Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 1 of 157
CVE-2012-1823P1CRITICALCVSS 9.8KEVPoC≥ 10.6.8, < 10.7.5≥ 10.8.0, < 10.8.22012-05-11
CVE-2012-1823 [CRITICAL] CWE-77 CVE-2012-1823: sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (ak
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for
nvd
CVE-2014-6271P1CRITICALCVSS 9.8KEVPoC≥ 10.0.0, < 10.10.02014-09-24
CVE-2014-6271 [CRITICAL] CWE-78 CVE-2014-6271: GNU Bash through 4.3 processes trailing strings after function definitions in the values of environm
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts execute
nvd
CVE-2014-7169P1CRITICALCVSS 9.8KEVPoC≥ 10.0.0, < 10.10.02014-09-25
CVE-2014-7169 [CRITICAL] CVE-2014-7169: GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definiti
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgi
nvd
CVE-2021-30657P1MEDIUMCVSS 5.5KEVPoC≥ 10.15, ≤ 10.15.5v10.15.6+1 more2021-09-08
CVE-2021-30657 [MEDIUM] CWE-862 CVE-2021-30657: A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been actively exploited..
nvd
CVE-2014-4404P1HIGHCVSS 7.8KEVPoCfixed in 10.10.0≥ 10.10.1, < 10.10.32014-09-18
CVE-2014-4404 [HIGH] CWE-787 CVE-2014-4404: Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attacke
Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context via an application that provides crafted key-mapping properties.
nvd
CVE-2020-27930P1HIGHCVSS 7.8KEVPoCfixed in 10.15.72020-12-08
CVE-2020-27930 [HIGH] CWE-787 CVE-2020-27930: A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. Processin
nvd
CVE-2019-8605P1HIGHCVSS 7.8KEVPoCfixed in 10.14.52019-12-18
CVE-2019-8605 [HIGH] CWE-416 CVE-2019-8605: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to execute arbitrary code with system privileges.
nvd
CVE-2020-3837P1HIGHCVSS 7.8KEVPoCfixed in 10.15.32020-02-27
CVE-2020-3837 [HIGH] CWE-787 CVE-2020-3837: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2019-7286P1HIGHCVSS 7.8KEVPoCfixed in 10.14.32019-12-18
CVE-2019-7286 [HIGH] CWE-787 CVE-2019-7286: A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 1
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. An application may be able to gain elevated privileges.
nvd
CVE-2022-2294P1HIGHCVSS 8.8KEVRansomwarefixed in 10.15.7v10.15.72022-07-28
CVE-2022-2294 [HIGH] CWE-787 CVE-2022-2294: Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2015-1130P1HIGHCVSS 7.8KEVPoCfixed in 10.10.32015-04-10
CVE-2015-1130 [HIGH] CWE-59 CVE-2015-1130: The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via unspecified vectors.
nvd
CVE-2021-1782P1HIGHCVSS 7.0KEVPoC≥ 10.14, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-04-02
CVE-2021-1782 [HIGH] CWE-667 CVE-2021-1782: A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Sec
A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited..
nvd
CVE-2021-30860P1HIGHCVSS 7.8KEV≥ 10.15, < 10.15.7v10.15.72021-08-24
CVE-2021-30860 [HIGH] CWE-190 CVE-2021-30860: An integer overflow was addressed with improved input validation. This issue is fixed in Security Up
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
nvd
CVE-2020-9934P2MEDIUMCVSS 5.5KEVPoCfixed in 10.15.62020-10-16
CVE-2020-9934 [MEDIUM] CVE-2020-9934: An issue existed in the handling of environment variables. This issue was addressed with improved va
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6. A local user may be able to view sensitive user information.
nvd
CVE-2021-1789P1HIGHCVSS 8.8KEV≥ 10.14, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-04-02
CVE-2021-1789 [HIGH] CWE-843 CVE-2021-1789: A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big
A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4, Safari 14.0.3. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2021-1870P1CRITICALCVSS 9.8KEV≥ 10.15, < 10.15.7v10.15.72021-04-02
CVE-2021-1870 [CRITICAL] CVE-2021-1870: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, S
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
nvd
CVE-2021-1871P1CRITICALCVSS 9.8KEV≥ 10.15, < 10.15.7v10.15.72021-04-02
CVE-2021-1871 [CRITICAL] CVE-2021-1871: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, S
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
nvd
CVE-2020-27932P1HIGHCVSS 7.8KEVfixed in 10.15.72020-12-08
CVE-2020-27932 [HIGH] CWE-843 CVE-2020-27932: A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big
A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. A malicious app
nvd
CVE-2021-30713P1HIGHCVSS 7.8KEV≥ 10.15, ≤ 10.15.7v10.15.72021-09-08
CVE-2021-30713 [HIGH] CWE-862 CVE-2021-30713: A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.
A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.4. A malicious application may be able to bypass Privacy preferences. Apple is aware of a report that this issue may have been actively exploited..
nvd
CVE-2021-30869P1HIGHCVSS 7.8KEV≥ 10.14, ≤ 10.14.6≥ 10.15, ≤ 10.15.6+2 more2021-08-24
CVE-2021-30869 [HIGH] CWE-843 CVE-2021-30869: A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 12.5.5
A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 12.5.5, iOS 14.4 and iPadOS 14.4, macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, Security Update 2021-006 Catalina. A malicious application may be able to execute arbitrary code with kernel privileges. Apple is aware o
nvd
1 / 157Next →