
CVE-2017-2523 – Apple macOS/iOS - NSUnarchiver Heap Corruption Due to Lack of Bounds Checking in [NSBuiltinCharacterSet initWithCoder:]
https://notcve.org/view.php?id=CVE-2017-2523
22 May 2017 — An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "Foundation" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted data. Fue encontrado un problema en algunos productos de Apple. iOS anteriores a la versión 10.3.2 se ven afectados. macOS anterior a la versión 10... • https://packetstorm.news/files/id/142649 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-6996 – Apple iOS < 10.3.1 - Kernel
https://notcve.org/view.php?id=CVE-2017-6996
22 May 2017 — An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. Se ha detectado un problema en ciertos productos de Apple. iOS versión anterior a 10.3.2 se ve afectado. TVOS versión anterior a 10.2.1 se ve afectado. • https://www.exploit-db.com/exploits/42555 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-6995 – Apple iOS < 10.3.1 - Kernel
https://notcve.org/view.php?id=CVE-2017-6995
22 May 2017 — An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. Se ha detectado un problema en ciertos productos de Apple. iOS versión anterior a 10.3.2 se ve afectado. TVOS versión anterior a 10.2.1 se ve afectado. • https://www.exploit-db.com/exploits/42555 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-6998 – Apple iOS < 10.3.1 - Kernel
https://notcve.org/view.php?id=CVE-2017-6998
22 May 2017 — An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. Se ha detectado un problema en ciertos productos de Apple. iOS versión anterior a 10.3.2 se ve afectado. TVOS versión anterior a 10.2.1 se ve afectado. • https://www.exploit-db.com/exploits/42555 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-6999 – Apple iOS < 10.3.1 - Kernel
https://notcve.org/view.php?id=CVE-2017-6999
22 May 2017 — An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. Se ha encontrado un problema en ciertos productos de Apple. iOS versión anterior a 10.3.2 se ve afectado. TVOS versión anterior a 10.2.1 se ve afectado. • https://www.exploit-db.com/exploits/42555 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-6994 – Apple iOS < 10.3.1 - Kernel
https://notcve.org/view.php?id=CVE-2017-6994
22 May 2017 — An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. Se ha detectado un problema en ciertos productos de Apple. iOS versión anterior a 10.3.2 se ve afectado. TVOS versión anterior a 10.2.1 se ve afectado. • https://www.exploit-db.com/exploits/42555 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-2505 – Apple Security Advisory 2017-05-15-3
https://notcve.org/view.php?id=CVE-2017-2505
15 May 2017 — An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. Fue encontrado un problema en algunos productos de Apple. iOS anteriores a la versión 10.3.2 se ven afectados. • https://packetstorm.news/files/id/142664 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-6989 – Apple iOS < 10.3.1 - Kernel
https://notcve.org/view.php?id=CVE-2017-6989
15 May 2017 — An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. Se ha detectado un problema en ciertos productos de Apple. iOS versión anterior a 10.3.2 se ve afectado. TVOS versión anterior a 10.2.1 se ve afectado. • https://www.exploit-db.com/exploits/42555 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-2507 – Apple Security Advisory 2017-05-15-3
https://notcve.org/view.php?id=CVE-2017-2507
15 May 2017 — An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app. Fue encontrado un problema en algunos productos de Apple. iOS anteriores a la versión 10.3.2 se ven afectados. macOS anterior a la versión 10.12.5 se ve afectado. tvOS anterior a la versión la 10.2.1 se v... • https://packetstorm.news/files/id/142647 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2017-2510 – WebKit - 'enqueuePageshowEvent' / 'enqueuePopstateEvent' Universal Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2017-2510
15 May 2017 — An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with pageshow events. Descubierto un problema en ciertos productos de Apple. • https://packetstorm.news/files/id/142666 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •