Advisories
OtherWeaponized exploitMEDIUM2019-04-03
The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access to the web interface when the web interface is enabled. This issue affected versions prior to v2.2.10.
CVEs:CVE-2018-4300
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| cups |
affected |
apple |
— |
— |
macOSActive exploitation (sightings)HIGH2019-04-03
A memory initialization issue was addressed with improved memory handling. This issue affected versions prior to macOS Mojave 10.14.1.
CVEs:CVE-2018-4421
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
iOSPoC exploitHIGH2019-04-03
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1.
CVEs:CVE-2018-4327
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
watchOSPoC exploitHIGH2019-04-03
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
CVEs:CVE-2018-4343
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| mac_os_x |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
tvOSEPSS <= 49%CRITICAL2019-04-03
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
CVEs:CVE-2018-4360
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| icloud |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
watchOSEPSS <= 49%HIGH2019-04-03
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
CVEs:CVE-2018-4332
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| mac_os_x |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
watchOSEPSS <= 49%CRITICAL2019-04-03
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.3, tvOS 11.3, watchOS 4.3, Safari 11.1, iTunes 12.7.4 for Windows, iCloud for Windows 7.4.
CVEs:CVE-2018-4145
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| icloud |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
watchOSEPSS <= 49%CRITICAL2019-04-03
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5, iTunes 12.9 for Windows, iCloud for Windows 7.7.
CVEs:CVE-2018-4347
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| icloud |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| mac_os_x |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
macOSEPSS <= 49%HIGH2019-04-03
A null pointer dereference was addressed with improved validation. This issue affected versions prior to macOS High Sierra 10.13.6.
CVEs:CVE-2018-4276
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
macOSEPSS <= 49%HIGH2019-04-03
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to macOS High Sierra 10.13.6, macOS Mojave 10.14.
CVEs:CVE-2018-4456
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
watchOSEPSS <= 49%CRITICAL2019-04-03
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5, iTunes 12.9 for Windows, iCloud for Windows 7.7.
CVEs:CVE-2018-4414
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| icloud |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| mac_os_x |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
watchOSEPSS <= 49%HIGH2019-04-03
A memory corruption issue was addressed with improved state management. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
CVEs:CVE-2018-4383
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| mac_os_x |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
watchOSEPSS <= 49%HIGH2019-04-03
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
CVEs:CVE-2018-4337
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| mac_os_x |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
watchOSEPSS <= 49%HIGH2019-04-03
A race condition was addressed with additional validation. This issue affected versions prior to iOS 11.2, macOS High Sierra 10.13.2, tvOS 11.2, watchOS 4.2, iTunes 12.7.2 for Windows, macOS High Sierra 10.13.4.
CVEs:CVE-2017-7151
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| mac_os_x |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
macOSEPSS <= 49%HIGH2019-04-03
A configuration issue was addressed with additional restrictions. This issue affected versions prior to macOS X El Capitan 10.11.6 Security Update 2018-002, macOS Sierra 10.12.6 Security Update 2018-002, macOS High Sierra 10.13.2.
CVEs:CVE-2017-13911
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
macOSEPSS <= 49%MEDIUM2019-04-03
A configuration issue was addressed with additional restrictions. This issue affected versions prior to iOS 12, macOS Mojave 10.14.
CVEs:CVE-2018-4355
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| mac_os_x |
affected |
apple |
— |
— |
macOSEPSS <= 49%MEDIUM2019-04-03
A memory initialization issue was addressed with improved memory handling. This issue affected versions prior to macOS Mojave 10.14.
CVEs:CVE-2018-4351
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
iOSEPSS <= 49%MEDIUM2019-04-03
A logic issue existed in the handling of call URLs. This issue was addressed with improved state management. This issue affected versions prior to iOS 11.4.1.
CVEs:CVE-2018-4216
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
macOSEPSS <= 49%MEDIUM2019-04-03
A privacy issue in the handling of Open Directory records was addressed with improved indexing. This issue affected versions prior to macOS High Sierra 10.13.6.
CVEs:CVE-2018-4470
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |