
CVE-2018-4290 – Apple Security Advisory 2018-7-9-2
https://notcve.org/view.php?id=CVE-2018-4290
09 Jul 2018 — A denial of service issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, watchOS 4.3.2. Un problema de denegación de servicio (DoS) se abordó con una gestión de memoria mejorada. Este problema afectaba a iOS en versiones anteriores a la 11.4.1 y watchOS en versiones anteriores a la 4.3.2. watchOS 4.3.2 is now available and addresses code execution and denial of service vulnerabilities. • https://support.apple.com/kb/HT208935 •

CVE-2018-4271 – Apple Security Advisory 2018-7-9-5
https://notcve.org/view.php?id=CVE-2018-4271
09 Jul 2018 — Multiple memory corruption issues were addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6. Múltiples problemas de corrupción de memoria se abordaron con una validación de entradas mejorada. El problema afectaba a iOS en versiones anteriores a la 11.4.1, tvOS en versiones anteriores a la 11.4.1, watchOS en versiones anteriores a la 4.3.2, Safari en versiones anteriores a la 11.1... • https://support.apple.com/kb/HT208932 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2018-4280 – Apple Security Advisory 2018-10-30-14
https://notcve.org/view.php?id=CVE-2018-4280
09 Jul 2018 — A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2. Un problema de corrupción de memoria se abordó con una gestión de memoria mejorada. Este problema afectaba a iOS en versiones anteriores a la 11.4.1; macOS High Sierra en versiones anteriores a la 10.13.6; tvOS en versiones anteriores a la 11.4.1 y watchOS en versiones anteriores a la 4.3.2. macOS High Sierra 10.13.6, Security Update ... • https://github.com/bazad/launchd-portrep • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2018-4282 – Apple Security Advisory 2018-7-9-3
https://notcve.org/view.php?id=CVE-2018-4282
09 Jul 2018 — An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2. Existía un problema de lectura fuera de límites que conducía a la divulgación de memoria del kernel. Este problema se abordó con una validación de entradas mejorada. • https://support.apple.com/kb/HT208935 • CWE-125: Out-of-bounds Read •

CVE-2018-4190 – Apple Security Advisory 2018-7-23-4
https://notcve.org/view.php?id=CVE-2018-4190
04 Jun 2018 — An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive credential information that is transmitted during a CSS mask-image fetch. Se ha descubierto un problema en algunos productos Apple. • http://www.securitytracker.com/id/1041029 • CWE-522: Insufficiently Protected Credentials •

CVE-2018-4218 – WebKit - Use-After-Free when Resuming Generator
https://notcve.org/view.php?id=CVE-2018-4218
04 Jun 2018 — An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site that triggers an @generatorState use-after-free. Se ha de... • https://packetstorm.news/files/id/148092 • CWE-416: Use After Free •

CVE-2018-4250 – Apple Security Advisory 2018-06-01-4
https://notcve.org/view.php?id=CVE-2018-4250
04 Jun 2018 — An issue was discovered in certain Apple products. iOS before 11.4 is affected. The issue involves the "Messages" component. It allows remote attackers to cause a denial of service via a crafted message. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11.4 se han visto afectadas. • http://www.securitytracker.com/id/1041031 • CWE-20: Improper Input Validation •

CVE-2018-4246 – Apple Security Advisory 2018-7-23-4
https://notcve.org/view.php?id=CVE-2018-4246
04 Jun 2018 — An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code via a crafted web site that leverages type confusion. Se ha descubierto un problema en algunos productos Apple. • http://www.securitytracker.com/id/1041029 • CWE-704: Incorrect Type Conversion or Cast •

CVE-2018-4199 – Apple Safari SVG Heap-based Buffer Overflow Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2018-4199
04 Jun 2018 — An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a crafted web site. Se ha descubierto un problema en algunos productos Apple. • http://www.securitytracker.com/id/1041029 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2018-4238 – Apple Security Advisory 2018-06-01-4
https://notcve.org/view.php?id=CVE-2018-4238
04 Jun 2018 — An issue was discovered in certain Apple products. iOS before 11.4 is affected. The issue involves the "Siri" component. It allows physically proximate attackers to bypass the lock-screen protection mechanism and enable Siri. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11.4 se han visto afectadas. • http://www.securitytracker.com/id/1041031 • CWE-732: Incorrect Permission Assignment for Critical Resource •