Vulnerabilities > Apple > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-01-11 CVE-2018-4194 Out-of-bounds Read vulnerability in Apple products
In iOS before 11.4, iCloud for Windows before 7.5, watchOS before 4.3.1, iTunes before 12.7.5 for Windows, and macOS High Sierra before 10.13.5, an out-of-bounds read was addressed with improved input validation.
6.8
2019-01-11 CVE-2018-4186 Information Exposure vulnerability in Apple Safari
In Safari before 11.1, an information leakage issue existed in the handling of downloads in Safari Private Browsing.
network
low complexity
apple CWE-200
5.0
2019-01-11 CVE-2018-4185 Information Exposure vulnerability in Apple products
In iOS before 11.3, tvOS before 11.3, watchOS before 4.3, and macOS before High Sierra 10.13.4, an information disclosure issue existed in the transition of program state.
network
low complexity
apple CWE-200
5.0
2019-01-11 CVE-2018-4181 In macOS High Sierra before 10.13.5, an issue existed in CUPS.
local
low complexity
apple canonical debian
4.9
2019-01-11 CVE-2018-4180 In macOS High Sierra before 10.13.5, an issue existed in CUPS.
local
low complexity
apple debian canonical
4.6
2019-01-11 CVE-2018-4147 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple products
In iCloud for Windows before 7.3, Safari before 11.0.3, iTunes before 12.7.3 for Windows, and iOS before 11.2.5, multiple memory corruption issues exist and were addressed with improved memory handling.
6.8
2019-01-11 CVE-2017-2411 7PK - Security Features vulnerability in Apple Iphone OS
In iOS before 11.2, exchange rates were retrieved from HTTP rather than HTTPS.
network
apple CWE-254
4.3
2019-01-11 CVE-2017-13891 Improper Input Validation vulnerability in Apple Iphone OS
In iOS before 11.2, an inconsistent user interface issue was addressed through improved state management.
network
apple CWE-20
4.3
2019-01-11 CVE-2017-13888 Incorrect Type Conversion or Cast vulnerability in Apple Iphone OS
In iOS before 11.2, a type confusion issue was addressed with improved memory handling.
network
low complexity
apple CWE-704
5.0
2019-01-11 CVE-2017-13887 Key Management Errors vulnerability in Apple mac OS X
In macOS High Sierra before 10.13.2, a logic issue existed in APFS when deleting keys during hibernation.
network
low complexity
apple CWE-320
5.0