Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2024-44142
Disclosure Date: January 30, 2025 (last updated January 31, 2025)
The issue was addressed with improved bounds checks. This issue is fixed in GarageBand 10.4.12. Processing a maliciously crafted image may lead to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2023-42867
Disclosure Date: December 20, 2024 (last updated January 13, 2025)
This issue was addressed with improved validation of the process entitlement and Team ID. This issue is fixed in GarageBand 10.4.9. An app may be able to gain root privileges.
0
Attacker Value
Unknown
CVE-2024-23300
Disclosure Date: March 12, 2024 (last updated December 21, 2024)
A use-after-free issue was addressed with improved memory management. This issue is fixed in GarageBand 10.4.11. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
0
Attacker Value
Unknown
CVE-2022-22664
Disclosure Date: March 18, 2022 (last updated October 07, 2023)
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Logic Pro 10.7.3, GarageBand 10.4.6, macOS Monterey 12.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution.
0
Attacker Value
Unknown
CVE-2022-22657
Disclosure Date: March 18, 2022 (last updated October 07, 2023)
A memory initialization issue was addressed with improved memory handling. This issue is fixed in Logic Pro 10.7.3, GarageBand 10.4.6, macOS Monterey 12.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution.
0
Attacker Value
Unknown
CVE-2021-30654
Disclosure Date: September 08, 2021 (last updated November 28, 2024)
This issue was addressed by removing additional entitlements. This issue is fixed in GarageBand 10.4.3. A local attacker may be able to read sensitive information.
0
Attacker Value
Unknown
CVE-2017-2372
Disclosure Date: February 20, 2017 (last updated November 26, 2024)
An issue was discovered in certain Apple products. GarageBand before 10.1.5 is affected. Logic Pro X before 10.3 is affected. The issue involves the "Projects" component, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted GarageBand project file.
0
Attacker Value
Unknown
CVE-2017-2374
Disclosure Date: February 20, 2017 (last updated November 26, 2024)
An issue was discovered in certain Apple products. GarageBand before 10.1.6 is affected. The issue involves the "Projects" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted GarageBand project file.
0
Attacker Value
Unknown
CVE-2009-2198
Disclosure Date: August 04, 2009 (last updated October 04, 2023)
Apple GarageBand before 5.1 reconfigures Safari to accept all cookies regardless of domain name, which makes it easier for remote web servers to track users.
0