VARIoT IoT vulnerabilities database
| VAR-202109-1695 | CVE-2021-40284 | D-Link DSL-3782 Classic buffer overflow vulnerability in |
CVSS V2: 6.8 CVSS V3: 6.5 Severity: MEDIUM |
D-Link DSL-3782 EU v1.01:EU v1.03 is affected by a buffer overflow which can cause a denial of service. This vulnerability exists in the web interface "/cgi-bin/New_GUI/Igmp.asp". Authenticated remote attackers can trigger this vulnerability by sending a long string in parameter 'igmpsnoopEnable' via an HTTP request. D-Link DSL-3782 Exists in a classic buffer overflow vulnerability.Service operation interruption (DoS) It may be in a state. D-Link DSL-3782 is a wireless router made by D-Link in Taiwan. The vulnerability is caused by the incorrect operation when performing operations on the memory in the WEB interface/cgi-bin/New_GUI/Igmp.asp Verify the data boundary
| VAR-202109-0545 | CVE-2021-25449 | Android Buffer error vulnerability in |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
An improper input validation vulnerability in libsapeextractor library prior to SMR Sep-2021 Release 1 allows attackers to execute arbitrary code in mediaextractor process. Android Exists in a buffer error vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Samsung libsapeextractor is a component of Samsung mobile devices.
Samsung libsapeextractor has an input validation error vulnerability, which is caused by incorrect input validation logic in the libsapeextractor library
| VAR-202109-1900 | CVE-2021-40346 | HAProxy Integer overflow vulnerability in |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs. HAProxy Exists in an integer overflow vulnerability.Information may be tampered with. HAProxy is an open source TCP/HTTP load balancing server from the French HAProxy= company. =
There is an input validation error vulnerability in HAProxy, which stems from the lack of header name length checking in the htx_add_header() and htx_add_trailer() functions in HAProxy, which can be exploited by attackers to cause request smuggling attacks or response splitting attacks. Description:
Red Hat Advanced Cluster Management for Kubernetes 2.2.11 images
Red Hat Advanced Cluster Management for Kubernetes provides the
capabilities to address common challenges that administrators and site
reliability engineers face as they work across a range of public and
private cloud environments.
Clusters and applications are all visible and managed from a single console
— with security policy built in. See the following Release Notes documentation, which
will be updated shortly for this release, for additional details about this
release:
https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.2/html/release_notes/
Security updates:
* object-path: Type confusion vulnerability can lead to a bypass of
CVE-2020-15256 (CVE-2021-23434)
* follow-redirects: Exposure of Private Personal Information to an
Unauthorized Actor (CVE-2022-0155)
Related bugs:
* RHACM 2.2.11 images (Bugzilla #2029508)
* ClusterImageSet has 4.5 which is not supported in ACM 2.2.10 (Bugzilla
#2030859)
3. Bugs fixed (https://bugzilla.redhat.com/):
1999810 - CVE-2021-23434 object-path: Type confusion vulnerability can lead to a bypass of CVE-2020-15256
2029508 - RHACM 2.2.11 images
2030859 - ClusterImageSet has 4.5 which is not supported in ACM 2.2.10
2044556 - CVE-2022-0155 follow-redirects: Exposure of Private Personal Information to an Unauthorized Actor
5. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-4968-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
September 07, 2021 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : haproxy
CVE ID : CVE-2021-40346
Ori Hollander reported that missing header name length checks in the
htx_add_header() and htx_add_trailer() functions in HAProxy, a fast and
reliable load balancing reverse proxy, could result in request smuggling
attacks or response splitting attacks.
Additionally this update addresses #993303 introduced in DSA 4960-1
causing HAProxy to fail serving URLs with HTTP/2 containing '//'.
For the stable distribution (bullseye), this problem has been fixed in
version 2.2.9-2+deb11u2.
We recommend that you upgrade your haproxy packages.
