CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2020-9818

Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability

Vendor: Apple

Product: iOS, iPadOS, and watchOS

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Apple iOS, iPadOS, and watchOS Mail contains an out-of-bounds write vulnerability which may allow memory modification or application termination when processing a maliciously crafted mail message.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2020-9819

Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability

Vendor: Apple

Product: iOS, iPadOS, and watchOS

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Apple iOS, iPadOS, and watchOS Mail contains a memory corruption vulnerability that may allow heap corruption when processing a maliciously crafted mail message.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2021-30762

Apple iOS WebKit Use-After-Free Vulnerability

Vendor: Apple

Product: iOS

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Apple iOS WebKit contains a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-416

CVE-2021-1782

Apple Multiple Products Race Condition Vulnerability

Vendor: Apple

Product: Multiple Products

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Apple iOS, iPadOs, macOS, watchOS, and tvOS contain a race condition vulnerability that may allow a malicious application to elevate privileges.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-362 CWE-667

CVE-2021-1870

Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability

Vendor: Apple

Product: iOS, iPadOS, and macOS

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-1173

CVE-2021-1871

Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability

Vendor: Apple

Product: iOS, iPadOS, and macOS

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-1173

CVE-2021-1879

Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability

Vendor: Apple

Product: iOS, iPadOS, and watchOS

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Apple iOS, iPadOS, and watchOS WebKit contain an unspecified vulnerability that allows for universal cross-site scripting (XSS) when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-79

CVE-2021-30661

Apple Multiple Products WebKit Storage Use-After-Free Vulnerability

Vendor: Apple

Product: Multiple Products

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit Storage contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-416

CVE-2021-30666

Apple iOS WebKit Buffer Overflow Vulnerability

Vendor: Apple

Product: iOS

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Apple iOS WebKit contains a buffer-overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2021-30713

Apple macOS Unspecified Vulnerability

Vendor: Apple

Product: macOS

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Apple macOS Transparency, Consent, and Control (TCC) contains an unspecified permissions issue which may allow a malicious application to bypass privacy preferences.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-862

CVE-2021-30657

Apple macOS Unspecified Vulnerability

Vendor: Apple

Product: macOS

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Apple macOS contains an unspecified logic issue in System Preferences that may allow a malicious application to bypass Gatekeeper checks.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-862

CVE-2021-30665

Apple Multiple Products WebKit Memory Corruption Vulnerability

Vendor: Apple

Product: Multiple Products

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Apple iOS, iPadOS, macOS, watchOS, and tvOS WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2021-30663

Apple Multiple Products WebKit Integer Overflow Vulnerability

Vendor: Apple

Product: Multiple Products

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain an integer overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20 CWE-190

CVE-2021-30761

Apple iOS WebKit Memory Corruption Vulnerability

Vendor: Apple

Product: iOS

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Apple iOS WebKit contains a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2021-30869

Apple iOS, iPadOS, and macOS Type Confusion Vulnerability

Vendor: Apple

Product: iOS, iPadOS, and macOS

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Apple iOS, iPadOS, and macOS contain a type confusion vulnerability in the XNU which may allow a malicious application to execute code with kernel privileges.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-843