cbcvebase.

Apple Xcode vulnerabilities

115 known vulnerabilities affecting apple/xcode.

Total CVEs
115
CISA KEV
2
actively exploited
Public exploits
7
Exploited in wild
2
Severity breakdown
CRITICAL10HIGH63MEDIUM38LOW4

Vulnerabilities

Page 1 of 6
CVE-2021-44228P1CRITICALCVSS 10.0KEVPoCRansomwarefixed in 13.32021-12-10
CVE-2021-44228 [CRITICAL] CWE-20 CVE-2021-44228: Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LD
nvdapple
CVE-2025-48384P1HIGHCVSS 8.0KEVPoCfixed in 26.02025-07-08
CVE-2025-48384 [HIGH] CWE-59 CVE-2025-48384: Git is a fast, scalable, distributed revision control system with an unusually rich command set that Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return and line feed (CRLF). When writing a config entry, values with a trailing CR are not quoted, causing the CR to be lost
nvdapple
CVE-2014-9390P1CRITICALCVSS 9.8PoC≤ 6.1.1v6.22020-02-12
CVE-2014-9390 [CRITICAL] CWE-20 CVE-2014-9390: Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2 Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit all versions before 08-12-2014 allo
nvdapple
CVE-2021-21300P2HIGHCVSS 7.5PoCfixed in 12.52021-03-09
CVE-2021-21300 [HIGH] CWE-59 CVE-2021-21300: Git is an open-source distributed revision control system. In affected versions of Git a specially c Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as files using a clean/smudge filter such as Git LFS, may cause just-checked out script to be executed while cloning onto a case-insensitive file system such as NTFS, HFS+ or APFS (i.e. the default f
nvd
CVE-2004-2687P2CRITICALCVSS 9.3PoCv1.52004-12-31
CVE-2004-2687 [CRITICAL] CWE-16 CVE-2004-2687: distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server po distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs, which are executed by the server without authorization checks.
nvd
CVE-2018-11235P2HIGHCVSS 7.8PoCv9.4.12018-06-13
CVE-2018-11235 [HIGH] CVE-2018-11235: Xcode 9.4.1 Apple Security Update: About the security content of Xcode 9.4.1 Product: Xcode Version: 9.4.1 CVE: CVE-2018-11235 Component: Git Impact: Multiple issues in git, the most significant of which may lead to arbitrary code execution Description: Multiple issues existed in git. These issues were addressed by updating git to version 2.15.2.
apple
CVE-2014-3566P3LOWCVSS 3.4PoCv7.0
CVE-2014-3566 [LOW] CVE-2014-3566: Xcode 7.0 Apple Security Update: About the security content of Xcode 7.0 Product: Xcode Version: 7.0 CVE: CVE-2014-3566 Component: CVE-2014-3566
apple
CVE-2024-32002P2CRITICALCVSS 9.0v162024-09-16
CVE-2024-32002 [CRITICAL] CVE-2024-32002: Xcode 16 Apple Security Update: About the security content of Xcode 16 Product: Xcode Version: 16 CVE: CVE-2024-32002 Component: CVE-2024-32002
apple
CVE-2017-7529P2HIGHCVSS 7.5fixed in 13.02017-07-13
CVE-2017-7529 [HIGH] CWE-190 CVE-2017-7529: Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerabili Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
nvdapple
CVE-2019-14379P2CRITICALCVSS 9.8fixed in 13.32019-07-29
CVE-2019-14379 [CRITICAL] CWE-1321 CVE-2019-14379: SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when eh SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.
nvdapple
CVE-2016-0742P3HIGHCVSS 7.5fixed in 13.02016-02-15
CVE-2016-0742 [HIGH] CWE-476 CVE-2016-0742: The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response.
nvdapple
CVE-2018-16843P3HIGHCVSS 7.5fixed in 13.02018-11-07
CVE-2018-16843 [HIGH] CWE-400 CVE-2018-16843: nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
nvdapple
CVE-2016-0705P3CRITICALCVSS 9.8v8.12016-10-27
CVE-2016-0705 [CRITICAL] CVE-2016-0705: Xcode 8.1 Apple Security Update: About the security content of Xcode 8.1 Product: Xcode Version: 8.1 CVE: CVE-2016-0705 Component: CVE-2016-0705
apple
CVE-2015-3193P3HIGHCVSS 7.5v8.12016-10-27
CVE-2015-3193 [HIGH] CVE-2015-3193: Xcode 8.1 Apple Security Update: About the security content of Xcode 8.1 Product: Xcode Version: 8.1 CVE: CVE-2015-3193 Component: CVE-2015-3193
apple
CVE-2022-39260P3HIGHCVSS 8.8fixed in 14.12022-10-19
CVE-2022-39260 [HIGH] CWE-122 CVE-2022-39260: Git is an open source, scalable, distributed revision control system. `git shell` is a restricted lo Git is an open source, scalable, distributed revision control system. `git shell` is a restricted login shell that can be used to implement Git's push/pull functionality via SSH. In versions prior to 2.30.6, 2.31.5, 2.32.4, 2.33.5, 2.34.5, 2.35.5, 2.36.3, and 2.37.4, the function that splits the command arguments into an array improperly uses an `int`
nvdapple
CVE-2019-3855P3HIGHCVSS 8.8fixed in 11.02019-03-21
CVE-2019-3855 [HIGH] CWE-190 CVE-2019-3855: An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.
nvdapple
CVE-2015-3194P3HIGHCVSS 7.5v8.12016-10-27
CVE-2015-3194 [HIGH] CVE-2015-3194: Xcode 8.1 Apple Security Update: About the security content of Xcode 8.1 Product: Xcode Version: 8.1 CVE: CVE-2015-3194 Component: CVE-2015-3194
apple
CVE-2016-0797P3HIGHCVSS 7.5v8.12016-10-27
CVE-2016-0797 [HIGH] CVE-2016-0797: Xcode 8.1 Apple Security Update: About the security content of Xcode 8.1 Product: Xcode Version: 8.1 CVE: CVE-2016-0797 Component: CVE-2016-0797
apple
CVE-2016-2216P3HIGHCVSS 7.5v8.12016-10-27
CVE-2016-2216 [HIGH] CVE-2016-2216: Xcode 8.1 Apple Security Update: About the security content of Xcode 8.1 Product: Xcode Version: 8.1 CVE: CVE-2016-2216 Component: CVE-2016-2216
apple
CVE-2019-8840P3HIGHCVSS 8.8fixed in 11.3≥ unspecified, < 11.32020-10-27
CVE-2019-8840 [HIGH] CWE-125 CVE-2019-8840: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 11.3 An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 11.3. Compiling with untrusted sources may lead to arbitrary code execution with user privileges.
nvdapple
Apple Xcode vulnerabilities | cvebase