Vulnerabilities > Apple > Xcode > Critical

DATE CVE VULNERABILITY TITLE RISK
2019-12-18 CVE-2019-8721 Improper Input Validation vulnerability in Apple Xcode
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4.
network
apple CWE-20
critical
9.3
2019-12-18 CVE-2019-8722 Improper Input Validation vulnerability in Apple Xcode
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4.
network
apple CWE-20
critical
9.3
2019-12-18 CVE-2019-8723 Improper Input Validation vulnerability in Apple Xcode
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4.
network
apple CWE-20
critical
9.3
2019-12-18 CVE-2019-8724 Improper Input Validation vulnerability in Apple Xcode
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4.
network
apple CWE-20
critical
9.3
2019-07-29 CVE-2019-14379 SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.
network
low complexity
fasterxml debian netapp fedoraproject redhat oracle apple
critical
9.8
2019-04-03 CVE-2018-4357 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple Xcode
A memory corruption issue was addressed with improved input validation.
network
apple CWE-119
critical
9.3
2018-04-03 CVE-2018-4164 Unspecified vulnerability in Apple Xcode
An issue was discovered in certain Apple products.
network
low complexity
apple
critical
10.0
2015-12-11 CVE-2015-7082 Unspecified vulnerability in GIT Project GIT 2.5.3
Multiple unspecified vulnerabilities in Git before 2.5.4, as used in Apple Xcode before 7.2, have unknown impact and attack vectors.
network
low complexity
git-project apple
critical
10.0
2004-12-31 CVE-2004-2687 Configuration vulnerability in multiple products
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs, which are executed by the server without authorization checks.
network
apple samba CWE-16
critical
9.3