Vulnerabilities > Apple > Xcode > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-09-17 CVE-2024-44191 Unspecified vulnerability in Apple products
This issue was addressed through improved state management.
local
low complexity
apple
5.5
2023-09-27 CVE-2023-40391 Unspecified vulnerability in Apple products
The issue was addressed with improved memory handling.
local
low complexity
apple
5.5
2023-09-27 CVE-2023-40435 Unspecified vulnerability in Apple Xcode
This issue was addressed by enabling hardened runtime.
local
low complexity
apple
5.5
2023-09-06 CVE-2022-32920 Unspecified vulnerability in Apple Xcode
The issue was addressed with improved checks.
local
low complexity
apple
5.5
2023-05-08 CVE-2023-27945 Unspecified vulnerability in Apple Xcode
This issue was addressed with improved entitlements.
local
low complexity
apple
6.3
2022-10-19 CVE-2022-39253 Link Following vulnerability in multiple products
Git is an open source, scalable, distributed revision control system.
local
low complexity
git-scm fedoraproject apple debian CWE-59
5.5
2021-04-02 CVE-2021-1800 Unspecified vulnerability in Apple Xcode
A path handling issue was addressed with improved validation.
local
low complexity
apple
5.5
2020-01-09 CVE-2019-20372 HTTP Request Smuggling vulnerability in multiple products
NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.
network
low complexity
f5 apple canonical opensuse netapp CWE-444
5.3
2018-11-07 CVE-2018-16845 Resource Exhaustion vulnerability in multiple products
nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file.
local
low complexity
f5 debian canonical opensuse apple CWE-400
6.1
2016-02-15 CVE-2016-0747 Resource Exhaustion vulnerability in multiple products
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.
network
low complexity
f5 canonical debian opensuse apple CWE-400
5.3