Show filters
84 Total Results
Displaying 41-50 of 84
Sort by:
Attacker Value
Unknown
CVE-2019-8723
Disclosure Date: December 18, 2019 (last updated November 27, 2024)
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.
0
Attacker Value
Unknown
CVE-2019-14379
Disclosure Date: November 12, 2019 (last updated November 08, 2023)
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.
0
Attacker Value
Unknown
CVE-2018-4357
Disclosure Date: April 03, 2019 (last updated November 27, 2024)
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to Xcode 10.
0
Attacker Value
Unknown
CVE-2019-3855
Disclosure Date: March 21, 2019 (last updated November 08, 2023)
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.
0
Attacker Value
Unknown
CVE-2018-16843
Disclosure Date: November 07, 2018 (last updated November 27, 2024)
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
0
Attacker Value
Unknown
CVE-2018-16845
Disclosure Date: November 07, 2018 (last updated November 27, 2024)
nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.
0
Attacker Value
Unknown
CVE-2018-16844
Disclosure Date: November 07, 2018 (last updated November 27, 2024)
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
0
Attacker Value
Unknown
CVE-2017-7167
Disclosure Date: April 03, 2018 (last updated November 26, 2024)
An issue was discovered in certain Apple products. Xcode before 9.2 is affected. The issue involves the "ld64" component. A buffer overflow allows remote attackers to execute arbitrary code via crafted source code.
0
Attacker Value
Unknown
CVE-2018-4164
Disclosure Date: April 03, 2018 (last updated November 26, 2024)
An issue was discovered in certain Apple products. Xcode before 9.3 is affected. The issue, which is unspecified, involves the "LLVM" component.
0
Attacker Value
Unknown
CVE-2017-7137
Disclosure Date: October 23, 2017 (last updated November 26, 2024)
An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Mach-O file.
0