Filtered by vendor Apple
Subscribe
Total
14854 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-62871 | 3 Apple, Linux, Microsoft | 6 Macos, Linux Kernel, .net and 3 more | 2026-08-13 | N/A | 7.8 HIGH |
| Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. | |||||
| CVE-2018-15982 | 6 Adobe, Apple, Google and 3 more | 11 Flash Player, Flash Player Installer, Mac Os X and 8 more | 2026-08-13 | 10.0 HIGH | 7.8 HIGH |
| Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution. | |||||
| CVE-2026-11980 | 4 Apple, Ibm, Linux and 1 more | 4 Macos, Aspera Desktop App, Linux Kernel and 1 more | 2026-08-12 | N/A | 7.3 HIGH |
| IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code execution by loading DLL files at start-up. | |||||
| CVE-2026-14973 | 4 Apple, Ibm, Linux and 1 more | 4 Macos, Aspera Desktop App, Linux Kernel and 1 more | 2026-08-12 | N/A | 9.3 CRITICAL |
| IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination. | |||||
| CVE-2023-44487 | 33 Akka, Amazon, Apache and 30 more | 324 Http Server, Opensearch Data Prepper, Apisix and 321 more | 2026-08-11 | N/A | 7.5 HIGH |
| The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |||||
| CVE-2021-44228 | 12 Apache, Apple, Bentley and 9 more | 166 Log4j, Xcode, Synchro and 163 more | 2026-08-11 | 9.3 HIGH | 10.0 CRITICAL |
| Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. | |||||
| CVE-2026-48373 | 3 Adobe, Apple, Microsoft | 5 Acrobat, Acrobat Dc, Acrobat Reader Dc and 2 more | 2026-08-11 | N/A | 7.8 HIGH |
| Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
| CVE-2021-38642 | 2 Apple, Microsoft | 2 Iphone Os, Edge | 2026-08-10 | 4.0 MEDIUM | 6.1 MEDIUM |
| Microsoft Edge for iOS Spoofing Vulnerability | |||||
| CVE-2026-17913 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-08-10 | N/A | 5.4 MEDIUM |
| Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-17724 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-08-10 | N/A | 4.2 MEDIUM |
| Race in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-17716 | 2 Apple, Google | 2 Macos, Chrome | 2026-08-10 | N/A | 8.4 HIGH |
| Use after free in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via malicious network traffic. (Chromium security severity: High) | |||||
| CVE-2026-34641 | 3 Adobe, Apple, Microsoft | 4 Premiere, Premiere Pro, Macos and 1 more | 2026-08-07 | N/A | 7.8 HIGH |
| Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
| CVE-2026-65400 | 1 Apple | 1 Macos | 2026-08-07 | N/A | 7.1 HIGH |
| An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials. | |||||
| CVE-2026-17654 | 2 Apple, Google | 2 Macos, Chrome | 2026-08-06 | N/A | 7.8 HIGH |
| Race in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Critical) | |||||
| CVE-2026-39875 | 1 Apple | 1 Macos | 2026-08-05 | N/A | 7.8 HIGH |
| A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges. | |||||
| CVE-2026-17789 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-08-04 | N/A | 6.5 MEDIUM |
| Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via malicious network traffic. (Chromium security severity: Medium) | |||||
| CVE-2026-18015 | 2 Apple, Google | 2 Macos, Chrome | 2026-08-04 | N/A | 9.6 CRITICAL |
| Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-17761 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-08-04 | N/A | 5.4 MEDIUM |
| Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via malicious network traffic. (Chromium security severity: Medium) | |||||
| CVE-2026-17762 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-08-04 | N/A | 4.3 MEDIUM |
| Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-17770 | 2 Apple, Google | 2 Macos, Chrome | 2026-08-04 | N/A | 5.8 MEDIUM |
| Out of bounds read in Media in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | |||||
