Vulnerabilities > Apple

DATE CVE VULNERABILITY TITLE RISK
2018-04-03 CVE-2017-13839 Information Exposure vulnerability in Apple mac OS X 10.13.0
An issue was discovered in certain Apple products.
local
low complexity
apple CWE-200
5.5
2018-04-03 CVE-2017-13837 Unspecified vulnerability in Apple mac OS X 10.13.0
An issue was discovered in certain Apple products.
network
low complexity
apple
7.5
2018-04-03 CVE-2017-13827 Unspecified vulnerability in Apple mac OS X 10.13.0
An issue was discovered in certain Apple products.
local
low complexity
apple
7.8
2018-04-03 CVE-2017-13806 Unspecified vulnerability in Apple Iphone OS
An issue was discovered in certain Apple products.
local
low complexity
apple
5.5
2018-03-26 CVE-2017-18248 Improper Input Validation vulnerability in Apple Cups
The add_job function in scheduler/ipp.c in CUPS before 2.2.6, when D-Bus support is enabled, can be crashed by remote attackers by sending print jobs with an invalid username, related to a D-Bus notification.
network
high complexity
apple CWE-20
5.3
2018-03-12 CVE-2014-8130 Divide By Zero vulnerability in multiple products
The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image that is mishandled by the TIFFWriteScanline function in tif_write.c, as demonstrated by tiffdither.
network
low complexity
libtiff redhat apple CWE-369
6.5
2018-03-12 CVE-2014-8129 Out-of-bounds Write vulnerability in multiple products
LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by failure of tif_next.c to verify that the BitsPerSample value is 2, and the t2p_sample_lab_signed_to_unsigned function in tiff2pdf.c.
network
low complexity
libtiff debian redhat apple CWE-787
8.8
2018-02-16 CVE-2017-18190 Authentication Bypass by Spoofing vulnerability in multiple products
A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 allows remote attackers to execute arbitrary IPP commands by sending POST requests to the CUPS daemon in conjunction with DNS rebinding.
network
low complexity
apple debian canonical CWE-290
7.5
2017-12-27 CVE-2017-7163 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple mac OS X
An issue was discovered in certain Apple products.
local
low complexity
apple CWE-119
7.8
2017-12-27 CVE-2017-7162 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple products
An issue was discovered in certain Apple products.
local
low complexity
apple CWE-119
7.8