cbcvebase.

Apple Xcode vulnerabilities

115 known vulnerabilities affecting apple/xcode.

Total CVEs
115
CISA KEV
2
actively exploited
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL10HIGH63MEDIUM38LOW4

Vulnerabilities

Page 4 of 6
CVE-2018-16845MEDIUMCVSS 6.1fixed in 13.02018-11-07
CVE-2018-16845 [MEDIUM] CWE-400 CVE-2018-16845: nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might all nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_modul
nvdapple
CVE-2018-11235HIGHCVSS 7.8PoCv9.4.12018-06-13
CVE-2018-11235 [HIGH] CVE-2018-11235: Xcode 9.4.1 Apple Security Update: About the security content of Xcode 9.4.1 Product: Xcode Version: 9.4.1 CVE: CVE-2018-11235 Component: Git Impact: Multiple issues in git, the most significant of which may lead to arbitrary code execution Description: Multiple issues existed in git. These issues were addressed by updating git to version 2.15.2.
apple
CVE-2018-11233HIGHCVSS 7.5v9.4.12018-06-13
CVE-2018-11233 [HIGH] CVE-2018-11233: Xcode 9.4.1 Apple Security Update: About the security content of Xcode 9.4.1 Product: Xcode Version: 9.4.1 CVE: CVE-2018-11233 Component: CVE-2018-11233
apple
CVE-2018-4164CRITICALCVSS 9.8fixed in 9.32018-04-03
CVE-2018-4164 [CRITICAL] CVE-2018-4164: An issue was discovered in certain Apple products. Xcode before 9.3 is affected. The issue, which is An issue was discovered in certain Apple products. Xcode before 9.3 is affected. The issue, which is unspecified, involves the "LLVM" component.
nvdapple
CVE-2017-7167HIGHCVSS 7.8fixed in 9.22018-04-03
CVE-2017-7167 [HIGH] CWE-119 CVE-2017-7167: An issue was discovered in certain Apple products. Xcode before 9.2 is affected. The issue involves An issue was discovered in certain Apple products. Xcode before 9.2 is affected. The issue involves the "ld64" component. A buffer overflow allows remote attackers to execute arbitrary code via crafted source code.
nvdapple
CVE-2017-7134HIGHCVSS 7.8≤ 8.3.32017-10-23
CVE-2017-7134 [HIGH] CWE-119 CVE-2017-7134: An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves th An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Mach-O file.
nvd
CVE-2017-7135HIGHCVSS 7.8≤ 8.3.32017-10-23
CVE-2017-7135 [HIGH] CWE-119 CVE-2017-7135: An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves th An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Mach-O file.
nvd
CVE-2017-7137HIGHCVSS 7.8≤ 8.3.32017-10-23
CVE-2017-7137 [HIGH] CWE-119 CVE-2017-7137: An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves th An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Mach-O file.
nvd
CVE-2017-7136HIGHCVSS 7.8≤ 8.3.32017-10-23
CVE-2017-7136 [HIGH] CWE-119 CVE-2017-7136: An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves th An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Mach-O file.
nvd
CVE-2017-7529HIGHCVSS 7.5fixed in 13.02017-07-13
CVE-2017-7529 [HIGH] CWE-190 CVE-2017-7529: Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerabili Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
nvdapple
CVE-2016-0705CRITICALCVSS 9.8v8.12016-10-27
CVE-2016-0705 [CRITICAL] CVE-2016-0705: Xcode 8.1 Apple Security Update: About the security content of Xcode 8.1 Product: Xcode Version: 8.1 CVE: CVE-2016-0705 Component: CVE-2016-0705
apple
CVE-2015-6764CRITICALCVSS 9.8v8.12016-10-27
CVE-2015-6764 [CRITICAL] CVE-2015-6764: Xcode 8.1 Apple Security Update: About the security content of Xcode 8.1 Product: Xcode Version: 8.1 CVE: CVE-2015-6764 Component: CVE-2015-6764
apple
CVE-2016-1669HIGHCVSS 8.8v8.12016-10-27
CVE-2016-1669 [HIGH] CVE-2016-1669: Xcode 8.1 Apple Security Update: About the security content of Xcode 8.1 Product: Xcode Version: 8.1 CVE: CVE-2016-1669 Component: CVE-2016-1669
apple
CVE-2016-2086HIGHCVSS 7.5v8.12016-10-27
CVE-2016-2086 [HIGH] CVE-2016-2086: Xcode 8.1 Apple Security Update: About the security content of Xcode 8.1 Product: Xcode Version: 8.1 CVE: CVE-2016-2086 Component: CVE-2016-2086
apple
CVE-2016-0797HIGHCVSS 7.5v8.12016-10-27
CVE-2016-0797 [HIGH] CVE-2016-0797: Xcode 8.1 Apple Security Update: About the security content of Xcode 8.1 Product: Xcode Version: 8.1 CVE: CVE-2016-0797 Component: CVE-2016-0797
apple
CVE-2015-8027HIGHCVSS 7.5v8.12016-10-27
CVE-2015-8027 [HIGH] CVE-2015-8027: Xcode 8.1 Apple Security Update: About the security content of Xcode 8.1 Product: Xcode Version: 8.1 CVE: CVE-2015-8027 Component: CVE-2015-8027
apple
CVE-2015-3193HIGHCVSS 7.5v8.12016-10-27
CVE-2015-3193 [HIGH] CVE-2015-3193: Xcode 8.1 Apple Security Update: About the security content of Xcode 8.1 Product: Xcode Version: 8.1 CVE: CVE-2015-3193 Component: CVE-2015-3193
apple
CVE-2016-2216HIGHCVSS 7.5v8.12016-10-27
CVE-2016-2216 [HIGH] CVE-2016-2216: Xcode 8.1 Apple Security Update: About the security content of Xcode 8.1 Product: Xcode Version: 8.1 CVE: CVE-2016-2216 Component: CVE-2016-2216
apple
CVE-2015-3194HIGHCVSS 7.5v8.12016-10-27
CVE-2015-3194 [HIGH] CVE-2015-3194: Xcode 8.1 Apple Security Update: About the security content of Xcode 8.1 Product: Xcode Version: 8.1 CVE: CVE-2015-3194 Component: CVE-2015-3194
apple
CVE-2016-0702MEDIUMCVSS 5.1v8.12016-10-27
CVE-2016-0702 [MEDIUM] CVE-2016-0702: Xcode 8.1 Apple Security Update: About the security content of Xcode 8.1 Product: Xcode Version: 8.1 CVE: CVE-2016-0702 Component: CVE-2016-0702
apple