Apple Security Advisories · June 2022 — Apple Security Advisories
12 advisories 12 CVEs

Apple-vendor CVEs for 2022-06. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2022-1968

OtherActive exploitation (sightings)CRITICAL2022-06-02

Use After Free in GitHub repository vim/vim prior to 8.2.

CVEs:CVE-2022-1968

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-32205

OtherPoC exploitHIGH2022-06-26

A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. A sufficiently large amount of (big) cookies make subsequent HTTP requests to this, or other servers to which the c...

CVEs:CVE-2022-32205

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-32207

OtherPoC exploitCRITICAL2022-06-26

When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* ...

CVEs:CVE-2022-32207

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-32208

OtherPoC exploitMEDIUM2022-06-26

When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.

CVEs:CVE-2022-32208

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-1720

OtherPoC exploitHIGH2022-06-20

Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.

CVEs:CVE-2022-1720

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-2125

OtherPoC exploitCRITICAL2022-06-19

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

CVEs:CVE-2022-2125

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-2000

OtherPoC exploitCRITICAL2022-06-07

Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.

CVEs:CVE-2022-2000

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-2126

OtherPoC exploitHIGH2022-06-19

Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

CVEs:CVE-2022-2126

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-2124

OtherPoC exploitHIGH2022-06-19

Buffer Over-read in GitHub repository vim/vim prior to 8.2.

CVEs:CVE-2022-2124

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-2042

OtherPoC exploitCRITICAL2022-06-10

Use After Free in GitHub repository vim/vim prior to 8.2.

CVEs:CVE-2022-2042

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-1642

OtherCoalition ESS < 30%CRITICAL2022-06-16

A program using swift-corelibs-foundation is vulnerable to a denial of service attack caused by a potentially malicious source producing a JSON document containing a type mismatch. This vulnerability is caused by the interaction between a deserializati...

CVEs:CVE-2022-1642

Affected products

ProductStatusVendorPackageEcosystem
swift affected apple
Upstream advisory

CVE-2019-25071

iOSEPSS <= 49%HIGH2022-06-25

A vulnerability was found in Apple iPhone up to 12.4.1. It has been declared as critical. Affected by this vulnerability is Siri. Playing an audio or video file might be able to initiate Siri on the same device which makes it possible to execute comman...

CVEs:CVE-2019-25071

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.