Vendor CVEs
Apple Inc.
All CVEs
9,002 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-43704 | Med | 0.00 | 5.3 | 0.00 | Jun 29, 2026 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious web extension may be able to cause an unexpected process crash. | ||
| CVE-2026-43703 | Med | 0.00 | 6.5 | 0.00 | Jun 29, 2026 | The issue was addressed with improved memory handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected… | ||
| CVE-2026-28975 | 0.00 | — | 0.00 | Jun 12, 2026 | ### Impact When `NIOHTTPRequestDecompressor` is configured with `.ratio(N)`, the decompression limit is enforced using the `Content-Length` header value from the incoming request rather than the actual number of compressed bytes received. Since `Content-Length` is… | |||
| CVE-2026-28970 | 0.00 | — | 0.00 | Jun 12, 2026 | Programs using swift-nio is vulnerable to HTTP request smuggling and HTTP response splitting attacks, caused by insufficient validation of outbound HTTP/1.1 request and response start line components. This vulnerability affects all swift-nio versions from 2.0.0 to 2.99.0. It is… | |||
| CVE-2026-46312 | 0.00 | — | 0.00 | Jun 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: media: videobuf2: Set vma_flags in vb2_dma_sg_mmap vb2_dma_contig sets VMA flags VM_DONTEXPAND and VM_DONTDUMP and I do not see a reason why vb2_dma_sg should behave differently. This avoids hitting… | |||
| CVE-2024-27301 | Hig | 0.00 | 7.3 | 0.00 | Mar 14, 2024 | Support App is an opensource application specialized in managing Apple devices. It's possible to abuse a vulnerability inside the postinstall installer script to make the installer execute arbitrary code as root. The cause of the vulnerability is the fact that the shebang… | ||
| CVE-2023-4752 | Hig | 0.00 | 7.8 | 0.01 | Sep 4, 2023 | Use After Free in GitHub repository vim/vim prior to 9.0.1858. | ||
| CVE-2023-4751 | Hig | 0.00 | 7.8 | 0.01 | Sep 3, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331. | ||
| CVE-2023-4738 | Hig | 0.00 | 7.8 | 0.01 | Sep 2, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848. | ||
| CVE-2023-38403 | Hig | 0.00 | 7.5 | 0.02 | Jul 17, 2023 | iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field. | ||
| CVE-2023-34241 | Med | 0.00 | 5.3 | 0.01 | Jun 22, 2023 | OpenPrinting CUPS is a standards-based, open source printing system for Linux and other Unix-like operating systems. Starting in version 2.0.0 and prior to version 2.4.6, CUPS logs data of free memory to the logging service AFTER the connection has been closed, when it should… | ||
| CVE-2022-3970 | Med | 0.00 | 6.3 | 0.01 | Nov 13, 2022 | A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed… | ||
| CVE-2022-1725 | Med | 0.00 | 5.5 | 0.01 | Sep 29, 2022 | NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4959. | ||
| CVE-2022-1720 | Hig | 0.00 | 7.8 | 0.02 | Jun 20, 2022 | Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution. | ||
| CVE-2022-2126 | Hig | 0.00 | 7.8 | 0.02 | Jun 19, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-2125 | Hig | 0.00 | 7.8 | 0.02 | Jun 19, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-2124 | Hig | 0.00 | 7.8 | 0.02 | Jun 19, 2022 | Buffer Over-read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-2042 | Hig | 0.00 | 7.8 | 0.01 | Jun 10, 2022 | Use After Free in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-2000 | Hig | 0.00 | 7.8 | 0.02 | Jun 9, 2022 | Out-of-bounds Write in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-1968 | Hig | 0.00 | 7.8 | 0.01 | Jun 2, 2022 | Use After Free in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-1942 | Hig | 0.00 | 7.8 | 0.02 | May 31, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-1927 | Hig | 0.00 | 7.8 | 0.02 | May 29, 2022 | Buffer Over-read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-1897 | Hig | 0.00 | 7.8 | 0.02 | May 27, 2022 | Out-of-bounds Write in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-1898 | Hig | 0.00 | 7.8 | 0.01 | May 27, 2022 | Use After Free in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-26691 | Med | 0.00 | 6.7 | 0.01 | May 26, 2022 | A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges. | ||
| CVE-2022-1851 | Hig | 0.00 | 7.8 | 0.02 | May 25, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-1735 | Hig | 0.00 | 7.8 | 0.01 | May 17, 2022 | Classic Buffer Overflow in GitHub repository vim/vim prior to 8.2.4969. | ||
| CVE-2022-1769 | Hig | 0.00 | 7.8 | 0.00 | May 17, 2022 | Buffer Over-read in GitHub repository vim/vim prior to 8.2.4974. | ||
| CVE-2022-1733 | Hig | 0.00 | 7.8 | 0.01 | May 17, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4968. | ||
| CVE-2022-1674 | Med | 0.00 | 5.5 | 0.02 | May 12, 2022 | NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 in GitHub repository vim/vim prior to 8.2.4938. NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 allows attackers to cause a denial of service (application crash) via a crafted input. | ||
| CVE-2022-1622 | Med | 0.00 | 5.5 | 0.02 | May 11, 2022 | LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:619, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit b4e79bfa. | ||
| CVE-2022-1629 | Hig | 0.00 | 7.8 | 0.02 | May 10, 2022 | Buffer Over-read in function find_next_quote in GitHub repository vim/vim prior to 8.2.4925. This vulnerabilities are capable of crashing software, Modify Memory, and possible remote execution | ||
| CVE-2022-1621 | Hig | 0.00 | 7.8 | 0.02 | May 10, 2022 | Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior to 8.2.4919. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution | ||
| CVE-2022-1620 | Hig | 0.00 | 7.5 | 0.02 | May 8, 2022 | NULL Pointer Dereference in function vim_regexec_string at regexp.c:2729 in GitHub repository vim/vim prior to 8.2.4901. NULL Pointer Dereference in function vim_regexec_string at regexp.c:2729 allows attackers to cause a denial of service (application crash) via a crafted input. | ||
| CVE-2022-1619 | Hig | 0.00 | 7.8 | 0.03 | May 8, 2022 | Heap-based Buffer Overflow in function cmdline_erase_chars in GitHub repository vim/vim prior to 8.2.4899. This vulnerabilities are capable of crashing software, modify memory, and possible remote execution | ||
| CVE-2022-1616 | Hig | 0.00 | 7.8 | 0.03 | May 7, 2022 | Use after free in append_command in GitHub repository vim/vim prior to 8.2.4895. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution | ||
| CVE-2022-1420 | Med | 0.00 | 5.5 | 0.01 | Apr 21, 2022 | Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4774. | ||
| CVE-2022-1381 | Hig | 0.00 | 7.8 | 0.03 | Apr 18, 2022 | global heap buffer overflow in skip_range in GitHub repository vim/vim prior to 8.2.4763. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution | ||
| CVE-2022-0943 | Hig | 0.00 | 7.8 | 0.01 | Mar 14, 2022 | Heap-based Buffer Overflow occurs in vim in GitHub repository vim/vim prior to 8.2.4563. | ||
| CVE-2022-23308 | Hig | 0.00 | 7.5 | 0.06 | Feb 26, 2022 | valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes. | ||
| CVE-2022-0729 | Hig | 0.00 | 8.8 | 0.02 | Feb 23, 2022 | Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4440. | ||
| CVE-2022-0696 | Med | 0.00 | 5.5 | 0.01 | Feb 21, 2022 | NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428. | ||
| CVE-2022-0685 | Hig | 0.00 | 7.8 | 0.02 | Feb 20, 2022 | Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4418. | ||
| CVE-2022-0629 | Hig | 0.00 | 7.8 | 0.02 | Feb 17, 2022 | Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-0554 | Hig | 0.00 | 7.8 | 0.02 | Feb 10, 2022 | Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-0392 | Hig | 0.00 | 7.8 | 0.02 | Jan 28, 2022 | Heap-based Buffer Overflow in GitHub repository vim prior to 8.2. | ||
| CVE-2022-0368 | Hig | 0.00 | 7.8 | 0.02 | Jan 26, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-0361 | Hig | 0.00 | 7.8 | 0.02 | Jan 26, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-0359 | Hig | 0.00 | 7.8 | 0.01 | Jan 26, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-0351 | Hig | 0.00 | 7.8 | 0.01 | Jan 25, 2022 | Access of Memory Location Before Start of Buffer in GitHub repository vim/vim prior to 8.2. |
- risk 0.00cvss 5.3epss 0.00
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious web extension may be able to cause an unexpected process crash.
- risk 0.00cvss 6.5epss 0.00
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected…
- CVE-2026-28975Jun 12, 2026risk 0.00cvss —epss 0.00
### Impact When `NIOHTTPRequestDecompressor` is configured with `.ratio(N)`, the decompression limit is enforced using the `Content-Length` header value from the incoming request rather than the actual number of compressed bytes received. Since `Content-Length` is…
- CVE-2026-28970Jun 12, 2026risk 0.00cvss —epss 0.00
Programs using swift-nio is vulnerable to HTTP request smuggling and HTTP response splitting attacks, caused by insufficient validation of outbound HTTP/1.1 request and response start line components. This vulnerability affects all swift-nio versions from 2.0.0 to 2.99.0. It is…
- CVE-2026-46312Jun 8, 2026risk 0.00cvss —epss 0.00
In the Linux kernel, the following vulnerability has been resolved: media: videobuf2: Set vma_flags in vb2_dma_sg_mmap vb2_dma_contig sets VMA flags VM_DONTEXPAND and VM_DONTDUMP and I do not see a reason why vb2_dma_sg should behave differently. This avoids hitting…
- risk 0.00cvss 7.3epss 0.00
Support App is an opensource application specialized in managing Apple devices. It's possible to abuse a vulnerability inside the postinstall installer script to make the installer execute arbitrary code as root. The cause of the vulnerability is the fact that the shebang…
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.1858.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.
- risk 0.00cvss 7.5epss 0.02
iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
- risk 0.00cvss 5.3epss 0.01
OpenPrinting CUPS is a standards-based, open source printing system for Linux and other Unix-like operating systems. Starting in version 2.0.0 and prior to version 2.4.6, CUPS logs data of free memory to the logging service AFTER the connection has been closed, when it should…
- risk 0.00cvss 6.3epss 0.01
A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed…
- risk 0.00cvss 5.5epss 0.01
NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4959.
- risk 0.00cvss 7.8epss 0.02
Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.
- risk 0.00cvss 7.8epss 0.02
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.02
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.02
Buffer Over-read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.02
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.02
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.02
Buffer Over-read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.02
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 6.7epss 0.01
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges.
- risk 0.00cvss 7.8epss 0.02
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.01
Classic Buffer Overflow in GitHub repository vim/vim prior to 8.2.4969.
- risk 0.00cvss 7.8epss 0.00
Buffer Over-read in GitHub repository vim/vim prior to 8.2.4974.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4968.
- risk 0.00cvss 5.5epss 0.02
NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 in GitHub repository vim/vim prior to 8.2.4938. NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 allows attackers to cause a denial of service (application crash) via a crafted input.
- risk 0.00cvss 5.5epss 0.02
LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:619, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit b4e79bfa.
- risk 0.00cvss 7.8epss 0.02
Buffer Over-read in function find_next_quote in GitHub repository vim/vim prior to 8.2.4925. This vulnerabilities are capable of crashing software, Modify Memory, and possible remote execution
- risk 0.00cvss 7.8epss 0.02
Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior to 8.2.4919. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution
- risk 0.00cvss 7.5epss 0.02
NULL Pointer Dereference in function vim_regexec_string at regexp.c:2729 in GitHub repository vim/vim prior to 8.2.4901. NULL Pointer Dereference in function vim_regexec_string at regexp.c:2729 allows attackers to cause a denial of service (application crash) via a crafted input.
- risk 0.00cvss 7.8epss 0.03
Heap-based Buffer Overflow in function cmdline_erase_chars in GitHub repository vim/vim prior to 8.2.4899. This vulnerabilities are capable of crashing software, modify memory, and possible remote execution
- risk 0.00cvss 7.8epss 0.03
Use after free in append_command in GitHub repository vim/vim prior to 8.2.4895. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution
- risk 0.00cvss 5.5epss 0.01
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4774.
- risk 0.00cvss 7.8epss 0.03
global heap buffer overflow in skip_range in GitHub repository vim/vim prior to 8.2.4763. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow occurs in vim in GitHub repository vim/vim prior to 8.2.4563.
- risk 0.00cvss 7.5epss 0.06
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
- risk 0.00cvss 8.8epss 0.02
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4440.
- risk 0.00cvss 5.5epss 0.01
NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428.
- risk 0.00cvss 7.8epss 0.02
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4418.
- risk 0.00cvss 7.8epss 0.02
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.02
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.02
Heap-based Buffer Overflow in GitHub repository vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.02
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.02
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.01
Access of Memory Location Before Start of Buffer in GitHub repository vim/vim prior to 8.2.
Page 124 of 181