Apple Macos High Sierra vulnerabilities
102 known vulnerabilities affecting apple/macos_high_sierra.
Total CVEs
102
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL17HIGH53MEDIUM29LOW3
Vulnerabilities
Page 4 of 6
CVE-2017-6452P4HIGHCVSS 7.8v10.132017-09-25
CVE-2017-6452 [HIGH] CVE-2017-6452: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-6452
Component: Mail Drafts
Impact: An attacker with a privileged network position may be able to intercept mail contents
Description: An encryption issue existed in the handling of mail drafts. This issue was addressed with improved handling of mail drafts meant to be sent encrypted.
apple
CVE-2016-9042P4MEDIUMCVSS 5.9v10.132017-09-25
CVE-2016-9042 [MEDIUM] CVE-2016-9042: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2016-9042
Component: Mail Drafts
Impact: An attacker with a privileged network position may be able to intercept mail contents
Description: An encryption issue existed in the handling of mail drafts. This issue was addressed with improved handling of mail drafts meant to be sent encrypted.
apple
CVE-2017-13834P4HIGHCVSS 7.8v10.132017-09-25
CVE-2017-13834 [HIGH] CVE-2017-13834: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-13834
Component: Kernel
Impact: Processing a malformed mach binary may lead to arbitrary code execution
Description: A memory corruption issue was addressed through improved validation.
apple
CVE-2017-0381P4HIGHCVSS 7.8v10.132017-09-25
CVE-2017-0381 [HIGH] CVE-2017-0381: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-0381
Component: CoreAudio
Impact: An application may be able to read restricted memory
Description: An out-of-bounds read was addressed by updating to Opus version 1.1.4.
apple
CVE-2017-6464P4MEDIUMCVSS 6.5v10.132017-09-25
CVE-2017-6464 [MEDIUM] CVE-2017-6464: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-6464
Component: Mail Drafts
Impact: An attacker with a privileged network position may be able to intercept mail contents
Description: An encryption issue existed in the handling of mail drafts. This issue was addressed with improved handling of mail drafts meant to be sent encrypted.
apple
CVE-2017-7122P4CRITICALCVSS 9.8v10.132017-09-25
CVE-2017-7122 [CRITICAL] CVE-2017-7122: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-7122
Component: Directory Utility
Impact: A local attacker may be able to determine the Apple ID of the owner of the computer
Description: A permissions issue existed in the handling of the Apple ID. This issue was addressed with improved access controls.
apple
CVE-2017-7121P4CRITICALCVSS 9.8v10.132017-09-25
CVE-2017-7121 [CRITICAL] CVE-2017-7121: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-7121
Component: Directory Utility
Impact: A local attacker may be able to determine the Apple ID of the owner of the computer
Description: A permissions issue existed in the handling of the Apple ID. This issue was addressed with improved access controls.
apple
CVE-2017-7124P4CRITICALCVSS 9.8v10.132017-09-25
CVE-2017-7124 [CRITICAL] CVE-2017-7124: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-7124
Component: Directory Utility
Impact: A local attacker may be able to determine the Apple ID of the owner of the computer
Description: A permissions issue existed in the handling of the Apple ID. This issue was addressed with improved access controls.
apple
CVE-2017-7123P4CRITICALCVSS 9.8v10.132017-09-25
CVE-2017-7123 [CRITICAL] CVE-2017-7123: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-7123
Component: Directory Utility
Impact: A local attacker may be able to determine the Apple ID of the owner of the computer
Description: A permissions issue existed in the handling of the Apple ID. This issue was addressed with improved access controls.
apple
CVE-2017-7125P4CRITICALCVSS 9.8v10.132017-09-25
CVE-2017-7125 [CRITICAL] CVE-2017-7125: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-7125
Component: Directory Utility
Impact: A local attacker may be able to determine the Apple ID of the owner of the computer
Description: A permissions issue existed in the handling of the Apple ID. This issue was addressed with improved access controls.
apple
CVE-2017-6455P4HIGHCVSS 7.0v10.132017-09-25
CVE-2017-6455 [HIGH] CVE-2017-6455: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-6455
Component: Mail Drafts
Impact: An attacker with a privileged network position may be able to intercept mail contents
Description: An encryption issue existed in the handling of mail drafts. This issue was addressed with improved handling of mail drafts meant to be sent encrypted.
apple
CVE-2017-6463P4MEDIUMCVSS 6.5v10.132017-09-25
CVE-2017-6463 [MEDIUM] CVE-2017-6463: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-6463
Component: Mail Drafts
Impact: An attacker with a privileged network position may be able to intercept mail contents
Description: An encryption issue existed in the handling of mail drafts. This issue was addressed with improved handling of mail drafts meant to be sent encrypted.
apple
CVE-2017-7141P4MEDIUMCVSS 5.3v10.132017-09-25
CVE-2017-7141 [MEDIUM] CVE-2017-7141: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-7141
Component: Mail
Impact: The sender of an email may be able to determine the IP address of the recipient
Description: Turning off "Load remote content in messages" did not apply to all mailboxes. This issue was addressed with improved setting propagation.
apple
CVE-2017-13820P4HIGHCVSS 7.1v10.132017-09-25
CVE-2017-13820 [HIGH] CVE-2017-13820: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-13820
Component: ATS
Impact: Processing a maliciously crafted font may result in the disclosure of process memory
Description: A memory corruption issue was addressed with improved input validation.
apple
CVE-2017-7078P4MEDIUMCVSS 5.3v10.132017-09-25
CVE-2017-7078 [MEDIUM] CVE-2017-7078: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-7078
Component: Mail Drafts
Impact: An attacker with a privileged network position may be able to intercept mail contents
Description: An encryption issue existed in the handling of mail drafts. This issue was addressed with improved handling of mail drafts meant to be sent encrypted.
apple
CVE-2017-7143P4MEDIUMCVSS 5.5v10.132017-09-25
CVE-2017-7143 [MEDIUM] CVE-2017-7143: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-7143
Component: Captive Network Assistant
Impact: A local user may unknowingly send a password unencrypted over the network
Description: The security state of the captive portal browser was not obvious. This issue was addressed with improved visibility of the captive portal browser security state.
apple
CVE-2017-13831P4HIGHCVSS 7.1v10.132017-09-25
CVE-2017-13831 [HIGH] CVE-2017-13831: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-13831
Component: ImageIO
Impact: Processing a maliciously crafted image may lead to a denial of service
Description: A memory corruption issue was addressed with improved input validation.
apple
CVE-2017-13909P4MEDIUMCVSS 5.5v10.132017-09-25
CVE-2017-13909 [MEDIUM] CVE-2017-13909: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-13909
Impact: A local attacker may gain access to iCloud authentication tokens
Description: An issue existed in the storage of sensitive tokens. This issue was addressed by placing the tokens in Keychain.
apple
CVE-2017-13819P4MEDIUMCVSS 6.1v10.132017-09-25
CVE-2017-13819 [MEDIUM] CVE-2017-13819: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-13819
Component: HelpViewer
Impact: A quarantined HTML file may execute arbitrary JavaScript cross-origin
Description: A cross-site scripting issue existed in HelpViewer. This issue was addressed by removing the affected file.
apple
CVE-2017-13851P4MEDIUMCVSS 5.5v10.132017-09-25
CVE-2017-13851 [MEDIUM] CVE-2017-13851: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-13851
Component: DesktopServices
Impact: A local attacker may be able to observe unprotected user data
Description: A file access issue existed with certain home folder files. This was addressed with improved access restrictions.
apple