Apple Security Advisories · January 2021 — Apple Security Advisories
14 advisories 14 CVEs 1 EXPLOITED

Apple-vendor CVEs for 2021-01. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2021-1782

iPadOSExploitedCISA KEV listedHIGH2021-01-27

A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application may be able t...

CVEs:CVE-2021-1782

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-36228

OtherPoC exploitHIGH2021-01-26

An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, resulting in denial of service.

CVEs:CVE-2020-36228

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2020-36221

OtherPoC exploitHIGH2021-01-26

An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c serialNumberAndIssuerCheck).

CVEs:CVE-2020-36221

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2020-36227

OtherPoC exploitHIGH2021-01-26

A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in denial of service.

CVEs:CVE-2020-36227

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2020-36222

OtherPoC exploitHIGH2021-01-26

A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of service.

CVEs:CVE-2020-36222

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2020-36230

OtherPoC exploitHIGH2021-01-26

A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, resulting in denial of service.

CVEs:CVE-2020-36230

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2020-36225

OtherPoC exploitCRITICAL2021-01-26

A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial of service.

CVEs:CVE-2020-36225

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2020-36229

OtherPoC exploitHIGH2021-01-26

A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resulting in denial of service.

CVEs:CVE-2020-36229

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2020-36223

OtherPoC exploitCRITICAL2021-01-26

A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling, resulting in denial of service (double free and out-of-bounds read).

CVEs:CVE-2020-36223

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2020-36224

OtherPoC exploitHIGH2021-01-26

A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting in denial of service.

CVEs:CVE-2020-36224

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2020-36226

OtherPoC exploitHIGH2021-01-26

A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in denial of service.

CVEs:CVE-2020-36226

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1781

iPadOSCoalition ESS < 30%MEDIUM2021-01-27

A privacy issue existed in the handling of Contact cards. This was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A mali...

CVEs:CVE-2021-1781

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1800

XcodeCoalition ESS < 30%CRITICAL2021-01-27

A path handling issue was addressed with improved validation. This issue is fixed in Xcode 12.4. A malicious application may be able to access arbitrary files on the host device while running an app that uses on-demand resources with Xcode.

CVEs:CVE-2021-1800

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple — —
Upstream advisory

CVE-2021-1780

iPadOSCoalition ESS < 30%MEDIUM2021-01-27

A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 14.4 and iPadOS 14.4. An attacker in a privileged position may be able to perform a denial of service attack.

CVEs:CVE-2021-1780

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.