
CVE-2018-4173
https://notcve.org/view.php?id=CVE-2018-4173
13 Apr 2018 — An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. The issue involves the "Status Bar" component. It allows invisible microphone access via a crafted app. Se ha descubierto un problema en ciertos productos Apple. Se han visto afectadas las versiones de iOS anteriores a la 11,3 y las versiones de macOS anteriores a la 10.13. • https://support.apple.com/HT208692 • CWE-269: Improper Privilege Management •

CVE-2017-2492
https://notcve.org/view.php?id=CVE-2017-2492
03 Apr 2018 — An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "JavaScriptCore" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that triggers prototype mishandling. Se ha descubierto un problema en algunos productos Apple. • https://support.apple.com/HT207600 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-13806
https://notcve.org/view.php?id=CVE-2017-13806
03 Apr 2018 — An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Profiles" component. It does not enforce the configuration profile's settings for whether pairings are allowed. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11 se han visto afectadas. • https://support.apple.com/HT208112 •

CVE-2017-13873
https://notcve.org/view.php?id=CVE-2017-13873
03 Apr 2018 — An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "Kernel" component. It allows attackers to obtain sensitive network-activity information about arbitrary apps via a crafted app. Se ha descubierto un problema en ciertos productos Apple. Se han visto afectadas las versiones de iOS anteriores a la 11, las versiones de macOS anteriores a la 10.13, las versiones de tvOS an... • https://support.apple.com/HT208112 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2017-13863
https://notcve.org/view.php?id=CVE-2017-13863
03 Apr 2018 — An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "APNs" component. It allows man-in-the-middle attackers to track users by leveraging the transmission of client certificates. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11 se han visto afectadas. • https://support.apple.com/HT208112 • CWE-295: Improper Certificate Validation •

CVE-2017-7003
https://notcve.org/view.php?id=CVE-2017-7003
03 Apr 2018 — An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service (application crash) via a crafted file. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 10.3.2, las versiones de macOS anteriores a la 10.12.5, las versiones de tvOS anteriores a la ... • https://support.apple.com/HT207797 • CWE-20: Improper Input Validation •

CVE-2018-4109
https://notcve.org/view.php?id=CVE-2018-4109
03 Apr 2018 — An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11.2.5, las versiones de tvOS anteriores a la 11.2.5 y las versiones de watchOS... • https://support.apple.com/HT208462 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-6976
https://notcve.org/view.php?id=CVE-2017-6976
03 Apr 2018 — An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "Sandbox Profiles" component. It allows attackers to bypass intended access restrictions (for iCloud user records) via a crafted app. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 10.3 se han visto afectadas. • https://support.apple.com/HT207617 •

CVE-2017-13877
https://notcve.org/view.php?id=CVE-2017-13877
03 Apr 2018 — An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Sandbox Profiles" component. It allows attackers to determine whether arbitrary files exist via a crafted app. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11 se han visto afectadas. • https://support.apple.com/HT208112 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2018-4148
https://notcve.org/view.php?id=CVE-2018-4148
03 Apr 2018 — An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "Telephony" component. A buffer overflow allows remote attackers to execute arbitrary code. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11.3 se han visto afectadas. • http://www.securityfocus.com/bid/103578 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •