Show filters
84 Total Results
Displaying 1-10 of 84
Sort by:
Attacker Value
Moderate
CVE-2021-21300
Disclosure Date: March 09, 2021 (last updated November 08, 2023)
Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as files using a clean/smudge filter such as Git LFS, may cause just-checked out script to be executed while cloning onto a case-insensitive file system such as NTFS, HFS+ or APFS (i.e. the default file systems on Windows and macOS). Note that clean/smudge filters have to be configured for that. Git for Windows configures Git LFS by default, and is therefore vulnerable. The problem has been patched in the versions published on Tuesday, March 9th, 2021. As a workaound, if symbolic link support is disabled in Git (e.g. via `git config --global core.symlinks false`), the described attack won't work. Likewise, if no clean/smudge filters such as Git LFS are configured globally (i.e. _before_ cloning), the attack is foiled. As always, it is best to avoid cloning repositories from untrusted sources. The earliest impacted version is 2.14.2.…
5
Attacker Value
Unknown
CVE-2024-44228
Disclosure Date: October 28, 2024 (last updated October 30, 2024)
This issue was addressed with improved permissions checking. This issue is fixed in Xcode 16. An app may be able to inherit Xcode permissions and access user data.
0
Attacker Value
Unknown
CVE-2024-44191
Disclosure Date: September 17, 2024 (last updated September 26, 2024)
This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, Xcode 16, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iPadOS 18, tvOS 18. An app may gain unauthorized access to Bluetooth.
0
Attacker Value
Unknown
CVE-2024-44162
Disclosure Date: September 17, 2024 (last updated September 29, 2024)
This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 16. A malicious application may gain access to a user's Keychain items.
0
Attacker Value
Unknown
CVE-2024-40862
Disclosure Date: September 17, 2024 (last updated December 21, 2024)
A privacy issue was addressed by removing sensitive data. This issue is fixed in Xcode 16. An attacker may be able to determine the Apple ID of the owner of the computer.
0
Attacker Value
Unknown
CVE-2024-23298
Disclosure Date: March 15, 2024 (last updated December 21, 2024)
A logic issue was addressed with improved state management.
0
Attacker Value
Unknown
CVE-2023-40435
Disclosure Date: September 27, 2023 (last updated October 08, 2023)
This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 15. An app may be able to access App Store credentials.
0
Attacker Value
Unknown
CVE-2023-40391
Disclosure Date: September 27, 2023 (last updated October 08, 2023)
The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, macOS Sonoma 14, Xcode 15. An app may be able to disclose kernel memory.
0
Attacker Value
Unknown
CVE-2023-32396
Disclosure Date: September 27, 2023 (last updated October 08, 2023)
This issue was addressed with improved checks. This issue is fixed in Xcode 15, tvOS 17, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to gain elevated privileges.
0
Attacker Value
Unknown
CVE-2022-32920
Disclosure Date: September 06, 2023 (last updated October 08, 2023)
The issue was addressed with improved checks. This issue is fixed in Xcode 14.0. Parsing a file may lead to disclosure of user information.
0