Apple Xcode vulnerabilities
115 known vulnerabilities affecting apple/xcode.
Total CVEs
115
CISA KEV
2
actively exploited
Public exploits
7
Exploited in wild
2
Severity breakdown
CRITICAL10HIGH63MEDIUM38LOW4
Vulnerabilities
Page 1 of 6
CVE-2021-44228P1CRITICALCVSS 10.0KEVPoCRansomwarefixed in 13.32021-12-10
CVE-2021-44228 [CRITICAL] CWE-20 CVE-2021-44228: Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LD
nvdapple
CVE-2025-48384P1HIGHCVSS 8.0KEVPoCfixed in 26.02025-07-08
CVE-2025-48384 [HIGH] CWE-59 CVE-2025-48384: Git is a fast, scalable, distributed revision control system with an unusually rich command set that
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return and line feed (CRLF). When writing a config entry, values with a trailing CR are not quoted, causing the CR to be lost
nvdapple
CVE-2014-9390P1CRITICALCVSS 9.8PoC≤ 6.1.1v6.22020-02-12
CVE-2014-9390 [CRITICAL] CWE-20 CVE-2014-9390: Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit all versions before 08-12-2014 allo
nvdapple
CVE-2021-21300P2HIGHCVSS 7.5PoCfixed in 12.52021-03-09
CVE-2021-21300 [HIGH] CWE-59 CVE-2021-21300: Git is an open-source distributed revision control system. In affected versions of Git a specially c
Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as files using a clean/smudge filter such as Git LFS, may cause just-checked out script to be executed while cloning onto a case-insensitive file system such as NTFS, HFS+ or APFS (i.e. the default f
nvd
CVE-2004-2687P2CRITICALCVSS 9.3PoCv1.52004-12-31
CVE-2004-2687 [CRITICAL] CWE-16 CVE-2004-2687: distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server po
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs, which are executed by the server without authorization checks.
nvd
CVE-2018-11235P2HIGHCVSS 7.8PoCv9.4.12018-06-13
CVE-2018-11235 [HIGH] CVE-2018-11235: Xcode 9.4.1
Apple Security Update: About the security content of Xcode 9.4.1
Product: Xcode
Version: 9.4.1
CVE: CVE-2018-11235
Component: Git
Impact: Multiple issues in git, the most significant of which may lead to arbitrary code execution
Description: Multiple issues existed in git. These issues were addressed by updating git to version 2.15.2.
apple
CVE-2014-3566P3LOWCVSS 3.4PoCv7.0
CVE-2014-3566 [LOW] CVE-2014-3566: Xcode 7.0
Apple Security Update: About the security content of Xcode 7.0
Product: Xcode
Version: 7.0
CVE: CVE-2014-3566
Component: CVE-2014-3566
apple
CVE-2024-32002P2CRITICALCVSS 9.0v162024-09-16
CVE-2024-32002 [CRITICAL] CVE-2024-32002: Xcode 16
Apple Security Update: About the security content of Xcode 16
Product: Xcode
Version: 16
CVE: CVE-2024-32002
Component: CVE-2024-32002
apple
CVE-2017-7529P2HIGHCVSS 7.5fixed in 13.02017-07-13
CVE-2017-7529 [HIGH] CWE-190 CVE-2017-7529: Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerabili
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
nvdapple
CVE-2019-14379P2CRITICALCVSS 9.8fixed in 13.32019-07-29
CVE-2019-14379 [CRITICAL] CWE-1321 CVE-2019-14379: SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when eh
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.
nvdapple
CVE-2016-0742P3HIGHCVSS 7.5fixed in 13.02016-02-15
CVE-2016-0742 [HIGH] CWE-476 CVE-2016-0742: The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response.
nvdapple
CVE-2018-16843P3HIGHCVSS 7.5fixed in 13.02018-11-07
CVE-2018-16843 [HIGH] CWE-400 CVE-2018-16843: nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
nvdapple
CVE-2016-0705P3CRITICALCVSS 9.8v8.12016-10-27
CVE-2016-0705 [CRITICAL] CVE-2016-0705: Xcode 8.1
Apple Security Update: About the security content of Xcode 8.1
Product: Xcode
Version: 8.1
CVE: CVE-2016-0705
Component: CVE-2016-0705
apple
CVE-2015-3193P3HIGHCVSS 7.5v8.12016-10-27
CVE-2015-3193 [HIGH] CVE-2015-3193: Xcode 8.1
Apple Security Update: About the security content of Xcode 8.1
Product: Xcode
Version: 8.1
CVE: CVE-2015-3193
Component: CVE-2015-3193
apple
CVE-2022-39260P3HIGHCVSS 8.8fixed in 14.12022-10-19
CVE-2022-39260 [HIGH] CWE-122 CVE-2022-39260: Git is an open source, scalable, distributed revision control system. `git shell` is a restricted lo
Git is an open source, scalable, distributed revision control system. `git shell` is a restricted login shell that can be used to implement Git's push/pull functionality via SSH. In versions prior to 2.30.6, 2.31.5, 2.32.4, 2.33.5, 2.34.5, 2.35.5, 2.36.3, and 2.37.4, the function that splits the command arguments into an array improperly uses an `int`
nvdapple
CVE-2019-3855P3HIGHCVSS 8.8fixed in 11.02019-03-21
CVE-2019-3855 [HIGH] CWE-190 CVE-2019-3855: An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.
nvdapple
CVE-2015-3194P3HIGHCVSS 7.5v8.12016-10-27
CVE-2015-3194 [HIGH] CVE-2015-3194: Xcode 8.1
Apple Security Update: About the security content of Xcode 8.1
Product: Xcode
Version: 8.1
CVE: CVE-2015-3194
Component: CVE-2015-3194
apple
CVE-2016-0797P3HIGHCVSS 7.5v8.12016-10-27
CVE-2016-0797 [HIGH] CVE-2016-0797: Xcode 8.1
Apple Security Update: About the security content of Xcode 8.1
Product: Xcode
Version: 8.1
CVE: CVE-2016-0797
Component: CVE-2016-0797
apple
CVE-2016-2216P3HIGHCVSS 7.5v8.12016-10-27
CVE-2016-2216 [HIGH] CVE-2016-2216: Xcode 8.1
Apple Security Update: About the security content of Xcode 8.1
Product: Xcode
Version: 8.1
CVE: CVE-2016-2216
Component: CVE-2016-2216
apple
CVE-2019-8840P3HIGHCVSS 8.8fixed in 11.3≥ unspecified, < 11.32020-10-27
CVE-2019-8840 [HIGH] CWE-125 CVE-2019-8840: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 11.3
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 11.3. Compiling with untrusted sources may lead to arbitrary code execution with user privileges.
nvdapple
1 / 6Next →