Vulnerability Summary for the Week of July 17, 2017
Total Page:16
File Type:pdf, Size:1020Kb
Vulnerability Summary for the Week of July 17, 2017 The vulnerabilities are based on the CVE vulnerability naming standard and are organized according to severity, determined by the Common Vulnerability Scoring System (CVSS) standard. The division of high, medium, and low severities correspond to the following scores: High - Vulnerabilities will be labeled High severity if they have a CVSS base score of 7.0 - 10.0 Medium - Vulnerabilities will be labeled Medium severity if they have a CVSS base score of 4.0 - 6.9 Low - Vulnerabilities will be labeled Low severity if they have a CVSS base score of 0.0 - 3.9 High Vulnerabilities CVS S Primary Publishe Scor Source & Vendor -- Product Description d e Patch Info CVE-2017- 7664 MLIST Uploaded XML documents were not correctly 2017-07- BID(link is apache -- openmeetings validated in Apache OpenMeetings 3.1.0. 17 7.5 external) An issue was discovered in certain Apple CVE-2017- products. iTunes before 12.6.2 on Windows is 7053 affected. The issue involves the "iTunes" BID(link is component. It allows attackers to execute external) arbitrary code in a privileged context via a crafted 2017-07- CONFIRM(lin apple -- itunes app. 20 9.3 k is external) CVE-2017- 7050 An issue was discovered in certain Apple BID(link is products. macOS before 10.12.6 is affected. The external) issue involves the "Bluetooth" component. It SECTRACK(li allows attackers to execute arbitrary code in a nk is external) privileged context or cause a denial of service 2017-07- CONFIRM(lin apple -- mac_os_x (memory corruption) via a crafted app. 20 7.9 k is external) CVE-2017- 7051 An issue was discovered in certain Apple BID(link is products. macOS before 10.12.6 is affected. The external) issue involves the "Bluetooth" component. It SECTRACK(li allows attackers to execute arbitrary code in a nk is external) privileged context or cause a denial of service 2017-07- CONFIRM(lin apple -- mac_os_x (memory corruption) via a crafted app. 20 7.9 k is external) An issue was discovered in certain Apple CVE-2017- 2017-07- products. macOS before 10.12.6 is affected. The 7054 apple -- mac_os_x 20 7.9 issue involves the "Bluetooth" component. It BID(link is CVS S Primary Publishe Scor Source & Vendor -- Product Description d e Patch Info allows attackers to execute arbitrary code in a external) privileged context or cause a denial of service SECTRACK(li (memory corruption) via a crafted app. nk is external) CONFIRM(lin k is external) CVE-2017- 7040 BID(link is external) SECTRACK(li nk is external) An issue was discovered in certain Apple CONFIRM(lin products. iOS before 10.3.3 is affected. Safari k is external) before 10.1.2 is affected. iCloud before 6.2.2 on CONFIRM(lin Windows is affected. iTunes before 12.6.2 on k is external) Windows is affected. tvOS before 10.2.2 is CONFIRM(lin affected. The issue involves the "WebKit" k is external) component. It allows remote attackers to execute CONFIRM(lin arbitrary code or cause a denial of service k is external) (memory corruption and application crash) via a 2017-07- CONFIRM(lin apple -- safari crafted web site. 20 9.3 k is external) CVE-2017- 7041 BID(link is external) SECTRACK(li nk is external) An issue was discovered in certain Apple CONFIRM(lin products. iOS before 10.3.3 is affected. Safari k is external) before 10.1.2 is affected. iCloud before 6.2.2 on CONFIRM(lin Windows is affected. iTunes before 12.6.2 on k is external) Windows is affected. tvOS before 10.2.2 is CONFIRM(lin affected. The issue involves the "WebKit" k is external) component. It allows remote attackers to execute CONFIRM(lin arbitrary code or cause a denial of service k is external) (memory corruption and application crash) via a 2017-07- CONFIRM(lin apple -- safari crafted web site. 20 9.3 k is external) An issue was discovered in certain Apple CVE-2017- products. iOS before 10.3.3 is affected. Safari 7042 2017-07- before 10.1.2 is affected. iCloud before 6.2.2 on BID(link is apple -- safari 20 9.3 Windows is affected. iTunes before 12.6.2 on external) CVS S Primary Publishe Scor Source & Vendor -- Product Description d e Patch Info Windows is affected. tvOS before 10.2.2 is SECTRACK(li affected. The issue involves the "WebKit" nk is external) component. It allows remote attackers to execute CONFIRM(lin arbitrary code or cause a denial of service k is external) (memory corruption and application crash) via a CONFIRM(lin crafted web site. k is external) CONFIRM(lin k is external) CONFIRM(lin k is external) CONFIRM(lin k is