Apple Tv vulnerabilities
168 known vulnerabilities affecting apple/apple_tv.
Total CVEs
168
CISA KEV
0
Public exploits
12
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH36MEDIUM111LOW7
Vulnerabilities
Page 8 of 9
CVE-2014-4491P4MEDIUMCVSS 5.0v7.0.3
CVE-2014-4491 [MEDIUM] CVE-2014-4491: Apple TV 7.0.3
Apple Security Update: About the security content of Apple TV 7.0.3
Product: Apple TV
Version: 7.0.3
CVE: CVE-2014-4491
Component: CVE-ID
apple
CVE-2018-4223P4MEDIUMCVSS 5.5fixed in 11.42018-06-08
CVE-2018-4223 [MEDIUM] CWE-200 CVE-2018-4223: An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "Security" component. It allows local users to bypass intended restrictions on the reading of a persistent account identifier.
nvd
CVE-2015-5749P4MEDIUMCVSS 4.3v7.2.1
CVE-2015-5749 [MEDIUM] CVE-2015-5749: Apple TV 7.2.1
Apple Security Update: About the security content of Apple TV 7.2.1
Product: Apple TV
Version: 7.2.1
CVE: CVE-2015-5749
Component: CVE-ID
apple
CVE-2015-3793P4MEDIUMCVSS 4.3v7.2.1
CVE-2015-3793 [MEDIUM] CVE-2015-3793: Apple TV 7.2.1
Apple Security Update: About the security content of Apple TV 7.2.1
Product: Apple TV
Version: 7.2.1
CVE: CVE-2015-3793
Component: CVE-ID
apple
CVE-2018-4235P4MEDIUMCVSS 5.5fixed in 11.42018-06-08
CVE-2018-4235 [MEDIUM] CWE-74 CVE-2018-4235: An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "Messages" component. It allows local users to perform impersonation attacks via an unspecified injection.
nvd
CVE-2015-1117P4MEDIUMCVSS 6.9v7.2
CVE-2015-1117 [MEDIUM] CVE-2015-1117: Apple TV 7.2
Apple Security Update: About the security content of Apple TV 7.2
Product: Apple TV
Version: 7.2
CVE: CVE-2015-1117
Component: CVE-ID
apple
CVE-2011-3259P4MEDIUMCVSS 5.0v4.0v4.1+2 more2011-10-14
CVE-2011-3259 [MEDIUM] CWE-399 CVE-2011-3259: The kernel in Apple iOS before 5 and Apple TV before 4.4 does not properly recover memory allocated
The kernel in Apple iOS before 5 and Apple TV before 4.4 does not properly recover memory allocated for incomplete TCP connections, which allows remote attackers to cause a denial of service (resource consumption) by making many connection attempts.
nvd
CVE-2018-4093P4MEDIUMCVSS 5.5fixed in 11.2.52018-04-03
CVE-2018-4093 [MEDIUM] CWE-200 CVE-2018-4093: An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvd
CVE-2015-3807P4MEDIUMCVSS 4.3v7.2.1
CVE-2015-3807 [MEDIUM] CVE-2015-3807: Apple TV 7.2.1
Apple Security Update: About the security content of Apple TV 7.2.1
Product: Apple TV
Version: 7.2.1
CVE: CVE-2015-3807
Component: CVE-ID
Impact: Multiple vulnerabilities existed in libxml2 versions prior to 2.9.2, the most serious of which may allow a remote attacker to cause a denial of service
Description: Multiple vulnerabilities existed in libxml2 versions prior to 2.9.2. These were addressed by updating libxml2 to version 2.9.2.
