Vulnerabilities > Apple > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-03-18 CVE-2022-22641 Use After Free vulnerability in Apple products
A use after free issue was addressed with improved memory management.
network
low complexity
apple CWE-416
critical
9.8
2022-03-18 CVE-2022-22642 Unspecified vulnerability in Apple Iphone OS
This issue was addressed with improved checks.
network
low complexity
apple
critical
9.8
2022-03-14 CVE-2022-22720 HTTP Request Smuggling vulnerability in multiple products
Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling
network
low complexity
apache fedoraproject debian oracle apple CWE-444
critical
9.8
2022-03-14 CVE-2022-22721 Integer Overflow or Wraparound vulnerability in multiple products
If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes.
network
low complexity
apache fedoraproject debian oracle apple CWE-190
critical
9.1
2022-01-21 CVE-2022-0318 Out-of-bounds Write vulnerability in multiple products
Heap-based Buffer Overflow in vim/vim prior to 8.2.
network
low complexity
vim apple debian CWE-787
critical
9.8
2021-12-23 CVE-2019-8643 Unspecified vulnerability in Apple mac OS X
CVE-2019-8643: Arun Sharma of VMWare This issue is fixed in macOS Mojave 10.14.
network
low complexity
apple
critical
9.8
2021-12-23 CVE-2019-8703 Unspecified vulnerability in Apple products
This issue was addressed with improved entitlements.
network
low complexity
apple
critical
9.8
2021-12-20 CVE-2021-44790 A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts).
network
low complexity
apache fedoraproject debian tenable netapp oracle apple
critical
9.8
2021-12-10 CVE-2021-44228 Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. 10.0
2021-10-19 CVE-2021-30820 Unspecified vulnerability in Apple Ipados and Iphone OS
A logic issue was addressed with improved state management.
network
low complexity
apple
critical
9.8