Apple Icloud vulnerabilities
449 known vulnerabilities affecting apple/icloud.
Total CVEs
449
CISA KEV
2
actively exploited
Public exploits
66
Exploited in wild
11
Severity breakdown
CRITICAL19HIGH343MEDIUM85LOW2
Vulnerabilities
Page 23 of 23
CVE-2020-15358P4MEDIUMCVSS 5.5fixed in 7.212020-06-27
CVE-2020-15358 [MEDIUM] CWE-787 CVE-2020-15358: In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectO
In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.
nvd
CVE-2020-13434P4MEDIUMCVSS 5.5fixed in 11.52020-05-24
CVE-2020-13434 [MEDIUM] CWE-190 CVE-2020-13434: SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.
SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.
nvd
CVE-2016-7614P4MEDIUMCVSS 5.5≤ 6.0.12017-02-20
CVE-2016-7614 [MEDIUM] CWE-200 CVE-2016-7614: An issue was discovered in certain Apple products. iCloud before 6.1 is affected. The issue involves
An issue was discovered in certain Apple products. iCloud before 6.1 is affected. The issue involves the "Windows Security" component. It allows local users to obtain sensitive information from iCloud desktop-client process memory via unspecified vectors.
nvd
CVE-2020-11765P4MEDIUMCVSS 5.5fixed in 7.20≥ 10.0, < 11.32020-04-14
CVE-2020-11765 [MEDIUM] CWE-125 CVE-2020-11765: An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h
An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier, leading to an out-of-bounds read.
nvd
CVE-2018-4440P4MEDIUMCVSS 4.3fixed in 7.92019-04-03
CVE-2018-4440 [MEDIUM] CWE-20 CVE-2018-4440: A logic issue was addressed with improved state management. This issue affected versions prior to iO
A logic issue was addressed with improved state management. This issue affected versions prior to iOS 12.1.1, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.
nvd
CVE-2019-8827P4MEDIUMCVSS 4.3fixed in 7.15≥ 10.0, < 10.9.22020-10-27
CVE-2019-8827 [MEDIUM] CVE-2019-8827: The HTTP referrer header may be used to leak browsing history. The issue was resolved by downgrading
The HTTP referrer header may be used to leak browsing history. The issue was resolved by downgrading all third party referrers to their origin. This issue is fixed in Safari 13.0.3, iTunes 12.10.2 for Windows, iCloud for Windows 10.9.2, tvOS 13.2, iOS 13.2 and iPadOS 13.2, iCloud for Windows 7.15. Visiting a maliciously crafted website may reveal the sites a
nvd
CVE-2018-4278P4MEDIUMCVSS 4.3fixed in 7.62019-01-11
CVE-2018-4278 [MEDIUM] CVE-2018-4278: In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iClo
In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, sound fetched through audio elements may be exfiltrated cross-origin. This issue was addressed with improved audio taint tracking.
nvd
CVE-2020-3894P4LOWCVSS 3.1fixed in 10.9.32020-04-01
CVE-2020-3894 [LOW] CWE-362 CVE-2020-3894: A race condition was addressed with additional validation. This issue is fixed in iOS 13.4 and iPadO
A race condition was addressed with additional validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. An application may be able to read restricted memory.
nvd
CVE-2017-2383P4LOWCVSS 3.1≤ 6.1.12017-04-02
CVE-2017-2383 [LOW] CVE-2017-2383: An issue was discovered in certain Apple products. iCloud before 6.2 on Windows is affected. iTunes
An issue was discovered in certain Apple products. iCloud before 6.2 on Windows is affected. iTunes before 12.6 on Windows is affected. The issue involves cleartext client-certificate transmission in the "APNs Server" component. It allows man-in-the-middle attackers to track users via correlation with this certificate.
nvd
← Previous23 / 23