external) CVE-2017- 7043 BID(link is external) SECTRACK(li nk is external) An issue was discovered in certain Apple CONFIRM(lin products. iOS before 10.3.3 is affected. Safari k is external) before 10.1.2 is affected. iCloud before 6.2.2 on CONFIRM(lin Windows is affected. iTunes before 12.6.2 on k is external) Windows is affected. tvOS before 10.2.2 is CONFIRM(lin affected. The issue involves the "WebKit" k is external) component. It allows remote attackers to execute CONFIRM(lin arbitrary code or cause a denial of service k is external) (memory corruption and application crash) via a 2017-07- CONFIRM(lin apple -- safari crafted web site. 20 9.3 k is external) CVE-2017- 7049 BID(link is An issue was discovered in certain Apple external) products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on SECTRACK(li nk is external) Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is CONFIRM(lin k is external) affected. The issue involves the "WebKit" CONFIRM(lin component. It allows remote attackers to execute k is external) arbitrary code or cause a denial of service CONFIRM(lin (memory corruption and application crash) via a 2017-07- k is external) apple -- safari crafted web site. 20 7.5 CONFIRM(lin CVS S Primary Publishe Scor Source & Vendor -- Product Description d e Patch Info k is external) CONFIRM(lin k is external) CVE-2017- 7052 BID(link is external) SECTRACK(li nk is external) An issue was discovered in certain Apple CONFIRM(lin products. iOS before 10.3.3 is affected. Safari k is external) before 10.1.2 is affected. iCloud before 6.2.2 on CONFIRM(lin Windows is affected. iTunes before 12.6.2 on k is external) Windows is affected. tvOS before 10.2.2 is CONFIRM(lin affected. The issue involves the "WebKit" k is external) component. It allows remote attackers to execute CONFIRM(lin arbitrary code or cause a denial of service k is external) (memory corruption and application crash) via a 2017-07- CONFIRM(lin apple -- safari crafted web site. 20 7.5 k is external) CVE-2017- 7055 BID(link is external) SECTRACK(li nk is external) An issue was discovered in certain Apple CONFIRM(lin products. iOS before 10.3.3 is affected. Safari k is external) before 10.1.2 is affected. iCloud before 6.2.2 on CONFIRM(lin Windows is affected. iTunes before 12.6.2 on k is external) Windows is affected. tvOS before 10.2.2 is CONFIRM(lin affected. The issue involves the "WebKit" k is external) component. It allows remote attackers to execute CONFIRM(lin arbitrary code or cause a denial of service k is external) (memory corruption and application crash) via a 2017-07- CONFIRM(lin apple -- safari crafted web site. 20 7.5 k is external) An issue was discovered in certain Apple CVE-2017- products. iOS before 10.3.3 is affected. Safari 7056 before 10.1.2 is affected. iCloud before 6.2.2 on BID(link is Windows is affected. iTunes before 12.6.2 on external) 2017-07- Windows is affected. tvOS before 10.2.2 is SECTRACK(li apple -- safari 20 7.5 affected. The issue involves the "WebKit" nk is external) CVS S Primary Publishe Scor Source & Vendor -- Product Description d e Patch Info component. It allows remote attackers to execute CONFIRM(lin arbitrary code or cause a denial of service k is external) (memory corruption and application crash) via a CONFIRM(lin crafted web site. k is external) CONFIRM(lin k is external) CONFIRM(lin k is external) CONFIRM(lin k is external) CVE-2017- 7061 BID(link is external) SECTRACK(li nk is external) An issue was discovered in certain Apple CONFIRM(lin products. iOS before 10.3.3 is affected. Safari k is external) before 10.1.2 is affected. iCloud before 6.2.2 on CONFIRM(lin Windows is affected. iTunes before 12.6.2 on k is external) Windows is affected. tvOS before 10.2.2 is CONFIRM(lin affected. The issue involves the "WebKit" k is external) component. It allows remote attackers to execute CONFIRM(lin arbitrary code or cause a denial of service k is external) (memory corruption and application crash) via a 2017-07- CONFIRM(lin apple -- safari crafted web site. 20 7.5 k is external) CVE-2017- 2246 Untrusted search path vulnerability in Installer of CONFIRM(lin Lhaz version 2.4.0 and earlier allows an attacker k is external) to gain privileges via a Trojan horse DLL in an 2017-07- JVN(link is chitora -- lhaz unspecified directory. 17 9.3 external) CVE-2017- Untrusted search path vulnerability in Self- 2247 extracting archive files created by Lhaz version CONFIRM(lin 2.4.0 and earlier allows an attacker to gain k is external) privileges via a Trojan horse DLL in an 2017-07- JVN(link is chitora -- lhaz unspecified directory.