CVE-2018-4309 – Apple Safari Subframe Same-Origin Policy Bypass Vulnerability
https://notcve.org/view.php?id=CVE-2018-4309
A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7. Existía un problema de Cross-Site Scripting (XSS) en Safari. Este problema se abordó con una validación de URL mejorada. • https://support.apple.com/kb/HT209106 https://support.apple.com/kb/HT209107 https://support.apple.com/kb/HT209109 https://support.apple.com/kb/HT209140 https://support.apple.com/kb/HT209141 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-4195
https://notcve.org/view.php?id=CVE-2018-4195
An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to Safari 12. Se abordó un problema de inconsistencia en la interfaz de usuario con una gestión de estado mejorada. Este problema afectaba a Safari en versiones anteriores a la 12. • https://support.apple.com/kb/HT209109 • CWE-20: Improper Input Validation •
CVE-2018-4307
https://notcve.org/view.php?id=CVE-2018-4307
A logic issue was addressed with improved state management. This issue affected versions prior to iOS 12, Safari 12. Un problema de lógica se abordó con una gestión de estado mejorada. Este problema afectaba a iOS en versiones anteriores a la 12 y Safari en versiones anteriores a la 12. • https://support.apple.com/kb/HT209106 https://support.apple.com/kb/HT209109 • CWE-20: Improper Input Validation •
CVE-2018-4329
https://notcve.org/view.php?id=CVE-2018-4329
Clearing a history item may not clear visits with redirect chains. The issue was addressed with improved data deletion. This issue affected versions prior to iOS 12, Safari 12. Limpiar un elemento del historial podría no limpiar las visitas con cadenas de redirección. Este problema se abordó con una supresión de datos mejorada. • https://support.apple.com/kb/HT209106 https://support.apple.com/kb/HT209109 • CWE-19: Data Processing Errors •
CVE-2018-4362
https://notcve.org/view.php?id=CVE-2018-4362
An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to Safari 11.1.2, iOS 12. Se abordó un problema de inconsistencia en la interfaz de usuario con una gestión de estado mejorada. Este problema afectaba a Safari, en versiones anteriores a la 11.1.2, y iOS en versiones anteriores a la 12. • https://support.apple.com/kb/HT208934 https://support.apple.com/kb/HT209106 • CWE-20: Improper Input Validation •