cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 106 of 157
CVE-2015-5830P4HIGHCVSS 7.2≤ 10.10.52015-10-09
CVE-2015-5830 [HIGH] CWE-119 CVE-2015-5830: The Intel Graphics Driver component in Apple OS X before 10.11 allows local users to gain privileges The Intel Graphics Driver component in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5877.
nvd
CVE-2015-5871P4HIGHCVSS 7.2≤ 10.10.52015-10-09
CVE-2015-5871 [HIGH] CWE-119 CVE-2015-5871: IOGraphics in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of ser IOGraphics in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5872, CVE-2015-5873, and CVE-2015-5890.
nvd
CVE-2015-5877P4HIGHCVSS 7.2≤ 10.10.52015-10-09
CVE-2015-5877 [HIGH] CVE-2015-5877: The Intel Graphics Driver component in Apple OS X before 10.11 allows local users to gain privileges The Intel Graphics Driver component in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5830.
nvd
CVE-2015-5896P4HIGHCVSS 7.2≤ 10.10.52015-09-18
CVE-2015-5896 [HIGH] CVE-2015-5896: The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5868 and CVE-2015-5903.
nvd
CVE-2015-5868P4HIGHCVSS 7.2≤ 10.10.52015-09-18
CVE-2015-5868 [HIGH] CWE-119 CVE-2015-5868: The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5896 and CVE-2015-5903.
nvd
CVE-2022-32851P4HIGHCVSS 7.1v10.15.72022-09-23
CVE-2022-32851 [HIGH] CWE-125 CVE-2022-32851: An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in Sec An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing a maliciously crafted AppleScript binary may result in unexpected termination or disclosure of process memory.
nvd
CVE-2022-32831P4HIGHCVSS 7.1v10.15.72022-09-23
CVE-2022-32831 [HIGH] CWE-125 CVE-2022-32831: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Security U An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing a maliciously crafted AppleScript binary may result in unexpected termination or disclosure of process memory.
nvd
CVE-2022-32853P4HIGHCVSS 7.1v10.15.72022-09-23
CVE-2022-32853 [HIGH] CWE-125 CVE-2022-32853: An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in Sec An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing a maliciously crafted AppleScript binary may result in unexpected termination or disclosure of process memory.
nvd
CVE-2020-3907P4HIGHCVSS 7.1fixed in 10.15.42020-04-01
CVE-2020-3907 [HIGH] CWE-125 CVE-2020-3907: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Cat An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A local user may be able to cause unexpected system termination or read kernel memory.
nvd
CVE-2019-8576P4HIGHCVSS 7.1fixed in 10.14.52019-12-18
CVE-2019-8576 [HIGH] CWE-125 CVE-2019-8576: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.3, An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A local user may be able to cause unexpected system termination or read kernel memory.
nvd
CVE-2020-3912P4HIGHCVSS 7.1fixed in 10.15.42020-04-01
CVE-2020-3912 [HIGH] CWE-125 CVE-2020-3912: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Cat An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A local user may be able to cause unexpected system termination or read kernel memory.
nvd
CVE-2020-3908P4HIGHCVSS 7.1fixed in 10.15.42020-04-01
CVE-2020-3908 [HIGH] CWE-125 CVE-2020-3908: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Cat An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A local user may be able to cause unexpected system termination or read kernel memory.
nvd
CVE-2014-4437P4MEDIUMCVSS 6.8≤ 10.9.52014-10-18
CVE-2014-4437 [MEDIUM] CWE-264 CVE-2014-4437: LaunchServices in Apple OS X before 10.10 allows attackers to bypass intended sandbox restrictions v LaunchServices in Apple OS X before 10.10 allows attackers to bypass intended sandbox restrictions via an application that specifies a crafted handler for the Content-Type field of an object.
nvd
CVE-2019-8759P4HIGHCVSS 7.1fixed in 10.15.12020-10-27
CVE-2019-8759 [HIGH] CWE-125 CVE-2019-8759: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Cata An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, macOS Catalina 10.15. A local user may be able to cause unexpected system termination or read kernel memory.
nvd
CVE-2020-9930P4HIGHCVSS 7.1fixed in 10.13.6≥ 10.14, < 10.14.6+3 more2021-04-02
CVE-2020-9930 [HIGH] CWE-125 CVE-2020-9930: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Cat An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra. A local user may be able to cause unexpected system termination or read kernel memory.
nvd
CVE-2008-0992P4MEDIUMCVSS 5.8v10.5.22008-03-18
CVE-2008-0992 [MEDIUM] CWE-119 CVE-2008-0992: Array index error in pax in Apple Mac OS X 10.5.2 allows context-dependent attackers to execute arbi Array index error in pax in Apple Mac OS X 10.5.2 allows context-dependent attackers to execute arbitrary code via an archive with a crafted length value.
nvd
CVE-2016-1734P4MEDIUMCVSS 6.8≤ 10.11.32016-03-24
CVE-2016-1734 [MEDIUM] CWE-119 CVE-2016-1734: AppleUSBNetworking in Apple iOS before 9.3 and OS X before 10.11.4 allows physically proximate attac AppleUSBNetworking in Apple iOS before 9.3 and OS X before 10.11.4 allows physically proximate attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted USB device.
nvd
CVE-2018-4406P4MEDIUMCVSS 6.5fixed in 10.142019-04-03
CVE-2018-4406 [MEDIUM] CWE-20 CVE-2018-4406: A denial of service issue was addressed with improved validation. This issue affected versions prior A denial of service issue was addressed with improved validation. This issue affected versions prior to macOS Mojave 10.14.
nvd
CVE-2018-4389P4MEDIUMCVSS 6.5fixed in 10.14.12019-04-03
CVE-2018-4389 [MEDIUM] CWE-20 CVE-2018-4389: An inconsistent user interface issue was addressed with improved state management. This issue affect An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to macOS Mojave 10.14.1.
nvd
CVE-2015-6563P4MEDIUMCVSS 6.4≤ 10.11.02015-08-24
CVE-2015-6563 [MEDIUM] CWE-20 CVE-2015-6563: The monitor component in sshd in OpenSSH before 7.0 on non-OpenBSD platforms accepts extraneous user The monitor component in sshd in OpenSSH before 7.0 on non-OpenBSD platforms accepts extraneous username data in MONITOR_REQ_PAM_INIT_CTX requests, which allows local users to conduct impersonation attacks by leveraging any SSH login access in conjunction with control of the sshd uid to send a crafted MONITOR_REQ_PWNAM request, related to monitor.c and
nvd
Apple macOS vulnerabilities | cvebase