Unknown · CVSS Not scored
A consistency issue existed in the handling of application snapshots. The issue was addressed with improved handling of message deletions. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5.
Published Apr 3, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A cookie management issue was addressed with improved checks. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
Published Apr 3, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1.
Published Apr 3, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
Published Apr 3, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to macOS High Sierra 10.13.6.
Published Apr 3, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access to the web interface when the web interface is enabled. This issue affected versions prior to v2.2.10.
Published Apr 3, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to Safari 11.1.2.
Published Apr 3, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue affected versions prior to macOS High Sierra 10.13.6.
Published Apr 3, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to iOS 11.4.1, Safari 11.1.2.
Published Apr 3, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A type confusion issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
Published Apr 3, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue affected versions prior to iOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
Published Apr 3, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2.
Published Apr 3, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
Published Apr 3, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
Published Apr 3, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A denial of service issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, watchOS 4.3.2.
Published Apr 3, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
Published Apr 3, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A type confusion issue was addressed with improved memory handling. This issue affected versions prior to macOS High Sierra 10.13.6.
Published Apr 3, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
Published Apr 3, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An out-of-bounds read was addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2.
Published Apr 3, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A memory corruption issue was addressed with improved validation. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
Published Apr 3, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. The issue involves the "Status Bar" component. It allows invisible microphone access via a crafted app.
Published Apr 13, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
Published Apr 3, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.3, tvOS 11.3, watchOS 4.3, Safari 11.1, iTunes 12.7.4 for Windows, iCloud for Windows 7.4.
Published Apr 3, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "NSURLSession" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
Published Apr 3, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
Published Apr 3, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in certain Apple products. Xcode before 9.3 is affected. The issue, which is unspecified, involves the "LLVM" component.
Published Apr 3, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "Find My iPhone" component. It allows physically proximate attackers to bypass the iCloud password requirement for disabling the "Find My iPhone" feature via vectors involving a backup restore.
Published Apr 3, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An out-of-bounds read was addressed with improved bounds checking. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
Published Apr 3, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "kext tools" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
Published Apr 3, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "SafariViewController" component. It allows remote attackers to spoof the user interface via a crafted web site that leverages input into a partially loaded page.
Published Apr 3, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A logic issue existed in the handling of call URLs. This issue was addressed with improved state management. This issue affected versions prior to iOS 11.4.1.
Published Apr 3, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "Files Widget" component. It allows physically proximate attackers to obtain sensitive information by leveraging the display of cached data on a locked device.
Published Apr 3, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A permissions issue existed in which execute permission was incorrectly granted. This issue was addressed with improved permission validation. This issue affected versions prior to macOS High Sierra 10.13.4.
Published Apr 3, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
Published Apr 3, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
Published Apr 3, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "Telephony" component. It allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via a Class 0 SMS message.
Published Apr 3, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. The issue involves the "PluginKit" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
Published Apr 3, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "LaunchServices" component. It allows attackers to bypass the code-signing protection mechanism via a crafted app.
Published Apr 3, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. The issue involves the "iCloud Drive" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
Published Apr 3, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
Published Apr 3, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
Published Apr 3, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (out-of-bounds read) via a crafted app.
Published Apr 3, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the user interface via a crafted web site.
Published Apr 3, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An injection issue was addressed with improved validation. This issue affected versions prior to macOS Mojave 10.14.
Published Apr 3, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
Published Apr 3, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows attackers to cause a denial of service (memory corruption) via a crafted web site.
Published Apr 3, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (out-of-bounds read) via a crafted app.
Published Apr 3, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
Published Apr 3, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is affected. The issue involves the fetch API in the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
Published Apr 3, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to Safari 12.
Published Apr 3, 2019 · Updated Aug 5, 2024