Show filters
3,536 Total Results
Displaying 81-90 of 3,536
Sort by:
Attacker Value
Unknown

CVE-2024-44246

Disclosure Date: December 12, 2024 (last updated December 19, 2024)
The issue was addressed with improved routing of Safari-originated requests. This issue is fixed in macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, Safari 18.2, iPadOS 17.7.3. On a device with Private Relay enabled, adding a website to the Safari Reading List may reveal the originating IP address to the website.
Attacker Value
Unknown

CVE-2024-44245

Disclosure Date: December 12, 2024 (last updated December 19, 2024)
The issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.3, visionOS 2.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, macOS Sonoma 14.7.2. An app may be able to cause unexpected system termination or corrupt kernel memory.
Attacker Value
Unknown

CVE-2024-44242

Disclosure Date: December 12, 2024 (last updated December 19, 2024)
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP firmware.
Attacker Value
Unknown

CVE-2024-44241

Disclosure Date: December 12, 2024 (last updated December 19, 2024)
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP firmware.
Attacker Value
Unknown

CVE-2024-44225

Disclosure Date: December 12, 2024 (last updated December 19, 2024)
A logic issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.3, watchOS 11.2, tvOS 18.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to gain elevated privileges.
Attacker Value
Unknown

CVE-2024-44212

Disclosure Date: December 12, 2024 (last updated December 18, 2024)
A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1, visionOS 2.1, tvOS 18.1, iOS 18.1 and iPadOS 18.1, watchOS 11.1. Cookies belonging to one origin may be sent to another origin.
Attacker Value
Unknown

CVE-2024-44201

Disclosure Date: December 12, 2024 (last updated December 18, 2024)
The issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.3, macOS Ventura 13.7.2, iOS 18.1 and iPadOS 18.1, macOS Sonoma 14.7.2. Processing a malicious crafted file may lead to a denial-of-service.
Attacker Value
Unknown

CVE-2024-44200

Disclosure Date: December 12, 2024 (last updated December 18, 2024)
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18.1. An app may be able to read sensitive location information.
Attacker Value
Unknown

CVE-2024-44309

Disclosure Date: November 20, 2024 (last updated December 21, 2024)
A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, macOS Sequoia 15.1.1, iOS 18.1.1 and iPadOS 18.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to a cross site scripting attack. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.
Attacker Value
Unknown

CVE-2024-44308

Disclosure Date: November 20, 2024 (last updated December 21, 2024)
The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, macOS Sequoia 15.1.1, iOS 18.1.1 and iPadOS 18.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.