For the detailed security status of haproxy please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/haproxy
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmE30edfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0QPzQ//Xl1VpOHuAwqodHnEx3DSP172eZ6lD3Mdrs+GXscbkCXTMHduSXGnSGA3
N1IrN8Wt1bfvxybqdR3CLTehTzmgBJLGEz8Ub5gu0IJ2o1edyiqpZBDhZvDSCPFC
iFHWucZ2asOb9c/rCapTi7AD+S7NpC5AnIGfNhUHYWnFwR7Id8gHvd9JaHUGrInh
P4T5lzY70fvNFPrSye7CQFPcSScHOe29i7igKXZmV+FxvnYEYJyavf6ijwGTJF87
e1lJAm8er9bQZp3GLzkbI3bRUDmO+IgGX+H3Qz/PxbU23PhyDN91QVWCY/CX11nN
yH4evBchPM1ap2o8hPZYpUYUznYekOA1CfYxTcuP5oc9QFMEzHMNUVhSihsjGA4Y
fCxFmdhcQzTLI7GcZTkSB2k0CikF4ncH7aqtM7oK2z/CM/uJeVO1WzRtvyJKuD72
Lv6PwQ/AbMa/dKYzROyQE0vDzRd23UzlQzg1npbpHlfPYXOgyfIRLCIfBPatyGrR
snpdsNnGejesNmsbxCBwQGz2jsrgSqMe1qkho9ebK3aeaSA1lRe+WXV87NYH2wZi
JOQH9JjqXCwkH/JDoOBWasOAhyKPs4jv1JT2L2iXCNVbFcgklnc+iaUgafYV9tob
QMoc5oZREvgkpu+TOOTOBmrOw4sDfEOgcNf3G1sBBFKS4ds5wv0=
=8IRe
-----END PGP SIGNATURE-----
. Bugs fixed (https://bugzilla.redhat.com/):
2050826 - CVE-2022-24348 gitops: Path traversal and dereference of symlinks when passing Helm value files
5. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
=====================================================================
Red Hat Security Advisory
Synopsis: Moderate: OpenShift Container Platform 4.9.6 packages and security update
Advisory ID: RHSA-2021:4118-01
Product: Red Hat OpenShift Enterprise
Advisory URL: https://access.redhat.com/errata/RHSA-2021:4118
Issue date: 2021-11-10
CVE Names: CVE-2021-39240 CVE-2021-39241 CVE-2021-39242
CVE-2021-40346
=====================================================================
1. Summary:
Red Hat OpenShift Container Platform release 4.9.6 is now available with
updates to packages and images that fix several bugs and add enhancements.
This release includes a security update for Red Hat OpenShift Container
Platform 4.9.
Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.
2. Relevant releases/architectures:
Red Hat OpenShift Container Platform 4.9 - aarch64, noarch, ppc64le, s390x, x86_64
3. Description:
Red Hat OpenShift Container Platform is Red Hat's cloud computing
Kubernetes application platform solution designed for on-premise or private
cloud deployments.
