Skip to content
Appaloosa Scout

Vulnerabilities

Tracked app vulnerabilities

172 entries

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

CVE
CVE-2024-54506
CRITICAL 9.8 Network

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.2. An attacker may be able to cause unexpect…

CVE-2024-54465
CRITICAL 9.8 Network

A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.2. An app may be able to elevate privileges.

CVE-2024-44299
CRITICAL 9.8 Network

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may be able to cause unex…

CVE-2024-44242
CRITICAL 9.8 Network

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may be able to cause unex…

CVE-2024-44241
CRITICAL 9.8 Network

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may be able to cause unex…

CVE-2023-47100
CRITICAL 9.8

[Apple Perl] Multiple issues in Perl

CVE-2024-44206
CRITICAL 9.3 Network

An issue in the handling of URL protocols was addressed with improved logic. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, t…

CVE-2024-44148
CRITICAL 10.0 Network

This issue was addressed with improved validation of file attributes. This issue is fixed in macOS Sequoia 15. An app may be able to break out of its sandbox.

CVE-2024-44146
CRITICAL 10.0 Network

A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15. An app may be able to break out of its sandbox.

CVE-2024-6387
CRITICAL 8.1

RedHat Openssh: CVE-2024-6387 Remote Code Execution Due To A Race Condition In Signal Handling

CVE-2024-38476
CRITICAL 9.8 Network

Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend application…

CVE-2024-27280
CRITICAL 9.8 Network

A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. The ungetbyte and ungetc methods …

CVE-2024-4558
CRITICAL 9.6 Network

Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chr…

CVE-2023-5841
CRITICAL 9.1 Network

Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing…

CVE-2023-50643
CRITICAL 9.8 Network 1 apps

An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments compon…

CVE-2021-44228
CRITICAL 10.0 KEV Network 1 apps

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameter…

CVE-2021-21300
CRITICAL 8.8 Network 2 apps

Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as f…

CVE-2014-9390
CRITICAL 9.8 Network 2 apps

Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows a…

CVE-2019-14379
CRITICAL 9.8 Network 1 apps

SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manage…

CVE-2018-15715
CRITICAL 9.8 Network 2 apps

Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are vulnerable to unauth…

CVE-2018-4164
CRITICAL 9.8 Network 1 apps

An issue was discovered in certain Apple products. Xcode before 9.3 is affected. The issue, which is unspecified, involves the "LLVM" component.

CVE-2016-0746
CRITICAL 9.8 Network 1 apps

Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker…