cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 100 of 157
CVE-2009-2830P4MEDIUMCVSS 6.8v10.6v10.6.12009-11-10
CVE-2009-2830 [MEDIUM] CVE-2009-2830: Multiple buffer overflows in Christos Zoulas file before 5.03 in Apple Mac OS X 10.6.x before 10.6.2 Multiple buffer overflows in Christos Zoulas file before 5.03 in Apple Mac OS X 10.6.x before 10.6.2 allow user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Common Document Format (CDF) file. NOTE: this might overlap CVE-2009-1515.
nvd
CVE-2009-2838P4MEDIUMCVSS 6.8v10.5.82009-11-10
CVE-2009-2838 [MEDIUM] CWE-189 CVE-2009-2838: Integer overflow in QuickLook in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary Integer overflow in QuickLook in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Office document that triggers a buffer overflow.
nvd
CVE-2007-4268P4HIGHCVSS 7.8≥ 10.4.0, ≤ 10.4.102007-11-15
CVE-2007-4268 [HIGH] CWE-681 CVE-2007-4268: Integer signedness error in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows l Integer signedness error in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows local users to execute arbitrary code via a crafted AppleTalk message with a negative value, which satisfies a signed comparison during mbuf allocation but is later interpreted as an unsigned value, which triggers a heap-based buffer overflow.
nvd
CVE-2005-1337P4HIGHCVSS 7.5v10.3.92005-05-04
CVE-2005-1337 [HIGH] CVE-2005-1337: Apple Help Viewer 2.0.7 and 3.0.0 in Mac OS X 10.3.9 allows remote attackers to read and execute arb Apple Help Viewer 2.0.7 and 3.0.0 in Mac OS X 10.3.9 allows remote attackers to read and execute arbitrary scrpts with less restrictive privileges via a help:// URI.
nvd
CVE-2015-3153P4MEDIUMCVSS 5.0v10.10.42015-05-01
CVE-2015-3153 [MEDIUM] CWE-200 CVE-2015-3153: The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the p The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information by reading the header contents.
nvd
CVE-2009-0157P4MEDIUMCVSS 6.8v10.5.0v10.5.1+5 more2009-05-13
CVE-2009-0157 [MEDIUM] CWE-119 CVE-2009-0157: Heap-based buffer overflow in CFNetwork in Apple Mac OS X 10.5 before 10.5.7 allows remote web serve Heap-based buffer overflow in CFNetwork in Apple Mac OS X 10.5 before 10.5.7 allows remote web servers to execute arbitrary code or cause a denial of service (application crash) via long HTTP headers.
nvd
CVE-2005-3706P4MEDIUMCVSS 6.4v10.4v10.4.1+4 more2005-12-31
CVE-2005-3706 [MEDIUM] CVE-2005-3706: Heap-based buffer overflow in LibSystem in Mac OS X 10.4 through 10.4.5 allows context-dependent att Heap-based buffer overflow in LibSystem in Mac OS X 10.4 through 10.4.5 allows context-dependent attackers to execute arbitrary code by causing an application that uses LibSystem to request a large amount of memory.
nvd
CVE-2008-2309P4MEDIUMCVSS 6.8v10.4.1v10.4.2+13 more2008-07-01
CVE-2008-2309 [MEDIUM] CWE-264 CVE-2008-2309: Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.4 allows user-assisted Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.4 allows user-assisted remote attackers to execute arbitrary code via a (1) .xht or (2) .xhtm file, which does not trigger a "potentially unsafe" warning message in (a) the Download Validation feature in Mac OS X 10.4 or (b) the Quarantine feature in Mac OS X 10.5.
nvd
CVE-2011-3449P4MEDIUMCVSS 6.8≤ 10.7.2v10.7.0+1 more2012-02-02
CVE-2011-3449 [MEDIUM] CWE-399 CVE-2011-3449: Use-after-free vulnerability in CoreText in Apple Mac OS X before 10.7.3 allows remote attackers to Use-after-free vulnerability in CoreText in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted embedded font in a document.
nvd
CVE-2010-4013P4MEDIUMCVSS 6.8v10.6.0v10.6.1+4 more2011-01-10
CVE-2010-4013 [MEDIUM] CWE-134 CVE-2010-4013: Format string vulnerability in PackageKit in Apple Mac OS X 10.6.x before 10.6.6 allows man-in-the-m Format string vulnerability in PackageKit in Apple Mac OS X 10.6.x before 10.6.6 allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to interaction between Software Update and distribution scripts.
