Apple Xcode vulnerabilities
115 known vulnerabilities affecting apple/xcode.
Total CVEs
115
CISA KEV
2
actively exploited
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL10HIGH63MEDIUM38LOW4
Vulnerabilities
Page 4 of 6
CVE-2018-16845MEDIUMCVSS 6.1fixed in 13.02018-11-07
CVE-2018-16845 [MEDIUM] CWE-400 CVE-2018-16845: nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might all
nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_modul
nvdapple
CVE-2018-11235HIGHCVSS 7.8PoCv9.4.12018-06-13
CVE-2018-11235 [HIGH] CVE-2018-11235: Xcode 9.4.1
Apple Security Update: About the security content of Xcode 9.4.1
Product: Xcode
Version: 9.4.1
CVE: CVE-2018-11235
Component: Git
Impact: Multiple issues in git, the most significant of which may lead to arbitrary code execution
Description: Multiple issues existed in git. These issues were addressed by updating git to version 2.15.2.
apple
CVE-2018-11233HIGHCVSS 7.5v9.4.12018-06-13
CVE-2018-11233 [HIGH] CVE-2018-11233: Xcode 9.4.1
Apple Security Update: About the security content of Xcode 9.4.1
Product: Xcode
Version: 9.4.1
CVE: CVE-2018-11233
Component: CVE-2018-11233
apple
CVE-2018-4164CRITICALCVSS 9.8fixed in 9.32018-04-03
CVE-2018-4164 [CRITICAL] CVE-2018-4164: An issue was discovered in certain Apple products. Xcode before 9.3 is affected. The issue, which is
An issue was discovered in certain Apple products. Xcode before 9.3 is affected. The issue, which is unspecified, involves the "LLVM" component.
nvdapple
CVE-2017-7167HIGHCVSS 7.8fixed in 9.22018-04-03
CVE-2017-7167 [HIGH] CWE-119 CVE-2017-7167: An issue was discovered in certain Apple products. Xcode before 9.2 is affected. The issue involves
An issue was discovered in certain Apple products. Xcode before 9.2 is affected. The issue involves the "ld64" component. A buffer overflow allows remote attackers to execute arbitrary code via crafted source code.
nvdapple
CVE-2017-7134HIGHCVSS 7.8≤ 8.3.32017-10-23
CVE-2017-7134 [HIGH] CWE-119 CVE-2017-7134: An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves th
An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Mach-O file.
nvd
CVE-2017-7135HIGHCVSS 7.8≤ 8.3.32017-10-23
CVE-2017-7135 [HIGH] CWE-119 CVE-2017-7135: An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves th
An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Mach-O file.
nvd
CVE-2017-7137HIGHCVSS 7.8≤ 8.3.32017-10-23
CVE-2017-7137 [HIGH] CWE-119 CVE-2017-7137: An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves th
An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Mach-O file.
nvd
CVE-2017-7136HIGHCVSS 7.8≤ 8.3.32017-10-23
CVE-2017-7136 [HIGH] CWE-119 CVE-2017-7136: An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves th
An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Mach-O file.
nvd
CVE-2017-7529HIGHCVSS 7.5fixed in 13.02017-07-13
CVE-2017-7529 [HIGH] CWE-190 CVE-2017-7529: Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerabili
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
nvdapple
CVE-2016-0705CRITICALCVSS 9.8v8.12016-10-27
CVE-2016-0705 [CRITICAL] CVE-2016-0705: Xcode 8.1
Apple Security Update: About the security content of Xcode 8.1
Product: Xcode
Version: 8.1
CVE: CVE-2016-0705
Component: CVE-2016-0705
apple
CVE-2015-6764CRITICALCVSS 9.8v8.12016-10-27
CVE-2015-6764 [CRITICAL] CVE-2015-6764: Xcode 8.1
Apple Security Update: About the security content of Xcode 8.1
Product: Xcode
Version: 8.1
CVE: CVE-2015-6764
Component: CVE-2015-6764
apple
CVE-2016-1669HIGHCVSS 8.8v8.12016-10-27
CVE-2016-1669 [HIGH] CVE-2016-1669: Xcode 8.1
Apple Security Update: About the security content of Xcode 8.1
Product: Xcode
Version: 8.1
CVE: CVE-2016-1669
Component: CVE-2016-1669
apple
CVE-2016-2086HIGHCVSS 7.5v8.12016-10-27
CVE-2016-2086 [HIGH] CVE-2016-2086: Xcode 8.1
Apple Security Update: About the security content of Xcode 8.1
Product: Xcode
Version: 8.1
CVE: CVE-2016-2086
Component: CVE-2016-2086
apple
CVE-2016-0797HIGHCVSS 7.5v8.12016-10-27
CVE-2016-0797 [HIGH] CVE-2016-0797: Xcode 8.1
Apple Security Update: About the security content of Xcode 8.1
Product: Xcode
Version: 8.1
CVE: CVE-2016-0797
Component: CVE-2016-0797
apple
CVE-2015-8027HIGHCVSS 7.5v8.12016-10-27
CVE-2015-8027 [HIGH] CVE-2015-8027: Xcode 8.1
Apple Security Update: About the security content of Xcode 8.1
Product: Xcode
Version: 8.1
CVE: CVE-2015-8027
Component: CVE-2015-8027
apple
CVE-2015-3193HIGHCVSS 7.5v8.12016-10-27
CVE-2015-3193 [HIGH] CVE-2015-3193: Xcode 8.1
Apple Security Update: About the security content of Xcode 8.1
Product: Xcode
Version: 8.1
CVE: CVE-2015-3193
Component: CVE-2015-3193
apple
CVE-2016-2216HIGHCVSS 7.5v8.12016-10-27
CVE-2016-2216 [HIGH] CVE-2016-2216: Xcode 8.1
Apple Security Update: About the security content of Xcode 8.1
Product: Xcode
Version: 8.1
CVE: CVE-2016-2216
Component: CVE-2016-2216
apple
CVE-2015-3194HIGHCVSS 7.5v8.12016-10-27
CVE-2015-3194 [HIGH] CVE-2015-3194: Xcode 8.1
Apple Security Update: About the security content of Xcode 8.1
Product: Xcode
Version: 8.1
CVE: CVE-2015-3194
Component: CVE-2015-3194
apple
CVE-2016-0702MEDIUMCVSS 5.1v8.12016-10-27
CVE-2016-0702 [MEDIUM] CVE-2016-0702: Xcode 8.1
Apple Security Update: About the security content of Xcode 8.1
Product: Xcode
Version: 8.1
CVE: CVE-2016-0702
Component: CVE-2016-0702
apple