Записи Apple
15 437 опубликованных записей вендора apple.
Профиль для исследователя
- Попали в KEV
- 167 · 1,1 %
- С эксплойтом
- 243 · 1,6 %
- Pre-auth RCE
- 4 143
- С записью об исправлении
- 24,3 %
- Медиана: публикация → KEV
- 234 дн.
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2 367
- CWE-416 Use After Free1 361
- CWE-125 Out-of-bounds Read1 353
- CWE-787 Out-of-bounds Write1 275
- CWE-20 Improper Input Validation825
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor746
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
10 000+ записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
100Срочно | CVE-2021-44228Готовый эксплойт | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpointsapache · log4j · CWE-20 | Критическая10,0 | KEV | 100,0 % | 10 дек. 2021 г. |
99Срочно | CVE-2014-6271Готовый эксплойт | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Критическая9,8 | KEV | 100,0 % | 24 сент. 2014 г. |
99Срочно | CVE-2012-1823Готовый эксплойт | sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle quephp · php · CWE-77 | Критическая9,8 | KEV | 100,0 % | 11 мая 2012 г. |
99Срочно | CVE-2015-3113Готовый эксплойт | Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11adobe · flash player · CWE-787 | Критическая9,8 | KEV | 99,9 % | 23 июн. 2015 г. |
99Срочно | CVE-2014-7169Готовый эксплойт | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Критическая9,8 | KEV | 99,9 % | 24 сент. 2014 г. |
99Срочно | CVE-2014-0497Готовый эксплойт | Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1adobe · flash player · CWE-191 | Критическая9,8 | KEV | 99,9 % | 5 февр. 2014 г. |
99Срочно | CVE-2015-5119Готовый эксплойт | Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296adobe · flash player · CWE-416 | Критическая9,8 | KEV | 99,3 % | 8 июл. 2015 г. |
98Срочно | CVE-2015-0313Готовый эксплойт | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before adobe · flash player · CWE-416 | Критическая9,8 | KEV | 95,3 % | 2 февр. 2015 г. |
97Срочно | CVE-2015-5122Готовый эксплойт | Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0adobe · flash player · CWE-416 | Критическая9,8 | KEV | 94,0 % | 14 июл. 2015 г. |
97Срочно | CVE-2013-0625Готовый эксплойт | Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly exeadobe · coldfusion · CWE-287 | Критическая9,8 | KEV | 93,8 % | 8 янв. 2013 г. |
96Срочно | CVE-2011-2462Готовый эксплойт | Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x adobe · acrobat · CWE-787 | Критическая9,8 | KEV | 88,5 % | 7 дек. 2011 г. |
95Срочно | CVE-2011-0611Готовый эксплойт | Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.adobe · flash player · CWE-843 | Высокая8,8 | KEV | 99,4 % | 13 апр. 2011 г. |
95Срочно | CVE-2015-0311Готовый эксплойт | Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and throuadobe · flash player | Критическая9,8 | KEV | 85,6 % | 23 янв. 2015 г. |
91Срочно | CVE-2021-21017Готовый эксплойт | Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Executionadobe · acrobat · CWE-122 | Высокая8,8 | KEV | 86,3 % | 11 февр. 2021 г. |
91Срочно | CVE-2015-3043Готовый эксплойт | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attadobe · flash player · CWE-787 | Критическая9,8 | KEV | 73,9 % | 14 апр. 2015 г. |
90Срочно | CVE-2023-44487Готовый эксплойт | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Высокая7,5 | KEV | 100,0 % | 10 окт. 2023 г. |
90Срочно | CVE-2009-3953Готовый эксплойт | The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remotadobe · acrobat · CWE-787 | Высокая8,8 | KEV | 83,2 % | 13 янв. 2010 г. |
89Срочно | CVE-2012-0754Готовый эксплойт | Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.xadobe · flash player · CWE-787 | Высокая8,1 | KEV | 91,2 % | 16 февр. 2012 г. |
88Срочно | CVE-2018-15982Готовый эксплойт | Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability.adobe · flash player · CWE-416 | Высокая7,8 | KEV | 89,6 % | 18 янв. 2019 г. |
88Срочно | CVE-2018-4878Готовый эксплойт | A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161.adobe · flash player · CWE-416 | Высокая7,8 | KEV | 89,5 % | 6 февр. 2018 г. |
87Срочно | CVE-2013-0640Готовый эксплойт | Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cadobe · acrobat · CWE-787 | Высокая7,8 | KEV | 86,9 % | 13 февр. 2013 г. |
86Срочно | CVE-2010-1297Готовый эксплойт | Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3,adobe · air · CWE-787 | Высокая7,8 | KEV | 82,5 % | 8 июн. 2010 г. |
86Срочно | CVE-2009-4324Готовый эксплойт | Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before adobe · acrobat · CWE-416 | Высокая7,8 | KEV | 81,9 % | 14 дек. 2009 г. |
86Срочно | CVE-2022-2294Готовый эксплойт | Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption viagoogle · chrome · CWE-787 | Высокая8,8 | KEV | 70,5 % | 27 июл. 2022 г. |
85Срочно | CVE-2015-8651Готовый эксплойт | Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on adobe · air sdk · CWE-190 | Высокая8,8 | KEV | 67,7 % | 28 дек. 2015 г. |
- CVE-2021-44228100Срочно
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %apache · log4j10 дек. 2021 г.
- CVE-2014-627199Срочно
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %gnu · bash24 сент. 2014 г.
- CVE-2012-182399Срочно
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %php · php11 мая 2012 г.
- CVE-2015-311399Срочно
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %adobe · flash player23 июн. 2015 г.
- CVE-2014-716999Срочно
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %gnu · bash24 сент. 2014 г.
- CVE-2014-049799Срочно
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %adobe · flash player5 февр. 2014 г.
- CVE-2015-511999Срочно
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %adobe · flash player8 июл. 2015 г.
- CVE-2015-031398Срочно
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 95 %adobe · flash player2 февр. 2015 г.
- CVE-2015-512297Срочно
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 94 %adobe · flash player14 июл. 2015 г.
- CVE-2013-062597Срочно
Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly exe
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 94 %adobe · coldfusion8 янв. 2013 г.
- CVE-2011-246296Срочно
Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 89 %adobe · acrobat7 дек. 2011 г.
- CVE-2011-061195Срочно
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 99 %adobe · flash player13 апр. 2011 г.
- CVE-2015-031195Срочно
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and throu
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 86 %adobe · flash player23 янв. 2015 г.
- CVE-2021-2101791Срочно
Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Execution
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 86 %adobe · acrobat11 февр. 2021 г.
- CVE-2015-304391Срочно
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows att
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 74 %adobe · flash player14 апр. 2015 г.
- CVE-2023-4448790Срочно
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 окт. 2023 г.
- CVE-2009-395390Срочно
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remot
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 83 %adobe · acrobat13 янв. 2010 г.
- CVE-2012-075489Срочно
Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 91 %adobe · flash player16 февр. 2012 г.
- CVE-2018-1598288Срочно
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability.
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 90 %adobe · flash player18 янв. 2019 г.
- CVE-2018-487888Срочно
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161.
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 90 %adobe · flash player6 февр. 2018 г.
- CVE-2013-064087Срочно
Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or c
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 87 %adobe · acrobat13 февр. 2013 г.
- CVE-2010-129786Срочно
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3,
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 83 %adobe · air8 июн. 2010 г.
- CVE-2009-432486Срочно
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 82 %adobe · acrobat14 дек. 2009 г.
- CVE-2022-229486Срочно
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 70 %google · chrome27 июл. 2022 г.
- CVE-2015-865185Срочно
Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 68 %adobe · air sdk28 дек. 2015 г.