Advisories
iPadOSExploitedCISA KEV listedCRITICAL2022-02-11
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content may lead to a...
CVEs:CVE-2022-22620
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
OtherPoC exploitCRITICAL2022-02-14
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
CVEs:CVE-2022-0572
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
OtherPoC exploitCRITICAL2022-02-22
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4436.
CVEs:CVE-2022-0714
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
OtherPoC exploitCRITICAL2022-02-22
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
CVEs:CVE-2022-23308
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| mac_os_x |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
OtherPoC exploitCRITICAL2022-02-09
A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code exec...
CVEs:CVE-2022-0530
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
| mac_os_x |
affected |
apple |
— |
— |
OtherPoC exploitCRITICAL2022-02-14
In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.
CVEs:CVE-2021-45444
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
| mac_os_x |
affected |
apple |
— |
— |
OtherPoC exploitCRITICAL2022-02-16
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
CVEs:CVE-2022-0629
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
OtherPoC exploitHIGH2022-02-20
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4418.
CVEs:CVE-2022-0685
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
OtherPoC exploitHIGH2022-02-23
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4440.
CVEs:CVE-2022-0729
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
OtherPoC exploitHIGH2022-02-09
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.
CVEs:CVE-2022-0554
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
OtherPoC exploitMEDIUM2022-02-21
NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428.
CVEs:CVE-2022-0696
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
OtherCoalition ESS < 30%CRITICAL2022-02-09
A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending a specially crafted HTTP/2 frame. This attack affects all swift-nio-http2 versions from 1.0.0 to 1.19.1. This vulnerability is caused by a log...
CVEs:CVE-2022-24666
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| swiftnio_http\/2 |
affected |
apple |
— |
— |
OtherCoalition ESS < 30%CRITICAL2022-02-09
A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending a specially crafted HPACK-encoded header block. This attack affects all swift-nio-http2 versions from 1.0.0 to 1.19.1. There are a number of i...
CVEs:CVE-2022-24667
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| swiftnio_http\/2 |
affected |
apple |
— |
— |
OtherCoalition ESS < 30%CRITICAL2022-02-09
A program using swift-nio-http2 is vulnerable to a denial of service attack caused by a network peer sending ALTSVC or ORIGIN frames. This attack affects all swift-nio-http2 versions from 1.0.0 to 1.19.1. This vulnerability is caused by a logical error...
CVEs:CVE-2022-24668
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| swiftnio_http\/2 |
affected |
apple |
— |
— |