CVE-2017-13839 – Apple Security Advisory 2017-10-31-8
https://notcve.org/view.php?id=CVE-2017-13839
02 Nov 2017 — An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "Spotlight" component. It allows local users to see results for other users' files. Se ha descubierto un problema en ciertos productos Apple. Se han visto afectadas las versiones de macOS anteriores a la 10.13. • https://support.apple.com/HT208144 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2017-13837 – Apple Security Advisory 2017-10-31-8
https://notcve.org/view.php?id=CVE-2017-13837
02 Nov 2017 — An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "Installer" component. It does not properly restrict an app's entitlements for accessing the FileVault unlock key. Se ha descubierto un problema en ciertos productos Apple. Se han visto afectadas las versiones de macOS anteriores a la 10.13. • https://support.apple.com/HT208144 •
CVE-2017-13827 – Apple Security Advisory 2017-10-31-8
https://notcve.org/view.php?id=CVE-2017-13827
02 Nov 2017 — An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "kext tools" component. It allows attackers to execute arbitrary code in a privileged context via a crafted app that performs kext loading. Se ha descubierto un problema en ciertos productos Apple. Se han visto afectadas las versiones de macOS anteriores a la 10.13. • https://support.apple.com/HT208144 •
CVE-2017-13825 – Apple Security Advisory 2017-10-31-2
https://notcve.org/view.php?id=CVE-2017-13825
01 Nov 2017 — An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "CoreText" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory consumption) via a crafted font file. Se ha descubierto un problema en algunos productos Apple. Las versiones de macOS anteriores a la 10.13.1 se han visto afectadas. • http://www.securitytracker.com/id/1039710 • CWE-400: Uncontrolled Resource Consumption •
CVE-2017-13834 – Apple Security Advisory 2017-10-31-2
https://notcve.org/view.php?id=CVE-2017-13834
01 Nov 2017 — An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted mach binary. Se ha descubierto un problema en algunos productos Apple. Las versiones de macOS anteriores a la 10.13.1 se han visto afectadas. • http://www.securitytracker.com/id/1039710 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2017-13842 – Apple Security Advisory 2017-10-31-2
https://notcve.org/view.php?id=CVE-2017-13842
01 Nov 2017 — An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app. Se ha descubierto un problema en algunos productos Apple. Las versiones de macOS anteriores a la 10.13.1 se han visto afectadas. • http://www.securitytracker.com/id/1039710 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2017-13814 – Apple Security Advisory 2017-10-31-2
https://notcve.org/view.php?id=CVE-2017-13814
01 Nov 2017 — An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "ImageIO" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted image file. Se ha descubierto un problema en algunos productos Apple. Las versiones de macOS anteriores a la 10.13.1 se han visto afectadas. • http://www.securitytracker.com/id/1039710 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2017-13823 – Apple Security Advisory 2017-10-31-2
https://notcve.org/view.php?id=CVE-2017-13823
01 Nov 2017 — An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "QuickTime" component. It allows attackers to bypass intended memory-read restrictions via a crafted app. Se ha descubierto un problema en algunos productos Apple. Las versiones de macOS anteriores a la 10.13.1 se han visto afectadas. • http://www.securitytracker.com/id/1039710 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2017-13836 – Apple Security Advisory 2017-10-31-2
https://notcve.org/view.php?id=CVE-2017-13836
01 Nov 2017 — An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app. Se ha descubierto un problema en algunos productos Apple. Las versiones de macOS anteriores a la 10.13.1 se han visto afectadas. • http://www.securitytracker.com/id/1039710 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2017-13817 – Apple Security Advisory 2017-10-31-2
https://notcve.org/view.php?id=CVE-2017-13817
01 Nov 2017 — An out-of-bounds read issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows local users to bypass intended memory-read restrictions. Se ha descubierto un problema de lectura fuera de límites en algunos productos Apple. Las versiones de macOS anteriores a la 10.13.1 se han visto afectadas. • http://www.securitytracker.com/id/1039710 • CWE-125: Out-of-bounds Read •