Aller au contenu
Appaloosa Scout

macOS

macOS 13.6.8

Advisory officiel

46 CVE corrigées par cette release.

Date de sortie
2024-07-29
Fin de support
2025-09-15 EOL
CVE corrigées
46
KEV CISA
0
Critique
1
Élevé
2
En attente NVD
39

CVE corrigées

CVE Sévérité
CVE-2024-2398

Microsoft Security Update Guide entry — NVD enrichira.

HIGH 8.6
CVE-2024-6387

RedHat Openssh: CVE-2024-6387 Remote Code Execution Due To A Race Condition In Signal Handling

CRITICAL 8.1
CVE-2023-52356

[Apple ImageIO] Processing an image may lead to a denial-of-service

HIGH 7.5
CVE-2023-6277

Microsoft Security Update Guide entry — NVD enrichira.

MEDIUM 6.5
CVE-2024-2466

Microsoft Security Update Guide entry — NVD enrichira.

MEDIUM 6.5
CVE-2024-2379

Microsoft Security Update Guide entry — NVD enrichira.

MEDIUM 6.3
CVE-2024-2004

Microsoft Security Update Guide entry — NVD enrichira.

LOW 3.5
CVE-2024-23261

[Apple Time Zone] An attacker may be able to read information belonging to another user

N/A
CVE-2024-27826

[Apple Apple Neural Engine] A local attacker may be able to cause unexpected system shutdown

N/A
CVE-2024-27873

[Apple CoreMedia] Processing a maliciously crafted video file may lead to unexpected app termination

N/A
CVE-2024-27877

[Apple AppleVA] Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory co…

N/A
CVE-2024-27881

[Apple Scripting Bridge] An app may be able to access information about a user’s contacts

N/A
CVE-2024-27882

[Apple PackageKit] An app may be able to modify protected parts of the file system

N/A
CVE-2024-27883

[Apple PackageKit] An app may be able to modify protected parts of the file system

N/A
CVE-2024-40774

[Apple AppleMobileFileIntegrity] An app may be able to bypass Privacy preferences

N/A
CVE-2024-40775

[Apple AppleMobileFileIntegrity] An app may be able to leak sensitive user information

N/A
CVE-2024-40781

[Apple PackageKit] A local attacker may be able to elevate their privileges

N/A
CVE-2024-40783

[Apple APFS] A malicious application may be able to bypass Privacy preferences

N/A
CVE-2024-40784

[Apple ImageIO] Processing a maliciously crafted file may lead to unexpected app termination

N/A
CVE-2024-40786

[Apple Siri] An attacker may be able to view sensitive user information

N/A
CVE-2024-40787

[Apple Shortcuts] A shortcut may be able to bypass Internet permission requirements

N/A
CVE-2024-40788

[Apple Kernel] A local attacker may be able to cause unexpected system shutdown

N/A
CVE-2024-40793

[Apple Shortcuts] An app may be able to access user-sensitive data

N/A
CVE-2024-40796

[Apple NetworkExtension] Private browsing may leak some browsing history

N/A
CVE-2024-40798

[Apple Security] An app may be able to read Safari's browsing history

N/A
CVE-2024-40799

[Apple CoreGraphics] Processing a maliciously crafted file may lead to unexpected app termination

N/A
CVE-2024-40800

[Apple Restore Framework] An app may be able to modify protected parts of the file system

N/A
CVE-2024-40802

[Apple PackageKit] A local attacker may be able to elevate their privileges

N/A
CVE-2024-40803

[Apple Keychain Access] An attacker may be able to cause unexpected app termination

N/A
CVE-2024-40806

[Apple ImageIO] Processing a maliciously crafted file may lead to unexpected app termination

N/A
CVE-2024-40807

[Apple Shortcuts] A shortcut may be able to use sensitive data with certain actions without prompting the user

N/A
CVE-2024-40809

[Apple Shortcuts] A shortcut may be able to bypass Internet permission requirements

N/A
CVE-2024-40812

[Apple Shortcuts] A shortcut may be able to bypass Internet permission requirements

N/A
CVE-2024-40815

[Apple dyld] A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication

N/A
CVE-2024-40816

[Apple Kernel] A local attacker may be able to cause unexpected system shutdown

N/A
CVE-2024-40817

[Apple Safari] Visiting a website that frames malicious content may lead to UI spoofing

N/A
CVE-2024-40818

[Apple Siri] An attacker with physical access may be able to use Siri to access sensitive user data

N/A
CVE-2024-40821

[Apple Security] Third party app extensions may not receive the correct sandbox restrictions

N/A
CVE-2024-40823

[Apple PackageKit] An app may be able to access user-sensitive data

N/A
CVE-2024-40827

[Apple DesktopServices] An app may be able to overwrite arbitrary files

N/A
CVE-2024-40828

[Apple Disk Management] A malicious app may be able to gain root privileges

N/A
CVE-2024-40829

[Apple VoiceOver] A user may be able to view restricted content from the lock screen

N/A
CVE-2024-40833

[Apple Shortcuts] A shortcut may be able to use sensitive data with certain actions without prompting the user

N/A
CVE-2024-40834

[Apple Shortcuts] A shortcut may be able to bypass sensitive Shortcuts app settings

N/A
CVE-2024-40835

[Apple Shortcuts] A shortcut may be able to use sensitive data with certain actions without prompting the user

N/A
CVE-2024-44205

[Apple Siri] A sandboxed app may be able to access sensitive user data in system logs

N/A