This advisory contains the RPM packages for Red Hat OpenShift Container
Platform 4.9.6. See the following advisory for the container images for
this release:
https://access.redhat.com/errata/RHBA-2021:4119
Security Fix(es):
* haproxy: does not ensure that the scheme and path portions of a URI have
the expected characters (CVE-2021-39240)
* haproxy: an HTTP method name may contain a space followed by the name of
a protected resource (CVE-2021-39241)
* haproxy: it can lead to a situation with an attacker-controlled HTTP Host
header because a mismatch between Host and authority is mishandled
(CVE-2021-39242)
* haproxy: request smuggling attack or response splitting via duplicate
content-length header (CVE-2021-40346)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
All OpenShift Container Platform 4.9 users are advised to upgrade to these
updated packages and images when they are available in the appropriate
release channel. To check for available updates, use the OpenShift Console
or the CLI oc command. Instructions for upgrading a cluster are available
at
https://docs.openshift.com/container-platform/4.9/updating/updating-cluster
- -between-minor.html#understanding-upgrade-channels_updating-cluster-between
- -minor
4. Solution:
For OpenShift Container Platform 4.9 see the following documentation, which
will be updated shortly for this release, for important instructions on how
to upgrade your cluster and fully apply this asynchronous errata update:
https://docs.openshift.com/container-platform/4.9/release_notes/ocp-4-9-rel
ease-notes.html
Details on how to access this content are available at
https://docs.openshift.com/container-platform/4.9/updating/updating-cluster
- -cli.html
5. Bugs fixed (https://bugzilla.redhat.com/):
1995104 - CVE-2021-39240 haproxy: does not ensure that the scheme and path portions of a URI have the expected characters
1995107 - CVE-2021-39241 haproxy: an HTTP method name may contain a space followed by the name of a protected resource
1995112 - CVE-2021-39242 haproxy: it can lead to a situation with an attacker-controlled HTTP Host header because a mismatch between Host and authority is mishandled
2000599 - CVE-2021-40346 haproxy: request smuggling attack or response splitting via duplicate content-length header
6. Package List:
Red Hat OpenShift Container Platform 4.9:
Source:
cri-o-1.22.0-91.rhaos4.9.gitd745cab.el7.src.rpm
openshift-4.9.0-202111020225.p0.git.d8c4430.assembly.stream.el7.src.rpm
x86_64:
cri-o-1.22.0-91.rhaos4.9.gitd745cab.el7.x86_64.rpm
cri-o-debuginfo-1.22.0-91.rhaos4.9.gitd745cab.el7.x86_64.rpm
openshift-hyperkube-4.9.0-202111020225.p0.git.d8c4430.assembly.stream.el7.x86_64.rpm
Red Hat OpenShift Container Platform 4.9:
Source:
cri-o-1.22.0-78.rhaos4.9.gitd745cab.el8.src.rpm
haproxy-2.2.15-2.el8.src.rpm
openshift-4.9.0-202111020225.p0.git.d8c4430.assembly.stream.el8.src.rpm
openshift-kuryr-4.9.0-202110281423.p0.git.4595a4e.assembly.stream.el8.src.rpm
openstack-ironic-18.1.1-0.20211019162143.e0437cd.el8.src.rpm
aarch64:
cri-o-1.22.0-78.rhaos4.9.gitd745cab.el8.aarch64.rpm
cri-o-debuginfo-1.22.0-78.rhaos4.9.gitd745cab.el8.aarch64.rpm
cri-o-debugsource-1.22.0-78.rhaos4.9.gitd745cab.el8.aarch64.rpm
haproxy-debugsource-2.2.15-2.el8.aarch64.rpm
openshift-hyperkube-4.9.0-202111020225.p0.git.d8c4430.assembly.stream.el8.aarch64.rpm
noarch:
openshift-kuryr-cni-4.9.0-202110281423.p0.git.4595a4e.assembly.stream.el8.noarch.rpm
openshift-kuryr-common-4.9.0-202110281423.p0.git.4595a4e.assembly.stream.el8.noarch.rpm
openshift-kuryr-controller-4.9.0-202110281423.p0.git.4595a4e.assembly.stream.el8.noarch.rpm
openstack-ironic-api-18.1.1-0.20211019162143.e0437cd.el8.noarch.rpm
openstack-ironic-common-18.1.1-0.20211019162143.e0437cd.el8.noarch.rpm
openstack-ironic-conductor-18.1.1-0.20211019162143.e0437cd.el8.noarch.rpm
python3-ironic-tests-18.1.1-0.20211019162143.e0437cd.el8.noarch.rpm
python3-kuryr-kubernetes-4.9.0-202110281423.p0.git.4595a4e.assembly.stream.el8.noarch.rpm
ppc64le:
cri-o-1.22.0-78.rhaos4.9.gitd745cab.el8.ppc64le.rpm
cri-o-debuginfo-1.22.0-78.rhaos4.9.gitd745cab.el8.ppc64le.rpm
cri-o-debugsource-1.22.0-78.rhaos4.9.gitd745cab.el8.ppc64le.rpm
haproxy-debugsource-2.2.15-2.el8.ppc64le.rpm
openshift-hyperkube-4.9.0-202111020225.p0.git.d8c4430.assembly.stream.el8.ppc64le.rpm
s390x:
cri-o-1.22.0-78.rhaos4.9.gitd745cab.el8.s390x.rpm
cri-o-debuginfo-1.22.0-78.rhaos4.9.gitd745cab.el8.s390x.rpm
cri-o-debugsource-1.22.0-78.rhaos4.9.gitd745cab.el8.s390x.rpm
haproxy-debugsource-2.2.15-2.el8.s390x.rpm
openshift-hyperkube-4.9.0-202111020225.p0.git.d8c4430.assembly.stream.el8.s390x.rpm
x86_64:
cri-o-1.22.0-78.rhaos4.9.gitd745cab.el8.x86_64.rpm
cri-o-debuginfo-1.22.0-78.rhaos4.9.gitd745cab.el8.x86_64.rpm
cri-o-debugsource-1.22.0-78.rhaos4.9.gitd745cab.el8.x86_64.rpm
haproxy-debugsource-2.2.15-2.el8.x86_64.rpm
openshift-hyperkube-4.9.0-202111020225.p0.git.d8c4430.assembly.stream.el8.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2021-39240
https://access.redhat.com/security/cve/CVE-2021-39241
https://access.redhat.com/security/cve/CVE-2021-39242
https://access.redhat.com/security/cve/CVE-2021-40346
https://access.redhat.com/security/updates/classification/#moderate
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2021 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBYYx8gNzjgjWX9erEAQjjTg/5AXMVm45fYdpV7EOawTw6ADN3G+MIC9F+
4/Yi3cEdClLzvColFg9mR8Ha/HrtSc8hl/ImYCdWpdaAgR69Z2ReFYR8skd6IQlg
2yqP8Fv34dXLxMkTgFpf2P4xsVdvAaKW5LXuZZ8tNYIRmCFmDJLbO1lyAAb0f7Tg
cYFQE5LsuBSFceuY405VYjdwrAR1N/EwzleqpTrgcdeGliwRnfpiOjTs9rXgIIkf
EFccGSIJpvlsibKm78o8PVxpoKmwRPnIUU/lOlLEsx4epYEal332i/JOhctXQ0MD
KIPy0Ghto00KDyBfp1JziS3by4TD3DPYoZ2LqlmN844BUc4de7h/48gwy8n3PK7g
A+0sguS3K4lTrb0INV6f3fPBsULZSAAhuPMkpAf0YgfnLdJlkm+oXBWDyiERZyaX
lcQREEMJoKWnw5s83ip+o+QQdisxQ5olqEMD6g0qT9msUvgha4OIEgnN1dYgFvEK
IY3zgShDHQGg2LwAXku1pvEB+N5MedDM/4OWV7qhFUN1edlTePGqN8tIE/bgEpib
464s1Q3FMcTwQDOmKpTh5GTt8TKkuNIibfHFqqwEJ/L/1L77qDjtp4EapFm0USxq
0R/bVd733gsEXghAv1NRBHQECb727Fne6cNLu+TffFQbtfSel+0MGogsSURVhy7e
7lkzoAA4Wc4=
=r4tE
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce
. Bugs fixed (https://bugzilla.redhat.com/):
2034067 - CVE-2021-45105 log4j-core: DoS in log4j 2.x with Thread Context Map (MDC) input data contains a recursive lookup and context lookup pattern
5
| VAR-202112-0670 | CVE-2021-36169 | Fortinet FortiOS Vulnerability in |
CVSS V2: 6.6 CVSS V3: 6.0 Severity: MEDIUM |
A Hidden Functionality in Fortinet FortiOS 7.x before 7.0.1, FortiOS 6.4.x before 6.4.7 allows attacker to Execute unauthorized code or commands via specific hex read/write operations. Fortinet FortiOS Exists in unspecified vulnerabilities.Information may be obtained and information may be tampered with. Fortinet FortiOS is a set of security operating system dedicated to the FortiGate network security platform developed by Fortinet. The system provides users with various security functions such as firewall, anti-virus, IPSec/SSLVPN, Web content filtering and anti-spam. Fortinet FortiOS has a security vulnerability in which the FortiOS CLI could allow local and authenticated users to be assigned to specific VDOMs to retrieve information from other VDOMs. An attacker could exploit this vulnerability to expose sensitive information to unauthorized actors
| VAR-202111-0986 | CVE-2021-32600 | FortiOS Vulnerability regarding information leakage in |
CVSS V2: 2.1 CVSS V3: 3.8 Severity: LOW |
