CVE-2017-13844
https://notcve.org/view.php?id=CVE-2017-13844
An issue was discovered in certain Apple products. iOS before 11.1 is affected. The issue involves the "Messages" component. It allows physically proximate attackers to view arbitrary photos via a Reply With Message action in the lock-screen state. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11.1 se han visto afectadas. • http://www.securityfocus.com/bid/102099 http://www.securitytracker.com/id/1039703 https://support.apple.com/HT208222 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2017-13805
https://notcve.org/view.php?id=CVE-2017-13805
An issue was discovered in certain Apple products. iOS before 11.1 is affected. The issue involves the "Siri" component. It allows physically proximate attackers to obtain sensitive information via a Siri request for private-content notifications that should not have been available in the lock-screen state. Se ha descubierto un problema en algunos productos Apple. Se han visto afectadas las versiones de iOS anteriores a la 11.1. • http://www.securitytracker.com/id/1039703 https://support.apple.com/HT208222 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2017-7113
https://notcve.org/view.php?id=CVE-2017-7113
An issue was discovered in certain Apple products. iOS before 11.1 is affected. The issue involves the "UIKit" component. It allows attackers to bypass intended read restrictions for secure text fields via vectors involving a focus-change event. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11.1 se han visto afectadas. • http://www.securitytracker.com/id/1039703 https://support.apple.com/HT208222 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2017-13802 – WebKit - 'WebCore::Style::TreeResolver::styleForElement' Use-After-Free
https://notcve.org/view.php?id=CVE-2017-13802
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. Se ha descubierto un problema en algunos productos Apple. • https://www.exploit-db.com/exploits/43173 http://www.securitytracker.com/id/1039703 https://security.gentoo.org/glsa/201712-01 https://support.apple.com/HT208219 https://support.apple.com/HT208222 https://support.apple.com/HT208223 https://support.apple.com/HT208224 https://support.apple.com/HT208225 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2017-13799
https://notcve.org/view.php?id=CVE-2017-13799
An issue was discovered in certain Apple products. iOS before 11.1 is affected. macOS before 10.13.1 is affected. tvOS before 11.1 is affected. watchOS before 4.1 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. Se ha descubierto un problema en algunos productos Apple. Se han visto afectadas las versiones de iOS anteriores a la 11.1, las versiones de macOS anteriores a la 10.13.1, las versiones de tvOS anteriores a la 11.1 y las versiones de watchOS anteriores a la 4.1. • http://www.securitytracker.com/id/1039703 https://support.apple.com/HT208219 https://support.apple.com/HT208220 https://support.apple.com/HT208221 https://support.apple.com/HT208222 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •