CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Feb 28, 2022

Logo Showcase with Slick Slider WordPress Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Logo Showcase with Slick Slider WordPress plugin, affecting versions prior to 2.0.1. The vulnerability arises because the plugin's AJAX action 'lswss_save_attachment_data' lacks proper CSRF protection. This flaw allows attackers to manipulate a logged-in user with high privileges into changing the title, description, alt text, and URL of any uploaded media.

4.2
Feb 28, 2022

Logo Showcase with Slick Slider WordPress Plugin Cross-Site Request Forgery Vulnerability in AJAX Action

A vulnerability exists in the Logo Showcase with Slick Slider WordPress plugin in versions prior to 1.2.5. The issue arises because the plugin's lswss_save_attachment_data AJAX action lacks Cross-Site Request Forgery (CSRF) protection and proper authorization checks. This flaw enables any authenticated user, including Subscribers, to modify the title, description, alt text, and URL of any uploaded media.

2.9
Feb 19, 2022

TYPO3 Varnishcache Extension Insecure Direct Object Reference Vulnerability

A vulnerability allowing insecure direct object reference (IDOR) has been identified in the Varnishcache extension for TYPO3, prior to version 2.0.1. The issue arises in the Edge Site Includes (ESI) content element renderer component, which lacks an access check. This flaw enables unauthenticated users to render various content elements, potentially exposing internal content.

4.6
Feb 17, 2022

Next.js User Interface Misrepresentation Vulnerability in Image Optimization API

A vulnerability allowing user interface misrepresentation of critical information has been identified in Next.js, a React framework. This issue affects versions 10.0.0 prior to 12.1.0. The vulnerability arises when the 'next.config.js' file includes an 'images.domains' array with a host that permits user-uploaded SVGs. If the 'images.loader' is set to anything other than the default, the vulnerability does not apply. Exploitation of this vulnerability could lead to improper handling of content security policies in the image optimization API, potentially allowing malicious SVGs to be processed.

4.7
Feb 11, 2022

Apache APISIX Batch-Requests Plugin Authentication Bypass Leading to Remote Code Execution Vulnerability

An authentication bypass vulnerability has been identified in the batch-requests plugin of Apache APISIX, allowing attackers to bypass IP restrictions on the Admin API. This vulnerability is present in versions 1.3 through 2.12.1. In a default configuration with the default API key, this flaw can be exploited to achieve remote code execution. Although changing the admin key or the Admin API port can reduce the impact, there remains a risk of bypassing IP restrictions on the data panel. The vulnerability arises because the batch-requests plugin is supposed to override the client IP with the real remote IP, but a bug allows this check to be bypassed.

4.9
Feb 9, 2022

Gin-Vue-Admin Authentication Bypass Vulnerability Allowing Unauthorized User Privilege Escalation

An authentication bypass vulnerability has been identified in Gin-Vue-Admin, a management system built with Vue and Gin. This vulnerability exists in versions prior to 2.4.7, where low-privilege users can modify the information of higher-privilege users. The issue arises because the 'setUserInfo' function lacks proper authentication, allowing unauthorized changes to user data. Exploitation involves using a low-privilege account to alter usernames, nicknames, and even passwords of administrators.

4.3
Feb 1, 2022

h2o HTTP Server Uninitialized Memory Access Vulnerability in QUIC Frame Handling

A vulnerability exists in the h2o HTTP server's QUIC frame handling in the HTTP/3 server-side implementation, specifically in the code between commits 93af138 and d1f0f65. This vulnerability allows for uninitialized memory to be accessed and potentially misinterpreted as received HTTP/3 frames. When h2o is used as a reverse proxy, an attacker could exploit this to send internal state information from h2o to backend servers under their control or to third-party servers. Additionally, if there is an HTTP endpoint that reflects client traffic, this vulnerability could be used to extract unencrypted internal state data from h2o, including TLS session tickets and traffic from other connections. It is important to note that none of the released versions of h2o are affected by this vulnerability, and there are no known workarounds. Users of unreleased versions of h2o with HTTP/3 support should upgrade immediately.

