Month | Quarter | Year |
---|---|---|
#124 | #75 | #N/A |
CVE-ID | CWE-ID | Type | Score |
---|---|---|---|
CVE-2019-9816 | CWE-704 | Incorrect Type Conversion or Cast | 5.9 |
A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security checks within these groups.
Note: this vulnerability has only been demonstrated with UnboxedObjects, which are disabled by default on all supported releases.
|
|||
CVE-2019-9792 | CWE-119 | Buffer Errors | 9.8 |
The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then be used by JavaScript to achieve memory corruption, which results in a potentially exploitable crash.
|
|||
CVE-2019-9791 | CWE-20 | Input Validation | 9.8 |
The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the constructor function is entered through on-stack replacement (OSR). This allows for possible arbitrary reading and writing of objects during an exploitable crash.
|
|||
CVE-2018-4404 | CWE-119 | Buffer Errors | 7.8 |
In iOS before 11.4 and macOS High Sierra before 10.13.5, a memory corruption issue exists and was addressed with improved memory handling.
|
|||
CVE-2018-4359 | CWE-119 | Buffer Errors | 8.8 |
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
|
|||
CVE-2018-4237 | CWE-264 | Permissions, Privileges, and Access Control | 7.8 |
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "libxpc" component. It allows attackers to gain privileges via a crafted app that leverages a logic error.
|
|||
CVE-2018-4233 | CWE-119 | Buffer Errors | 8.8 |
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
|
|||
CVE-2018-4167 | CWE-362 | Race Conditions | 7.0 |
An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "File System Events" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
|
|||
CVE-2018-4166 | CWE-362 | Race Conditions | 7.0 |
An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "NSURLSession" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
|
|||
CVE-2018-4158 | CWE-362 | Race Conditions | 7.0 |
An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. watchOS before 4.3 is affected. The issue involves the "CoreFoundation" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
|