VYPR

macOS High Sierra

by Apple Inc.

CVEs (37)

  • CVE-2017-13892HigDec 23, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue existed in the handling of Contact sharing. This issue was addressed with improved handling of user information. This issue is fixed in macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan. Sharing contact information may…

  • CVE-2020-9941HigOct 27, 2020
    risk 0.49cvss 7.5epss 0.03

    This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave. A remote attacker may be able to unexpectedly alter application state.

  • CVE-2020-9782HigOct 27, 2020
    risk 0.49cvss 7.5epss 0.01

    A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. A remote attacker may be able to overwrite existing files.

  • CVE-2018-4248HigApr 3, 2019
    risk 0.49cvss 7.5epss 0.02

    An out-of-bounds read was addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2.

  • CVE-2018-4277HigJan 11, 2019
    risk 0.49cvss 7.5epss 0.02

    In iOS before 11.4.1, watchOS before 4.3.2, tvOS before 11.4.1, Safari before 11.1.1, macOS High Sierra before 10.13.6, a spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation.

  • CVE-2017-7151HigApr 3, 2019
    risk 0.46cvss 7.0epss 0.02

    A race condition was addressed with additional validation. This issue affected versions prior to iOS 11.2, macOS High Sierra 10.13.2, tvOS 11.2, watchOS 4.2, iTunes 12.7.2 for Windows, macOS High Sierra 10.13.4.

  • CVE-2018-4183HigJan 11, 2019
    risk 0.46cvss 8.2epss 0.00

    In macOS High Sierra before 10.13.5, an access issue was addressed with additional sandbox restrictions.

  • CVE-2018-4478MedDec 23, 2021
    risk 0.44cvss 6.8epss 0.00

    A validation issue was addressed with improved logic. This issue is fixed in macOS High Sierra 10.13.5, Security Update 2018-003 Sierra, Security Update 2018-003 El Capitan. An attacker with physical access to a device may be able to elevate privileges.

  • CVE-2017-13907MedDec 23, 2021
    risk 0.44cvss 6.8epss 0.00

    A state management issue was addressed with improved state validation. This issue is fixed in macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan. The screen lock may unexpectedly remain unlocked.

  • CVE-2017-13910MedDec 23, 2021
    risk 0.36cvss 5.5epss 0.00

    An access issue was addressed with additional sandbox restrictions on applications. This issue is fixed in macOS High Sierra 10.13. An application may be able to access restricted files.

  • CVE-2017-13909MedDec 23, 2021
    risk 0.36cvss 5.5epss 0.00

    An issue existed in the storage of sensitive tokens. This issue was addressed by placing the tokens in Keychain. This issue is fixed in macOS High Sierra 10.13. A local attacker may gain access to iCloud authentication tokens.

  • CVE-2019-8839MedOct 27, 2020
    risk 0.36cvss 5.5epss 0.01

    A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. An attacker in a privileged position may be able to perform a denial of service attack.

  • CVE-2018-4391MedOct 27, 2020
    risk 0.36cvss 5.5epss 0.01

    An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan, watchOS 4.3, iOS 12.1. Processing a maliciously crafted text message may…

  • CVE-2018-4390MedOct 27, 2020
    risk 0.36cvss 5.5epss 0.01

    An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan, watchOS 4.3, iOS 12.1. Processing a maliciously crafted text message may…

  • CVE-2018-4289MedApr 3, 2019
    risk 0.36cvss 5.5epss 0.01

    An information disclosure issue was addressed by removing the vulnerable code. This issue affected versions prior to macOS High Sierra 10.13.6.

  • CVE-2018-4178MedApr 3, 2019
    risk 0.36cvss 5.5epss 0.00

    A permissions issue existed in which execute permission was incorrectly granted. This issue was addressed with improved permission validation. This issue affected versions prior to macOS High Sierra 10.13.4.

  • CVE-2018-4293MedApr 3, 2019
    risk 0.35cvss 5.3epss 0.01

    A cookie management issue was addressed with improved checks. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.

Page 2 of 2