Apple Swift vulnerabilities

4 known vulnerabilities affecting apple/swift.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2022-1642HIGHCVSS 7.5fixed in 5.6.22022-06-16
CVE-2022-1642 [HIGH] CWE-241 CVE-2022-1642: A program using swift-corelibs-foundation is vulnerable to a denial of service attack caused by a po A program using swift-corelibs-foundation is vulnerable to a denial of service attack caused by a potentially malicious source producing a JSON document containing a type mismatch. This vulnerability is caused by the interaction between a deserialization mechanism offered by the Swift standard library, the Codable protocol; and the JSONDecoder class off
nvd
CVE-2020-9861HIGHCVSS 7.5≤ 5.1.42020-11-02
CVE-2020-9861 [HIGH] CWE-674 CVE-2020-9861: A stack overflow issue existed in Swift for Linux. The issue was addressed with improved input valid A stack overflow issue existed in Swift for Linux. The issue was addressed with improved input validation for dealing with deeply nested malicious JSON input.
nvd
CVE-2019-8790MEDIUMCVSS 5.5fixed in 5.1.12020-10-27
CVE-2019-8790 [MEDIUM] CWE-922 CVE-2019-8790: This issue was addresses by updating incorrect URLSession file descriptors management logic to match This issue was addresses by updating incorrect URLSession file descriptors management logic to match Swift 5.0. This issue is fixed in Swift 5.1.1 for Ubuntu. Incorrect management of file descriptors in URLSession could lead to inadvertent data disclosure.
nvd
CVE-2018-4220HIGHCVSS 8.8fixed in 4.1.12018-06-08
CVE-2018-4220 [HIGH] CWE-732 CVE-2018-4220: An issue was discovered in certain Apple products. Swift before 4.1.1 Security Update 2018-001 is af An issue was discovered in certain Apple products. Swift before 4.1.1 Security Update 2018-001 is affected. The issue involves the "Swift for Ubuntu" component. It allows attackers to execute arbitrary code in a privileged context because write and execute permissions are enabled during library loading.
nvd