Apple records
15,437 published records for vendor apple.
Researcher profile
- Entered KEV
- 167 · 1.1%
- Weaponized
- 243 · 1.6%
- Pre-auth RCE
- 4,143
- With a fix record
- 24.3%
- Median publish → KEV
- 234 days
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2,367
- CWE-416 Use After Free1,361
- CWE-125 Out-of-bounds Read1,353
- CWE-787 Out-of-bounds Write1,275
- CWE-20 Improper Input Validation825
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor746
The weakness classes this vendor ships most often: where to look.
CWEAll records
10,000+ records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
100Now | CVE-2021-44228Weaponized | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpointsapache · log4j · CWE-20 | Critical10.0 | KEV | 100.0% | Dec 10, 2021 |
99Now | CVE-2014-6271Weaponized | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Critical9.8 | KEV | 100.0% | Sep 24, 2014 |
99Now | CVE-2012-1823Weaponized | sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle quephp · php · CWE-77 | Critical9.8 | KEV | 100.0% | May 11, 2012 |
99Now | CVE-2015-3113Weaponized | Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11adobe · flash player · CWE-787 | Critical9.8 | KEV | 99.9% | Jun 23, 2015 |
99Now | CVE-2014-7169Weaponized | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Critical9.8 | KEV | 99.9% | Sep 24, 2014 |
99Now | CVE-2014-0497Weaponized | Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1adobe · flash player · CWE-191 | Critical9.8 | KEV | 99.9% | Feb 5, 2014 |
99Now | CVE-2015-5119Weaponized | Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296adobe · flash player · CWE-416 | Critical9.8 | KEV | 99.3% | Jul 8, 2015 |
98Now | CVE-2015-0313Weaponized | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before adobe · flash player · CWE-416 | Critical9.8 | KEV | 95.3% | Feb 2, 2015 |
97Now | CVE-2015-5122Weaponized | Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0adobe · flash player · CWE-416 | Critical9.8 | KEV | 94.0% | Jul 14, 2015 |
97Now | CVE-2013-0625Weaponized | Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly exeadobe · coldfusion · CWE-287 | Critical9.8 | KEV | 93.8% | Jan 8, 2013 |
96Now | CVE-2011-2462Weaponized | Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x adobe · acrobat · CWE-787 | Critical9.8 | KEV | 88.5% | Dec 7, 2011 |
95Now | CVE-2011-0611Weaponized | Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.adobe · flash player · CWE-843 | High8.8 | KEV | 99.4% | Apr 13, 2011 |
95Now | CVE-2015-0311Weaponized | Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and throuadobe · flash player | Critical9.8 | KEV | 85.6% | Jan 23, 2015 |
91Now | CVE-2021-21017Weaponized | Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Executionadobe · acrobat · CWE-122 | High8.8 | KEV | 86.3% | Feb 11, 2021 |
91Now | CVE-2015-3043Weaponized | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attadobe · flash player · CWE-787 | Critical9.8 | KEV | 73.9% | Apr 14, 2015 |
90Now | CVE-2023-44487Weaponized | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | High7.5 | KEV | 100.0% | Oct 10, 2023 |
90Now | CVE-2009-3953Weaponized | The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remotadobe · acrobat · CWE-787 | High8.8 | KEV | 83.2% | Jan 13, 2010 |
89Now | CVE-2012-0754Weaponized | Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.xadobe · flash player · CWE-787 | High8.1 | KEV | 91.2% | Feb 16, 2012 |
88Now | CVE-2018-15982Weaponized | Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability.adobe · flash player · CWE-416 | High7.8 | KEV | 89.6% | Jan 18, 2019 |
88Now | CVE-2018-4878Weaponized | A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161.adobe · flash player · CWE-416 | High7.8 | KEV | 89.5% | Feb 6, 2018 |
87Now | CVE-2013-0640Weaponized | Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cadobe · acrobat · CWE-787 | High7.8 | KEV | 86.9% | Feb 13, 2013 |
86Now | CVE-2010-1297Weaponized | Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3,adobe · air · CWE-787 | High7.8 | KEV | 82.5% | Jun 8, 2010 |
