cbcvebase.

Apple Xcode vulnerabilities

115 known vulnerabilities affecting apple/xcode.

Total CVEs
115
CISA KEV
2
actively exploited
Public exploits
7
Exploited in wild
2
Severity breakdown
CRITICAL10HIGH63MEDIUM38LOW4

Vulnerabilities

Page 5 of 6
CVE-2015-7030P4HIGHCVSS 7.5≤ 7.02015-10-23
CVE-2015-7030 [HIGH] CWE-17 CVE-2015-7030: The Swift implementation in Apple Xcode before 7.1 mishandles type conversion, which has unspecified The Swift implementation in Apple Xcode before 7.1 mishandles type conversion, which has unspecified impact and attack vectors.
nvdapple
CVE-2014-3580P4MEDIUMCVSS 5.0v6.1.12014-12-18
CVE-2014-3580 [MEDIUM] CVE-2014-3580: The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1 The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a REPORT request for a resource that does not exist.
nvdapple
CVE-2014-3528P4MEDIUMCVSS 4.0v6.1.12014-08-19
CVE-2014-3528 [MEDIUM] CWE-255 CVE-2014-3528: Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication realm.
nvdapple
CVE-2016-0702P4MEDIUMCVSS 5.1v8.12016-10-27
CVE-2016-0702 [MEDIUM] CVE-2016-0702: Xcode 8.1 Apple Security Update: About the security content of Xcode 8.1 Product: Xcode Version: 8.1 CVE: CVE-2016-0702 Component: CVE-2016-0702
apple
CVE-2021-1800P4MEDIUMCVSS 5.5fixed in 12.4≥ unspecified, < 12.42021-04-02
CVE-2021-1800 [MEDIUM] CVE-2021-1800: A path handling issue was addressed with improved validation. This issue is fixed in Xcode 12.4. A m A path handling issue was addressed with improved validation. This issue is fixed in Xcode 12.4. A malicious application may be able to access arbitrary files on the host device while running an app that uses on-demand resources with Xcode.
nvd
CVE-2006-5327P4HIGHCVSS 7.2≤ 2.22006-10-17
CVE-2006-5327 [HIGH] CVE-2006-5327: Untrusted search path vulnerability in OpenBase SQL 10.0 and earlier, as used in Apple Xcode 2.2 2.2 Untrusted search path vulnerability in OpenBase SQL 10.0 and earlier, as used in Apple Xcode 2.2 2.2 and earlier and possibly other products, allows local users to execute arbitrary code via a modified PATH that references a malicious gzip program, which is executed by gnutar with certain TAR_OPTIONS environment variable settings, when gnutar is invoked by Open
nvd
CVE-2015-0251P4MEDIUMCVSS 4.0v7.02015-04-08
CVE-2015-0251 [MEDIUM] CWE-345 CVE-2015-0251: The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote aut The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a crafted v1 HTTP protocol request sequences.
nvdapple
CVE-2015-5909P4MEDIUMCVSS 5.0≤ 6.42015-09-18
CVE-2015-5909 [MEDIUM] CWE-200 CVE-2015-5909: IDE Xcode Server in Apple Xcode before 7.0 does not properly restrict access to repository e-mail li IDE Xcode Server in Apple Xcode before 7.0 does not properly restrict access to repository e-mail lists, which allows remote attackers to obtain potentially sensitive build information in opportunistic circumstances by leveraging incorrect notification delivery.
nvdapple
CVE-2025-30441P4MEDIUMCVSS 5.5fixed in 16.32025-03-31
CVE-2025-30441 [MEDIUM] CWE-787 CVE-2025-30441: This issue was addressed through improved state management. This issue is fixed in Xcode 16.3. An ap This issue was addressed through improved state management. This issue is fixed in Xcode 16.3. An app may be able to overwrite arbitrary files.
nvdapple
CVE-2024-44191P4MEDIUMCVSS 5.5fixed in 16.0fixed in 162024-09-17
CVE-2024-44191 [MEDIUM] CVE-2024-44191: This issue was addressed through improved state management. This issue is fixed in Xcode 16, iOS 17. This issue was addressed through improved state management. This issue is fixed in Xcode 16, iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. An app may gain unauthorized access to Bluetooth.
nvdapple
CVE-2024-40862P4MEDIUMCVSS 5.3fixed in 16.0fixed in 162024-09-17
