cbcvebase.

Apple Xcode vulnerabilities

115 known vulnerabilities affecting apple/xcode.

Total CVEs
115
CISA KEV
2
actively exploited
Public exploits
7
Exploited in wild
2
Severity breakdown
CRITICAL10HIGH63MEDIUM38LOW4

Vulnerabilities

Page 2 of 6
CVE-2018-16844P3HIGHCVSS 7.5fixed in 13.02018-11-07
CVE-2018-16844 [HIGH] CWE-400 CVE-2018-16844: nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
nvdapple
CVE-2025-43505P3HIGHCVSS 8.8fixed in 26.12025-11-04
CVE-2025-43505 [HIGH] CWE-787 CVE-2025-43505: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Xc An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Xcode 26.1. Processing a maliciously crafted file may lead to heap corruption.
nvdapple
CVE-2019-8723P3HIGHCVSS 8.8fixed in 11.0≥ unspecified, < Xcode 11.02019-12-18
CVE-2019-8723 [HIGH] CWE-20 CVE-2019-8723: Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. Th Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.
nvdapple
CVE-2019-8724P3HIGHCVSS 8.8fixed in 11.0≥ unspecified, < Xcode 11.02019-12-18
CVE-2019-8724 [HIGH] CWE-20 CVE-2019-8724: Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. Th Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.
nvdapple
CVE-2019-8722P3HIGHCVSS 8.8fixed in 11.0≥ unspecified, < Xcode 11.02019-12-18
CVE-2019-8722 [HIGH] CWE-20 CVE-2019-8722: Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. Th Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.
nvdapple
CVE-2019-8721P3HIGHCVSS 8.8fixed in 11.0≥ unspecified, < Xcode 11.02019-12-18
CVE-2019-8721 [HIGH] CWE-20 CVE-2019-8721: Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. Th Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.
nvdapple
CVE-2016-0746P3CRITICALCVSS 9.8fixed in 13.02016-02-15
CVE-2016-0746 [CRITICAL] CWE-416 CVE-2016-0746: Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 a Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker process crash) or possibly have unspecified other impact via a crafted DNS response related to CNAME response processing.
nvdapple
CVE-2014-6394P3HIGHCVSS 7.5v7.02014-10-08
CVE-2014-6394 [HIGH] CWE-22 CVE-2014-6394: visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a director visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "public" directory.
nvdapple
CVE-2016-2086P3HIGHCVSS 7.5v8.12016-10-27
CVE-2016-2086 [HIGH] CVE-2016-2086: Xcode 8.1 Apple Security Update: About the security content of Xcode 8.1 Product: Xcode Version: 8.1 CVE: CVE-2016-2086 Component: CVE-2016-2086
apple
CVE-2014-3513P3HIGHCVSS 7.1v7.0
CVE-2014-3513 [HIGH] CVE-2014-3513: Xcode 7.0 Apple Security Update: About the security content of Xcode 7.0 Product: Xcode Version: 7.0 CVE: CVE-2014-3513 Component: CVE-2014-3513
apple
CVE-2015-3185P3MEDIUMCVSS 4.3v7.02015-07-20
CVE-2015-3185 [MEDIUM] CWE-264 CVE-2015-3185: The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the pres
nvdapple
CVE-2020-9992P3HIGHCVSS 7.8fixed in 12.0≥ unspecified, < Xcode 12.02020-10-16
CVE-2020-9992 [HIGH] CVE-2020-9992: This issue was addressed by encrypting communications over the network to devices running iOS 14, iP This issue was addressed by encrypting communications over the network to devices running iOS 14, iPadOS 14, tvOS 14, and watchOS 7. This issue is fixed in iOS 14.0 and iPadOS 14.0, Xcode 12.0. An attacker in a privileged network position may be able to execute arbitrary code on a paired device during a debug session over the network.
nvd
CVE-2022-29187P3HIGHCVSS 7.8fixed in 14.12022-07-12
CVE-2022-29187 [HIGH] CVE-2022-29187: Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5, is vulnerable to privilege escalation in all platforms. An unsuspecting user could still be affected by the issue reported in CVE-2022-24765, for example when navigating as root into a shared tmp directory that is owned by the
nvdapple
CVE-2022-24765P3HIGHCVSS 7.8fixed in 13.42022-04-12
CVE-2022-24765 [HIGH] CWE-427 CVE-2022-24765: Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects use Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties have write access to the same hard disk. Those untrusted parties could create the folder `C:\.git`, which would be picked up by Git operations run supposedly outside a repository while searching
nvdapple
CVE-2015-8027P3HIGHCVSS 7.5v8.12016-10-27
CVE-2015-8027 [HIGH] CVE-2015-8027: Xcode 8.1 Apple Security Update: About the security content of Xcode 8.1 Product: Xcode Version: 8.1 CVE: CVE-2015-8027 Component: CVE-2015-8027
apple
CVE-2018-11233P3HIGHCVSS 7.5v9.4.12018-06-13
CVE-2018-11233 [HIGH] CVE-2018-11233: Xcode 9.4.1 Apple Security Update: About the security content of Xcode 9.4.1 Product: Xcode Version: 9.4.1 CVE: CVE-2018-11233 Component: CVE-2018-11233
apple
CVE-2023-27967P3HIGHCVSS 8.6fixed in 14.3≥ unspecified, < 14.32023-05-08
CVE-2023-27967 [HIGH] CVE-2023-27967: The issue was addressed with improved memory handling. This issue is fixed in Xcode 14.3. An app may The issue was addressed with improved memory handling. This issue is fixed in Xcode 14.3. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.
nvdapple
CVE-2014-3567P3HIGHCVSS 7.1v7.0
CVE-2014-3567 [HIGH] CVE-2014-3567: Xcode 7.0 Apple Security Update: About the security content of Xcode 7.0 Product: Xcode Version: 7.0 CVE: CVE-2014-3567 Component: CVE-2014-3567
apple
CVE-2015-6764P3CRITICALCVSS 9.8v8.12016-10-27
CVE-2015-6764 [CRITICAL] CVE-2015-6764: Xcode 8.1 Apple Security Update: About the security content of Xcode 8.1 Product: Xcode Version: 8.1 CVE: CVE-2015-6764 Component: CVE-2015-6764
apple
CVE-2016-1669P3HIGHCVSS 8.8v8.12016-10-27
CVE-2016-1669 [HIGH] CVE-2016-1669: Xcode 8.1 Apple Security Update: About the security content of Xcode 8.1 Product: Xcode Version: 8.1 CVE: CVE-2016-1669 Component: CVE-2016-1669
apple
Apple Xcode vulnerabilities | cvebase