cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 102 of 157
CVE-2016-4646P4MEDIUMCVSS 6.5≤ 10.11.52016-07-22
CVE-2016-4646 [MEDIUM] CWE-200 CVE-2016-4646: Audio in Apple OS X before 10.11.6 mishandles a size value, which allows remote attackers to obtain Audio in Apple OS X before 10.11.6 mishandles a size value, which allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read) via a crafted audio file.
nvd
CVE-2014-4416P4MEDIUMCVSS 6.9v10.8.5v10.9+4 more2014-09-19
CVE-2014-4416 [MEDIUM] CVE-2014-4416: An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4394, CVE-2014-4395, CVE-2014-4396, CVE-2014-4397, CVE-2014-4398, CVE-
nvd
CVE-2014-4399P4MEDIUMCVSS 6.9v10.8.5v10.9+4 more2014-09-19
CVE-2014-4399 [MEDIUM] CVE-2014-4399: An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4394, CVE-2014-4395, CVE-2014-4396, CVE-2014-4397, CVE-2014-4398, CVE-
nvd
CVE-2014-4400P4MEDIUMCVSS 6.9v10.8.5v10.9+4 more2014-09-19
CVE-2014-4400 [MEDIUM] CVE-2014-4400: An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4394, CVE-2014-4395, CVE-2014-4396, CVE-2014-4397, CVE-2014-4398, CVE-
nvd
CVE-2014-4396P4MEDIUMCVSS 6.9v10.8.5v10.9+4 more2014-09-19
CVE-2014-4396 [MEDIUM] CVE-2014-4396: An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4394, CVE-2014-4395, CVE-2014-4397, CVE-2014-4398, CVE-2014-4399, CVE-
nvd
CVE-2014-4398P4MEDIUMCVSS 6.9v10.8.5v10.9+4 more2014-09-19
CVE-2014-4398 [MEDIUM] CVE-2014-4398: An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4394, CVE-2014-4395, CVE-2014-4396, CVE-2014-4397, CVE-2014-4399, CVE-
nvd
CVE-2014-4394P4MEDIUMCVSS 6.9v10.8.5v10.9+4 more2014-09-19
CVE-2014-4394 [MEDIUM] CWE-20 CVE-2014-4394: An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4395, CVE-2014-4396, CVE-2014-4397, CVE-2014-4398, CVE-2014-439
nvd
CVE-2014-4397P4MEDIUMCVSS 6.9v10.8.5v10.9+4 more2014-09-19
CVE-2014-4397 [MEDIUM] CVE-2014-4397: An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4394, CVE-2014-4395, CVE-2014-4396, CVE-2014-4398, CVE-2014-4399, CVE-
nvd
CVE-2019-8606P4HIGHCVSS 7.0fixed in 10.14.52019-12-18
CVE-2019-8606 [HIGH] CWE-362 CVE-2019-8606: A validation issue existed in the handling of symlinks. This issue was addressed with improved valid A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Mojave 10.14.5. A local user may be able to load unsigned kernel extensions.
nvd
CVE-2014-4395P4MEDIUMCVSS 6.9v10.8.5v10.9+4 more2014-09-19
CVE-2014-4395 [MEDIUM] CVE-2014-4395: An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4394, CVE-2014-4396, CVE-2014-4397, CVE-2014-4398, CVE-2014-4399, CVE-
nvd
CVE-2014-4401P4MEDIUMCVSS 6.9v10.8.5v10.9+4 more2014-09-19
CVE-2014-4401 [MEDIUM] CVE-2014-4401: An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4394, CVE-2014-4395, CVE-2014-4396, CVE-2014-4397, CVE-2014-4398, CVE-
nvd
CVE-2015-1101P4MEDIUMCVSS 6.9≤ 10.10.22015-04-10
CVE-2015-1101 [MEDIUM] CVE-2015-1101: The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attack The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2010-0058P4MEDIUMCVSS 6.4v10.5.82010-03-30
CVE-2010-0058 [MEDIUM] CWE-16 CVE-2010-0058: freshclam in ClamAV in Apple Mac OS X 10.5.8 with Security Update 2009-005 has an incorrect launchd. freshclam in ClamAV in Apple Mac OS X 10.5.8 with Security Update 2009-005 has an incorrect launchd.plist ProgramArguments key and consequently does not run, which might allow remote attackers to introduce viruses into the system.
nvd
CVE-2021-30965P4MEDIUMCVSS 6.5≥ 10.15, ≤ 10.15.7v10.15.72021-08-24
CVE-2021-30965 [MEDIUM] CVE-2021-30965: A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12 A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.1, Security Update 2021-008 Catalina, macOS Big Sur 11.6.2. A malicious application may be able to cause a denial of service to Endpoint Security clients.
nvd
CVE-2012-0655P4MEDIUMCVSS 6.4≤ 10.7.3v10.0+68 more2012-05-11
CVE-2012-0655 [MEDIUM] CWE-310 CVE-2012-0655: libsecurity in Apple Mac OS X before 10.7.4 does not properly restrict the length of RSA keys within libsecurity in Apple Mac OS X before 10.7.4 does not properly restrict the length of RSA keys within X.509 certificates, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by conducting a spoofing or network-sniffing attack during communication with a site that uses a short key.
nvd
CVE-2013-6712P4MEDIUMCVSS 5.0≤ 10.10.22013-11-28
CVE-2013-6712 [MEDIUM] CWE-119 CVE-2013-6712: The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restr The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted interval specification.
nvd
CVE-2004-0824P4LOWCVSS 2.1PoCv10.2.8v10.3+5 more2004-12-31
CVE-2004-0824 [LOW] CVE-2004-0824: PPPDialer for Mac OS X 10.2.8 through 10.3.5 allows local users to overwrite system files via a syml PPPDialer for Mac OS X 10.2.8 through 10.3.5 allows local users to overwrite system files via a symlink attack on PPPDialer log files.
nvd
CVE-2007-0742P4HIGHCVSS 7.8≤ 10.3.92007-04-24
CVE-2007-0742 [HIGH] CVE-2007-0742: The WebFoundation framework in Apple Mac OS X 10.3.9 and earlier allows subdomain cookies to be acce The WebFoundation framework in Apple Mac OS X 10.3.9 and earlier allows subdomain cookies to be accessed by the parent domain, which allows remote attackers to obtain sensitive information.
nvd
CVE-2019-8754P4MEDIUMCVSS 6.5fixed in 10.15.12020-10-27
CVE-2019-8754 [MEDIUM] CWE-346 CVE-2019-8754: A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of se A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006. A malicious HTML document may be able to render iframes with sensitive user information.
nvd
CVE-2014-3660P4MEDIUMCVSS 5.0≤ 10.10.42014-11-04
CVE-2014-3660 [MEDIUM] CVE-2014-3660: parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substit parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML document containing a large number of nested entity references, a variant of the "billion laughs" attack.
nvd
Apple macOS vulnerabilities | cvebase