Subscribe via feed.
Archive for September, 2017

Apple AppleBCMWLANCore Driver Heap Overflow

Posted by deepcore under Apple (No Respond)

There is a heap overflow in Apple’s AppleBCMWLANCore driver when handling Completed Firmware Timestamp messages (0x27).

Tags: , ,

Apple assembleBGScanResults Heap Overflow

Posted by deepcore under Apple (No Respond)

There is a heap overflow vulnerability in Apple’s assembleBGScanResults when handling ioctl results.

Tags: , ,

Apple updateRateSetAsyncCallback Heap Overflow

Posted by deepcore under Apple (No Respond)

A heap overflow vulnerability exists in Apple’s updateRateSetAsyncCallback when handling ioctl results.

Tags: , ,

Apple Out-Of-Bounds NUL Byte Write

Posted by deepcore under Apple (No Respond)

Apple products suffer from an issue where an out-of-band NUL byte write occurs when handling WLC_E_TRACE event packets.

Tags: , ,

Apple setVendorIE Heap Overflow / Information Disclosure

Posted by deepcore under Apple (No Respond)

Heap overflow and information disclosure vulnerabilities exist in Apple’s setVendorIE when handling ioctl results.

Tags: , ,

Apple PCIe Message Ring Protocol Race Conditions

Posted by deepcore under Apple (No Respond)

The Apple PCIe Message Ring protocol suffers from multiple race conditions that can lead to out-of-bounds read and writes.

Tags: , ,

Apple WLC_E_COUNTRY_CODE_CHANGED Information Leak

Posted by deepcore under Apple (No Respond)

Apple products suffers from an information leak when handling WLC_E_COUNTRY_CODE_CHANGED event packets.

Tags: , ,

Apple Security Advisory 2017-09-19-2

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2017-09-19-2 – Safari 11 is now available and addresses address bar spoofing and other vulnerabilities.

Tags: , ,

Apple Security Advisory 2017-09-19-3

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2017-09-19-3 – Xcode 9 is now available and addresses code execution and various other vulnerabilities.

Tags: , ,

Apple Security Advisory 2017-09-20-1

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2017-09-20-1 – This advisory provides additional information for APPLE-SA-2017-09-19-1 iOS 11.

Tags: , ,