NVD disclosure day

Published threat advisories for January 9, 2024

CVE advisoryKnown Exploit

CVE-2022-48618

Apple Software Bypass of Pointer Authentication

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Apple operating systems could permit an attacker with read and write access to bypass security features, potentially impacting data integrity and system access. Reports suggest exploitation occurred on certain iOS versions prior to 15.7.1. Organizations should apply vendor-provided updates to mitigat

• CISA KEV

CVE advisoryCRITICAL

CVE-2023-26999

NetScout nGeniusOne Code Execution and Denial of Service Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated remote attacker can execute arbitrary code and cause a denial of service on NetScout nGeniusOne via a crafted file. This impacts the availability and integrity of network performance monitoring and service assurance functions.

CVE advisoryCRITICAL

CVE-2023-50643

Evernote for macOS Code Execution Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in Evernote for macOS, allowing remote attackers to execute arbitrary code through specific components. While the attack vector is network-based, the vulnerability's relevance depends on whether the affected version is present in the environment, as it impacts a desktop application. Conf