6.4
Jan 28, 2022

Products.ATContentTypes Reflected Cross-Site Scripting and Open Redirect Vulnerability

A reflected cross-site scripting and open redirect vulnerability has been identified in Products.ATContentTypes versions prior to 3.0.6, which are used in Plone versions 2.1 to 4.3. The vulnerability arises when an attacker manages to cache a compromised version of the 'image_view_fullscreen' page, for example, using Varnish. This cache poisoning can lead to redirection of subsequent visitors who click on links on the affected page. While this issue typically impacts only anonymous users, it can vary based on individual cache settings.

3.9
Jan 28, 2022

Next.js Denial-of-Service Vulnerability in i18n Functionality

A denial-of-service vulnerability has been identified in Next.js, a React framework, affecting versions 12.0.0 prior to 12.0.9. The issue arises for users employing the built-in internationalization (i18n) support, and who are running their applications with 'next start' or a custom server. In these cases, a malicious actor could exploit the vulnerability by sending requests that trigger a heap overflow error, causing the application to crash. Notably, deployments on Vercel or similar environments that filter invalid requests before they reach Next.js are not affected.

5.1
Jan 26, 2022

Varnish Cache and Varnish Enterprise Request Smuggling Vulnerability on HTTP/1 Connections

A request smuggling vulnerability has been identified in Varnish Cache versions prior to 6.6.2 and 7.x prior to 7.0.2, as well as in Varnish Cache 6.0 LTS versions prior to 6.0.10. Additionally, Varnish Enterprise (Cache Plus) versions 4.1.x prior to 4.1.11r6 and 6.0.x prior to 6.0.9r4 are affected. This vulnerability allows smuggled requests to be processed as normal requests by the Varnish server, potentially leading to information disclosure and cache poisoning.

4.4
Jan 24, 2022

PHP CRUD Ajax DataTables Tutorial Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in the PHP CRUD tutorial by oretnom23, specifically in the version that utilizes Ajax and DataTables. This vulnerability allows remote attackers to execute arbitrary code by injecting malicious scripts into the first_name, last_name, and email parameters of the /ajax_crud endpoint. The absence of proper input sanitization enables the execution of these scripts, potentially leading to stored XSS attacks.

2.3
Jan 24, 2022

Image Hover Effects Ultimate WordPress Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Image Hover Effects Ultimate WordPress plugin, affecting versions prior to 9.7.1. The issue arises because the plugin fails to properly escape the effects parameter before displaying it in an attribute on an admin page.

4.7
Jan 4, 2022

CodeIgniter 4 Deserialization Vulnerability in the 'old()' Function Allowing Object Injection and Potential SQL Injection

A deserialization vulnerability has been identified in CodeIgniter 4 versions prior to 4.1.6, specifically within the 'old()' function. This issue allows remote attackers to inject auto-loadable arbitrary objects, which could lead to the execution of existing PHP code on the server. There is a known exploit for this vulnerability that can result in SQL injection.

3.5
Jan 3, 2022

CAOS WordPress Plugin Path Traversal Vulnerability Allowing Arbitrary Folder Deletion

A vulnerability in the CAOS | Host Google Analytics Locally WordPress plugin, affecting versions prior to 4.1.9, allows high privilege users to exploit a path traversal issue. The plugin fails to properly validate the cache directory setting, enabling users to delete arbitrary folders by directing the plugin to a traversed path during uninstallation.

2.8
Jan 3, 2022

WP Travel Engine Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WP Travel Engine WordPress plugin, affecting versions prior to 5.3.1. The issue arises because the plugin does not properly escape the Description field in Trip Destination, Activities, Trip Type, and Pricing Category pages. This flaw allows users with editor roles to inject malicious scripts, even when the unfiltered_html capability is restricted.

4.2
Dec 16, 2021

Auth0 Next.js SDK Open Redirect Vulnerability

An open redirect vulnerability has been identified in the Auth0 Next.js SDK, specifically in versions through 1.6.1. The issue arises because the SDK does not properly validate certain returnTo parameter values in the login URL, allowing for potential redirection to malicious sites. This vulnerability could be exploited by manipulating the returnTo parameter to redirect users to an external URL, potentially leading to phishing attacks or other malicious activities.

5.6
Dec 15, 2021

Microsoft Windows App Installer Spoofing Vulnerability Allowing Malware Distribution

A spoofing vulnerability has been identified in the AppX installer for Microsoft Windows. This vulnerability allows attackers to craft malicious packages that can bypass standard security measures and deliver malware, including families like Emotet, TrickBot, and BazarLoader. The vulnerability is particularly concerning because it can be exploited through social engineering tactics, convincing users to open harmful attachments. While users with lower privileges may face reduced risk, those with administrative rights are more vulnerable.

