Apple

macOS

2323 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.16%
  • Published 03.11.2020 03:15:12
  • Last modified 21.11.2024 05:06:34

Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • EPSS 1.47%
  • Published 27.10.2020 21:15:15
  • Last modified 21.11.2024 05:41:34

This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave. A remote attacker may be able to unexpectedly alter application state.

  • EPSS 1.06%
  • Published 22.10.2020 18:15:15
  • Last modified 21.11.2024 05:41:27

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Pr...

  • EPSS 1.77%
  • Published 22.10.2020 18:15:14
  • Last modified 21.11.2024 05:41:27

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.2...

Exploit
  • EPSS 0.04%
  • Published 27.06.2020 12:15:11
  • Last modified 21.11.2024 05:05:24

In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.

  • EPSS 0.15%
  • Published 15.06.2020 17:15:10
  • Last modified 21.11.2024 05:02:45

libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.

  • EPSS 0.18%
  • Published 15.06.2020 17:15:09
  • Last modified 21.11.2024 04:39:29

libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \X or \R has more than one fixed quantifier, a related issue to CVE-2019-20454.

  • EPSS 0.08%
  • Published 27.05.2020 15:15:12
  • Last modified 21.11.2024 05:01:38

ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.

  • EPSS 0.09%
  • Published 27.05.2020 15:15:12
  • Last modified 21.11.2024 05:01:38

SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.

Exploit
  • EPSS 0.05%
  • Published 24.05.2020 22:15:10
  • Last modified 21.11.2024 05:01:15

SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.