An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS CLI 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, 6.0.x and 5.6.x may allow a local and authenticated user assigned to a specific VDOM to retrieve other VDOMs information such as the admin account list and the network interface list. FortiOS There is a vulnerability related to information leakage.Information may be obtained. Fortinet FortiOS is a set of security operating system dedicated to the FortiGate network security platform developed by Fortinet. The system provides users with various security functions such as firewall, anti-virus, IPSec/SSLVPN, Web content filtering and anti-spam. An attacker could exploit this vulnerability to expose sensitive information to unauthorized actors
| VAR-202109-1922 | CVE-2021-26116 | FortiAuthenticator In OS Command injection vulnerability |
CVSS V2: 6.5 CVSS V3: 8.8 Severity: HIGH |
An improper neutralization of special elements used in an OS command vulnerability in the command line interpreter of FortiAuthenticator before 6.3.1 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands. FortiAuthenticator for, OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202109-1366 | CVE-2021-30756 | plural Apple Product vulnerabilities |
CVSS V2: 2.1 CVSS V3: 5.5 Severity: MEDIUM |
A local attacker may be able to view Now Playing information from the lock screen. This issue is fixed in macOS Big Sur 11.4, iOS 14.6 and iPadOS 14.6. A privacy issue in Now Playing was addressed with improved permissions
| VAR-202109-1365 | CVE-2021-30755 | Apple Buffer error vulnerabilities in multiple products |
CVSS V2: 4.3 CVSS V3: 6.5 Severity: MEDIUM |
Processing a maliciously crafted font may result in the disclosure of process memory. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5. An out-of-bounds read was addressed with improved input validation
| VAR-202109-1364 | CVE-2021-30753 | Apple Buffer error vulnerabilities in multiple products |
CVSS V2: 4.3 CVSS V3: 5.5 Severity: MEDIUM |
Processing a maliciously crafted font may result in the disclosure of process memory. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. An out-of-bounds read was addressed with improved input validation
| VAR-202109-1363 | CVE-2021-30752 | plural Apple Product out-of-bounds read vulnerability |
CVSS V2: 6.8 CVSS V3: 7.8 Severity: HIGH |
Processing a maliciously crafted image may lead to arbitrary code execution. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. An out-of-bounds read was addressed with improved input validation. plural Apple The product contains an out-of-bounds read vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202109-1362 | CVE-2021-30751 | macOS Vulnerability in |
CVSS V2: 4.3 CVSS V3: 5.5 Severity: MEDIUM |
This issue was addressed with improved data protection. This issue is fixed in macOS Big Sur 11.4. A malicious application may be able to bypass certain Privacy preferences. macOS Exists in unspecified vulnerabilities.Information may be tampered with
| VAR-202109-1361 | CVE-2021-30750 | macOS Vulnerability regarding improper default permissions in |
CVSS V2: 4.3 CVSS V3: 5.5 Severity: MEDIUM |
The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.3. A malicious application may be able to access the user's recent contacts. macOS There is a vulnerability in improper default permissions.Information may be obtained
| VAR-202109-1314 | CVE-2021-30664 | plural Apple Out-of-bounds write vulnerabilities in the product |
CVSS V2: 6.8 CVSS V3: 7.8 Severity: HIGH |
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing a maliciously crafted file may lead to arbitrary code execution. plural Apple The product contains a vulnerability related to out-of-bounds writes.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202109-0502 | CVE-2021-36182 | Fortinet FortiWeb In OS Command injection vulnerability |
CVSS V2: 6.5 CVSS V3: 8.8 Severity: HIGH |
