CVEs (95)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Clang in LLVM, as used in Apple Xcode before 6.3, performs incorrect register allocation in a way that triggers stack storage for stack cookie pointers, which might allow context-dependent attackers to bypass a stack-gua...Show more |
Integer overflow in the simulator in Swift in Apple Xcode before 6.3 allows context-dependent attackers to cause a denial of service or possibly have unspecified other impact by triggering an incorrect result of a type c...Show more |
5Apache AppleOpensuse+2 more9Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+6 moreMay 6, 2026 Apr 8, 2015 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a crafted v1 HTTP protocol request sequences. |
5Apache AppleOpensuse+2 more9Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+6 moreMay 6, 2026 Apr 8, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.8.11 allow remote attackers to cause a denial of service (assertion failure and abort) via crafted parameter combination...Show more |
3Apache AppleRedhat6Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+3 moreMay 6, 2026 Dec 18, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.7.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a request for a UR...Show more |
4Apache AppleDebian+1 more8Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+5 moreMay 6, 2026 Dec 18, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a REPORT requ...Show more |
3Apple FedoraprojectJoyent3Fedora Node.jsXcodeMay 6, 2026 Oct 8, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "pu...Show more |
5Apache AppleCanonical+2 more9Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+6 moreMay 6, 2026 Aug 19, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credent...Show more |
4Apache AppleCanonical+1 more4Opensuse SubversionUbuntu Linux+1 moreMay 6, 2026 Aug 19, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or subjectAltName field of the X.509 certificate, which allows m...Show more |
Apple Xcode before 4.4 does not properly compose a designated requirement (DR) during signing of programs that lack bundle identifiers, which allows remote attackers to read keychain entries via a crafted app, as demonst...Show more |
The WOHyperlink implementation in WebObjects in Apple Xcode tools before 3.1 appends local session IDs to generated non-local URLs, which allows remote attackers to obtain potentially sensitive information by reading the...Show more |
2Apple Openbase International Ltd2Openbase XcodeApr 23, 2026 Oct 17, 2006 N/A· v4 N/A· v3 7.2 HIGH· v2 OpenBase SQL 10.0 and earlier, as used in Apple Xcode 2.2 2.2 and earlier and possibly other products, allows local users to create arbitrary files via a symlink attack on the simulation.sql file. |
2Apple Openbase International Ltd2Openbase XcodeApr 23, 2026 Oct 17, 2006 N/A· v4 N/A· v3 7.2 HIGH· v2 Untrusted search path vulnerability in OpenBase SQL 10.0 and earlier, as used in Apple Xcode 2.2 2.2 and earlier and possibly other products, allows local users to execute arbitrary code via a modified PATH that referenc...Show more |
Xcode Tools before 2.3 for Mac OS X 10.4, when running the WebObjects plugin, allows remote attackers to access or modify WebObjects projects through a network service. |
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs, which are executed by the server without...Show more |