cbcvebase.

Apple Keynote vulnerabilities

7 known vulnerabilities affecting apple/keynote.

Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM7

Vulnerabilities

Page 1 of 1
CVE-2015-3784P4MEDIUMCVSS 5.0≤ 6.52015-08-16
CVE-2015-3784 [MEDIUM] CWE-200 CVE-2015-3784: Office Viewer in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to read arbi Office Viewer in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
nvd
CVE-2015-7033P4MEDIUMCVSS 6.8≤ 6.52015-10-18
CVE-2015-7033 [MEDIUM] CWE-119 CVE-2015-7033: The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, an The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted document.
nvd
CVE-2017-20159P4MEDIUM≥ 0, < 1.0.02022-12-31
CVE-2017-20159 [MEDIUM] CWE-79 keynote Cross-site Scripting vulnerability keynote Cross-site Scripting vulnerability A vulnerability was found in rf Keynote up to 0.x. It has been rated as problematic. Affected by this issue is some unknown functionality of the file lib/keynote/rumble.rb. The manipulation of the argument value leads to cross site scripting. The attack may be launched remotely. Upgrading to version 1.0.0 can address this issue. The name of the patch is 05be4356b0a6ca7de48da926a9
ghsaosv
CVE-2017-2391P4MEDIUMCVSS 5.3≤ 7.0.5≤ 3.0.52017-04-02
CVE-2017-2391 [MEDIUM] CWE-326 CVE-2017-2391: An issue was discovered in certain Apple products. Pages before 6.1, Numbers before 4.1, and Keynote An issue was discovered in certain Apple products. Pages before 6.1, Numbers before 4.1, and Keynote before 7.1 on macOS and Pages before 3.1, Numbers before 3.1, and Keynote before 3.1 on iOS are affected. The issue involves the "Export" component. It allows users to bypass iWork PDF password protection by leveraging use of 40-bit RC4.
nvd
CVE-2005-1408P4MEDIUMCVSS 5.0v2.0.0v2.0.12005-05-26
CVE-2005-1408 [MEDIUM] CVE-2005-1408: Apple Keynote 2.0 and 2.0.1 allows remote attackers to read arbitrary files via the keynote: URI han Apple Keynote 2.0 and 2.0.1 allows remote attackers to read arbitrary files via the keynote: URI handler in a crafted Keynote presentation.
nvd
CVE-2025-46306P4MEDIUMCVSS 5.5fixed in 15.12026-01-28
CVE-2025-46306 [MEDIUM] CWE-125 CVE-2025-46306: The issue was addressed with improved bounds checks. This issue is fixed in Keynote 15.1, iOS 26 and The issue was addressed with improved bounds checks. This issue is fixed in Keynote 15.1, iOS 26 and iPadOS 26, macOS Tahoe 26. Processing a maliciously crafted Keynote file may disclose memory contents.
nvdapple
CVE-2015-7032P4MEDIUMCVSS 4.3≤ 6.52015-10-18
CVE-2015-7032 [MEDIUM] CWE-200 CVE-2015-7032: The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, an The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to obtain sensitive information via a crafted document.
nvd
Apple Keynote vulnerabilities | cvebase