
CVE-2024-44157
https://notcve.org/view.php?id=CVE-2024-44157
11 Oct 2024 — A stack buffer overflow was addressed through improved input validation. This issue is fixed in Apple TV 1.5.0.152 for Windows, iTunes 12.13.3 for Windows. Parsing a maliciously crafted video file may lead to unexpected system termination. • https://support.apple.com/en-us/121328 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2020-27940
https://notcve.org/view.php?id=CVE-2020-27940
08 Sep 2021 — This issue was addressed with improved file handling. This issue is fixed in Apple TV app for Fire OS 6.1.0.6A142:7.1.0. An attacker with file system access may modify scripts used by the app. Este problema es abordado con una administración de archivos mejorada. Este problema se corrigió en Apple TV app for Fire OS versión 6.1.0.6A142:7.1.0. • https://support.apple.com/en-us/HT212197 •

CVE-2018-4189
https://notcve.org/view.php?id=CVE-2018-4189
11 Jan 2019 — In iOS before 11.2.5, macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, watchOS before 4.2.2, and tvOS before 11.2.5, a memory corruption issue exists and was addressed with improved memory handling. En iOS en versiones anteriores a la 11.2.5, macOS High Sierra en versiones anteriores a la 10.13.3, las actualizaciones de seguridad (Security Update) 2018-001 Sierra y 2018-001 El Capitan, watchOS en versiones anteriores a la 4.2.2 y tvOS en versiones a... • https://support.apple.com/HT208462 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2018-4298
https://notcve.org/view.php?id=CVE-2018-4298
11 Jan 2019 — In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, a permissions issue existed in Remote Management. This issue was addressed through improved permission validation. En macOS High Sierra en versiones anteriores a la 10.13.3, la actualización de seguridad (Security Update) 2018-001 Sierra y el Security Update 2018-001 El Capitan, existía un problema de permisos en la gestión remota. Este problema se abordó mediante la mejora de la validación de perm... • https://support.apple.com/HT208465 •

CVE-2016-4642
https://notcve.org/view.php?id=CVE-2016-4642
11 Jan 2019 — In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, proxy authentication incorrectly reported HTTP proxies received credentials securely. This issue was addressed through improved warnings. En iOS en versiones anteriores a la 9.3.3, tvOS en versiones anteriores a la 9.2.2 y OS X El Capitan en versiones anteriores a la v10.11.6 y la actualización de seguridad (Security Update) 2016-004, la autenticación por proxy reportó incorrectamente los proxies HTTP q... • https://support.apple.com/HT206902 • CWE-254: 7PK - Security Features •

CVE-2016-4643
https://notcve.org/view.php?id=CVE-2016-4643
11 Jan 2019 — In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a validation issue existed in the parsing of 407 responses. This issue was addressed through improved response validation. En iOS en versiones anteriores a la 9.3.3, tvOS en versiones anteriores a la 9.2.2 y OS X El Capitan en versiones anteriores a la v10.11.6 y la actualización de seguridad (Security Update) 2016-004, existía un problema de validación en el análisis de respuestas 407. Este problema se... • https://support.apple.com/HT206902 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2016-4644
https://notcve.org/view.php?id=CVE-2016-4644
11 Jan 2019 — In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a downgrade issue existed with HTTP authentication credentials saved in Keychain. This issue was addressed by storing the authentication types with the credentials. En iOS en versiones anteriores a la 9.3.3, tvOS en versiones anteriores a la 9.2.2 y OS X El Capitan en versiones anteriores a la v10.11.6 y la actualización de seguridad (Security Update) 2016-004, existía un problema de degradación con las... • https://support.apple.com/HT206902 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2018-4188 – Apple Security Advisory 2018-7-23-4
https://notcve.org/view.php?id=CVE-2018-4188
04 Jun 2018 — An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to spoof the address bar via a crafted web site. Se ha descubierto un problema en algunos productos Apple. • http://www.securitytracker.com/id/1041029 • CWE-20: Improper Input Validation •

CVE-2018-4198 – Apple Security Advisory 2018-7-23-4
https://notcve.org/view.php?id=CVE-2018-4198
01 Jun 2018 — An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "UIKit" component. It allows remote attackers to cause a denial of service via a crafted text file. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11.4, las versiones de macOS anteriores a la 10.13.5, las versiones de tvOS anteriores a la 11.4 y las versiones de ... • http://www.securitytracker.com/id/1041027 • CWE-20: Improper Input Validation •

CVE-2018-4211 – Apple Security Advisory 2018-7-23-4
https://notcve.org/view.php?id=CVE-2018-4211
01 Jun 2018 — An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "FontParser" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file. Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11.4, las versiones de macOS anteriores a l... • http://www.securitytracker.com/id/1041027 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •