Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 104 of 157
CVE-2010-0065P4MEDIUMCVSS 6.8≤ 10.6.2v10.5+11 more2010-03-30
CVE-2010-0065 [MEDIUM] CWE-119 CVE-2010-0065: Disk Images in Apple Mac OS X before 10.6.3 allows user-assisted remote attackers to execute arbitra
Disk Images in Apple Mac OS X before 10.6.3 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted disk image with bzip2 compression.
nvd
CVE-2009-2803P4MEDIUMCVSS 6.8v10.4.11v10.5.82009-09-14
CVE-2009-2803 [MEDIUM] CWE-399 CVE-2009-2803: CarbonCore in Apple Mac OS X 10.4.11 and 10.5.8 allows attackers to execute arbitrary code or cause
CarbonCore in Apple Mac OS X 10.4.11 and 10.5.8 allows attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a file with a crafted resource fork.
nvd
CVE-2008-0052P4MEDIUMCVSS 6.8v10.4.112008-03-18
CVE-2008-0052 [MEDIUM] CWE-200 CVE-2008-0052: CoreServices in Apple Mac OS X 10.4.11 treats .ief as a safe file type, which allows remote attacker
CoreServices in Apple Mac OS X 10.4.11 treats .ief as a safe file type, which allows remote attackers to force Safari users into opening an .ief file in AppleWorks, even when the "Open 'Safe' files" preference is set.
nvd
CVE-2022-22625P4HIGHCVSS 7.1≥ 10.15, < 10.15.7v10.15.72022-03-18
CVE-2022-22625 [HIGH] CWE-125 CVE-2022-22625: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. Processing a maliciously crafted AppleScript binary may result in unexpected application termination or disclosure of process memory.
nvd
CVE-2011-3227P4MEDIUMCVSS 6.8≤ 10.7.1v10.0+66 more2011-10-14
CVE-2011-3227 [MEDIUM] CWE-20 CVE-2011-3227: libsecurity in Apple Mac OS X before 10.7.2 does not properly handle errors during processing of a n
libsecurity in Apple Mac OS X before 10.7.2 does not properly handle errors during processing of a nonstandard extension in a Certificate Revocation list (CRL), which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) a crafted (1) web site or (2) e-mail message.
nvd
CVE-2022-26697P4HIGHCVSS 7.1fixed in 10.15.7v10.15.72022-05-26
CVE-2022-26697 [HIGH] CWE-125 CVE-2022-26697: An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in Sec
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. Processing a maliciously crafted AppleScript binary may result in unexpected application termination or disclosure of process memory.
nvd
CVE-2021-1828P4HIGHCVSS 7.1≥ 10.14, ≤ 10.14.5≥ 10.15, ≤ 10.15.5+3 more2021-09-08
CVE-2021-1828 [HIGH] CWE-787 CVE-2021-1828: A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Big S
A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. An application may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2021-30710P4HIGHCVSS 7.1≥ 10.14, ≤ 10.14.5≥ 10.15, ≤ 10.15.6+2 more2021-09-08
CVE-2021-30710 [HIGH] CWE-787 CVE-2021-30710: A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS
A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. A malicious application may cause a denial of service or potentially disclose memory contents.
nvd
CVE-2010-0063P4MEDIUMCVSS 6.8≤ 10.6.2v10.5+11 more2010-03-30
CVE-2010-0063 [MEDIUM] CVE-2010-0063: Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.6.3 makes it easier for
Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.6.3 makes it easier for user-assisted remote attackers to execute arbitrary JavaScript via a web page that offers a download with a Content-Type value that is not on the list of possibly unsafe content types for Safari, as demonstrated by the values for the (1) .ibplugin and (2) .url e
nvd
CVE-2015-1133P4HIGHCVSS 7.2fixed in 10.10.32015-04-10
CVE-2015-1133 [HIGH] CVE-2015-1133: fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privilege
fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1131, CVE-2015-1132, CVE-2015-1134, and CVE-2015-1135.
nvd
CVE-2015-1131P4HIGHCVSS 7.2fixed in 10.10.32015-04-10
CVE-2015-1131 [HIGH] CWE-20 CVE-2015-1131: fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privilege
fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1132, CVE-2015-1133, CVE-2015-1134, and CVE-2015-1135.
nvd
CVE-2015-1134P4HIGHCVSS 7.2fixed in 10.10.32015-04-10
CVE-2015-1134 [HIGH] CVE-2015-1134: fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privilege
fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1131, CVE-2015-1132, CVE-2015-1133, and CVE-2015-1135.
nvd
CVE-2007-5848P4HIGHCVSS 7.2v10.4.112007-12-19
CVE-2007-5848 [HIGH] CWE-119 CVE-2007-5848: Buffer overflow in CUPS in Apple Mac OS X 10.4.11 allows local admin users to execute arbitrary code
Buffer overflow in CUPS in Apple Mac OS X 10.4.11 allows local admin users to execute arbitrary code via a crafted URI to the CUPS service.
nvd
CVE-2012-0675P4MEDIUMCVSS 4.3≤ 10.7.3v10.0+68 more2012-05-11
CVE-2012-0675 [MEDIUM] CWE-287 CVE-2012-0675: Time Machine in Apple Mac OS X before 10.7.4 does not require continued use of SRP-based authenticat
Time Machine in Apple Mac OS X before 10.7.4 does not require continued use of SRP-based authentication after this authentication method is first used, which allows remote attackers to read Time Capsule credentials by spoofing the backup volume.
nvd
CVE-2015-1135P4HIGHCVSS 7.2fixed in 10.10.32015-04-10
CVE-2015-1135 [HIGH] CVE-2015-1135: fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privilege
fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1131, CVE-2015-1132, CVE-2015-1133, and CVE-2015-1134.
nvd
CVE-2017-7151P4HIGHCVSS 7.0fixed in 10.13.2≥ 10.13.3, < 10.13.42019-04-03
CVE-2017-7151 [HIGH] CWE-362 CVE-2017-7151: A race condition was addressed with additional validation. This issue affected versions prior to iOS
A race condition was addressed with additional validation. This issue affected versions prior to iOS 11.2, macOS High Sierra 10.13.2, tvOS 11.2, watchOS 4.2, iTunes 12.7.2 for Windows, macOS High Sierra 10.13.4.
nvd
CVE-2015-3695P4HIGHCVSS 7.2≤ 10.10.32015-07-03
CVE-2015-3695 [HIGH] CWE-119 CVE-2015-3695: Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain
Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3696, CVE-2015-3697, CVE-2015-3698, CVE-2015-3699, CVE-2015-3700, CVE-2015-3701, and CVE-2015-3702.
nvd
CVE-2015-3701P4HIGHCVSS 7.2≤ 10.10.32015-07-03
CVE-2015-3701 [HIGH] CVE-2015-3701: Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain
Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3696, CVE-2015-3697, CVE-2015-3698, CVE-2015-3699, CVE-2015-3700, and CVE-2015-3702.
nvd
CVE-2015-3697P4HIGHCVSS 7.2≤ 10.10.32015-07-03
CVE-2015-3697 [HIGH] CVE-2015-3697: Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain
Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3696, CVE-2015-3698, CVE-2015-3699, CVE-2015-3700, CVE-2015-3701, and CVE-2015-3702.
nvd
CVE-2015-3696P4HIGHCVSS 7.2≤ 10.10.32015-07-03
CVE-2015-3696 [HIGH] CVE-2015-3696: Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain
Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3697, CVE-2015-3698, CVE-2015-3699, CVE-2015-3700, CVE-2015-3701, and CVE-2015-3702.
nvd