cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 11 of 157
CVE-2015-3329P3HIGHCVSS 7.5≤ 10.6.8v10.9.5+5 more2015-06-09
CVE-2015-3329 [HIGH] CWE-119 CVE-2015-3329: Multiple stack-based buffer overflows in the phar_set_inode function in phar_internal.h in PHP befor Multiple stack-based buffer overflows in the phar_set_inode function in phar_internal.h in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allow remote attackers to execute arbitrary code via a crafted length value in a (1) tar, (2) phar, or (3) ZIP archive.
nvd
CVE-2017-2533P3HIGHCVSS 7.0PoC≤ 10.12.42017-05-22
CVE-2017-2533 [HIGH] CWE-362 CVE-2017-2533: An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "DiskArbitration" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2018-4230P3HIGHCVSS 7.0PoCfixed in 10.13.52018-06-08
CVE-2018-4230 [HIGH] CWE-362 CVE-2018-4230: An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "NVIDIA Graphics Drivers" component. It allows attackers to execute arbitrary code in a privileged context via a crafted app that triggers a SetAppSupportBits use-after-free because of a race condition.
nvd
CVE-2017-6979P3HIGHCVSS 7.0PoC≤ 10.12.42017-05-22
CVE-2017-6979 [HIGH] CWE-362 CVE-2017-6979: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "IOSurface" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2016-1863P3HIGHCVSS 7.8PoCfixed in 10.11.62016-07-22
CVE-2016-1863 [HIGH] CWE-416 CVE-2016-1863: The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2 The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4582 and CVE-2016-4653.
nvd
CVE-2007-6276P3HIGHCVSS 7.8PoCv10.5v10.5.1+2 more2007-12-07
CVE-2007-6276 [HIGH] CWE-189 CVE-2007-6276: The accept_connections function in the virtual private network daemon (vpnd) in Apple Mac OS X 10.5 The accept_connections function in the virtual private network daemon (vpnd) in Apple Mac OS X 10.5 before 10.5.4 allows remote attackers to cause a denial of service (divide-by-zero error and daemon crash) via a crafted load balancing packet to UDP port 4112.
nvd
CVE-2011-1516P3HIGHCVSS 7.6PoCv10.5.0v10.5.1+19 more2011-11-15
CVE-2011-1516 [HIGH] CVE-2011-1516: The kSBXProfileNoNetwork and kSBXProfileNoInternet sandbox profiles in Apple Mac OS X 10.5.x through The kSBXProfileNoNetwork and kSBXProfileNoInternet sandbox profiles in Apple Mac OS X 10.5.x through 10.7.x do not propagate restrictions to all created processes, which allows remote attackers to access network resources via a crafted application, as demonstrated by use of osascript to send Apple events to the launchd daemon, a related issue to CVE-2008-7303.
nvd
CVE-2016-0777P3MEDIUMCVSS 6.5≤ 10.11.32016-01-14
CVE-2016-0777 [MEDIUM] CWE-200 CVE-2016-0777: The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.
nvd
CVE-2016-7661P3HIGHCVSS 7.8PoC≤ 10.12.12017-02-20
CVE-2016-7661 [HIGH] CWE-264 CVE-2016-7661: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. The issue involves the "Power Management" component. It allows local users to gain privileges via unspecified vectors related to Mach port name references.
nvd
CVE-2016-7637P3HIGHCVSS 7.8PoC≤ 10.12.12017-02-20
CVE-2016-7637 [HIGH] CWE-119 CVE-2016-7637: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2016-7660P3HIGHCVSS 7.8PoC≤ 10.12.12017-02-20
CVE-2016-7660 [HIGH] CWE-264 CVE-2016-7660: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "syslog" component. It allows local users to gain privileges via unspecified vectors related to Mach port name references.
nvd
CVE-2007-0462P3CRITICALCVSS 10.0PoCv10.4.82007-01-26
CVE-2007-0462 [CRITICAL] CVE-2007-0462: The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PICT image with a malformed Alpha RGB (ARGB) record, which triggers memory corruption.
nvd
CVE-2007-0355P3HIGHCVSS 7.2PoCv10.4.82007-01-19
CVE-2007-0355 [HIGH] CWE-119 CVE-2007-0355: Buffer overflow in the Apple Minimal SLP v2 Service Agent (slpd) in Mac OS X 10.4.11 and earlier, in Buffer overflow in the Apple Minimal SLP v2 Service Agent (slpd) in Mac OS X 10.4.11 and earlier, including 10.4.8, allows local users, and possibly remote attackers, to gain privileges and possibly execute arbitrary code via a registration request with an invalid attr-list field.
nvd
CVE-2015-3673P3HIGHCVSS 7.2PoC≤ 10.10.32015-07-03
CVE-2015-3673 [HIGH] CWE-264 CVE-2015-3673: Admin Framework in Apple OS X before 10.10.4 does not properly restrict the location of writeconfig Admin Framework in Apple OS X before 10.10.4 does not properly restrict the location of writeconfig clients, which allows local users to obtain root privileges by moving and then modifying Directory Utility.
nvd
CVE-2007-4677P3CRITICALCVSS 9.3v10.3.9v10.4.10+1 more2007-11-07
CVE-2007-4677 [CRITICAL] CWE-119 CVE-2007-4677: Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrar Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via an invalid color table size when parsing the color table atom (CTAB) in a movie file, related to the CTAB RGB values.
nvd
CVE-2016-3141P3CRITICALCVSS 9.8≤ 10.11.42016-03-31
CVE-2016-3141 [CRITICAL] CWE-119 CVE-2016-3141: Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5 Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact by triggering a wddx_deserialize call on XML data containing a crafted var element.
nvd
CVE-2014-4433P3HIGHCVSS 7.2PoC≤ 10.9.52014-10-18
CVE-2014-4433 [HIGH] CWE-119 CVE-2014-4433: Heap-based buffer overflow in the kernel in Apple OS X before 10.10 allows physically proximate atta Heap-based buffer overflow in the kernel in Apple OS X before 10.10 allows physically proximate attackers to execute arbitrary code via crafted resource forks in an HFS filesystem.
nvd
CVE-2022-22616P3MEDIUMCVSS 5.5PoC≥ 10.15, < 10.15.7v10.15.72022-05-26
CVE-2022-22616 [MEDIUM] CVE-2022-22616: This issue was addressed with improved checks. This issue is fixed in Security Update 2022-003 Catal This issue was addressed with improved checks. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. A maliciously crafted ZIP archive may bypass Gatekeeper checks.
nvd
CVE-2016-7633P3HIGHCVSS 7.8PoC≤ 10.12.12017-02-20
CVE-2016-7633 [HIGH] CWE-416 CVE-2016-7633: An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Directory Services" component. It allows local users to gain privileges or cause a denial of service (use-after-free) via unspecified vectors.
nvd
CVE-2007-3751P3CRITICALCVSS 9.3v10.3.9v10.4.10+1 more2007-11-07
CVE-2007-3751 [CRITICAL] CVE-2007-3751: Unspecified vulnerability in QuickTime for Java in Apple QuickTime before 7.3 allows remote attacker Unspecified vulnerability in QuickTime for Java in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via untrusted Java applets that gain privileges via unspecified vectors.
nvd
Apple macOS vulnerabilities | cvebase