Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 101 of 157
CVE-2021-30877P4HIGHCVSS 7.1≥ 10.15, ≤ 10.15.6v10.15.72021-08-24
CVE-2021-30877 [HIGH] CWE-125 CVE-2021-30877: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Mont
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.0.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. Processing a maliciously crafted AppleScript binary may result in unexpected application termination or disclosure of process memory.
nvd
CVE-2021-30880P4HIGHCVSS 7.1≥ 10.15, ≤ 10.15.6v10.15.72021-08-24
CVE-2021-30880 [HIGH] CWE-125 CVE-2021-30880: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Mont
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.0.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. Processing a maliciously crafted AppleScript binary may result in unexpected application termination or disclosure of process memory.
nvd
CVE-2007-4267P4HIGHCVSS 7.2v10.4v10.4.1+9 more2007-11-15
CVE-2007-4267 [HIGH] CWE-119 CVE-2007-4267: Stack-based buffer overflow in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allow
Stack-based buffer overflow in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows local users to execute arbitrary code via a crafted IOCTL request that adds an AppleTalk zone to a routing table.
nvd
CVE-2015-1143P4HIGHCVSS 7.2fixed in 10.10.32015-04-10
CVE-2015-1143 [HIGH] CVE-2015-1143: LaunchServices in Apple OS X before 10.10.3 allows local users to gain privileges via a crafted loca
LaunchServices in Apple OS X before 10.10.3 allows local users to gain privileges via a crafted localized string, related to a "type confusion" issue.
nvd
CVE-2009-0017P4HIGHCVSS 7.2v10.4.11v10.5.62009-02-13
CVE-2009-0017 [HIGH] CWE-119 CVE-2009-0017: csregprinter in the Printing component in Apple Mac OS X 10.4.11 and 10.5.6 does not properly handle
csregprinter in the Printing component in Apple Mac OS X 10.4.11 and 10.5.6 does not properly handle error conditions, which allows local users to execute arbitrary code via unknown vectors that trigger a heap-based buffer overflow.
nvd
CVE-2015-5774P4HIGHCVSS 7.2≤ 10.10.42015-08-17
CVE-2015-5774 [HIGH] CWE-119 CVE-2015-5774: Buffer overflow in IOHIDFamily in Apple iOS before 8.4.1 and OS X before 10.10.5 allows local users
Buffer overflow in IOHIDFamily in Apple iOS before 8.4.1 and OS X before 10.10.5 allows local users to gain privileges via unspecified vectors.
nvd
CVE-2015-3775P4HIGHCVSS 7.2≤ 10.10.42015-08-16
CVE-2015-3775 [HIGH] CWE-287 CVE-2015-3775: Apple OS X before 10.10.5 does not properly implement authentication, which allows local users to ob
Apple OS X before 10.10.5 does not properly implement authentication, which allows local users to obtain admin privileges via unspecified vectors.
nvd
CVE-2015-1144P4HIGHCVSS 7.2≤ 10.10.22015-04-10
CVE-2015-1144 [HIGH] CWE-119 CVE-2015-1144: Buffer overflow in the UniformTypeIdentifiers component in Apple OS X before 10.10.3 allows local us
Buffer overflow in the UniformTypeIdentifiers component in Apple OS X before 10.10.3 allows local users to gain privileges via a crafted Uniform Type Identifier.
nvd
CVE-2015-3672P4HIGHCVSS 7.2≤ 10.10.32015-07-03
CVE-2015-3672 [HIGH] CWE-284 CVE-2015-3672: Admin Framework in Apple OS X before 10.10.4 does not properly handle authentication errors, which a
Admin Framework in Apple OS X before 10.10.4 does not properly handle authentication errors, which allows local users to obtain admin privileges via unspecified vectors.
nvd
CVE-2011-3463P4HIGHCVSS 7.2v10.7.0v10.7.1+1 more2012-02-02
CVE-2011-3463 [HIGH] CWE-287 CVE-2011-3463: WebDAV Sharing in Apple Mac OS X 10.7.x before 10.7.3 does not properly perform authentication, whic
WebDAV Sharing in Apple Mac OS X 10.7.x before 10.7.3 does not properly perform authentication, which allows local users to gain privileges by leveraging access to (1) the server or (2) a bound directory.
nvd
CVE-2015-3761P4HIGHCVSS 7.2≤ 10.10.42015-08-16
CVE-2015-3761 [HIGH] CWE-264 CVE-2015-3761: The kernel in Apple OS X before 10.10.5 does not properly validate pathnames in the environment, whi
The kernel in Apple OS X before 10.10.5 does not properly validate pathnames in the environment, which allows local users to gain privileges via unspecified vectors.
nvd
CVE-2015-7063P4HIGHCVSS 7.2≤ 10.11.12015-12-11
CVE-2015-7063 [HIGH] CWE-264 CVE-2015-7063: The kernel loader in EFI in Apple OS X before 10.11.2 allows local users to gain privileges via a cr
The kernel loader in EFI in Apple OS X before 10.11.2 allows local users to gain privileges via a crafted pathname.
nvd
CVE-2010-0498P4HIGHCVSS 7.2≤ 10.6.2v10.5+11 more2010-03-30
CVE-2010-0498 [HIGH] CWE-287 CVE-2010-0498: Directory Services in Apple Mac OS X before 10.6.3 does not properly perform authorization during pr
Directory Services in Apple Mac OS X before 10.6.3 does not properly perform authorization during processing of record names, which allows local users to gain privileges via unspecified vectors.
nvd
CVE-2021-30676P4HIGHCVSS 7.1≥ 10.14, ≤ 10.14.5≥ 10.15, ≤ 10.15.6+2 more2021-09-08
CVE-2021-30676 [HIGH] CVE-2021-30676: A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A local user may be able to cause unexpected system termination or read kernel memory.
nvd
CVE-2019-8545P4HIGHCVSS 7.1fixed in 10.14.42019-12-18
CVE-2019-8545 [HIGH] CWE-787 CVE-2019-8545: A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 1
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A local user may be able to cause unexpected system termination or read kernel memory.
nvd
CVE-2020-9929P4HIGHCVSS 7.1fixed in 10.15.62020-10-22
CVE-2020-9929 [HIGH] CWE-787 CVE-2020-9929: A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.6. A local user may be able to cause unexpected system termination or read kernel memory.
nvd
CVE-2020-9779P4HIGHCVSS 7.1≥ 10.13.6, < 10.15.42020-10-22
CVE-2020-9779 [HIGH] CWE-125 CVE-2020-9779: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Cat
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A local user may be able to cause unexpected system termination or read kernel memory.
nvd
CVE-2020-27936P4HIGHCVSS 7.1fixed in 11.1.02021-04-02
CVE-2020-27936 [HIGH] CWE-125 CVE-2020-27936: An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A local user may be able to cause unexpected system termination or read kernel memory.
nvd
CVE-2020-9908P4HIGHCVSS 7.1fixed in 10.15.62020-10-22
CVE-2020-9908 [HIGH] CWE-125 CVE-2020-9908: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Cat
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.6. A local user may be able to cause unexpected system termination or read kernel memory.
nvd
CVE-2021-30719P4HIGHCVSS 7.1≥ 10.15, ≤ 10.15.6v10.15.72021-09-08
CVE-2021-30719 [HIGH] CWE-125 CVE-2021-30719: A local user may be able to cause unexpected system termination or read kernel memory. This issue is
A local user may be able to cause unexpected system termination or read kernel memory. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina. An out-of-bounds read issue was addressed by removing the vulnerable code.
nvd