Vulnerabilities
Vulnerable Software
Apple:  >> Xcode  Security Vulnerabilities
A memory corruption issue was addressed with improved state management. This issue is fixed in Xcode 11.0. Processing a maliciously crafted file may lead to arbitrary code execution.
CVSS Score
7.8
EPSS Score
0.004
Published
2019-12-18
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.
CVSS Score
8.8
EPSS Score
0.005
Published
2019-12-18
A memory corruption issue was addressed with improved state management. This issue is fixed in Xcode 11.0. Processing a maliciously crafted file may lead to arbitrary code execution.
CVSS Score
7.8
EPSS Score
0.004
Published
2019-12-18
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.
CVSS Score
8.8
EPSS Score
0.006
Published
2019-12-18
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.
CVSS Score
8.8
EPSS Score
0.006
Published
2019-12-18
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.
CVSS Score
8.8
EPSS Score
0.005
Published
2019-12-18
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.
CVSS Score
9.8
EPSS Score
0.015
Published
2019-07-29
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to Xcode 10.
CVSS Score
7.8
EPSS Score
0.002
Published
2019-04-03
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.
CVSS Score
7.5
EPSS Score
0.102
Published
2019-03-21
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
CVSS Score
5.3
EPSS Score
0.517
Published
2018-11-07


Contact Us

Shodan ® - All rights reserved