CVE-2018-4222 – WebKit - WebAssembly Compilation Info Leak
https://notcve.org/view.php?id=CVE-2018-4222
04 Jun 2018 — An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code via a crafted web site that leverages a getWasmBufferFromValue out-of-bounds read during WebAssembly compilation. Se ha descubierto un problema en algu... • https://packetstorm.news/files/id/148089 • CWE-125: Out-of-bounds Read •
CVE-2018-4227 – Apple Security Advisory 2018-06-01-1
https://notcve.org/view.php?id=CVE-2018-4227
01 Jun 2018 — An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. The issue involves the "Mail" component. It allows remote attackers to read the cleartext content of S/MIME encrypted messages via direct exfiltration. Se ha descubierto un problema en ciertos productos Apple. Se han visto afectadas las versiones de iOS anteriores a la 11.4 y las versiones de macOS anteriores a la 10.13.5. • http://www.securityfocus.com/bid/104897 • CWE-319: Cleartext Transmission of Sensitive Information •
CVE-2018-4235 – Apple Security Advisory 2018-7-23-4
https://notcve.org/view.php?id=CVE-2018-4235
01 Jun 2018 — An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "Messages" component. It allows local users to perform impersonation attacks via an unspecified injection. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11.4, las versiones de macOS anteriores a la 10.13.5, las versiones de tvOS anteriores a la 11.4 y las versio... • http://www.securitytracker.com/id/1041027 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •
CVE-2018-4237 – Apple macOS task_set_special_port Port Overwrite Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2018-4237
01 Jun 2018 — An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "libxpc" component. It allows attackers to gain privileges via a crafted app that leverages a logic error. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11.4, las versiones de macOS anteriores a la 10.13.5, las versiones de tvOS anteriores a la 11.4 y las versio... • https://packetstorm.news/files/id/150488 •
CVE-2018-4240 – Apple macOS 10.13.4 - Denial of Service (PoC)
https://notcve.org/view.php?id=CVE-2018-4240
01 Jun 2018 — An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "Messages" component. It allows remote attackers to cause a denial of service via a crafted message. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11.4, las versiones de macOS anteriores a la 10.13.5, las versiones de tvOS anteriores a la 11.4 y las versiones de... • https://packetstorm.news/files/id/149330 • CWE-20: Improper Input Validation •
CVE-2018-4241 – XNU Kernel - Heap Overflow Due to Bad Bounds Checking in MPTCP
https://notcve.org/view.php?id=CVE-2018-4241
01 Jun 2018 — An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "Kernel" component. A buffer overflow in mptcp_usr_connectx allows attackers to execute arbitrary code in a privileged context via a crafted app. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11.4, las versiones de macOS anteriores a la 10.13.5, las versiones de... • https://packetstorm.news/files/id/148061 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2018-4243 – Apple macOS/iOS Kernel - Heap Overflow Due to Lack of Lower Size Check in getvolattrlist
https://notcve.org/view.php?id=CVE-2018-4243
01 Jun 2018 — An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "Kernel" component. A buffer overflow in getvolattrlist allows attackers to execute arbitrary code in a privileged context via a crafted app. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11.4, las versiones de macOS anteriores a la 10.13.5, las versiones de tvO... • https://packetstorm.news/files/id/148062 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2018-4249 – Apple packet-mangler Remote Code Execution
https://notcve.org/view.php?id=CVE-2018-4249
01 Jun 2018 — An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves pktmnglr_ipfilter_input in com.apple.packet-mangler in the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (integer overflow and stack-based buffer overflow) via a crafted app. Se ha descubierto un problema en algunos productos Apple. Las versi... • https://packetstorm.news/files/id/172828 • CWE-190: Integer Overflow or Wraparound CWE-787: Out-of-bounds Write •
CVE-2018-4198 – Apple Security Advisory 2018-7-23-4
https://notcve.org/view.php?id=CVE-2018-4198
01 Jun 2018 — An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "UIKit" component. It allows remote attackers to cause a denial of service via a crafted text file. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11.4, las versiones de macOS anteriores a la 10.13.5, las versiones de tvOS anteriores a la 11.4 y las versiones de ... • http://www.securitytracker.com/id/1041027 • CWE-20: Improper Input Validation •
CVE-2018-4202 – Apple Security Advisory 2018-06-01-1
https://notcve.org/view.php?id=CVE-2018-4202
01 Jun 2018 — An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. The issue involves the "iBooks" component. It allows man-in-the-middle attackers to spoof a password prompt. Se ha descubierto un problema en ciertos productos Apple. Se han visto afectadas las versiones de iOS anteriores a la 11.4 y las versiones de macOS anteriores a la 10.13.5. • http://www.securityfocus.com/bid/104897 • CWE-20: Improper Input Validation •