CVE-2024-40862 [MEDIUM] CWE-200 CVE-2024-40862: A privacy issue was addressed by removing sensitive data. This issue is fixed in Xcode 16. An attack A privacy issue was addressed by removing sensitive data. This issue is fixed in Xcode 16. An attacker may be able to determine the Apple ID of the owner of the computer.
nvdapple
CVE-2006-5328P4HIGHCVSS 7.2≤ 2.22006-10-17
CVE-2006-5328 [HIGH] CVE-2006-5328: OpenBase SQL 10.0 and earlier, as used in Apple Xcode 2.2 2.2 and earlier and possibly other product OpenBase SQL 10.0 and earlier, as used in Apple Xcode 2.2 2.2 and earlier and possibly other products, allows local users to create arbitrary files via a symlink attack on the simulation.sql file.
nvd
CVE-2022-39253P4MEDIUMCVSS 5.5fixed in 14.12022-10-19
CVE-2022-39253 [MEDIUM] CWE-200 CVE-2022-39253: Git is an open source, scalable, distributed revision control system. Versions prior to 2.30.6, 2.31 Git is an open source, scalable, distributed revision control system. Versions prior to 2.30.6, 2.31.5, 2.32.4, 2.33.5, 2.34.5, 2.35.5, 2.36.3, and 2.37.4 are subject to exposure of sensitive information to a malicious actor. When performing a local clone (where the source and target of the clone are on the same volume), Git copies the contents of t
nvdapple
CVE-2015-3027P4MEDIUMCVSS 5.0≤ 6.22015-04-10
CVE-2015-3027 [MEDIUM] CWE-264 CVE-2015-3027: Clang in LLVM, as used in Apple Xcode before 6.3, performs incorrect register allocation in a way th Clang in LLVM, as used in Apple Xcode before 6.3, performs incorrect register allocation in a way that triggers stack storage for stack cookie pointers, which might allow context-dependent attackers to bypass a stack-guard protection mechanism via crafted input to an affected C program.
nvd
CVE-2023-27945P4MEDIUMCVSS 6.3fixed in 14.3≥ unspecified, < 14.32023-05-08
CVE-2023-27945 [MEDIUM] CWE-125 CVE-2023-27945: This issue was addressed with improved entitlements. This issue is fixed in Xcode 14.3, macOS Big Su This issue was addressed with improved entitlements. This issue is fixed in Xcode 14.3, macOS Big Sur 11.7.7, macOS Monterey 12.6.6. A sandboxed app may be able to collect system logs.
nvdapple
CVE-2014-3522P4MEDIUMCVSS 4.0v6.1.12014-08-19
CVE-2014-3522 [MEDIUM] CWE-297 CVE-2014-3522: The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 doe The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.
nvdapple
CVE-2023-40391P4MEDIUMCVSS 5.5fixed in 15.0≥ unspecified, < 152023-09-27
CVE-2023-40391 [MEDIUM] CVE-2023-40391: The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, iOS 17 and iP The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, macOS Sonoma 14, Xcode 15. An app may be able to disclose kernel memory.
nvdapple
CVE-2012-3698P4MEDIUMCVSS 5.0≤ 4.3.3v1.5.0+25 more2012-07-26
CVE-2012-3698 [MEDIUM] CWE-264 CVE-2012-3698: Apple Xcode before 4.4 does not properly compose a designated requirement (DR) during signing of pro Apple Xcode before 4.4 does not properly compose a designated requirement (DR) during signing of programs that lack bundle identifiers, which allows remote attackers to read keychain entries via a crafted app, as demonstrated by the keychain entries of a (1) helper tool or (2) command-line tool.
nvd
CVE-2025-43504P4MEDIUMCVSS 4.9fixed in 26.12025-11-04
CVE-2025-43504 [MEDIUM] CWE-119 CVE-2025-43504: A buffer overflow was addressed with improved bounds checking. This issue is fixed in Xcode 26.1. A A buffer overflow was addressed with improved bounds checking. This issue is fixed in Xcode 26.1. A user in a privileged network position may be able to cause a denial-of-service.
nvdapple
CVE-2015-3187P4MEDIUMCVSS 4.0≤ 7.2.12015-08-12
CVE-2015-3187 [MEDIUM] CWE-200 CVE-2015-3187: The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 and 1.8.x before 1.8. The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 and 1.8.x before 1.8.14, when path-based authorization is used, allows remote authenticated users to obtain sensitive path information by reading the history of a node that has been moved from a hidden path.
nvdapple
Apple Xcode vulnerabilities | cvebase