86Now | CVE-2009-4324Weaponized | Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before adobe · acrobat · CWE-416 | High7.8 | KEV | 81.9% | Dec 14, 2009 |
86Now | CVE-2022-2294Weaponized | Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption viagoogle · chrome · CWE-787 | High8.8 | KEV | 70.5% | Jul 27, 2022 |
85Now | CVE-2015-8651Weaponized | Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on adobe · air sdk · CWE-190 | High8.8 | KEV | 67.7% | Dec 28, 2015 |
- CVE-2021-44228100Now
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
CriticalCVSS 10.0KEVWeaponizedEPSS 100%apache · log4jDec 10, 2021
- CVE-2014-627199Now
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
CriticalCVSS 9.8KEVWeaponizedEPSS 100%gnu · bashSep 24, 2014
- CVE-2012-182399Now
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que
CriticalCVSS 9.8KEVWeaponizedEPSS 100%php · phpMay 11, 2012
- CVE-2015-311399Now
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11
CriticalCVSS 9.8KEVWeaponizedEPSS 100%adobe · flash playerJun 23, 2015
- CVE-2014-716999Now
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
CriticalCVSS 9.8KEVWeaponizedEPSS 100%gnu · bashSep 24, 2014
- CVE-2014-049799Now
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1
CriticalCVSS 9.8KEVWeaponizedEPSS 100%adobe · flash playerFeb 5, 2014
- CVE-2015-511999Now
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296
CriticalCVSS 9.8KEVWeaponizedEPSS 99%adobe · flash playerJul 8, 2015
- CVE-2015-031398Now
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before
CriticalCVSS 9.8KEVWeaponizedEPSS 95%adobe · flash playerFeb 2, 2015
- CVE-2015-512297Now
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0
CriticalCVSS 9.8KEVWeaponizedEPSS 94%adobe · flash playerJul 14, 2015
- CVE-2013-062597Now
Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly exe
CriticalCVSS 9.8KEVWeaponizedEPSS 94%adobe · coldfusionJan 8, 2013
- CVE-2011-246296Now
Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x
CriticalCVSS 9.8KEVWeaponizedEPSS 89%adobe · acrobatDec 7, 2011
- CVE-2011-061195Now
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.
HighCVSS 8.8KEVWeaponizedEPSS 99%adobe · flash playerApr 13, 2011
- CVE-2015-031195Now
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and throu
CriticalCVSS 9.8KEVWeaponizedEPSS 86%adobe · flash playerJan 23, 2015
- CVE-2021-2101791Now
Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Execution
HighCVSS 8.8KEVWeaponizedEPSS 86%adobe · acrobatFeb 11, 2021
- CVE-2015-304391Now
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows att
CriticalCVSS 9.8KEVWeaponizedEPSS 74%adobe · flash playerApr 14, 2015
- CVE-2023-4448790Now
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
HighCVSS 7.5KEVWeaponizedEPSS 100%siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023
- CVE-2009-395390Now
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remot
HighCVSS 8.8KEVWeaponizedEPSS 83%adobe · acrobatJan 13, 2010
- CVE-2012-075489Now
Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x
HighCVSS 8.1KEVWeaponizedEPSS 91%adobe · flash playerFeb 16, 2012
- CVE-2018-1598288Now
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability.
HighCVSS 7.8KEVWeaponizedEPSS 90%adobe · flash playerJan 18, 2019
- CVE-2018-487888Now
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161.
HighCVSS 7.8KEVWeaponizedEPSS 90%adobe · flash playerFeb 6, 2018
- CVE-2013-064087Now
Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or c
HighCVSS 7.8KEVWeaponizedEPSS 87%adobe · acrobatFeb 13, 2013
- CVE-2010-129786Now
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3,
HighCVSS 7.8KEVWeaponizedEPSS 83%adobe · airJun 8, 2010
- CVE-2009-432486Now
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before
HighCVSS 7.8KEVWeaponizedEPSS 82%adobe · acrobatDec 14, 2009
- CVE-2022-229486Now
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via
HighCVSS 8.8KEVWeaponizedEPSS 70%google · chromeJul 27, 2022
- CVE-2015-865185Now
Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on
HighCVSS 8.8KEVWeaponizedEPSS 68%adobe · air sdkDec 28, 2015