
CVE-2017-7158
https://notcve.org/view.php?id=CVE-2017-7158
25 Dec 2017 — An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Screen Sharing Server" component. It allows attackers to obtain root privileges for reading files by leveraging screen-sharing access. Se ha descubierto un problema en algunos productos Apple. Se han visto afectadas las versiones de macOS anteriores a la 10.13.2. • https://support.apple.com/HT208331 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-7159
https://notcve.org/view.php?id=CVE-2017-7159
25 Dec 2017 — An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "IOAcceleratorFamily" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. Se ha descubierto un problema en algunos productos Apple. Se han visto afectadas las versiones de macOS anteriores a la 10.13.2. • https://support.apple.com/HT208331 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-7162 – Apple iOS backboardd Double Free Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2017-7162
25 Dec 2017 — An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "IOKit" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11.2, las versiones de macOS anteriores a la 10.13.2, las ver... • https://support.apple.com/HT208325 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-7163
https://notcve.org/view.php?id=CVE-2017-7163
25 Dec 2017 — An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. Se ha descubierto un problema en algunos productos Apple. Se han visto afectadas las versiones de macOS anteriores a la 10.13.2. • https://support.apple.com/HT208331 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-13847 – Apple macOS/iOS - Multiple Kernel Use-After-Frees due to Incorrect IOKit Object Lifetime Management in IOTimeSyncClockManagerUserClient
https://notcve.org/view.php?id=CVE-2017-13847
08 Dec 2017 — An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. The issue involves the "IOKit" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. Se ha descubierto un problema en ciertos productos Apple. Se han visto afectadas las versiones de iOS anteriores a la 11.2 y las versiones de macOS anteriores a la 10.13.2. • https://packetstorm.news/files/id/145361 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-13848 – Apple Security Advisory 2017-12-6-1
https://notcve.org/view.php?id=CVE-2017-13848
08 Dec 2017 — An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "IOKit" component. It allows attackers to execute arbitrary code in a privileged context via a crafted app. Se ha descubierto un problema en algunos productos Apple. Se han visto afectadas las versiones de macOS anteriores a la 10.13.2. • http://www.securityfocus.com/bid/102099 • CWE-20: Improper Input Validation •

CVE-2017-13855 – Apple macOS - 'necp_get_socket_attributes' so_pcb Type Confusion
https://notcve.org/view.php?id=CVE-2017-13855
08 Dec 2017 — An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app that triggers type confusion. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11.2, las versiones de macOS anteriores a la 10.13.2, las versiones de tvOS anteriores... • https://packetstorm.news/files/id/145363 • CWE-704: Incorrect Type Conversion or Cast •

CVE-2017-13858 – Apple Security Advisory 2017-12-6-1
https://notcve.org/view.php?id=CVE-2017-13858
08 Dec 2017 — An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "IOKit" component. It allows attackers to execute arbitrary code in a privileged context via a crafted app. Se ha descubierto un problema en algunos productos Apple. Se han visto afectadas las versiones de macOS anteriores a la 10.13.2. • http://www.securityfocus.com/bid/102099 • CWE-20: Improper Input Validation •

CVE-2017-13860 – Apple Security Advisory 2017-12-6-2
https://notcve.org/view.php?id=CVE-2017-13860
08 Dec 2017 — An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. The issue involves the "Mail Drafts" component. It allows man-in-the-middle attackers to read e-mail content by leveraging mishandling of S/MIME credential encryption. Se ha descubierto un problema en ciertos productos Apple. Se han visto afectadas las versiones de iOS anteriores a la 11.2 y las versiones de macOS anteriores a la 10.13.2. • http://www.securityfocus.com/bid/102097 •

CVE-2017-13862 – Apple Security Advisory 2017-12-6-4
https://notcve.org/view.php?id=CVE-2017-13862
08 Dec 2017 — An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11.2, las versiones de macOS anteriores a la 10.13.2, las ve... • http://www.securityfocus.com/bid/102100 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •