Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 103 of 157
CVE-2021-1884P4MEDIUMCVSS 5.9≥ 10.14.0, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-09-08
CVE-2021-1884 [MEDIUM] CWE-362 CVE-2021-1884: A race condition was addressed with improved locking. This issue is fixed in Security Update 2021-00
A race condition was addressed with improved locking. This issue is fixed in Security Update 2021-004 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, Security Update 2021-003 Catalina, tvOS 14.5, macOS Big Sur 11.3. A remote attacker may be able to cause a denial of service.
nvd
CVE-2021-30982P4MEDIUMCVSS 5.9≥ 10.15, < 10.15.7v10.15.72021-08-24
CVE-2021-30982 [MEDIUM] CWE-362 CVE-2021-30982: A race condition was addressed with improved locking. This issue is fixed in macOS Monterey 12.1, Se
A race condition was addressed with improved locking. This issue is fixed in macOS Monterey 12.1, Security Update 2021-008 Catalina, macOS Big Sur 11.6.2. A remote attacker may be able to cause unexpected application termination or heap corruption.
nvd
CVE-2015-7023P4MEDIUMCVSS 5.8≤ 10.11.02015-10-23
CVE-2015-7023 [MEDIUM] CWE-17 CVE-2015-7023: CFNetwork in Apple iOS before 9.1 and OS X before 10.11.1 does not properly consider the uppercase-v
CFNetwork in Apple iOS before 9.1 and OS X before 10.11.1 does not properly consider the uppercase-versus-lowercase distinction during cookie parsing, which allows remote web servers to overwrite cookies via unspecified vectors.
nvd
CVE-2017-2497P4MEDIUMCVSS 6.1≤ 10.12.42017-05-22
CVE-2017-2497 [MEDIUM] CWE-601 CVE-2017-2497: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "iBooks" component. It allows remote attackers to trigger visits to arbitrary URLs via a crafted book.
nvd
CVE-2019-15165P4MEDIUMCVSS 5.3≥ 10.13, < 10.13.6v10.13.6+2 more2019-10-03
CVE-2019-15165 [MEDIUM] CWE-770 CVE-2019-15165: sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocati
sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.
nvd
CVE-2008-1571P4MEDIUMCVSS 5.0v10.4.112008-06-02
CVE-2008-1571 [MEDIUM] CWE-22 CVE-2008-1571: Directory traversal vulnerability in the embedded web server in Image Capture in Apple Mac OS X befo
Directory traversal vulnerability in the embedded web server in Image Capture in Apple Mac OS X before 10.5 allows remote attackers to read arbitrary files via directory traversal sequences in the URI.
nvd
CVE-2018-4111P4MEDIUMCVSS 5.9fixed in 10.13.42018-04-03
CVE-2018-4111 [MEDIUM] CWE-347 CVE-2018-4111: An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Mail" component. It allows man-in-the-middle attackers to read S/MIME encrypted message content by sending HTML e-mail that references remote resources but lacks a valid S/MIME signature.
nvd
CVE-2009-2836P4MEDIUMCVSS 6.2v10.6v10.6.12009-11-10
CVE-2009-2836 [MEDIUM] CWE-362 CVE-2009-2836: Race condition in Login Window in Apple Mac OS X 10.6.x before 10.6.2, when at least one account has
Race condition in Login Window in Apple Mac OS X 10.6.x before 10.6.2, when at least one account has a blank password, allows attackers to bypass password authentication and obtain login access to an arbitrary account via unspecified vectors.
nvd
CVE-2009-2831P4MEDIUMCVSS 5.8v10.5.82009-11-10
CVE-2009-2831 [MEDIUM] CVE-2009-2831: Dictionary in Apple Mac OS X 10.5.8 allows remote attackers to create arbitrary files with any conte
Dictionary in Apple Mac OS X 10.5.8 allows remote attackers to create arbitrary files with any contents, and thereby execute arbitrary code, via crafted JavaScript, related to a "design issue."
nvd
CVE-2008-1576P4MEDIUMCVSS 6.8v10.0v10.1+3 more2008-06-02
CVE-2008-1576 [MEDIUM] CWE-399 CVE-2008-1576: Mail in Apple Mac OS X before 10.5, when an IPv6 SMTP server is used, does not properly initialize m
Mail in Apple Mac OS X before 10.5, when an IPv6 SMTP server is used, does not properly initialize memory, which might allow remote attackers to execute arbitrary code or cause a denial of service (application crash), or obtain sensitive information (memory contents) in opportunistic circumstances, by sending an e-mail message.
nvd
CVE-2005-1332P4HIGHCVSS 7.5v10.3.92005-05-04
CVE-2005-1332 [HIGH] CVE-2005-1332: Bluetooth-enabled systems in Mac OS X 10.3.9 enables the Bluetooth file exchange service by default,
Bluetooth-enabled systems in Mac OS X 10.3.9 enables the Bluetooth file exchange service by default, which allows remote attackers to access files without the user being notified, and local users to access files via the default directory.
nvd
CVE-2004-0538P4HIGHCVSS 7.5v10.2.8v10.3.42004-08-06
CVE-2004-0538 [HIGH] CVE-2004-0538: LaunchServices in Mac OS X 10.3.4 and 10.2.8 automatically registers and executes new applications,
LaunchServices in Mac OS X 10.3.4 and 10.2.8 automatically registers and executes new applications, which could allow attackers to execute arbitrary code without warning the user.
nvd
CVE-2014-8130P4MEDIUMCVSS 6.5v10.8.5v10.9.5+4 more2018-03-12
CVE-2014-8130 [MEDIUM] CWE-369 CVE-2014-8130: The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows re
The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image that is mishandled by the TIFFWriteScanline function in tif_write.c, as demonstrated by tiffdither.
nvd
CVE-2005-1340P4HIGHCVSS 7.5v10.3.92005-05-04
CVE-2005-1340 [HIGH] CVE-2005-1340: The HTTP proxy service in Server Admin for Mac OS X 10.3.9 does not restrict access when it is enabl
The HTTP proxy service in Server Admin for Mac OS X 10.3.9 does not restrict access when it is enabled, which allows remote attackers to use the proxy.
nvd
CVE-2007-0721P4MEDIUMCVSS 6.8v10.3.9v10.4+8 more2007-03-13
CVE-2007-0721 [MEDIUM] CVE-2007-0721: Unspecified vulnerability in diskimages-helper in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allo
Unspecified vulnerability in diskimages-helper in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via a crafted compressed disk image that triggers memory corruption.
nvd
CVE-2006-1445P4MEDIUMCVSS 6.5v10.3.9v10.4.62006-05-12
CVE-2006-1445 [MEDIUM] CVE-2006-1445: Buffer overflow in the FTP server (FTPServer) in Apple Mac OS X 10.3.9 and 10.4.6 allows remote auth
Buffer overflow in the FTP server (FTPServer) in Apple Mac OS X 10.3.9 and 10.4.6 allows remote authenticated users to execute arbitrary code via vectors related to "FTP server path name handling."
nvd
CVE-2009-1727P4MEDIUMCVSS 6.8v10.5.6v10.5+7 more2009-08-06
CVE-2009-1727 [MEDIUM] CVE-2009-1727: Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X 10.5 before 10.5.8 makes it easier
Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X 10.5 before 10.5.8 makes it easier for user-assisted remote attackers to execute arbitrary JavaScript via a web page that offers a download with a Content-Type value that is not on the list of possibly unsafe content types for Safari.
nvd
CVE-2009-0009P4MEDIUMCVSS 6.8v10.4.11v10.5.62009-02-13
CVE-2009-0009 [MEDIUM] CWE-119 CVE-2009-0009: Unspecified vulnerability in the Pixlet codec in Apple Mac OS X 10.4.11 and 10.5.6 allows remote att
Unspecified vulnerability in the Pixlet codec in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted movie file that triggers memory corruption.
nvd
CVE-2015-6994P4HIGHCVSS 7.1≤ 10.11.02015-10-23
CVE-2015-6994 [HIGH] CWE-399 CVE-2015-6994: The kernel in Apple iOS before 9.1 and OS X before 10.11.1 mishandles reuse of virtual memory, which
The kernel in Apple iOS before 9.1 and OS X before 10.11.1 mishandles reuse of virtual memory, which allows attackers to cause a denial of service via a crafted app.
nvd
CVE-2015-1102P4HIGHCVSS 7.1≤ 10.10.22015-04-10
CVE-2015-1102 [HIGH] CWE-20 CVE-2015-1102: The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 does not prop
The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 does not properly handle TCP headers, which allows man-in-the-middle attackers to cause a denial of service via unspecified vectors.
nvd