CVE-2023-42896
- EPSS 0.06%
- Published 28.03.2024 16:15:07
- Last modified 21.11.2024 08:23:26
An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Sonoma 14.2. An app may be able to modify protected pa...
CVE-2024-2004
- EPSS 0.91%
- Published 27.03.2024 08:15:41
- Last modified 30.07.2025 19:42:14
When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below command would perform a request to c...
CVE-2024-2379
- EPSS 0.21%
- Published 27.03.2024 08:15:41
- Last modified 30.07.2025 19:42:09
libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any ...
CVE-2024-2398
- EPSS 1.96%
- Published 27.03.2024 08:15:41
- Last modified 30.07.2025 19:42:27
When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all...
CVE-2024-2466
- EPSS 0.15%
- Published 27.03.2024 08:15:41
- Last modified 30.07.2025 19:42:21
libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address,...
CVE-2024-23287
- EPSS 0.18%
- Published 08.03.2024 02:15:50
- Last modified 13.03.2025 22:15:13
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14.4, iOS 17.4 and iPadOS 17.4, watchOS 10.4. An app may be able to access user-sensitive data.
CVE-2024-23288
- EPSS 0.03%
- Published 08.03.2024 02:15:50
- Last modified 20.03.2025 22:15:13
This issue was addressed by removing the vulnerable code. This issue is fixed in tvOS 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. An app may be able to elevate privileges.
CVE-2024-23289
- EPSS 0.04%
- Published 08.03.2024 02:15:50
- Last modified 09.12.2024 14:43:14
A lock screen issue was addressed with improved state management. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. A person with physical access to a device may be able to use Siri to acc...
CVE-2024-23290
- EPSS 0.03%
- Published 08.03.2024 02:15:50
- Last modified 09.12.2024 14:51:21
A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. An app may be able to access user-sensitive data.
CVE-2024-23291
- EPSS 0.17%
- Published 08.03.2024 02:15:50
- Last modified 09.12.2024 14:41:40
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in tvOS 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. A malicious app may be able to observe user data in log entries related t...