3.6
Dec 14, 2021

Apache Log4j Remote Code Execution and Denial-of-Service Vulnerability via Thread Context Map Patterns

A vulnerability in Apache Log4j 2.15.0 has been identified, where the fix for a previous remote code execution vulnerability (CVE-2021-44228) was incomplete in certain non-default configurations. This new vulnerability allows attackers to exploit Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup or a Thread Context Map pattern. Exploitation can lead to an information leak and remote code execution in some environments, while all environments are susceptible to local code execution. Log4j versions 2.16.0 (Java 8) and 2.12.2 (Java 7) address this vulnerability by removing support for message lookup patterns and disabling JNDI functionality by default.

6.4
Dec 10, 2021

Apache Log4j2 Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Apache Log4j2 versions 2.0-beta9 through 2.15.0, excluding security releases 2.12.2, 2.12.3, and 2.3.1. The vulnerability arises because JNDI features used in configuration, log messages, and parameters do not adequately protect against attacker-controlled LDAP and other JNDI-related endpoints. An attacker who can manipulate log messages or their parameters can execute arbitrary code loaded from LDAP servers, provided that message lookup substitution is enabled. This issue is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

6.4
Dec 10, 2021

Next.js Denial-of-Service Vulnerability via Invalid URL Processing

A denial-of-service vulnerability has been identified in Next.js, a React framework, affecting versions prior to 12.0.5 and 11.1.3. When deployments using Node.js versions above 15.0.0 receive invalid or malformed URLs, it can lead to a server crash. This issue arises because the server fails to properly handle the invalid URLs, causing an unhandled promise rejection that terminates the server process. The vulnerability is not present in environments like Vercel, where such invalid requests are filtered out before reaching the Next.js application.

5.9
Dec 8, 2021

Ivanti Endpoint Manager Cloud Service Appliance Code Injection Vulnerability Leading to Remote Code Execution

A code injection vulnerability has been identified in Ivanti Endpoint Manager Cloud Service Appliance (CSA) versions 4.5 and 4.6. This vulnerability allows an unauthenticated user to execute arbitrary code with limited permissions, specifically as the 'nobody' user. The issue arises from a cookie-based command injection that can be exploited by manipulating cookie values in HTTP requests.

5.4
Dec 8, 2021

Mozilla Firefox, Thunderbird, and Firefox ESR Use-After-Free Vulnerability in HTTP/2 Session Object

A use-after-free vulnerability has been identified in Mozilla Firefox, Thunderbird, and Firefox ESR. This issue arises when an HTTP/2 session object is released on a different thread, leading to memory corruption and a potentially exploitable crash. The vulnerability affects Firefox versions prior to 93, Thunderbird versions prior to 91.3, and Firefox ESR versions prior to 91.3.

5.8
Dec 8, 2021

Mozilla Firefox and Thunderbird Same-Origin Policy Bypass Vulnerability via HTTP/2 Opportunistic Encryption

A vulnerability exists in Mozilla Firefox and Thunderbird that allows a network attacker to bypass the Same-Origin Policy on services hosted on encrypted ports that did not opt-in to HTTP/2 Opportunistic Encryption. This issue affects Firefox versions prior to 94, Thunderbird versions prior to 91.3, and Firefox ESR versions prior to 91.3. The vulnerability arises because the browser can be coaxed into treating content from a non-opted-in encrypted port as same-origin with unencrypted HTTP, potentially leading to unauthorized access to sensitive information or resources.

5.9
Dec 8, 2021

SonicWall SMA 100 Series Stack-Based Buffer Overflow Vulnerability in Apache httpd mod_cgi Module Allowing Unauthenticated Remote Code Execution

A stack-based buffer overflow vulnerability has been identified in the SonicWall SMA 100 series appliances, specifically in the Apache httpd server's mod_cgi module. This vulnerability allows a remote, unauthenticated attacker to execute code as the 'nobody' user on the affected appliance. The issue arises from the mod_cgi module improperly handling environment variables, leading to a buffer overflow on the stack. The vulnerability affects several firmware versions across the SMA 100 series, including SMA 200, 210, 400, 410, and 500v.

