Vulnerabilities > Apple > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-04-12 CVE-2022-29048 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
A cross-site request forgery (CSRF) vulnerability in Jenkins Subversion Plugin 2.15.3 and earlier allows attackers to connect to an attacker-specified URL.
network
low complexity
jenkins apple CWE-352
4.3
2022-04-12 CVE-2021-28544 Information Exposure vulnerability in multiple products
Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules.
network
low complexity
apache debian fedoraproject apple CWE-200
4.3
2022-03-23 CVE-2020-20095 Unspecified vulnerability in Apple Imessage
iMessage (Messages app) iOS 12.4 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages.
network
apple
4.3
2022-03-18 CVE-2021-30771 Out-of-bounds Write vulnerability in Apple products
An out-of-bounds write was addressed with improved input validation.
network
apple CWE-787
6.8
2022-03-18 CVE-2022-22583 Unspecified vulnerability in Apple mac OS X and Macos
A permissions issue was addressed with improved validation.
local
low complexity
apple
5.5
2022-03-18 CVE-2022-22584 Out-of-bounds Write vulnerability in Apple products
A memory corruption issue was addressed with improved validation.
network
apple CWE-787
6.8
2022-03-18 CVE-2022-22585 Link Following vulnerability in Apple products
An issue existed within the path validation logic for symlinks.
network
low complexity
apple CWE-59
5.0
2022-03-18 CVE-2022-22588 Improper Input Validation vulnerability in Apple Iphone OS
A resource exhaustion issue was addressed with improved input validation.
local
low complexity
apple CWE-20
5.5
2022-03-18 CVE-2022-22589 Unspecified vulnerability in Apple products
A validation issue was addressed with improved input sanitization.
network
low complexity
apple
6.1
2022-03-18 CVE-2022-22590 Use After Free vulnerability in Apple products
A use after free issue was addressed with improved memory management.
network
apple CWE-416
6.8