CVE-2018-4208
https://notcve.org/view.php?id=CVE-2018-4208
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks. En iOS en versiones anteriores a la 11.3, Safari en versiones anteriores a la 11.1, iCloud para Windows en versiones anteriores a la 7.4, tvOS en versiones anteriores a la 11.3, watchOS en versiones anteriores a la 4.3 e iTunes en versiones anteriores a la 12.7.4 para Windows, una interacción inesperada provoca un fallo ASSERT. Este problema se abordó mediante la mejora de las comprobaciones. • https://security.gentoo.org/glsa/201812-04 https://support.apple.com/HT208693%2C https://support.apple.com/HT208694%2C https://support.apple.com/HT208695%2C https://support.apple.com/HT208696 https://support.apple.com/HT208697%2C https://support.apple.com/HT208698%2C https://usn.ubuntu.com/3781-1 • CWE-20: Improper Input Validation •
CVE-2018-4209
https://notcve.org/view.php?id=CVE-2018-4209
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks. En iOS en versiones anteriores a la 11.3, Safari en versiones anteriores a la 11.1, iCloud para Windows en versiones anteriores a la 7.4, tvOS en versiones anteriores a la 11.3, watchOS en versiones anteriores a la 4.3 e iTunes en versiones anteriores a la 12.7.4 para Windows, una interacción inesperada provoca un fallo ASSERT. Este problema se abordó mediante la mejora de las comprobaciones. • https://security.gentoo.org/glsa/201812-04 https://support.apple.com/HT208693%2C https://support.apple.com/HT208694 https://support.apple.com/HT208695%2C https://support.apple.com/HT208696%2C https://support.apple.com/HT208697%2C https://support.apple.com/HT208698%2C https://support.apple.com/en-us/HT208693 https://support.apple.com/en-us/HT208695 https://support.apple.com/en-us/HT208696 https://support.apple.com/en-us/HT208697 https://support.apple.com/en-us • CWE-20: Improper Input Validation •
CVE-2018-4319
https://notcve.org/view.php?id=CVE-2018-4319
A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue affected versions prior to iOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7. Existía un problema de orígenes cruzados con elementos "iframe". Este problema se abordó con una rastreo de orígenes de la seguridad mejorado. • https://support.apple.com/kb/HT209106 https://support.apple.com/kb/HT209108 https://support.apple.com/kb/HT209109 https://support.apple.com/kb/HT209140 https://support.apple.com/kb/HT209141 • CWE-346: Origin Validation Error •
CVE-2018-4311
https://notcve.org/view.php?id=CVE-2018-4311
The issue was addressed by removing origin information. This issue affected versions prior to iOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7. El problema se abordó eliminando la información de origen. El problema afectaba a iOS en versiones anteriores a la 12, watchOS en versiones anteriores a la 5, Safari en versiones anteriores a la 12, iTunes para Windows en versiones anteriores a la 12.9 y iCloud para Windows en versiones anteriores a la 7.7. • https://support.apple.com/kb/HT209106 https://support.apple.com/kb/HT209108 https://support.apple.com/kb/HT209109 https://support.apple.com/kb/HT209140 https://support.apple.com/kb/HT209141 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2018-4314 – WebKit - 'WebCore::SVGAnimateElementBase::resetAnimatedType' Use-After-Free
https://notcve.org/view.php?id=CVE-2018-4314
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7. Se abordó un problema de uso de memoria previamente liberada con una gestión de memoria mejorada. El problema afectaba a iOS en versiones anteriores a la 12, tvOS en versiones anteriores a la 12, Safari en versiones anteriores a la 12, iTunes para Windows en versiones anteriores a la 12.9 y iCloud para Windows en versiones anteriores a la 7.7. WebKit suffers from a WebCore::SVGAnimateElementBase::resetAnimatedType use-after-free vulnerability. • https://www.exploit-db.com/exploits/45480 https://support.apple.com/kb/HT209106 https://support.apple.com/kb/HT209107 https://support.apple.com/kb/HT209109 https://support.apple.com/kb/HT209140 https://support.apple.com/kb/HT209141 • CWE-416: Use After Free •