6.8
Dec 6, 2021

Wiki.js Directory Traversal Vulnerability on Windows

A directory traversal vulnerability allowing access to files outside of the Wiki.js context has been identified in Wiki.js versions prior to 2.5.254. This issue occurs on Windows hosts when a storage module with local asset cache fetching, such as Local File System or Git, is enabled. The vulnerability can be exploited by crafting a special URL that takes advantage of directory traversal, potentially allowing a malicious user to read any file on the file system. This exploitation is possible only if no web application firewall, like Cloudflare, intercepts and strips harmful URLs.

4.2
Nov 23, 2021

Logo Showcase with Slick Slider WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Logo Showcase with Slick Slider WordPress plugin, affecting versions prior to 1.2.4. The issue arises because the plugin fails to properly sanitize the Grid Settings, allowing users with at least Author role to inject malicious scripts via post metadata. This vulnerability could be exploited to execute harmful scripts when the affected content is viewed.

3.0
Nov 5, 2021

Sitecore Experience Platform (XP) Insecure Deserialization Vulnerability Leading to Remote Code Execution

A remote code execution vulnerability has been identified in Sitecore Experience Platform (XP) versions 7.5 Initial Release to 8.2 Update-7. This vulnerability arises from an insecure deserialization issue in the Report.ashx file, which was used for the Executive Insight Dashboard, a feature that has been deprecated. The vulnerability allows unauthorized users to execute arbitrary code on the server where Sitecore is running.

7.0
Nov 3, 2021

Grafana Cross-Site Scripting Vulnerability Allowing Arbitrary JavaScript Execution

A cross-site scripting (XSS) vulnerability has been identified in Grafana, an open-source monitoring and observability platform. This issue affects Grafana versions 8.0.0-beta1 prior to 8.2.3. The vulnerability allows an attacker to execute arbitrary JavaScript in the context of the victim's browser. Exploitation requires convincing the victim to visit a crafted URL that references a vulnerable page, specifically one that includes the login button in the menu bar. The URL must be designed to exploit AngularJS rendering by incorporating interpolation bindings for AngularJS expressions, which are denoted by double curly braces. When the malicious link is followed, the AngularJS rendering engine executes the embedded JavaScript, potentially leading to unauthorized actions or data exposure.

5.8
Nov 3, 2021

Mozilla Firefox and Thunderbird Header Splitting Vulnerability in HTTP/3

A header splitting vulnerability has been identified in Mozilla Firefox and Thunderbird. The issue arises because the applications incorrectly processed newlines in HTTP/3 headers, splitting them into two separate headers. This flaw, present in Firefox and Thunderbird versions prior to 91.0.1, allows for header splitting attacks on servers using HTTP/3.

5.8
Oct 26, 2021

jQuery UI Cross-Site Scripting Vulnerability in the 'of' Option of the .position() Utility

A cross-site scripting (XSS) vulnerability has been identified in jQuery UI versions prior to 1.13.0. This issue arises in the 'of' option of the '.position()' utility, where untrusted input can be accepted and executed as code. The vulnerability is present in an embedded version of jQuery UI within OTRS 7.10.6-rev61 and 8.22, as well as in various NetApp products. The issue has been fixed in jQuery UI 1.13.0, and the relevant components have been updated in OTRS and Tenable.sc.

5.9
Oct 26, 2021

jQuery UI Datepicker Vulnerability in jQuery UI Versions Prior to 1.13.0 Allows Cross-Site Scripting

A cross-site scripting (XSS) vulnerability has been identified in the jQuery UI Datepicker widget, affecting jQuery UI versions prior to 1.13.0. The vulnerability arises from accepting values for various '*Text' options from untrusted sources, which could execute malicious code. This issue has been addressed in jQuery UI 1.13.0, where such values are now treated as plain text rather than HTML. The vulnerability is present in several applications and frameworks that bundle jQuery UI, including Drupal 7, OTRS 6, and NetApp products.

5.8
Oct 26, 2021

jQuery UI Datepicker Vulnerability in altField Option Allowing Cross-Site Scripting

A cross-site scripting vulnerability has been identified in the Datepicker widget of jQuery UI, versions prior to 1.13.0. This issue arises from the altField option, which can execute untrusted code if the value is sourced from untrusted inputs. The vulnerability is present in various applications and products that bundle jQuery UI, including Drupal 7, OTRS 6, and several NetApp products. The issue has been acknowledged in the jQuery UI blog and is part of a larger set of vulnerabilities addressed in the 1.13.0 release.

5.9
Oct 19, 2021

Juniper Networks CTPView HTTP Strict Transport Security Not Enforced Vulnerability

A vulnerability exists in Juniper Networks CTPView server versions 7.3 prior to 7.3R7 and 9.1 prior to 9.1R3, due to the server not enforcing HTTP Strict Transport Security (HSTS). This lack of HSTS can leave the system open to downgrade attacks, SSL-stripping man-in-the-middle attacks, and reduces protections against cookie hijacking.

1.2
Oct 19, 2021

Apple Multiple Products IOMobileFrameBuffer Memory Corruption Vulnerability Allowing Arbitrary Code Execution with Kernel Privileges

A memory corruption vulnerability has been identified in the IOMobileFrameBuffer component of multiple Apple operating systems, including macOS Big Sur, iOS, iPadOS, and watchOS. This vulnerability may allow an application to execute arbitrary code with kernel privileges. Apple is aware of reports suggesting that this issue may have been actively exploited.

6.1
Oct 8, 2021

Google Chrome and Chromium Portals Use-After-Free Vulnerability Allowing Sandbox Escape

A use-after-free vulnerability has been identified in the Portals feature of Google Chrome and Chromium, prior to version 94.0.4606.61. This vulnerability allows a remote attacker who has compromised the renderer process to potentially escape the sandbox by using a crafted HTML page. The issue arises because the renderer can manipulate frame-bound Mojo interfaces, bypassing normal security restrictions.

6.3
Oct 7, 2021

Apache HTTP Server Path Traversal and Remote Code Execution Vulnerability

A path traversal vulnerability allowing remote code execution has been identified in Apache HTTP Server versions 2.4.49 and 2.4.50. The issue arises from an insufficient fix for a previous vulnerability (CVE-2021-41773), which allowed attackers to map URLs to files outside the designated directories. If these files are not protected by the default 'require all denied' configuration, the requests can succeed. The vulnerability is particularly concerning when CGI scripts are enabled for the affected paths, as it could lead to arbitrary code execution.

8.7
Oct 5, 2021

Apache HTTP Server Path Traversal and Remote Code Execution Vulnerability

A path traversal vulnerability allowing remote code execution has been identified in Apache HTTP Server versions 2.4.49 and 2.4.50. The vulnerability arises from an improper handling of path normalization, which allows attackers to map URLs to files outside the designated document root. If these files are not secured by the default 'require all denied' directive, the requests may succeed. Additionally, if CGI scripts are enabled for the affected paths, this could lead to arbitrary code execution.

8.7
Oct 4, 2021

Akamai EAA Client Unquoted Path Vulnerability Allowing Privilege Escalation

A vulnerability exists in the Akamai Enterprise Application Access (EAA) Client for Windows, specifically in versions prior to 2.3.1, 2.4.x prior to 2.4.1, and 2.5.x prior to 2.5.3. The issue arises from an unquoted service path that can be exploited to hijack the execution flow. This unquoted path vulnerability, a type of path interception, takes advantage of how Windows processes paths with spaces when launching applications or services. If not properly quoted, the operating system may misinterpret the path, leading to the execution of unintended applications. In the case of the EAA Client, this could allow a malicious actor to place a harmful executable that would be run with administrative privileges, potentially escalating privileges on the system.

2.1
Sep 27, 2021

DataTables HTML Escape Function Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability exists in the DataTables library versions prior to 1.11.3. The issue arises because the HTML escape entities function does not properly escape the contents of an array if one is passed, leading to potential injection of malicious scripts.

5.3
Sep 16, 2021

Apache HTTP Server mod_proxy Server-Side Request Forgery Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in the Apache HTTP Server's mod_proxy component. This vulnerability allows an attacker to craft a request that is forwarded to an arbitrary origin server of their choice. The issue affects Apache HTTP Server versions 2.4.48 and earlier.

7.9
Sep 15, 2021

Vuelidate Inefficient Regular Expression Complexity Vulnerability Allowing ReDoS

A denial-of-service vulnerability has been identified in the Vuelidate library, specifically within the URL validation function of the @vuelidate/validators package. This vulnerability arises from inefficient regular expression processing, which can be exploited by providing crafted input that causes excessive CPU consumption. The issue has been fixed in version 2.0.4 of the @vuelidate/validators package.

