Vulnerabilities
Vulnerable Software
Apple:  >> Iphone Os  Security Vulnerabilities
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, watchOS 10.2, macOS Ventura 13.6.3, tvOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Monterey 12.7.2. Processing an image may lead to arbitrary code execution.
CVSS Score
7.8
EPSS Score
0.0
Published
2023-12-12
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1. Processing maliciously crafted input may lead to arbitrary code execution in user-installed apps.
CVSS Score
7.8
EPSS Score
0.001
Published
2023-12-12
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.
CVSS Score
6.3
EPSS Score
0.239
Published
2023-12-08
CVE-2023-42916
Known exploited
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.
CVSS Score
6.5
EPSS Score
0.0
Published
2023-11-30
CVE-2023-42917
Known exploited
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.
CVSS Score
8.8
EPSS Score
0.0
Published
2023-11-30
Improper input validationation for some Intel Unison software may allow a privileged user to potentially enable denial of service via local access.
CVSS Score
5.0
EPSS Score
0.0
Published
2023-11-14
Cross-site request forgery in some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access.
CVSS Score
5.4
EPSS Score
0.002
Published
2023-11-14
Access of memory location after end of buffer for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via local access.
CVSS Score
5.3
EPSS Score
0.001
Published
2023-11-14
Improper access control for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access.
CVSS Score
5.4
EPSS Score
0.002
Published
2023-11-14
Improper access control for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access.
CVSS Score
5.3
EPSS Score
0.001
Published
2023-11-14


Contact Us

Shodan ® - All rights reserved