Skip to content
Noroxi

Apple records

15,437 published records for vendor apple.

Researcher profile

Entered KEV
167 · 1.1%
Weaponized
243 · 1.6%
Pre-auth RCE
4,143
With a fix record
24.3%
Median publish → KEV
234 days

All records

10,000+ records
  • Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    apache · log4jDec 10, 2021

  • GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    gnu · bashSep 24, 2014

  • sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    php · phpMay 11, 2012

  • Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    adobe · flash playerJun 23, 2015

  • GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    gnu · bashSep 24, 2014

  • Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    adobe · flash playerFeb 5, 2014

  • Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    adobe · flash playerJul 8, 2015

  • Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before

    CriticalCVSS 9.8KEVWeaponizedEPSS 95%

    adobe · flash playerFeb 2, 2015

  • Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0

    CriticalCVSS 9.8KEVWeaponizedEPSS 94%

    adobe · flash playerJul 14, 2015

  • Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly exe

    CriticalCVSS 9.8KEVWeaponizedEPSS 94%

    adobe · coldfusionJan 8, 2013

  • Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x

    CriticalCVSS 9.8KEVWeaponizedEPSS 89%

    adobe · acrobatDec 7, 2011

  • Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.

    HighCVSS 8.8KEVWeaponizedEPSS 99%

    adobe · flash playerApr 13, 2011

  • Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and throu

    CriticalCVSS 9.8KEVWeaponizedEPSS 86%

    adobe · flash playerJan 23, 2015

  • Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Execution

    HighCVSS 8.8KEVWeaponizedEPSS 86%

    adobe · acrobatFeb 11, 2021

  • Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows att

    CriticalCVSS 9.8KEVWeaponizedEPSS 74%

    adobe · flash playerApr 14, 2015

  • The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023

  • The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remot

    HighCVSS 8.8KEVWeaponizedEPSS 83%

    adobe · acrobatJan 13, 2010

  • Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x

    HighCVSS 8.1KEVWeaponizedEPSS 91%

    adobe · flash playerFeb 16, 2012

  • Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability.

    HighCVSS 7.8KEVWeaponizedEPSS 90%

    adobe · flash playerJan 18, 2019

  • A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161.

    HighCVSS 7.8KEVWeaponizedEPSS 90%

    adobe · flash playerFeb 6, 2018

  • Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or c

    HighCVSS 7.8KEVWeaponizedEPSS 87%

    adobe · acrobatFeb 13, 2013

  • Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3,

    HighCVSS 7.8KEVWeaponizedEPSS 83%

    adobe · airJun 8, 2010

  • Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before

    HighCVSS 7.8KEVWeaponizedEPSS 82%

    adobe · acrobatDec 14, 2009

  • Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via

    HighCVSS 8.8KEVWeaponizedEPSS 70%

    google · chromeJul 27, 2022

  • Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on

    HighCVSS 8.8KEVWeaponizedEPSS 68%

    adobe · air sdkDec 28, 2015