4.9
Sep 14, 2021

Siemens SIPROTEC 5 Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in Siemens SIPROTEC 5 relays with CPU variants CP050, CP100, and CP300, all running versions prior to V8.80. The issue arises because received webpackets are not properly processed, allowing an unauthenticated remote attacker with access to any Ethernet interface to send specially crafted packets that force the target device to restart.

4.5
Sep 9, 2021

Cloudflare OctoRPKI RPKI Validation Bypass Vulnerability Leading to BGP Hijacking

A vulnerability in Cloudflare's OctoRPKI RPKI validator, prior to version 1.3.0, allows any CA issuer in the RPKI to manipulate the validator into accepting an invalid VRP 'MaxLength' value. This manipulation causes RTR sessions to terminate, disrupting RPKI Origin Validation. As a result, networks relying on this validation, such as AS 13335 (Cloudflare), could inadvertently accept BGP routes that would normally be rejected due to RPKI invalidity. Furthermore, the resulting flapping of RTR sessions could create additional BGP routing instability, leading to availability issues.

1.2
Sep 8, 2021

Apple macOS TCC Privacy Preference Bypass Vulnerability

A permissions vulnerability in the Transparency, Consent, and Control (TCC) framework of Apple macOS has been identified, allowing a malicious application to bypass privacy preferences. This issue is present in macOS Big Sur 11.4 and was actively exploited, according to Apple.

6.4
Sep 8, 2021

Apple iOS WebKit Buffer Overflow Vulnerability Allowing Arbitrary Code Execution

A buffer overflow vulnerability has been identified in the WebKit component of Apple iOS, specifically in versions 12.5.3 and prior. This vulnerability arises from improper memory handling, which can be exploited by processing maliciously crafted web content, leading to arbitrary code execution. There are reports suggesting that this issue may have been actively exploited.

3.6
Sep 8, 2021

Apple WebKit Memory Corruption Vulnerability Allowing Arbitrary Code Execution

A memory corruption vulnerability has been identified in the WebKit component of multiple Apple operating systems, including iOS, iPadOS, macOS, watchOS, and tvOS. This vulnerability arises from improper state management, which can be exploited by processing maliciously crafted web content, leading to arbitrary code execution. Notably, there are reports suggesting that this vulnerability may have been actively exploited in the wild.

6.3
Sep 8, 2021

Apple WebKit Integer Overflow Vulnerability Allowing Arbitrary Code Execution

An integer overflow vulnerability has been identified in the WebKit component of multiple Apple products, including iOS, iPadOS, macOS, tvOS, and Safari. This vulnerability arises from inadequate input validation, which can be exploited by processing maliciously crafted web content, leading to arbitrary code execution. The issue has been actively exploited in the wild.

6.5
Sep 8, 2021

Apple WebKit Storage Use-After-Free Vulnerability Allowing Arbitrary Code Execution

A use-after-free vulnerability has been identified in the WebKit Storage component of multiple Apple products, including iOS, iPadOS, macOS, tvOS, watchOS, and Safari. This vulnerability arises from improper memory management, which can be exploited by processing maliciously crafted web content, leading to arbitrary code execution. Notably, this issue may have been actively exploited in the wild.

6.5
Sep 8, 2021

Apple macOS Gatekeeper Bypass Vulnerability in System Preferences

A logic vulnerability has been identified in the System Preferences component of Apple macOS. This issue allows a malicious application to bypass Gatekeeper checks, which are designed to prevent the execution of untrusted software. The vulnerability arises from an unspecified logic issue that could be exploited to manipulate the state management of the application. It affects multiple versions of macOS, including Big Sur and Catalina.

6.5
Sep 8, 2021

Apple iOS WebKit Use-After-Free Vulnerability Allowing Arbitrary Code Execution

A use-after-free vulnerability has been identified in the WebKit component of Apple iOS. This issue affects iOS devices including the iPhone 5s, iPhone 6, iPhone 6 Plus, iPad Air, iPad mini 2, iPad mini 3, and iPod touch (6th generation). The vulnerability arises from a memory corruption issue in the ASN.1 decoder, which was addressed by removing the vulnerable code. However, the vulnerability could still be exploited by processing maliciously crafted web content, leading to arbitrary code execution. Apple is aware of reports suggesting that this issue may have been actively exploited.

3.6