Vulnerabilities > Apple > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-05-22 CVE-2019-7141 Out-of-bounds Read vulnerability in Adobe Acrobat DC and Acrobat Reader DC
Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have an out-of-bounds read vulnerability.
4.3
2019-05-22 CVE-2019-7140 Out-of-bounds Read vulnerability in Adobe Acrobat DC and Acrobat Reader DC
Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have an out-of-bounds read vulnerability.
4.3
2019-05-17 CVE-2019-12172 Path Traversal vulnerability in Typora 0.9.9.21.1
Typora 0.9.9.21.1 (1913) allows arbitrary code execution via a modified file: URL syntax in the HREF attribute of an AREA element, as demonstrated by file:\\\ on macOS or Linux, or file://C| on Windows.
6.8
2019-05-16 CVE-2019-12137 Path Traversal vulnerability in Typora 0.9.9.24.6
Typora 0.9.9.24.6 on macOS allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substring in a shared note.
network
typora apple CWE-22
6.8
2019-04-03 CVE-2018-4470 Unspecified vulnerability in Apple mac OS X
A privacy issue in the handling of Open Directory records was addressed with improved indexing.
network
apple
4.3
2019-04-03 CVE-2018-4464 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple products
Multiple memory corruption issues were addressed with improved memory handling.
6.8
2019-04-03 CVE-2018-4462 Improper Input Validation vulnerability in Apple mac OS X
A validation issue was addressed with improved input sanitization.
network
apple CWE-20
4.3
2019-04-03 CVE-2018-4460 Improper Input Validation vulnerability in Apple products
A denial of service issue was addressed by removing the vulnerable code.
network
low complexity
apple CWE-20
4.0
2019-04-03 CVE-2018-4446 Improper Input Validation vulnerability in Apple Iphone OS
This issue was addressed with improved entitlements.
network
apple CWE-20
4.3
2019-04-03 CVE-2018-4445 Information Exposure vulnerability in Apple Iphone OS and Safari
"Clear History and Website Data" did not clear the history.
network
low complexity
apple CWE-200
4.0