A Improper neutralization of special elements used in a command ('Command Injection') in Fortinet FortiWeb version 6.3.13 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests. Fortinet FortiWeb for, OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Fortinet FortiWeb is a web application layer firewall developed by Fortinet, which can block threats such as cross-site scripting, SQL injection, cookie poisoning, schema poisoning, etc., to ensure the security of web applications and protect sensitive database content. FortiWeb has a buffer error vulnerability that stems from multiple stack-based buffer overflow vulnerabilities in the FortiWeb CLI interface
| VAR-202109-0501 | CVE-2021-36179 | Fortinet FortiWeb Out-of-bounds write vulnerability in |
CVSS V2: 6.5 CVSS V3: 8.8 Severity: HIGH |
A stack-based buffer overflow in Fortinet FortiWeb version 6.3.14 and below, 6.2.4 and below allows attacker to execute unauthorized code or commands via crafted parameters in CLI command execution. Fortinet FortiWeb Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Fortinet FortiWeb is a web application layer firewall developed by Fortinet, which can block threats such as cross-site scripting, SQL injection, cookie poisoning, schema poisoning, etc., to ensure the security of web applications and protect sensitive database content. FortiWeb has a buffer error vulnerability that stems from multiple stack-based buffer overflow vulnerabilities in the FortiWeb CLI interface
| VAR-202109-0347 | CVE-2021-1833 | iOS and iPadOS Vulnerability in |
CVSS V2: 6.8 CVSS V3: 7.8 Severity: HIGH |
This issue was addressed with improved checks. This issue is fixed in iOS 14.5 and iPadOS 14.5. An application may be able to gain elevated privileges. iOS and iPadOS Exists in unspecified vulnerabilities.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202109-0326 | CVE-2021-1863 | iOS and iPadOS Authentication vulnerability in |
CVSS V2: 2.1 CVSS V3: 2.4 Severity: LOW |
An issue existed with authenticating the action triggered by an NFC tag. The issue was addressed with improved action authentication. This issue is fixed in iOS 14.5 and iPadOS 14.5. A person with physical access to an iOS device may be able to place phone calls to any phone number. iOS and iPadOS There is an authentication vulnerability in.Information may be tampered with
| VAR-202109-0325 | CVE-2021-1862 | Apple iOS and Apple iPadOS Authorization problem vulnerability |
CVSS V2: 2.1 CVSS V3: 2.4 Severity: LOW |
Description: A person with physical access may be able to access contacts. This issue is fixed in iOS 14.5 and iPadOS 14.5. Impact: An issue with Siri search access to information was addressed with improved logic
| VAR-202109-0287 | CVE-2021-1770 | plural Apple Buffer error vulnerability in the product |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
A buffer overflow may result in arbitrary code execution. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A logic issue was addressed with improved state management. plural Apple The product contains a buffer error vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. macOS Big Sur versions prior to 11.3, iOS versions prior to 14.5 and iPadOS versions prior to 14.5, watchOS versions prior to 7.4, and tvOS versions prior to 14.5 have a security vulnerability due to a buffer overflow that may lead to arbitrary code execution
| VAR-202109-0278 | CVE-2021-1812 | iOS and iPadOS Vulnerability in |
CVSS V2: 9.3 CVSS V3: 7.8 Severity: HIGH |
A logic issue was addressed with improved validation. This issue is fixed in iOS 14.5 and iPadOS 14.5. A malicious application may be able to execute arbitrary code with system privileges. iOS and iPadOS Exists in unspecified vulnerabilities.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Both Apple iOS and Apple iPadOS are products of Apple (Apple). Apple iOS is an operating system developed for mobile devices. Apple iPadOS is an operating system for iPad tablets