CVE-2018-4222 – WebKit - WebAssembly Compilation Info Leak
https://notcve.org/view.php?id=CVE-2018-4222
04 Jun 2018 — An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code via a crafted web site that leverages a getWasmBufferFromValue out-of-bounds read during WebAssembly compilation. Se ha descubierto un problema en algu... • https://packetstorm.news/files/id/148089 • CWE-125: Out-of-bounds Read •
CVE-2018-4200 – WebKit - 'WebCore::jsElementScrollHeightGetter' Use-After-Free
https://notcve.org/view.php?id=CVE-2018-4200
26 Apr 2018 — An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. Safari before 11.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site that triggers a WebCore::jsElementScrollHeightGetter use-after-free. Se ha descubierto un p... • https://packetstorm.news/files/id/147421 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-416: Use After Free •
CVE-2018-4204 – Apple Safari Array splice Out-Of-Bounds Access Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2018-4204
26 Apr 2018 — An issue was discovered in certain Apple products. iOS before 11.4 is affected. iOS before 11.3.1 is affected. Safari before 11.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. Se ha descubierto un problema en ciertos productos Apple. • http://www.securityfocus.com/bid/103961 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2017-2492
https://notcve.org/view.php?id=CVE-2017-2492
03 Apr 2018 — An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "JavaScriptCore" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that triggers prototype mishandling. Se ha descubierto un problema en algunos productos Apple. • https://support.apple.com/HT207600 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-4101 – Ubuntu Security Notice USN-3635-1
https://notcve.org/view.php?id=CVE-2018-4101
30 Mar 2018 — An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. Se ha descubierto un problema en algunos productos Apple. • http://www.securitytracker.com/id/1040604 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2018-4102 – Apple Security Advisory 2018-3-29-6
https://notcve.org/view.php?id=CVE-2018-4102
30 Mar 2018 — An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site. Se ha descubierto un problema en algunos productos Apple. • http://www.securityfocus.com/bid/103580 • CWE-20: Improper Input Validation •
CVE-2018-4113 – Ubuntu Security Notice USN-3635-1
https://notcve.org/view.php?id=CVE-2018-4113
30 Mar 2018 — An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves a JavaScriptCore function in the "WebKit" component. It allows attackers to trigger an assertion failure by leveraging improper array indexing. Se ha descubierto un problema en algunos productos Apple. • http://www.securitytracker.com/id/1040604 • CWE-617: Reachable Assertion •
CVE-2018-4114 – Ubuntu Security Notice USN-3635-1
https://notcve.org/view.php?id=CVE-2018-4114
30 Mar 2018 — An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. Se ha descubierto un problema en algunos productos Apple. • http://www.securitytracker.com/id/1040604 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2018-4116 – Apple Security Advisory 2018-3-29-6
https://notcve.org/view.php?id=CVE-2018-4116
30 Mar 2018 — An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site. Se ha descubierto un problema en algunos productos Apple. • http://www.securitytracker.com/id/1040606 • CWE-20: Improper Input Validation •
CVE-2018-4117 – chromium-browser: Cross origin information leak in Blink
https://notcve.org/view.php?id=CVE-2018-4117
30 Mar 2018 — An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is affected. The issue involves the fetch API in the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site. Se ha descubierto un problema en algunos productos Apple. • http://www.securityfocus.com/bid/104887 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •