Aller au contenu
Appaloosa Scout

macOS

103 CVE corrigées par cette release.

Date de sortie
2024-09-16
Fin de support
CVE corrigées
103
KEV CISA
0
Critique
0
Élevé
2
En attente NVD
100

CVE corrigées

CVE Sévérité
CVE-2024-39894

Microsoft Security Update Guide entry — NVD enrichira.

HIGH 7.5
CVE-2023-4504

Microsoft Security Update Guide entry — NVD enrichira.

HIGH 7.0
CVE-2024-41957

Microsoft Security Update Guide entry — NVD enrichira.

MEDIUM 5.3
CVE-2024-44172

[Apple Contacts] An app may be able to access contacts

N/A
CVE-2024-40855

[Apple DiskArbitration] A sandboxed app may be able to access sensitive user data

N/A
CVE-2024-44122

[Apple LaunchServices] An application may be able to break out of its sandbox

N/A
CVE-2024-44126

[Apple ARKit] Processing a maliciously crafted file may lead to heap corruption

N/A
CVE-2024-44137

[Apple Screen Capture] An attacker with physical access may be able to share items from the lock screen

N/A
CVE-2024-44144

[Apple SceneKit] Processing a maliciously crafted file may lead to unexpected app termination

N/A
CVE-2024-44155

[Apple Safari] Maliciously crafted web content may violate iframe sandboxing policy

N/A
CVE-2024-44175

[Apple Kernel] An app may be able to access sensitive user data

N/A
CVE-2023-5841

[Apple Model I/O] Processing a maliciously crafted image may lead to a denial-of-service

N/A
CVE-2024-23237

[Apple Wi-Fi] An app may be able to cause a denial-of-service

N/A
CVE-2024-27795

[Apple AppSandbox] A camera extension may be able to access the internet

N/A
CVE-2024-27849

[Apple Core Data] An app may be able to read sensitive location information

N/A
CVE-2024-27858

[Apple Music] An app may be able to access protected user data

N/A
CVE-2024-27860

[Apple AppleVA] An application may be able to read restricted memory

N/A
CVE-2024-27861

[Apple AppleVA] An application may be able to read restricted memory

N/A
CVE-2024-27869

[Apple Control Center] An app may be able to record the screen without an indicator

N/A
CVE-2024-27875

[Apple Control Center] Privacy Indicators for microphone or camera access may be attributed incorrectly

N/A
CVE-2024-27876

[Apple Compression] Unpacking a maliciously crafted archive may allow an attacker to write arbitrary files

N/A
CVE-2024-27880

[Apple ImageIO] Processing a maliciously crafted file may lead to unexpected app termination

N/A
CVE-2024-40770

[Apple Wi-Fi] A non-privileged user may be able to modify restricted network settings

N/A
CVE-2024-40791

[Apple Mail Accounts] An app may be able to access information about a user's contacts

N/A
CVE-2024-40792

[Apple Airport] A malicious app may be able to change network settings

N/A
CVE-2024-40797

[Apple Safari] Visiting a malicious website may lead to user interface spoofing

N/A
CVE-2024-40801

[Apple Security Initialization] An app may be able to access protected user data

N/A
CVE-2024-40825

[Apple APFS] A malicious app with root privileges may be able to modify the contents of system files

N/A
CVE-2024-40826

[Apple Printing] An unencrypted document may be written to a temporary file when using print preview

N/A
CVE-2024-40831

[Apple Image Capture] An app may be able to access a user's Photos Library

N/A
CVE-2024-40837

[Apple AppleMobileFileIntegrity] An app may be able to access protected user data

N/A
CVE-2024-40838

[Apple Notification Center] A malicious app may be able to access notifications from the user's device

N/A
CVE-2024-40841

[Apple AppleVA] Processing a maliciously crafted video file may lead to unexpected app termination

N/A
CVE-2024-40842

[Apple XProtect] An app may be able to access user-sensitive data

N/A
CVE-2024-40843

[Apple XProtect] An app may be able to modify protected parts of the file system

N/A
CVE-2024-40844

[Apple Shortcuts] An app may be able to observe data displayed to the user by Shortcuts

N/A
CVE-2024-40845

[Apple AppleGraphicsControl] Processing a maliciously crafted video file may lead to unexpected app termination

N/A
CVE-2024-40846

[Apple AppleGraphicsControl] Processing a maliciously crafted video file may lead to unexpected app termination

N/A
CVE-2024-40847

[Apple AppleMobileFileIntegrity] An app may be able to access sensitive user data

N/A
CVE-2024-40848

[Apple AppleMobileFileIntegrity] An attacker may be able to read sensitive information

N/A
CVE-2024-40850

[Apple Game Center] An app may be able to access user-sensitive data

N/A
CVE-2024-40856

[Apple Wi-Fi] An attacker may be able to force a device to disconnect from a secure network

N/A
CVE-2024-40857

[Apple WebKit] Processing maliciously crafted web content may lead to universal cross site scripting

N/A
CVE-2024-40859

[Apple TV App] An app may be able to access user-sensitive data

N/A
CVE-2024-40860

[Apple sudo] An app may be able to modify protected parts of the file system

N/A
CVE-2024-40861

[Apple Installer] An app may be able to gain root privileges

N/A
CVE-2024-40866

[Apple WebKit] Visiting a malicious website may lead to address bar spoofing

N/A
CVE-2024-44123

[Apple Security] A malicious app with root privileges may be able to access keyboard input and location information wit…

N/A
CVE-2024-44125

[Apple Sandbox] A malicious application may be able to leak sensitive user information

N/A
CVE-2024-44128

[Apple Automator] An Automator Quick Action workflow may be able to bypass Gatekeeper

N/A
CVE-2024-44129

[Apple Accounts] An app may be able to leak sensitive user information

N/A
CVE-2024-44130

[Apple APNs] An app with root privileges may be able to access private information

N/A
CVE-2024-44131

[Apple FileProvider] An app may be able to access sensitive user data

N/A
CVE-2024-44132

[Apple ArchiveService] An app may be able to break out of its sandbox

N/A
CVE-2024-44133

[Apple TCC] On MDM managed devices, an app may be able to bypass certain Privacy preferences

N/A
CVE-2024-44134

[Apple Wi-Fi] An app may be able to read sensitive location information

N/A
CVE-2024-44135

[Apple AppSandbox] An app may be able to access protected files within an App Sandbox container

N/A
CVE-2024-44145

[Apple Sidecar] An attacker with physical access to a macOS device with Sidecar enabled may be able to bypass the Lock …

N/A
CVE-2024-44146

[Apple copyfile] An app may be able to break out of its sandbox

N/A
CVE-2024-44148

[Apple Disk Images] An app may be able to break out of its sandbox

N/A
CVE-2024-44149

[Apple Quick Look] An app may be able to access protected user data

N/A
CVE-2024-44151

[Apple bless] An app may be able to modify protected parts of the file system

N/A
CVE-2024-44152

[Apple System Settings] An app may be able to access user-sensitive data

N/A
CVE-2024-44153

[Apple Accounts] An app may be able to access user-sensitive data

N/A
CVE-2024-44154

[Apple AppleGraphicsControl] Processing a maliciously crafted file may lead to unexpected app termination

N/A
CVE-2024-44158

[Apple Shortcuts] A shortcut may output sensitive user data without consent

N/A
CVE-2024-44160

[Apple Intel Graphics Driver] Processing a maliciously crafted texture may lead to unexpected app termination

N/A
CVE-2024-44161

[Apple Intel Graphics Driver] Processing a maliciously crafted texture may lead to unexpected app termination

N/A
CVE-2024-44163

[Apple Sandbox] A malicious application may be able to access private information

N/A
CVE-2024-44164

[Apple AppleMobileFileIntegrity] An app may be able to bypass Privacy preferences

N/A
CVE-2024-44165

[Apple Kernel] Network traffic may leak outside a VPN tunnel

N/A
CVE-2024-44166

[Apple System Settings] An app may be able to access user-sensitive data

N/A
CVE-2024-44167

[Apple Notes] An app may be able to overwrite arbitrary files

N/A
CVE-2024-44168

[Apple AppleMobileFileIntegrity] An app may be able to modify protected parts of the file system

N/A
CVE-2024-44169

[Apple IOSurfaceAccelerator] An app may be able to cause unexpected system termination

N/A
CVE-2024-44170

[Apple Siri] An app may be able to access user-sensitive data

N/A
CVE-2024-44174

[Apple Screen Capture] An attacker may be able to view restricted content from the lock screen

N/A
CVE-2024-44176

[Apple ImageIO] Processing an image may lead to a denial-of-service

N/A
CVE-2024-44177

[Apple Dock] An app may be able to access user-sensitive data

N/A
CVE-2024-44178

[Apple PackageKit] An app may be able to modify protected parts of the file system

N/A
CVE-2024-44179

[Apple Siri] An attacker with physical access to a device may be able to read contact numbers from the lock screen

N/A
CVE-2024-44181

[Apple Maps] An app may be able to read sensitive location information

N/A
CVE-2024-44182

[Apple App Intents] An app may be able to access sensitive data logged when a shortcut fails to launch another app

N/A
CVE-2024-44183

[Apple mDNSResponder] An app may be able to cause a denial-of-service

N/A
CVE-2024-44184

[Apple Transparency] An app may be able to access user-sensitive data

N/A
CVE-2024-44186

[Apple NSColor] An app may be able to access protected user data

N/A
CVE-2024-44187

[Apple WebKit] A malicious website may exfiltrate data cross-origin

N/A
CVE-2024-44188

[Apple Accounts] An app may be able to access protected user data

N/A
CVE-2024-44189

[Apple WindowServer] A logic issue existed where a process may be able to capture screen contents without user consent

N/A
CVE-2024-44190

[Apple System Settings] An app may be able to read arbitrary files

N/A
CVE-2024-44191

[Apple Kernel] An app may gain unauthorized access to Bluetooth

N/A
CVE-2024-44192

[Apple WebKit] Processing maliciously crafted web content may lead to an unexpected process crash

N/A
CVE-2024-44198

[Apple libxml2] Processing maliciously crafted web content may lead to an unexpected process crash

N/A
CVE-2024-44203

[Apple Sandbox] An app may be able to access a user's Photos Library

N/A
CVE-2024-44208

[Apple WindowServer] An app may be able to bypass certain Privacy preferences

N/A
CVE-2024-44227

[Apple Wi-Fi] An app may be able to cause unexpected system termination or corrupt kernel memory

N/A
CVE-2024-54463

[Apple Image Capture] An app may be able to access removable volumes without user consent

N/A
CVE-2024-54467

[Apple WebKit] A malicious website may exfiltrate data cross-origin

N/A
CVE-2024-54469

[Apple FileProvider] A local user may be able to leak sensitive user information

N/A
CVE-2024-54473

[Apple Maps] An app may be able to access user-sensitive data

N/A
CVE-2024-54546

[Apple Wi-Fi] An app may be able to cause unexpected system termination or corrupt kernel memory

N/A
CVE-2024-54558

[Apple TCC] An app may be able to trick a user into granting access to photos from the user's photo library

N/A
CVE-2024-54560

[Apple LaunchServices] A malicious app may be able to modify other apps without having App Management permission

N/A