Apple Xcode vulnerabilities
115 known vulnerabilities affecting apple/xcode.
Total CVEs
115
CISA KEV
2
actively exploited
Public exploits
7
Exploited in wild
2
Severity breakdown
CRITICAL10HIGH63MEDIUM38LOW4
Vulnerabilities
Page 3 of 6
CVE-2024-44162P3HIGHCVSS 7.8fixed in 16.0fixed in 162024-09-17
CVE-2024-44162 [HIGH] CWE-863 CVE-2024-44162: This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 16. A malicious
This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 16. A malicious application may gain access to a user's Keychain items.
nvdapple
CVE-2019-20372P3MEDIUMCVSS 5.3fixed in 13.02020-01-09
CVE-2019-20372 [MEDIUM] CWE-444 CVE-2019-20372: NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demon
NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.
nvdapple
CVE-2018-4164P3CRITICALCVSS 9.8fixed in 9.32018-04-03
CVE-2018-4164 [CRITICAL] CVE-2018-4164: An issue was discovered in certain Apple products. Xcode before 9.3 is affected. The issue, which is
An issue was discovered in certain Apple products. Xcode before 9.3 is affected. The issue, which is unspecified, involves the "LLVM" component.
nvdapple
CVE-2019-8739P3HIGHCVSS 7.8fixed in 11.0≥ unspecified, < Xcode 11.02019-12-18
CVE-2019-8739 [HIGH] CWE-787 CVE-2019-8739: A memory corruption issue was addressed with improved state management. This issue is fixed in Xcode
A memory corruption issue was addressed with improved state management. This issue is fixed in Xcode 11.0. Processing a maliciously crafted file may lead to arbitrary code execution.
nvdapple
CVE-2019-8738P3HIGHCVSS 7.8fixed in 11.0≥ unspecified, < Xcode 11.02019-12-18
CVE-2019-8738 [HIGH] CWE-787 CVE-2019-8738: A memory corruption issue was addressed with improved state management. This issue is fixed in Xcode
A memory corruption issue was addressed with improved state management. This issue is fixed in Xcode 11.0. Processing a maliciously crafted file may lead to arbitrary code execution.
nvdapple
CVE-2019-8800P3HIGHCVSS 7.8fixed in 11.2≥ unspecified, < Xcode 11.22019-12-18
CVE-2019-8800 [HIGH] CWE-787 CVE-2019-8800: A memory corruption issue was addressed with improved validation. This issue is fixed in Xcode 11.2.
A memory corruption issue was addressed with improved validation. This issue is fixed in Xcode 11.2. Processing a maliciously crafted file may lead to arbitrary code execution.
nvdapple
CVE-2019-8806P3HIGHCVSS 7.8fixed in 11.2≥ unspecified, < Xcode 11.22019-12-18
CVE-2019-8806 [HIGH] CWE-787 CVE-2019-8806: A memory corruption issue was addressed with improved validation. This issue is fixed in Xcode 11.2.
A memory corruption issue was addressed with improved validation. This issue is fixed in Xcode 11.2. Processing a maliciously crafted file may lead to arbitrary code execution.
nvdapple
CVE-2024-44228P3HIGHCVSS 7.5fixed in 16.0fixed in 162024-10-28
CVE-2024-44228 [HIGH] CWE-276 CVE-2024-44228: This issue was addressed with improved permissions checking. This issue is fixed in Xcode 16. An app
This issue was addressed with improved permissions checking. This issue is fixed in Xcode 16. An app may be able to inherit Xcode permissions and access user data.
nvdapple
CVE-2017-7167P3HIGHCVSS 7.8fixed in 9.22018-04-03
CVE-2017-7167 [HIGH] CWE-119 CVE-2017-7167: An issue was discovered in certain Apple products. Xcode before 9.2 is affected. The issue involves
An issue was discovered in certain Apple products. Xcode before 9.2 is affected. The issue involves the "ld64" component. A buffer overflow allows remote attackers to execute arbitrary code via crafted source code.
nvdapple
CVE-2022-22606P3HIGHCVSS 7.8fixed in 13.3≥ unspecified, < 13.32022-03-18
CVE-2022-22606 [HIGH] CWE-125 CVE-2022-22606: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution.
nvdapple
CVE-2022-22602P3HIGHCVSS 7.8fixed in 13.3≥ unspecified, < 13.32022-03-18
CVE-2022-22602 [HIGH] CWE-125 CVE-2022-22602: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution.
nvdapple
CVE-2022-22601P3HIGHCVSS 7.8fixed in 13.3≥ unspecified, < 13.32022-03-18
CVE-2022-22601 [HIGH] CWE-125 CVE-2022-22601: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution.
nvdapple
CVE-2022-22603P3HIGHCVSS 7.8fixed in 13.3≥ unspecified, < 13.32022-03-18
CVE-2022-22603 [HIGH] CWE-125 CVE-2022-22603: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution.
nvdapple
CVE-2022-22604P3HIGHCVSS 7.8fixed in 13.3≥ unspecified, < 13.32022-03-18
CVE-2022-22604 [HIGH] CWE-125 CVE-2022-22604: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution.
nvdapple
CVE-2022-22607P3HIGHCVSS 7.8fixed in 13.3≥ unspecified, < 13.32022-03-18
CVE-2022-22607 [HIGH] CWE-125 CVE-2022-22607: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution.
nvdapple
CVE-2022-22608P3HIGHCVSS 7.8fixed in 13.3≥ unspecified, < 13.32022-03-18
CVE-2022-22608 [HIGH] CWE-125 CVE-2022-22608: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution.
nvdapple
CVE-2022-22605P3HIGHCVSS 7.8fixed in 13.3≥ unspecified, < 13.32022-03-18
CVE-2022-22605 [HIGH] CWE-125 CVE-2022-22605: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution.
nvdapple
CVE-2023-32396P3HIGHCVSS 7.8fixed in 15.0≥ unspecified, < 152023-09-27
CVE-2023-32396 [HIGH] CVE-2023-32396: This issue was addressed with improved checks. This issue is fixed in Xcode 15, tvOS 17, watchOS 10,
This issue was addressed with improved checks. This issue is fixed in Xcode 15, tvOS 17, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to gain elevated privileges.
nvdapple
CVE-2018-4461P3HIGHCVSS 7.8v10.22019-03-25
CVE-2018-4461 [HIGH] CVE-2018-4461: Xcode 10.2
Apple Security Update: About the security content of Xcode 10.2
Product: Xcode
Version: 10.2
CVE: CVE-2018-4461
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed with improved input validation.
apple
CVE-2022-42797P3HIGHCVSS 7.8fixed in 14.1≥ unspecified, < 14.12023-02-27
CVE-2022-42797 [HIGH] CWE-74 CVE-2022-42797: An injection issue was addressed with improved input validation. This issue is fixed in Xcode 14.1.
An injection issue was addressed with improved input validation. This issue is fixed in Xcode 14.1. An app may be able to gain root privileges.
nvdapple