nvd
CVE-2008-0060P4MEDIUMCVSS 6.8v10.4.11v10.5.22008-03-18
CVE-2008-0060 [MEDIUM] CWE-94 CVE-2008-0060: Help Viewer in Apple Mac OS X 10.4.11 and 10.5.2 allows remote attackers to execute arbitrary Apples Help Viewer in Apple Mac OS X 10.4.11 and 10.5.2 allows remote attackers to execute arbitrary Applescript via a help:topic_list URL that injects HTML or JavaScript into a topic list page, as demonstrated using a help:runscript link.
nvd
CVE-2022-22626P4HIGHCVSS 7.1≥ 10.15, < 10.15.7v10.15.72022-03-18
CVE-2022-22626 [HIGH] CWE-125 CVE-2022-22626: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. Processing a maliciously crafted AppleScript binary may result in unexpected application termination or disclosure of process memory.
nvd
CVE-2022-32797P4HIGHCVSS 7.1v10.15.72022-09-23
CVE-2022-32797 [HIGH] CWE-20 CVE-2022-32797: This issue was addressed with improved checks. This issue is fixed in Security Update 2022-005 Catal This issue was addressed with improved checks. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing a maliciously crafted AppleScript binary may result in unexpected termination or disclosure of process memory.
nvd
CVE-2011-0173P4MEDIUMCVSS 6.8≤ 10.6.6v10.6.0+5 more2011-03-23
CVE-2011-0173 [MEDIUM] CWE-134 CVE-2011-0173: Multiple format string vulnerabilities in AppleScript in Apple Mac OS X before 10.6.7 allow context- Multiple format string vulnerabilities in AppleScript in Apple Mac OS X before 10.6.7 allow context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a (1) display dialog or (2) display alert command in a dialog in an AppleScript Studio application.
nvd
CVE-2015-5932P4HIGHCVSS 7.2≤ 10.11.02015-10-23
CVE-2015-5932 [HIGH] CVE-2015-5932: The kernel in Apple OS X before 10.11.1 allows local users to gain privileges by leveraging an unspe The kernel in Apple OS X before 10.11.1 allows local users to gain privileges by leveraging an unspecified "type confusion" during Mach task processing.
nvd
CVE-2022-22627P4HIGHCVSS 7.1≥ 10.15, < 10.15.7v10.15.72022-03-18
CVE-2022-22627 [HIGH] CWE-125 CVE-2022-22627: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. Processing a maliciously crafted AppleScript binary may result in unexpected application termination or disclosure of process memory.
nvd
CVE-2022-26698P4HIGHCVSS 7.1≥ 10.15, < 10.15.7v10.15.72022-05-26
CVE-2022-26698 [HIGH] CWE-125 CVE-2022-26698: An out-of-bounds read issue was addressed with improved bounds checking. This issue is fixed in Secu An out-of-bounds read issue was addressed with improved bounds checking. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. Processing a maliciously crafted AppleScript binary may result in unexpected application termination or disclosure of process memory.
nvd
CVE-2021-30876P4HIGHCVSS 7.1≥ 10.15, ≤ 10.15.6v10.15.72021-08-24
CVE-2021-30876 [HIGH] CWE-125 CVE-2021-30876: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Mont An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.0.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. Processing a maliciously crafted AppleScript binary may result in unexpected application termination or disclosure of process memory.
nvd
CVE-2021-30879P4HIGHCVSS 7.1≥ 10.15, ≤ 10.15.6v10.15.72021-08-24
CVE-2021-30879 [HIGH] CWE-125 CVE-2021-30879: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Mont An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.0.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. Processing a maliciously crafted AppleScript binary may result in unexpected application termination or disclosure of process memory.
nvd
CVE-2006-3508P4HIGHCVSS 7.2v10.4.72006-09-21
CVE-2006-3508 [HIGH] CVE-2006-3508: Heap-based buffer overflow in the AirPort wireless driver on Apple Mac OS X 10.4.7 allows physically Heap-based buffer overflow in the AirPort wireless driver on Apple Mac OS X 10.4.7 allows physically proximate attackers to cause a denial of service (crash), gain privileges, and execute arbitrary code via a crafted frame that is not properly handled during scan cache updates.
nvd
Apple macOS vulnerabilities | cvebase