
CVE-2017-13816 – Apple Security Advisory 2017-10-31-2
https://notcve.org/view.php?id=CVE-2017-13816
01 Nov 2017 — An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "libarchive" component. It allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a crafted archive file. Se ha descubierto un problema en algunos productos Apple. Las versiones de macOS anteriores a la 10.13.1 se han visto afectadas. • http://www.securitytracker.com/id/1039710 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-13819 – Apple Security Advisory 2017-10-31-2
https://notcve.org/view.php?id=CVE-2017-13819
01 Nov 2017 — An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "HelpViewer" component. A cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML by bypassing the Same Origin Policy for quarantined HTML documents. Se ha descubierto un problema en algunos productos Apple. Las versiones de macOS anteriores a la 10.13.1 se han visto afectadas. • http://www.securitytracker.com/id/1039710 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-13811 – Apple Security Advisory 2017-10-31-2
https://notcve.org/view.php?id=CVE-2017-13811
01 Nov 2017 — An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "fsck_msdos" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. Se ha descubierto un problema en algunos productos Apple. Las versiones de macOS anteriores a la 10.13.1 se han visto afectadas. • http://www.securitytracker.com/id/1039710 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-13840 – Apple Security Advisory 2017-10-31-2
https://notcve.org/view.php?id=CVE-2017-13840
01 Nov 2017 — An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app. Se ha descubierto un problema en algunos productos Apple. Las versiones de macOS anteriores a la 10.13.1 se han visto afectadas. • http://www.securitytracker.com/id/1039710 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2017-13830 – Apple Security Advisory 2017-10-31-2
https://notcve.org/view.php?id=CVE-2017-13830
01 Nov 2017 — An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "HFS" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. Se ha descubierto un problema en algunos productos Apple. Las versiones de macOS anteriores a la 10.13.1 se han visto afectadas. • http://www.securitytracker.com/id/1039710 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-13838 – Apple Security Advisory 2017-10-31-2
https://notcve.org/view.php?id=CVE-2017-13838
01 Nov 2017 — An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Sandbox" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. Se ha descubierto un problema en algunos productos Apple. Las versiones de macOS anteriores a la 10.13.1 se han visto afectadas. • http://www.securitytracker.com/id/1039710 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-13782 – Apple XNU Kernel Memory Exposure
https://notcve.org/view.php?id=CVE-2017-13782
01 Nov 2017 — An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a /dev/dtracehelper attack involving the dtrace_dif_variable and dtrace_getarg functions. Se ha descubierto un problema en algunos productos Apple. Se han visto afectadas las versiones de macOS anteriores a la 10.13.1. • https://packetstorm.news/files/id/172827 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2017-13832 – Apple Security Advisory 2017-10-31-2
https://notcve.org/view.php?id=CVE-2017-13832
01 Nov 2017 — An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "802.1X" component. It allows attackers to have an unspecified impact by leveraging TLS 1.0 support. Se ha descubierto un problema en algunos productos Apple. Las versiones de macOS anteriores a la 10.13.1 se han visto afectadas. • http://www.securitytracker.com/id/1039710 •

CVE-2017-7150 – Apple Security Advisory 2017-10-05-1
https://notcve.org/view.php?id=CVE-2017-7150
05 Oct 2017 — An issue was discovered in certain Apple products. macOS before 10.13 Supplemental Update is affected. The issue involves the "Security" component. It allows attackers to bypass the keychain access prompt, and consequently extract passwords, via a synthetic click. Se ha descubierto un problema en ciertos productos Apple. Se han visto afectadas las versiones de macOS anteriores a la 10.13 Supplemental Update. • http://www.securityfocus.com/bid/101177 • CWE-521: Weak Password Requirements •

CVE-2017-7149 – Apple Security Advisory 2017-10-05-1
https://notcve.org/view.php?id=CVE-2017-7149
05 Oct 2017 — An issue was discovered in certain Apple products. macOS before 10.13 Supplemental Update is affected. The issue involves the "StorageKit" component. It allows attackers to discover passwords for APFS encrypted volumes by reading Disk Utility hints, because the stored hint value was accidentally set to the password itself, not the entered hint value. Se ha descubierto un problema en ciertos productos Apple. Se han visto afectadas las versiones de macOS anteriores a la 10.13 Supplemental Update. • http://www.securityfocus.com/bid/101178 •