CVE-2018-4131
https://notcve.org/view.php?id=CVE-2018-4131
30 Mar 2018 — An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. The issue involves the "WindowServer" component. It allows attackers to bypass the Secure Input Mode protection mechanism, and log keystrokes of arbitrary apps, via a crafted app that scans key states. Se ha descubierto un problema en ciertos productos Apple. Se han visto afectadas las versiones de iOS anteriores a la 11,3 y las versiones de macOS anteriores a la 10.13. • http://www.securityfocus.com/bid/103581 •
CVE-2018-4142
https://notcve.org/view.php?id=CVE-2018-4142
30 Mar 2018 — An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service (application crash) via a crafted string. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11.3, las versiones de macOS anteriores a la 10.13.4, las versiones de tvOS anteriores a la 11.3 y... • http://www.securitytracker.com/id/1040604 • CWE-20: Improper Input Validation •
CVE-2018-4143
https://notcve.org/view.php?id=CVE-2018-4143
30 Mar 2018 — An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11.3, las versiones de macOS anteriores a la 10.13.4, las ve... • http://www.securitytracker.com/id/1040604 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2018-4144
https://notcve.org/view.php?id=CVE-2018-4144
30 Mar 2018 — An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "Security" component. A buffer overflow allows attackers to execute arbitrary code in a privileged context via a crafted app. Se ha descubierto un problema en ciertos productos Apple. Se han visto afectadas las versiones de iO... • http://www.securityfocus.com/bid/103582 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2018-4150
https://notcve.org/view.php?id=CVE-2018-4150
30 Mar 2018 — An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11.3, las versiones de macOS anteriores a la 10.13.4, las ve... • https://github.com/Jailbreaks/CVE-2018-4150 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2018-4115
https://notcve.org/view.php?id=CVE-2018-4115
30 Mar 2018 — An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves CFPreferences in the "System Preferences" component. It allows attackers to bypass intended access restrictions by leveraging incorrect configuration-profile persistence. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11.3, las versiones de macOS anteriores a la 10.13.... • http://www.securitytracker.com/id/1040604 • CWE-281: Improper Preservation of Permissions •
CVE-2018-4124
https://notcve.org/view.php?id=CVE-2018-4124
19 Feb 2018 — An issue was discovered in certain Apple products. iOS before 11.2.6 is affected. macOS before 10.13.3 Supplemental Update is affected. tvOS before 11.2.6 is affected. watchOS before 4.2.3 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via a crafted string containing a certain Telugu character. Se ha descubierto un problema en algunos productos Apple. Las versione... • https://github.com/jamf/TELUGU_CVE-2018-4124_POC • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2018-4083 – macOS Kernel - Use-After-Free Due to Lack of Locking in 'AppleEmbeddedOSSupportHostClient::registerNotificationPort'
https://notcve.org/view.php?id=CVE-2018-4083
08 Feb 2018 — An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue involves the "Touch Bar Support" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. Se ha descubierto un problema en algunos productos Apple. Las versiones de macOS anteriores a la 10.13.3 se han visto afectadas. • https://www.exploit-db.com/exploits/44007 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2017-7172 – Apple Safari UIProcess Out-Of-Bounds Access Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2017-7172
07 Feb 2018 — An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "CFNetwork Session" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. Se ha descubierto un problema en ciertos productos Apple.... • https://support.apple.com/HT208325 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2017-7171 – Apple iOS backboardd Untrusted Pointer Dereference Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2017-7171
07 Feb 2018 — An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "CoreAnimation" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11.2, las versiones de macOS anteriores a la 10.13.2,... • https://support.apple.com/HT208325 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •