Apple Security Advisories · March 2018 — Apple Security Advisories
65 advisories 65 CVEs

Apple-vendor CVEs for 2018-03. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2018-4162

watchOSWeaponized exploitCRITICAL2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is a...

CVEs:CVE-2018-4162

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4121

watchOSWeaponized exploitCRITICAL2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is a...

CVEs:CVE-2018-4121

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4139

macOSWeaponized exploitHIGH2018-03-30

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "kext tools" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) v...

CVEs:CVE-2018-4139

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2018-4150

watchOSPoC exploitHIGH2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute ar...

CVEs:CVE-2018-4150

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4110

iOSPoC exploitCRITICAL2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "Web App" component. It allows remote attackers to bypass intended restrictions on cookie persistence.

CVEs:CVE-2018-4110

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

CVE-2018-4140

iOSCoalition ESS < 30%HIGH2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "Telephony" component. It allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via a Class 0 SMS message.

CVEs:CVE-2018-4140

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

CVE-2018-4117

watchOSCoalition ESS < 30%HIGH2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is affected. The issue involves th...

CVEs:CVE-2018-4117

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4142

watchOSCoalition ESS < 30%HIGH2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "CoreText" component. It allows remote attackers to c...

CVEs:CVE-2018-4142

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4164

XcodeCoalition ESS < 30%HIGH2018-03-30

An issue was discovered in certain Apple products. Xcode before 9.3 is affected. The issue, which is unspecified, involves the "LLVM" component.

CVEs:CVE-2018-4164

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple — —
Upstream advisory

CVE-2018-4137

iOSCoalition ESS < 30%HIGH2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. The issue involves the "Safari Login AutoFill" component. It allows remote attackers to read autofilled data by leveraging lack of a user-co...

CVEs:CVE-2018-4137

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
safari affected apple — —
Upstream advisory

CVE-2018-4115

watchOSCoalition ESS < 30%CRITICAL2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves CFPreferences in the "System Preferences" component. It a...

CVEs:CVE-2018-4115

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4113

watchOSCoalition ESS < 30%MEDIUM2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is a...

CVEs:CVE-2018-4113

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4122

watchOSCoalition ESS < 30%CRITICAL2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is a...

CVEs:CVE-2018-4122

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4129

watchOSCoalition ESS < 30%CRITICAL2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is a...

CVEs:CVE-2018-4129

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4112

macOSCoalition ESS < 30%HIGH2018-03-30

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "ATS" component. It allows attackers to obtain sensitive information by leveraging symlink mishandling.

CVEs:CVE-2018-4112

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2018-4114

watchOSCoalition ESS < 30%CRITICAL2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is a...

CVEs:CVE-2018-4114

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4125

watchOSCoalition ESS < 30%CRITICAL2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is a...

CVEs:CVE-2018-4125

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4163

watchOSCoalition ESS < 30%CRITICAL2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is a...

CVEs:CVE-2018-4163

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4107

macOSCoalition ESS < 30%MEDIUM2018-03-30

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "PDFKit" component. It allows remote attackers to bypass intended restrictions on visiting URLs within a PDF document.

CVEs:CVE-2018-4107

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2018-4144

watchOSCoalition ESS < 30%HIGH2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is...

CVEs:CVE-2018-4144

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4101

tvOSCoalition ESS < 30%CRITICAL2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the ...

CVEs:CVE-2018-4101

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2018-4118

tvOSCoalition ESS < 30%CRITICAL2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the ...

CVEs:CVE-2018-4118

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2018-4120

tvOSCoalition ESS < 30%CRITICAL2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the ...

CVEs:CVE-2018-4120

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2018-4127

tvOSCoalition ESS < 30%CRITICAL2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the ...

CVEs:CVE-2018-4127

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2018-4128

tvOSCoalition ESS < 30%CRITICAL2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the ...

CVEs:CVE-2018-4128

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2018-4119

tvOSCoalition ESS < 30%CRITICAL2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the ...

CVEs:CVE-2018-4119

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2018-4165

tvOSCoalition ESS < 30%CRITICAL2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the ...

CVEs:CVE-2018-4165

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2018-4161

watchOSCoalition ESS < 30%CRITICAL2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is a...

CVEs:CVE-2018-4161

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4130

tvOSCoalition ESS < 30%CRITICAL2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the ...

CVEs:CVE-2018-4130

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2018-4105

macOSCoalition ESS < 30%CRITICAL2018-03-30

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "APFS" component. It allows attackers to trigger truncation of an APFS volume password via an unspecified injection.

CVEs:CVE-2018-4105

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2018-4108

macOSCoalition ESS < 30%CRITICAL2018-03-30

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Disk Management" component. It allows attackers to trigger truncation of an APFS volume password via an unspecified injection.

CVEs:CVE-2018-4108

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2018-4106

macOSCoalition ESS < 30%HIGH2018-03-30

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the Bracketed Paste Mode of the "Terminal" component. It allows user-assisted attackers to inject arbitrary commands within pasted content.

CVEs:CVE-2018-4106

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2018-4134

iOSCoalition ESS < 30%HIGH2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the user interface via a crafted web site.

CVEs:CVE-2018-4134

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

CVE-2018-4149

iOSCoalition ESS < 30%HIGH2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "SafariViewController" component. It allows remote attackers to spoof the user interface via a crafted web site that leverages input into a partially...

CVEs:CVE-2018-4149

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

CVE-2018-4133

SafariCoalition ESS < 30%CRITICAL2018-03-30

An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involves the "WebKit" component. A Safari cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via a crafted...

CVEs:CVE-2018-4133

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple — —
Upstream advisory

CVE-2018-4136

macOSCoalition ESS < 30%HIGH2018-03-30

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (out-of-bounds read) via ...

CVEs:CVE-2018-4136

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2018-4160

macOSCoalition ESS < 30%HIGH2018-03-30

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (out-of-bounds read) via ...

CVEs:CVE-2018-4160

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2018-4174

macOSCoalition ESS < 30%MEDIUM2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. The issue involves the "Mail" component. It allows man-in-the-middle attackers to read S/MIME encrypted messages by leveraging an inconsis...

CVEs:CVE-2018-4174

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2018-4143

watchOSCoalition ESS < 30%HIGH2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute ar...

CVEs:CVE-2018-4143

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4132

macOSCoalition ESS < 30%HIGH2018-03-30

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory co...

CVEs:CVE-2018-4132

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2018-4135

macOSCoalition ESS < 30%HIGH2018-03-30

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "IOFireWireFamily" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corrupt...

CVEs:CVE-2018-4135

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2018-4146

watchOSCoalition ESS < 30%CRITICAL2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is a...

CVEs:CVE-2018-4146

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4116

SafariCoalition ESS < 30%MEDIUM2018-03-30

An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site.

CVEs:CVE-2018-4116

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple — —
Upstream advisory

CVE-2018-4102

SafariCoalition ESS < 30%MEDIUM2018-03-30

An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site.

CVEs:CVE-2018-4102

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple — —
Upstream advisory

CVE-2018-4131

macOSCoalition ESS < 30%HIGH2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. The issue involves the "WindowServer" component. It allows attackers to bypass the Secure Input Mode protection mechanism, and log keystro...

CVEs:CVE-2018-4131

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2018-4111

macOSCoalition ESS < 30%CRITICAL2018-03-30

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Mail" component. It allows man-in-the-middle attackers to read S/MIME encrypted message content by sending HTML e-mail that references remote r...

CVEs:CVE-2018-4111

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2018-4154

macOSCoalition ESS < 30%HIGH2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. The issue involves the "Storage" component. A race condition allows attackers to execute arbitrary code in a privileged context via a craf...

CVEs:CVE-2018-4154

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2018-4155

watchOSCoalition ESS < 30%HIGH2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "CoreFoundation" component. A race condition allows a...

CVEs:CVE-2018-4155

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4156

macOSCoalition ESS < 30%HIGH2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. The issue involves the "PluginKit" component. A race condition allows attackers to execute arbitrary code in a privileged context via a cr...

CVEs:CVE-2018-4156

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2018-4157

watchOSCoalition ESS < 30%HIGH2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "Quick Look" component. A race condition allows attac...

CVEs:CVE-2018-4157

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4166

watchOSCoalition ESS < 30%HIGH2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "NSURLSession" component. A race condition allows att...

CVEs:CVE-2018-4166

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4167

watchOSCoalition ESS < 30%HIGH2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "File System Events" component. A race condition allo...

CVEs:CVE-2018-4167

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4104

watchOSCoalition ESS < 30%MEDIUM2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "Kernel" component. It allows attackers to bypass int...

CVEs:CVE-2018-4104

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4151

macOSCoalition ESS < 30%HIGH2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. The issue involves the "iCloud Drive" component. A race condition allows attackers to execute arbitrary code in a privileged context via a...

CVEs:CVE-2018-4151

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2018-4158

watchOSCoalition ESS < 30%HIGH2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. watchOS before 4.3 is affected. The issue involves the "CoreFoundation" component. A race condition allows attackers to execute arbitrary ...

CVEs:CVE-2018-4158

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4138

macOSCoalition ESS < 30%MEDIUM2018-03-30

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "NVIDIA Graphics Drivers" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.

CVEs:CVE-2018-4138

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2018-4175

macOSCoalition ESS < 30%HIGH2018-03-30

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "LaunchServices" component. It allows attackers to bypass the code-signing protection mechanism via a crafted app.

CVEs:CVE-2018-4175

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2018-4152

macOSCoalition ESS < 30%HIGH2018-03-30

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Notes" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.

CVEs:CVE-2018-4152

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2018-4176

macOSCoalition ESS < 30%MEDIUM2018-03-30

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Disk Images" component. It allows attackers to trigger an app launch upon mounting a crafted disk image.

CVEs:CVE-2018-4176

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2018-4172

iOSCoalition ESS < 30%MEDIUM2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "Find My iPhone" component. It allows physically proximate attackers to bypass the iCloud password requirement for disabling the "Find My iPhone" fea...

CVEs:CVE-2018-4172

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

CVE-2018-4168

iOSCoalition ESS < 30%HIGH2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "Files Widget" component. It allows physically proximate attackers to obtain sensitive information by leveraging the display of cached data on a lock...

CVEs:CVE-2018-4168

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

CVE-2018-4123

iOSCoalition ESS < 30%LOW2018-03-30

An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves alarm and timer handling in the "Clock" component. It allows physically proximate attackers to discover the iTunes e-mail address.

CVEs:CVE-2018-4123

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

CVE-2018-4170

macOSCoalition ESS < 30%HIGH2018-03-30

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Admin Framework" component. It allows local users to discover a password by listing a process and its arguments during sysadminctl execution.

CVEs:CVE-2018-4170

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2017-18248

OtherEPSS <= 49%HIGH2018-03-26

The add_job function in scheduler/ipp.c in CUPS before 2.2.6, when D-Bus support is enabled, can be crashed by remote attackers by sending print jobs with an invalid username, related to a D-Bus notification.

CVEs:CVE-2017-18248

Affected products

ProductStatusVendorPackageEcosystem
cups affected apple — —
Upstream advisory

CVE-2017-13890

macOSEPSS <= 49%HIGH2018-03-30

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. macOS before 10.13 is affected. The issue involves the "CoreTypes" component. It allows remote attackers to trigger disk-image mounting via a crafted web site.

CVEs:CVE-2017-13890

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.