Vulnerabilities
Tracked app vulnerabilities
172 entries
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2024-54506
CRITICAL 9.8
Network
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.2. An attacker may be able to cause unexpect… |
|
CVE-2024-54465
CRITICAL 9.8
Network
A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.2. An app may be able to elevate privileges. |
|
CVE-2024-44299
CRITICAL 9.8
Network
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may be able to cause unex… |
|
CVE-2024-44242
CRITICAL 9.8
Network
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may be able to cause unex… |
|
CVE-2024-44241
CRITICAL 9.8
Network
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may be able to cause unex… |
|
CVE-2023-47100
CRITICAL 9.8
[Apple Perl] Multiple issues in Perl |
|
CVE-2024-44206
CRITICAL 9.3
Network
An issue in the handling of URL protocols was addressed with improved logic. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, t… |
|
CVE-2024-44148
CRITICAL 10.0
Network
This issue was addressed with improved validation of file attributes. This issue is fixed in macOS Sequoia 15. An app may be able to break out of its sandbox. |
|
CVE-2024-44146
CRITICAL 10.0
Network
A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15. An app may be able to break out of its sandbox. |
|
CVE-2024-6387
CRITICAL 8.1
RedHat Openssh: CVE-2024-6387 Remote Code Execution Due To A Race Condition In Signal Handling |
|
CVE-2024-38476
CRITICAL 9.8
Network
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend application… |
|
CVE-2024-27280
CRITICAL 9.8
Network
A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. The ungetbyte and ungetc methods … |
|
CVE-2024-4558
CRITICAL 9.6
Network
Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chr… |
|
CVE-2023-5841
CRITICAL 9.1
Network
Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing… |
|
CVE-2023-50643
CRITICAL 9.8
Network 1 apps
An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments compon… |
|
CVE-2021-44228
CRITICAL 10.0
KEV
Network 1 apps
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameter… |
|
CVE-2021-21300
CRITICAL 8.8
Network 2 apps
Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as f… |
|
CVE-2014-9390
CRITICAL 9.8
Network 2 apps
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows a… |
|
CVE-2019-14379
CRITICAL 9.8
Network 1 apps
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manage… |
|
CVE-2018-15715
CRITICAL 9.8
Network 2 apps
Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are vulnerable to unauth… |
|
CVE-2018-4164
CRITICAL 9.8
Network 1 apps
An issue was discovered in certain Apple products. Xcode before 9.3 is affected. The issue, which is unspecified, involves the "LLVM" component. |
|
CVE-2016-0746
CRITICAL 9.8
Network 1 apps
Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker… |