Vulnerabilities > Apple

DATE CVE VULNERABILITY TITLE RISK
2023-05-26 CVE-2023-28320 Resource Exhaustion vulnerability in multiple products
A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time.
network
high complexity
haxx apple netapp CWE-400
5.9
2023-05-26 CVE-2023-28321 Improper Certificate Validation vulnerability in multiple products
An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates.
network
high complexity
haxx debian fedoraproject netapp apple CWE-295
5.9
2023-05-26 CVE-2023-28322 An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously wasused to issue a `PUT` request which used that callback.
network
high complexity
haxx fedoraproject apple netapp
3.7
2023-05-19 CVE-2023-30774 Out-of-bounds Write vulnerability in multiple products
A vulnerability was found in the libtiff library.
local
low complexity
libtiff apple CWE-787
5.5
2023-05-08 CVE-2022-32885 Out-of-bounds Write vulnerability in Apple products
A memory corruption issue was addressed with improved validation.
network
low complexity
apple CWE-787
8.8
2023-05-08 CVE-2022-46720 Integer Overflow or Wraparound vulnerability in Apple Ipados and Iphone OS
An integer overflow was addressed with improved input validation.
local
low complexity
apple CWE-190
8.6
2023-05-08 CVE-2023-23494 Classic Buffer Overflow vulnerability in Apple Iphone OS
A buffer overflow was addressed with improved bounds checking.
network
high complexity
apple CWE-120
5.3
2023-05-08 CVE-2023-23523 Unspecified vulnerability in Apple Iphone OS
A logic issue was addressed with improved restrictions.
local
low complexity
apple
3.3
2023-05-08 CVE-2023-23525 Unspecified vulnerability in Apple Iphone OS
This issue was addressed with improved checks.
local
low complexity
apple
7.8
2023-05-08 CVE-2023-23526 Unspecified vulnerability in Apple Iphone OS
This was addressed with additional checks by Gatekeeper on files downloaded from an iCloud shared-by-me folder.
network
low complexity
apple
critical
9.8