CVE-2017-2492
https://notcve.org/view.php?id=CVE-2017-2492
03 Apr 2018 — An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "JavaScriptCore" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that triggers prototype mishandling. Se ha descubierto un problema en algunos productos Apple. • https://support.apple.com/HT207600 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2017-13806
https://notcve.org/view.php?id=CVE-2017-13806
03 Apr 2018 — An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Profiles" component. It does not enforce the configuration profile's settings for whether pairings are allowed. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11 se han visto afectadas. • https://support.apple.com/HT208112 •
CVE-2018-4109
https://notcve.org/view.php?id=CVE-2018-4109
03 Apr 2018 — An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11.2.5, las versiones de tvOS anteriores a la 11.2.5 y las versiones de watchOS... • https://support.apple.com/HT208462 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2017-13904 – Apple packet-mangler Remote Code Execution
https://notcve.org/view.php?id=CVE-2017-13904
03 Apr 2018 — An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11.2, las versiones de macOS anteriores a la 10.13.2, las ve... • https://packetstorm.news/files/id/172828 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2018-4123 – Apple Security Advisory 2018-3-29-1
https://notcve.org/view.php?id=CVE-2018-4123
30 Mar 2018 — An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves alarm and timer handling in the "Clock" component. It allows physically proximate attackers to discover the iTunes e-mail address. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11.3 se han visto afectadas. • http://www.securityfocus.com/bid/103578 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2018-4122 – Apple Safari Spread Operator Type Confusion Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2018-4122
30 Mar 2018 — An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. Se ha descubierto un problema en algunos productos Apple. • http://www.securitytracker.com/id/1040604 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2018-4158 – Apple Security Advisory 2018-3-29-1
https://notcve.org/view.php?id=CVE-2018-4158
30 Mar 2018 — An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. watchOS before 4.3 is affected. The issue involves the "CoreFoundation" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11.3, las versiones de macOS anteriores a la 10.13.4 y las versiones de watchOS anteriores a la 4.3 se han visto afec... • http://www.securityfocus.com/bid/103581 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •
CVE-2018-4110 – Apple Security Advisory 2018-3-29-1
https://notcve.org/view.php?id=CVE-2018-4110
30 Mar 2018 — An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "Web App" component. It allows remote attackers to bypass intended restrictions on cookie persistence. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11.3 se han visto afectadas. • https://github.com/bencompton/ios11-cookie-set-expire-issue •
CVE-2018-4125 – Apple Safari Math abs Type Confusion Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2018-4125
30 Mar 2018 — An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. Se ha descubierto un problema en algunos productos Apple. • http://www.securitytracker.com/id/1040604 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2018-4129 – Apple Safari TypedArray Use-After-Free Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2018-4129
30 Mar 2018 — An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. Se ha descubierto un problema en algunos productos Apple. • http://www.securitytracker.com/id/1040604 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •