Apple Xcode vulnerabilities
115 known vulnerabilities affecting apple/xcode.
Total CVEs
115
CISA KEV
2
actively exploited
Public exploits
7
Exploited in wild
2
Severity breakdown
CRITICAL10HIGH63MEDIUM38LOW4
Vulnerabilities
Page 4 of 6
CVE-2014-3568P3MEDIUMCVSS 4.3v7.0
CVE-2014-3568 [MEDIUM] CVE-2014-3568: Xcode 7.0
Apple Security Update: About the security content of Xcode 7.0
Product: Xcode
Version: 7.0
CVE: CVE-2014-3568
Component: CVE-2014-3568
apple
CVE-2015-3184P3MEDIUMCVSS 5.0≤ 7.2.12015-08-12
CVE-2015-3184 [MEDIUM] CWE-200 CVE-2015-3184: mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache ht
mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access, which allows remote anonymous users to read hidden files via the path name.
nvdapple
CVE-2016-0747P3MEDIUMCVSS 5.3fixed in 13.02016-02-15
CVE-2016-0747 [MEDIUM] CWE-400 CVE-2016-0747: The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution,
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.
nvdapple
CVE-2025-43371P3HIGHCVSS 8.2fixed in 26.0fixed in 262025-09-15
CVE-2025-43371 [HIGH] CWE-284 CVE-2025-43371: This issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able t
This issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to break out of its sandbox.
nvdapple
CVE-2015-7082P4CRITICALCVSS 10.0v7.2
CVE-2015-7082 [CRITICAL] CVE-2015-7082: Xcode 7.2
Apple Security Update: About the security content of Xcode 7.2
Product: Xcode
Version: 7.2
CVE: CVE-2015-7082
Component: CVE-2015-7082
apple
CVE-2018-4357P3HIGHCVSS 7.8fixed in 10vVersions prior to: Xcode 102019-04-03
CVE-2018-4357 [HIGH] CWE-119 CVE-2018-4357: A memory corruption issue was addressed with improved input validation. This issue affected versions
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to Xcode 10.
nvdapple
CVE-2022-26747P3HIGHCVSS 7.8fixed in 13.4≥ unspecified, < 13.42022-05-26
CVE-2022-26747 [HIGH] CVE-2022-26747: This issue was addressed with improved checks. This issue is fixed in Xcode 13.4. An app may be able
This issue was addressed with improved checks. This issue is fixed in Xcode 13.4. An app may be able to gain elevated privileges.
nvdapple
CVE-2018-16845P4MEDIUMCVSS 6.1fixed in 13.02018-11-07
CVE-2018-16845 [MEDIUM] CWE-400 CVE-2018-16845: nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might all
nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_modul
nvdapple
CVE-2017-7134P4HIGHCVSS 7.8≤ 8.3.32017-10-23
CVE-2017-7134 [HIGH] CWE-119 CVE-2017-7134: An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves th
An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Mach-O file.
nvd
CVE-2017-7135P4HIGHCVSS 7.8≤ 8.3.32017-10-23
CVE-2017-7135 [HIGH] CWE-119 CVE-2017-7135: An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves th
An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Mach-O file.
nvd
CVE-2017-7137P4HIGHCVSS 7.8≤ 8.3.32017-10-23
CVE-2017-7137 [HIGH] CWE-119 CVE-2017-7137: An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves th
An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Mach-O file.
nvd
CVE-2017-7136P4HIGHCVSS 7.8≤ 8.3.32017-10-23
CVE-2017-7136 [HIGH] CWE-119 CVE-2017-7136: An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves th
An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Mach-O file.
nvd
CVE-2016-4705P4HIGHCVSS 7.8≤ 7.3.12016-09-18
CVE-2016-4705 [HIGH] CVE-2016-4705: otool in Apple Xcode before 8 allows local users to gain privileges or cause a denial of service (me
otool in Apple Xcode before 8 allows local users to gain privileges or cause a denial of service (memory corruption and application crash) via unspecified vectors, a different vulnerability than CVE-2016-4704.
nvd
CVE-2016-1765P4HIGHCVSS 7.8≤ 7.2.12016-03-24
CVE-2016-1765 [HIGH] CWE-119 CVE-2016-1765: otool in Apple Xcode before 7.3 allows local users to gain privileges or cause a denial of service (
otool in Apple Xcode before 7.3 allows local users to gain privileges or cause a denial of service (memory corruption and application crash) via unspecified vectors.
nvdapple
CVE-2016-4704P4HIGHCVSS 7.8≤ 7.3.12016-09-18
CVE-2016-4704 [HIGH] CWE-119 CVE-2016-4704: otool in Apple Xcode before 8 allows local users to gain privileges or cause a denial of service (me
otool in Apple Xcode before 8 allows local users to gain privileges or cause a denial of service (memory corruption and application crash) via unspecified vectors, a different vulnerability than CVE-2016-4705.
nvd
CVE-2015-1149P4HIGHCVSS 7.5≤ 6.22015-04-10
CVE-2015-1149 [HIGH] CWE-189 CVE-2015-1149: Integer overflow in the simulator in Swift in Apple Xcode before 6.3 allows context-dependent attack
Integer overflow in the simulator in Swift in Apple Xcode before 6.3 allows context-dependent attackers to cause a denial of service or possibly have unspecified other impact by triggering an incorrect result of a type conversion.
nvdapple
CVE-2015-0248P4MEDIUMCVSS 5.0v7.02015-04-08
CVE-2015-0248 [MEDIUM] CWE-399 CVE-2015-0248: The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.
The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.8.11 allow remote attackers to cause a denial of service (assertion failure and abort) via crafted parameter combinations related to dynamically evaluated revision numbers.
nvdapple
CVE-2025-43263P4HIGHCVSS 7.1fixed in 26.0fixed in 262025-09-15
CVE-2025-43263 [HIGH] CWE-284 CVE-2025-43263: The issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to
The issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to read and write files outside of its sandbox.
nvdapple
CVE-2014-8108P4MEDIUMCVSS 5.0v6.1.12014-12-18
CVE-2014-8108 [MEDIUM] CVE-2014-8108: The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.7.x before 1.7.19 and 1.8.x before
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.7.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a request for a URI that triggers a lookup for a virtual transaction name that does not exist.
nvdapple
CVE-2026-28889P4MEDIUMCVSS 6.2fixed in 26.42026-03-25
CVE-2026-28889 [MEDIUM] CWE-269 CVE-2026-28889: A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 26.4. A
A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 26.4. An app may be able to read arbitrary files as root.
nvd