Vulnerabilities > Apple > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-04-03 CVE-2017-13884 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple products
An issue was discovered in certain Apple products.
6.8
2018-04-03 CVE-2017-13877 Information Exposure vulnerability in Apple Iphone OS
An issue was discovered in certain Apple products.
network
apple CWE-200
4.3
2018-04-03 CVE-2017-13873 Information Exposure vulnerability in Apple products
An issue was discovered in certain Apple products.
network
apple CWE-200
4.3
2018-04-03 CVE-2017-13863 Improper Certificate Validation vulnerability in Apple Iphone OS
An issue was discovered in certain Apple products.
network
apple CWE-295
4.3
2018-04-03 CVE-2017-13850 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple mac OS X
An issue was discovered in certain Apple products.
network
apple CWE-119
5.8
2018-04-03 CVE-2017-13837 Unspecified vulnerability in Apple mac OS X 10.13.0
An issue was discovered in certain Apple products.
network
low complexity
apple
5.0
2018-04-03 CVE-2017-13806 Unspecified vulnerability in Apple Iphone OS
An issue was discovered in certain Apple products.
network
apple
4.3
2018-03-12 CVE-2014-8130 Divide By Zero vulnerability in multiple products
The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image that is mishandled by the TIFFWriteScanline function in tif_write.c, as demonstrated by tiffdither.
4.3
2018-02-16 CVE-2017-18190 Authentication Bypass by Spoofing vulnerability in multiple products
A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 allows remote attackers to execute arbitrary IPP commands by sending POST requests to the CUPS daemon in conjunction with DNS rebinding.
network
low complexity
apple debian canonical CWE-290
5.0
2018-01-11 CVE-2017-4950 Integer Overflow or Wraparound vulnerability in VMWare Fusion and Workstation
VMware Workstation and Fusion contain an integer overflow vulnerability in VMware NAT service when IPv6 mode is enabled.
6.9