Vulnerabilities > Apple > Xcode > 7.0

DATE CVE VULNERABILITY TITLE RISK
2019-12-18 CVE-2019-8723 Improper Input Validation vulnerability in Apple Xcode
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4.
network
apple CWE-20
critical
9.3
2019-12-18 CVE-2019-8722 Improper Input Validation vulnerability in Apple Xcode
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4.
network
apple CWE-20
critical
9.3
2019-12-18 CVE-2019-8721 Improper Input Validation vulnerability in Apple Xcode
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4.
network
apple CWE-20
critical
9.3
2019-07-29 CVE-2019-14379 SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.
network
low complexity
fasterxml debian netapp fedoraproject redhat oracle apple
critical
9.8
2019-04-03 CVE-2018-4357 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple Xcode
A memory corruption issue was addressed with improved input validation.
network
apple CWE-119
critical
9.3
2019-03-21 CVE-2019-3855 Integer Overflow or Wraparound vulnerability in multiple products
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from the server.
8.8
2018-11-07 CVE-2018-16845 Resource Exhaustion vulnerability in multiple products
nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file.
5.8
2018-11-07 CVE-2018-16844 Resource Exhaustion vulnerability in multiple products
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage.
network
low complexity
f5 debian canonical apple CWE-400
7.8
2018-11-07 CVE-2018-16843 Resource Exhaustion vulnerability in multiple products
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption.
network
low complexity
f5 debian canonical opensuse apple CWE-400
7.8
2018-04-03 CVE-2018-4164 Unspecified vulnerability in Apple Xcode
An issue was discovered in certain Apple products.
network
low complexity
apple
critical
10.0