apple
CVE-2015-1118P4MEDIUMCVSS 5.0v7.2
CVE-2015-1118 [MEDIUM] CVE-2015-1118: Apple TV 7.2
Apple Security Update: About the security content of Apple TV 7.2
Product: Apple TV
Version: 7.2
CVE: CVE-2015-1118
Component: CVE-ID
apple
CVE-2024-44157P4MEDIUMCVSS 5.5fixed in 1.5.0.152fixed in 1.5.02024-10-11
CVE-2024-44157 [MEDIUM] CWE-787 CVE-2024-44157: A stack buffer overflow was addressed through improved input validation. This issue is fixed in Appl
A stack buffer overflow was addressed through improved input validation. This issue is fixed in Apple TV 1.5.0.152 for Windows, iTunes 12.13.3 for Windows. Parsing a maliciously crafted video file may lead to unexpected system termination.
nvd
CVE-2015-5782P4MEDIUMCVSS 4.3v7.2.1
CVE-2015-5782 [MEDIUM] CVE-2015-5782: Apple TV 7.2.1
Apple Security Update: About the security content of Apple TV 7.2.1
Product: Apple TV
Version: 7.2.1
CVE: CVE-2015-5782
Component: CVE-ID
apple
CVE-2015-5781P4MEDIUMCVSS 4.3v7.2.1
CVE-2015-5781 [MEDIUM] CVE-2015-5781: Apple TV 7.2.1
Apple Security Update: About the security content of Apple TV 7.2.1
Product: Apple TV
Version: 7.2.1
CVE: CVE-2015-5781
Component: CVE-ID
apple
CVE-2018-4092P4MEDIUMCVSS 4.7fixed in 11.2.52018-04-03
CVE-2018-4092 [MEDIUM] CWE-362 CVE-2018-4092: An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "Kernel" component. A race condition allows attackers to bypass intended memory-read restrictions via a crafted app.
nvd
CVE-2020-27940P4MEDIUMCVSS 4.3fixed in 5.12021-09-08
CVE-2020-27940 [MEDIUM] CVE-2020-27940: This issue was addressed with improved file handling. This issue is fixed in Apple TV app for Fire O
This issue was addressed with improved file handling. This issue is fixed in Apple TV app for Fire OS 6.1.0.6A142:7.1.0. An attacker with file system access may modify scripts used by the app.
nvd
CVE-2018-4198P4MEDIUMCVSS 5.5fixed in 11.42018-06-08
CVE-2018-4198 [MEDIUM] CWE-20 CVE-2018-4198: An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "UIKit" component. It allows remote attackers to cause a denial of service via a crafted text file.
nvd
CVE-2011-1418P4MEDIUMCVSS 5.0v4.02011-03-11
CVE-2011-1418 [MEDIUM] CWE-200 CVE-2011-1418: The stateless address autoconfiguration (aka SLAAC) functionality in the IPv6 networking implementat
The stateless address autoconfiguration (aka SLAAC) functionality in the IPv6 networking implementation in Apple iOS before 4.3 and Apple TV before 4.2 places the MAC address into the IPv6 address, which makes it easier for remote IPv6 servers to track users by logging source IPv6 addresses.
nvd
CVE-2015-3782P4MEDIUMCVSS 4.3v7.2.1
CVE-2015-3782 [MEDIUM] CVE-2015-3782: Apple TV 7.2.1
Apple Security Update: About the security content of Apple TV 7.2.1
Product: Apple TV
Version: 7.2.1
CVE: CVE-2015-3782
Component: CVE-ID
apple
CVE-2015-3766P4MEDIUMCVSS 4.3v7.2.1
CVE-2015-3766 [MEDIUM] CVE-2015-3766: Apple TV 7.2.1
Apple Security Update: About the security content of Apple TV 7.2.1
Product: Apple TV
Version: 7.2.1
CVE: CVE-2015-3766
Component: CVE-ID
apple
CVE-2015-3759P4MEDIUMCVSS 4.6v7.2.1
CVE-2015-3759 [MEDIUM] CVE-2015-3759: Apple TV 7.2.1
Apple Security Update: About the security content of Apple TV 7.2.1
Product: Apple TV
Version: 7.2.1
CVE: CVE-2015-3759
Component: CVE-ID
apple