Apple Macos High Sierra vulnerabilities
102 known vulnerabilities affecting apple/macos_high_sierra.
Total CVEs
102
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL17HIGH53MEDIUM29LOW3
Vulnerabilities
Page 3 of 6
CVE-2017-13824P3HIGHCVSS 7.8v10.132017-09-25
CVE-2017-13824 [HIGH] CVE-2017-13824: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-13824
Component: Open Scripting Architecture
Impact: Decompiling an AppleScript with osadecompile may lead to arbitrary code execution
Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2017-13833P3HIGHCVSS 7.8v10.132017-09-25
CVE-2017-13833 [HIGH] CVE-2017-13833: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-13833
Component: CFNetwork
Impact: An application may be able to execute arbitrary code with system privileges
Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2017-13807P3HIGHCVSS 7.8v10.132017-09-25
CVE-2017-13807 [HIGH] CVE-2017-13807: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-13807
Component: Audio
Impact: Parsing a maliciously crafted QuickTime file may lead to an unexpected application termination or arbitrary code execution
Description: A memory consumption issue was addressed through improved memory handling.
apple
CVE-2017-7077P3HIGHCVSS 7.8v10.132017-09-25
CVE-2017-7077 [HIGH] CVE-2017-7077: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-7077
Component: IOFireWireFamily
Impact: An application may be able to execute arbitrary code with system privileges
Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2017-13830P3HIGHCVSS 7.8v10.132017-09-25
CVE-2017-13830 [HIGH] CVE-2017-13830: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-13830
Component: HFS
Impact: An application may be able to execute arbitrary code with system privileges
Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2017-13811P3HIGHCVSS 7.8v10.132017-09-25
CVE-2017-13811 [HIGH] CVE-2017-13811: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-13811
Component: Fonts
Impact: Rendering untrusted text may lead to spoofing
Description: An inconsistent user interface issue was addressed with improved state management.
apple
CVE-2017-13808P3HIGHCVSS 7.8v10.132017-09-25
CVE-2017-13808 [HIGH] CVE-2017-13808: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-13808
Component: Remote Management
Impact: An application may be able to execute arbitrary code with system privileges
Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2017-13906P3HIGHCVSS 7.8v10.132017-09-25
CVE-2017-13906 [HIGH] CVE-2017-13906: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-13906
Component: CVE-2017-13906
apple
CVE-2017-6451P3HIGHCVSS 7.8v10.132017-09-25
CVE-2017-6451 [HIGH] CVE-2017-6451: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-6451
Component: Mail Drafts
Impact: An attacker with a privileged network position may be able to intercept mail contents
Description: An encryption issue existed in the handling of mail drafts. This issue was addressed with improved handling of mail drafts meant to be sent encrypted.
apple
CVE-2017-13832P3CRITICALCVSS 9.8v10.132017-09-25
CVE-2017-13832 [CRITICAL] CVE-2017-13832: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-13832
Component: About Apple security updates
Impact: An attacker may be able to exploit weaknesses in TLS 1.0
Description: A protocol security issue was addressed by enabling TLS 1.1 and TLS 1.2.
apple
CVE-2017-13837P3HIGHCVSS 7.5v10.132017-09-25
CVE-2017-13837 [HIGH] CVE-2017-13837: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-13837
Component: Installer
Impact: A malicious application may be able to access the FileVault unlock key
Description: This issue was addressed by removing additional entitlements.
apple
CVE-2017-13815P4CRITICALCVSS 9.8v10.132017-09-25
CVE-2017-13815 [CRITICAL] CVE-2017-13815: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-13815
Component: CVE-2017-13815
apple
CVE-2017-13846P4CRITICALCVSS 9.8v10.132017-09-25
CVE-2017-13846 [CRITICAL] CVE-2017-13846: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-13846
Component: CVE-2017-13846
apple
CVE-2017-13812P3HIGHCVSS 7.8v10.132017-09-25
CVE-2017-13812 [HIGH] CVE-2017-13812: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-13812
Component: Kernel
Impact: A malicious application may be able to learn information about the presence and operation of other applications on the device.
Description: An application was able to access network activity information maintained by the operating system unrestricted. This issue was addres
apple
CVE-2017-13814P3HIGHCVSS 7.8v10.132017-09-25
CVE-2017-13814 [HIGH] CVE-2017-13814: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-13814
Component: ImageIO
Impact: Processing a maliciously crafted image may lead to arbitrary code execution
Description: A memory corruption issue was addressed with improved input validation.
apple
CVE-2017-13829P3HIGHCVSS 7.8v10.132017-09-25
CVE-2017-13829 [HIGH] CVE-2017-13829: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-13829
Component: CFNetwork
Impact: An application may be able to execute arbitrary code with system privileges
Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2017-13843P3HIGHCVSS 7.8v10.132017-09-25
CVE-2017-13843 [HIGH] CVE-2017-13843: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-13843
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2017-13838P3HIGHCVSS 7.8v10.132017-09-25
CVE-2017-13838 [HIGH] CVE-2017-13838: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-13838
Component: Sandbox
Impact: An application may be able to execute arbitrary code with system privileges
Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2017-13890P3HIGHCVSS 7.4v10.132017-09-25
CVE-2017-13890 [HIGH] CVE-2017-13890: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-13890
Component: CoreTypes
Impact: Processing a maliciously crafted webpage may result in the mounting of a disk image
Description: A logic issue was addressed with improved restrictions.
apple
CVE-2017-7126P4CRITICALCVSS 9.8v10.132017-09-25
CVE-2017-7126 [CRITICAL] CVE-2017-7126: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-7126
Component: Directory Utility
Impact: A local attacker may be able to determine the Apple ID of the owner of the computer
Description: A permissions issue existed in the handling of the Apple ID. This issue was addressed with improved access controls.
apple