macOS
macOS 13.7.2
Advisory officiel33 CVE corrigées par cette release.
- Date de sortie
- 2024-12-11
- Fin de support
- 2025-09-15 EOL
- CVE corrigées
- 33
- KEV CISA
- 0
- Critique
- 0
- Élevé
- 1
- En attente NVD
- 32
CVE corrigées
| CVE | Sévérité | KEV | Publié | Description |
|---|---|---|---|---|
|
CVE-2024-45490
Microsoft Security Update Guide entry — NVD enrichira. |
HIGH 9.8 | — | Microsoft Security Update Guide entry — NVD enrichira. | |
|
CVE-2024-44201
[Apple libarchive] Processing a malicious crafted file may lead to a denial-of-service |
N/A | — | [Apple libarchive] Processing a malicious crafted file may lead to a denial-of-service | |
|
CVE-2024-44224
[Apple StorageKit] A malicious app may be able to gain root privileges |
N/A | — | [Apple StorageKit] A malicious app may be able to gain root privileges | |
|
CVE-2024-44225
[Apple libxpc] An app may be able to gain elevated privileges |
N/A | — | [Apple libxpc] An app may be able to gain elevated privileges | |
|
CVE-2024-44248
[Apple Screen Sharing Server] A user with screen sharing access may be able to view another user's screen |
N/A | — | [Apple Screen Sharing Server] A user with screen sharing access may be able to view another user's screen | |
|
CVE-2024-44291
[Apple Software Update] A malicious app may be able to gain root privileges |
N/A | — | [Apple Software Update] A malicious app may be able to gain root privileges | |
|
CVE-2024-44300
[Apple Crash Reporter] An app may be able to access protected user data |
N/A | — | [Apple Crash Reporter] An app may be able to access protected user data | |
|
CVE-2024-45306
[Apple Vim] Processing a maliciously crafted file may lead to heap corruption |
N/A | — | [Apple Vim] Processing a maliciously crafted file may lead to heap corruption | |
|
CVE-2024-54466
[Apple DiskArbitration] An encrypted volume may be accessed by a different user without prompting for the password |
N/A | — | [Apple DiskArbitration] An encrypted volume may be accessed by a different user without prompting for the password | |
|
CVE-2024-54468
[Apple Kernel] An app may be able to break out of its sandbox |
N/A | — | [Apple Kernel] An app may be able to break out of its sandbox | |
|
CVE-2024-54474
[Apple PackageKit] An app may be able to access user-sensitive data |
N/A | — | [Apple PackageKit] An app may be able to access user-sensitive data | |
|
CVE-2024-54475
[Apple System Settings] An app may be able to determine a user’s current location |
N/A | — | [Apple System Settings] An app may be able to determine a user’s current location | |
|
CVE-2024-54476
[Apple PackageKit] An app may be able to access user-sensitive data |
N/A | — | [Apple PackageKit] An app may be able to access user-sensitive data | |
|
CVE-2024-54477
[Apple Apple Software Restore] An app may be able to access user-sensitive data |
N/A | — | [Apple Apple Software Restore] An app may be able to access user-sensitive data | |
|
CVE-2024-54486
[Apple FontParser] Processing a maliciously crafted font may result in the disclosure of process memory |
N/A | — | [Apple FontParser] Processing a maliciously crafted font may result in the disclosure of process memory | |
|
CVE-2024-54488
[Apple Accounts] Photos in the Hidden Photos Album may be viewed without authentication |
N/A | — | [Apple Accounts] Photos in the Hidden Photos Album may be viewed without authentication | |
|
CVE-2024-54489
[Apple Disk Utility] Running a mount command may unexpectedly execute arbitrary code |
N/A | — | [Apple Disk Utility] Running a mount command may unexpectedly execute arbitrary code | |
|
CVE-2024-54494
[Apple Kernel] An attacker may be able to create a read-only memory mapping that can be written to |
N/A | — | [Apple Kernel] An attacker may be able to create a read-only memory mapping that can be written to | |
|
CVE-2024-54498
[Apple SharedFileList] An app may be able to break out of its sandbox |
N/A | — | [Apple SharedFileList] An app may be able to break out of its sandbox | |
|
CVE-2024-54500
[Apple ImageIO] Processing a maliciously crafted image may result in disclosure of process memory |
N/A | — | [Apple ImageIO] Processing a maliciously crafted image may result in disclosure of process memory | |
|
CVE-2024-54501
[Apple SceneKit] Processing a maliciously crafted file may lead to a denial of service |
N/A | — | [Apple SceneKit] Processing a maliciously crafted file may lead to a denial of service | |
|
CVE-2024-54510
[Apple Kernel] An app may be able to leak sensitive kernel state |
N/A | — | [Apple Kernel] An app may be able to leak sensitive kernel state | |
|
CVE-2024-54514
[Apple libxpc] An app may be able to break out of its sandbox |
N/A | — | [Apple libxpc] An app may be able to break out of its sandbox | |
|
CVE-2024-54520
[Apple System Settings] An app may be able to overwrite arbitrary files |
N/A | — | [Apple System Settings] An app may be able to overwrite arbitrary files | |
|
CVE-2024-54526
[Apple AppleMobileFileIntegrity] A malicious app may be able to access private information |
N/A | — | [Apple AppleMobileFileIntegrity] A malicious app may be able to access private information | |
|
CVE-2024-54527
[Apple AppleMobileFileIntegrity] An app may be able to access sensitive user data |
N/A | — | [Apple AppleMobileFileIntegrity] An app may be able to access sensitive user data | |
|
CVE-2024-54528
[Apple SharedFileList] An app may be able to overwrite arbitrary files |
N/A | — | [Apple SharedFileList] An app may be able to overwrite arbitrary files | |
|
CVE-2024-54529
[Apple Audio] An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges |
N/A | — | [Apple Audio] An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges | |
|
CVE-2024-54537
[Apple QuickTime Player] An app may be able to read and write files outside of its sandbox |
N/A | — | [Apple QuickTime Player] An app may be able to read and write files outside of its sandbox | |
|
CVE-2024-54539
[Apple WindowServer] An app may be able to capture keyboard events from the lock screen |
N/A | — | [Apple WindowServer] An app may be able to capture keyboard events from the lock screen | |
|
CVE-2024-54541
[Apple APFS] An app may be able to access user-sensitive data |
N/A | — | [Apple APFS] An app may be able to access user-sensitive data | |
|
CVE-2024-54547
[Apple Dock] An app may be able to access protected user data |
N/A | — | [Apple Dock] An app may be able to access protected user data | |
|
CVE-2024-54557
[Apple SharedFileList] An attacker may gain access to protected parts of the file system |
N/A | — | [Apple SharedFileList] An attacker may gain access to protected parts of the file system |