Apple Macos High Sierra vulnerabilities
102 known vulnerabilities affecting apple/macos_high_sierra.
Total CVEs
102
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL17HIGH53MEDIUM29LOW3
Vulnerabilities
Page 2 of 6
CVE-2017-7114P3HIGHCVSS 7.8v10.132017-09-25
CVE-2017-7114 [HIGH] CVE-2017-7114: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-7114
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2017-7127P3HIGHCVSS 7.8v10.132017-09-25
CVE-2017-7127 [HIGH] CVE-2017-7127: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-7127
Component: SQLite
Impact: An application may be able to execute arbitrary code with system privileges
Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2017-13835P3HIGHCVSS 7.8v10.132017-09-25
CVE-2017-13835 [HIGH] CVE-2017-13835: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-13835
Component: Fonts
Impact: Rendering untrusted text may lead to spoofing
Description: An inconsistent user interface issue was addressed with improved state management.
apple
CVE-2018-4302P3HIGHCVSS 7.5v10.132017-09-25
CVE-2018-4302 [HIGH] CVE-2018-4302: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2018-4302
Component: CVE-2017-9233
Impact: Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution
Description: A null pointer dereference was addressed with improved validation.
apple
CVE-2017-9049P3HIGHCVSS 7.5v10.132017-09-25
CVE-2017-9049 [HIGH] CVE-2017-9049: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-9049
Component: CVE-2017-9233
Impact: Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution
Description: A null pointer dereference was addressed with improved validation.
apple
CVE-2017-13809P3HIGHCVSS 7.8v10.132017-09-25
CVE-2017-13809 [HIGH] CVE-2017-13809: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-13809
Component: AppleScript
Impact: Decompiling an AppleScript with osadecompile may lead to arbitrary code execution
Description: A validation issue was addressed with improved input sanitization.
apple
CVE-2017-13854P3HIGHCVSS 7.8v10.132017-09-25
CVE-2017-13854 [HIGH] CVE-2017-13854: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-13854
Component: Kernel
Impact: An application may be able to execute arbitrary code with system privileges
Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2017-13908P3HIGHCVSS 7.8v10.132017-09-25
CVE-2017-13908 [HIGH] CVE-2017-13908: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-13908
Component: SMB
Impact: A local attacker may be able to execute non-executable text files via an SMB share
Description: An issue in handling file permissions was addressed with improved validation.
apple
CVE-2017-7086P3HIGHCVSS 7.5v10.132017-09-25
CVE-2017-7086 [HIGH] CVE-2017-7086: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-7086
Component: Kernel
Impact: A malicious application may be able to learn information about the presence and operation of other applications on the device.
Description: An application was able to access network activity information maintained by the operating system unrestricted. This issue was addressed
apple
CVE-2017-13827P3HIGHCVSS 7.8v10.132017-09-25
CVE-2017-13827 [HIGH] CVE-2017-13827: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-13827
Component: Kernel
Impact: A malicious application may be able to learn information about the presence and operation of other applications on the device.
Description: An application was able to access network activity information maintained by the operating system unrestricted. This issue was addres
apple
CVE-2017-7128P3CRITICALCVSS 9.8v10.132017-09-25
CVE-2017-7128 [CRITICAL] CVE-2017-7128: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-7128
Component: SQLite
Impact: Multiple issues in SQLite
Description: Multiple issues were addressed by updating to version 3.19.3.
apple
CVE-2017-7129P3CRITICALCVSS 9.8v10.132017-09-25
CVE-2017-7129 [CRITICAL] CVE-2017-7129: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-7129
Component: SQLite
Impact: Multiple issues in SQLite
Description: Multiple issues were addressed by updating to version 3.19.3.
apple
CVE-2017-7130P3CRITICALCVSS 9.8v10.132017-09-25
CVE-2017-7130 [CRITICAL] CVE-2017-7130: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-7130
Component: SQLite
Impact: Multiple issues in SQLite
Description: Multiple issues were addressed by updating to version 3.19.3.
apple
CVE-2017-10140P3HIGHCVSS 7.8v10.132017-09-25
CVE-2017-10140 [HIGH] CVE-2017-10140: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-10140
Component: Postfix
Impact: Multiple issues in Postfix
Description: Multiple issues were addressed by updating to version 3.2.2.
apple
CVE-2017-6462P3HIGHCVSS 7.8v10.132017-09-25
CVE-2017-6462 [HIGH] CVE-2017-6462: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-6462
Component: Mail Drafts
Impact: An attacker with a privileged network position may be able to intercept mail contents
Description: An encryption issue existed in the handling of mail drafts. This issue was addressed with improved handling of mail drafts meant to be sent encrypted.
apple
CVE-2017-7080P3HIGHCVSS 7.5v10.132017-09-25
CVE-2017-7080 [HIGH] CVE-2017-7080: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-7080
Component: Security
Impact: A revoked certificate may be trusted
Description: A certificate validation issue existed in the handling of revocation data. This issue was addressed through improved validation.
apple
CVE-2017-13816P3HIGHCVSS 7.8v10.132017-09-25
CVE-2017-13816 [HIGH] CVE-2017-13816: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-13816
Component: Kernel
Impact: A malicious application may be able to learn information about the presence and operation of other applications on the device.
Description: An application was able to access network activity information maintained by the operating system unrestricted. This issue was addres
apple
CVE-2017-13813P3HIGHCVSS 7.8v10.132017-09-25
CVE-2017-13813 [HIGH] CVE-2017-13813: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-13813
Component: Kernel
Impact: A malicious application may be able to learn information about the presence and operation of other applications on the device.
Description: An application was able to access network activity information maintained by the operating system unrestricted. This issue was addres
apple
CVE-2017-7132P3HIGHCVSS 7.8v10.132017-09-25
CVE-2017-7132 [HIGH] CVE-2017-7132: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-7132
Component: Quick Look
Impact: Parsing a maliciously crafted office document may lead to an unexpected application termination or arbitrary code execution
Description: A memory consumption issue was addressed through improved memory handling.
apple
CVE-2017-13825P3HIGHCVSS 7.8v10.132017-09-25
CVE-2017-13825 [HIGH] CVE-2017-13825: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-13825
Component: CoreText
Impact: Processing a maliciously crafted font file may lead to arbitrary code execution
Description: A memory consumption issue was addressed with improved memory handling.
apple