CVE-2018-4387
https://notcve.org/view.php?id=CVE-2018-4387
A lock screen issue allowed access to photos via Reply With Message on a locked device. This issue was addressed with improved state management. This issue affected versions prior to iOS 12.1. Un problema de pantalla de bloqueo permitía el acceso a las fotos mediante la función "Reply With Message" en un dispositivo bloqueado. Este problema se abordó con una gestión de estado mejorada. • https://support.apple.com/kb/HT209192 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2018-4409
https://notcve.org/view.php?id=CVE-2018-4409
A resource exhaustion issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1, tvOS 12.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8. Un problema de agotamiento de recursos se abordó con una validación de entradas mejorada. El problema afectaba a iOS en versiones anteriores a la 12.1, tvOS en versiones anteriores a la 12.1, Safari en versiones anteriores a la 12.0.1, iTunes en versiones anteriores a la 12.9.1 y iCloud para Windows en versiones anteriores a la 7.8. • https://support.apple.com/kb/HT209192 https://support.apple.com/kb/HT209194 https://support.apple.com/kb/HT209196 https://support.apple.com/kb/HT209197 https://support.apple.com/kb/HT209198 • CWE-400: Uncontrolled Resource Consumption •
CVE-2018-4391
https://notcve.org/view.php?id=CVE-2018-4391
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan, watchOS 4.3, iOS 12.1. Processing a maliciously crafted text message may lead to UI spoofing. Se abordó un problema de interfaz de usuario inconsistente con una administración de estado mejorada. Este problema se corrigió en macOS High Sierra versión 10.13.1, Security Update 2017-001 Sierra y Security Update 2017-004 El Capitan, watchOS versión 4.3, iOS versión 12.1. • https://support.apple.com/en-us/HT208221 https://support.apple.com/en-us/HT208696 https://support.apple.com/en-us/HT209192 •
CVE-2018-4377
https://notcve.org/view.php?id=CVE-2018-4377
A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue affected versions prior to iOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8. Existía un problema de cross-Site Scripting (XSS) en Safari. Este problema se abordó con una validación de URL mejorada. • https://support.apple.com/kb/HT209192 https://support.apple.com/kb/HT209195 https://support.apple.com/kb/HT209196 https://support.apple.com/kb/HT209197 https://support.apple.com/kb/HT209198 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-4388
https://notcve.org/view.php?id=CVE-2018-4388
A lock screen issue allowed access to the share function on a locked device. This issue was addressed by restricting options offered on a locked device. This issue affected versions prior to iOS 12.1. Un problema de pantalla de bloqueo permitía el acceso a la función "share" en un dispositivo bloqueado. El problema se abordó restringiendo las opciones que se ofrecían en el dispositivo bloqueado. • https://support.apple.com/kb/HT209192 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •