CVE-2018-4205
https://notcve.org/view.php?id=CVE-2018-4205
04 Jun 2018 — An issue was discovered in certain Apple products. Safari before 11.1.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site. Se ha descubierto un problema en algunos productos Apple. • http://www.securityfocus.com/bid/104358 • CWE-20: Improper Input Validation •
CVE-2018-4233 – Apple Safari CreateThis Type Confusion Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2018-4233
04 Jun 2018 — An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. Se ha descubierto un problema en algunos productos Apple... • https://www.exploit-db.com/exploits/45998 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2018-4192 – JavaScript Core - Arbitrary Code Execution
https://notcve.org/view.php?id=CVE-2018-4192
04 Jun 2018 — An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code via a crafted web site that leverages a race condition. Se ha descubierto un problema en algunos productos Apple. • https://www.exploit-db.com/exploits/45048 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •
CVE-2018-4214
https://notcve.org/view.php?id=CVE-2018-4214
04 Jun 2018 — An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to cause a denial of service (memory corruption and Safari crash) or possibly have unspecified other impact via a crafted web site. Se ha descubierto un problema en algunos prod... • http://www.securitytracker.com/id/1041029 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2018-4232
https://notcve.org/view.php?id=CVE-2018-4232
04 Jun 2018 — An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to overwrite cookies via a crafted web site. Se ha descubierto un problema en algunos productos Apple. • http://www.securitytracker.com/id/1041029 •
CVE-2018-4218 – WebKit - Use-After-Free when Resuming Generator
https://notcve.org/view.php?id=CVE-2018-4218
04 Jun 2018 — An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site that triggers an @generatorState use-after-free. Se ha de... • https://www.exploit-db.com/exploits/44861 • CWE-416: Use After Free •
CVE-2018-4247
https://notcve.org/view.php?id=CVE-2018-4247
04 Jun 2018 — An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. The issue involves the "Safari" component. It allows remote attackers to cause a denial of service (persistent Safari outage) via a crafted web site. Se ha descubierto un problema en algunos productos Apple. • http://www.securityfocus.com/bid/104366 • CWE-20: Improper Input Validation •
CVE-2018-4190
https://notcve.org/view.php?id=CVE-2018-4190
04 Jun 2018 — An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive credential information that is transmitted during a CSS mask-image fetch. Se ha descubierto un problema en algunos productos Apple. • http://www.securitytracker.com/id/1041029 • CWE-522: Insufficiently Protected Credentials •
CVE-2018-4246
https://notcve.org/view.php?id=CVE-2018-4246
04 Jun 2018 — An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code via a crafted web site that leverages type confusion. Se ha descubierto un problema en algunos productos Apple. • http://www.securitytracker.com/id/1041029 • CWE-704: Incorrect Type Conversion or Cast •
CVE-2018-4188
https://notcve.org/view.php?id=CVE-2018-4188
04 Jun 2018 — An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to spoof the address bar via a crafted web site. Se ha descubierto un problema en algunos productos Apple. • http://www.securitytracker.com/id/1041029 • CWE-20: Improper Input Validation •