40783
MEDIUM 5.5
The issue was addressed with improved restriction of data container access. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6… |
|
CVE-2024-40784
MEDIUM 5.5
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 1… |
|
CVE-2024-27863
MEDIUM 5.5
An information disclosure issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sono… |
|
CVE-2024-27871
MEDIUM 5.5
A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. An app may be able to access … |
|
CVE-2024-27872
MEDIUM 5.5
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sonoma 14.6. An app may be able to access protected user data. |
|
CVE-2024-27873
MEDIUM 5.5
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS… |
|
CVE-2024-40794
MEDIUM 5.3
This issue was addressed through improved state management. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. Private Browsing t… |
|
CVE-2024-40796
MEDIUM 5.3
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, macOS Monterey 12.7.6,… |
|
CVE-2024-27881
MEDIUM 5.3
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Vent… |
|
CVE-2023-27952
MEDIUM 4.7
A race condition was addressed with improved locking. This issue is fixed in macOS Ventura 13.3. An app may bypass Gatekeeper checks. |
|
CVE-2024-40818
MEDIUM 4.6
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macO… |
|
CVE-2024-40834
MEDIUM 4.4
This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8… |
|
CVE-2024-27882
MEDIUM 4.4
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app m… |
|
CVE-2024-27883
MEDIUM 4.4
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app m… |
|
CVE-2024-40776
MEDIUM 4.3
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.… |
|
CVE-2024-2004
LOW 3.5
Microsoft Security Update Guide entry — NVD enrichira. |
|
CVE-2024-40832
LOW 3.3
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. An app may be able to view a contact's phone number in system logs. |
|
CVE-2024-40795
LOW 3.3
This issue was addressed with improved data protection. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, watchOS 10.6. An app may… |
|
CVE-2024-40798
LOW 3.3
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, macOS Monterey 12.7.6, macOS So… |
|
CVE-2024-40778
LOW 3.3
An authentication issue was addressed with improved state management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sono… |
|
CVE-2024-40822
LOW 2.4
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macO… |
|
CVE-2024-27862
LOW 2.4
A logic issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.6. Enabling Lockdown Mode while setting up a Mac may cause F… |
Déployer cette mise à jour macOS sur votre flotte
Appaloosa déploie et contrôle les mises à jour macOS sur tout votre parc.