CVE-2024-44142
- EPSS 0.02%
- Veröffentlicht 30.01.2025 19:15:13
- Zuletzt bearbeitet 18.03.2025 16:06:18
The issue was addressed with improved bounds checks. This issue is fixed in GarageBand 10.4.12. Processing a maliciously crafted image may lead to arbitrary code execution.
CVE-2023-42867
- EPSS 0.09%
- Veröffentlicht 20.12.2024 04:15:05
- Zuletzt bearbeitet 06.01.2025 14:20:04
This issue was addressed with improved validation of the process entitlement and Team ID. This issue is fixed in GarageBand 10.4.9. An app may be able to gain root privileges.
CVE-2024-23300
- EPSS 0.11%
- Veröffentlicht 12.03.2024 21:15:58
- Zuletzt bearbeitet 09.12.2024 15:00:30
A use-after-free issue was addressed with improved memory management. This issue is fixed in GarageBand 10.4.11. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
CVE-2022-22664
- EPSS 0.47%
- Veröffentlicht 18.03.2022 18:15:15
- Zuletzt bearbeitet 21.11.2024 06:47:13
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Logic Pro 10.7.3, GarageBand 10.4.6, macOS Monterey 12.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code ex...
CVE-2022-22657
- EPSS 0.36%
- Veröffentlicht 18.03.2022 18:15:14
- Zuletzt bearbeitet 21.11.2024 06:47:13
A memory initialization issue was addressed with improved memory handling. This issue is fixed in Logic Pro 10.7.3, GarageBand 10.4.6, macOS Monterey 12.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary...
CVE-2021-30654
- EPSS 0.13%
- Veröffentlicht 08.09.2021 15:15:12
- Zuletzt bearbeitet 21.11.2024 06:04:22
This issue was addressed by removing additional entitlements. This issue is fixed in GarageBand 10.4.3. A local attacker may be able to read sensitive information.
CVE-2017-2372
- EPSS 0.85%
- Veröffentlicht 20.02.2017 08:59:05
- Zuletzt bearbeitet 20.04.2025 01:37:25
An issue was discovered in certain Apple products. GarageBand before 10.1.5 is affected. Logic Pro X before 10.3 is affected. The issue involves the "Projects" component, which allows remote attackers to execute arbitrary code or cause a denial of se...
CVE-2017-2374
- EPSS 0.63%
- Veröffentlicht 20.02.2017 08:59:05
- Zuletzt bearbeitet 20.04.2025 01:37:25
An issue was discovered in certain Apple products. GarageBand before 10.1.6 is affected. The issue involves the "Projects" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application...
CVE-2009-2198
- EPSS 0.5%
- Veröffentlicht 04.08.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Apple GarageBand before 5.1 reconfigures Safari to accept all cookies regardless of domain name, which makes it easier for remote web servers to track users.