CVE-2018-4111
https://notcve.org/view.php?id=CVE-2018-4111
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Mail" component. It allows man-in-the-middle attackers to read S/MIME encrypted message content by sending HTML e-mail that references remote resources but lacks a valid S/MIME signature. Se ha descubierto un problema en algunos productos Apple. Las versiones de macOS anteriores a la 10.13.4 se han visto afectadas. • http://www.securityfocus.com/bid/103582 http://www.securitytracker.com/id/1040608 https://support.apple.com/HT208692 • CWE-347: Improper Verification of Cryptographic Signature •
CVE-2018-4132
https://notcve.org/view.php?id=CVE-2018-4132
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. Se ha descubierto un problema en algunos productos Apple. Las versiones de macOS anteriores a la 10.13.4 se han visto afectadas. • http://www.securityfocus.com/bid/103582 http://www.securitytracker.com/id/1040608 https://support.apple.com/HT208692 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2018-4139 – Apple macOS 10.13.2 - Double mach_port_deallocate in kextd due to Failure to Comply with MIG Ownership Rules
https://notcve.org/view.php?id=CVE-2018-4139
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "kext tools" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. Se ha descubierto un problema en algunos productos Apple. Las versiones de macOS anteriores a la 10.13.4 se han visto afectadas. • https://www.exploit-db.com/exploits/44561 http://www.securityfocus.com/bid/103582 http://www.securitytracker.com/id/1040608 https://support.apple.com/HT208692 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2018-4106
https://notcve.org/view.php?id=CVE-2018-4106
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the Bracketed Paste Mode of the "Terminal" component. It allows user-assisted attackers to inject arbitrary commands within pasted content. Se ha descubierto un problema en algunos productos Apple. Las versiones de macOS anteriores a la 10.13.4 se han visto afectadas. • http://www.securityfocus.com/bid/103582 http://www.securitytracker.com/id/1040608 https://support.apple.com/HT208692 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •
CVE-2018-4156
https://notcve.org/view.php?id=CVE-2018-4156
An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. The issue involves the "PluginKit" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app. Se ha descubierto un problema en ciertos productos Apple. Se han visto afectadas las versiones de iOS anteriores a la 11.3 y las versiones de macOS anteriores a la 10.13. • http://www.securityfocus.com/bid/103581 http://www.securitytracker.com/id/1040604 http://www.securitytracker.com/id/1040608 https://support.apple.com/HT208692 https://support.apple.com/HT208693 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •