cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 110 of 157
CVE-2019-8768P4MEDIUMCVSS 5.3fixed in 10.152019-12-18
CVE-2019-8768 [MEDIUM] CWE-459 CVE-2019-8768: "Clear History and Website Data" did not clear the history. The issue was addressed with improved da "Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This issue is fixed in macOS Catalina 10.15. A user may be unable to delete browsing history items.
nvd
CVE-2017-7141P4MEDIUMCVSS 5.3≤ 10.12.62017-10-23
CVE-2017-7141 [MEDIUM] CWE-200 CVE-2017-7141: An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involve An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "Mail" component. It allows remote attackers to bypass an intended off value of the "Load remote content in messages" setting, and consequently discover an e-mail recipient's IP address, via an HTML email message.
nvd
CVE-2021-1760P4MEDIUMCVSS 5.5≥ 10.14, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-04-02
CVE-2021-1760 [MEDIUM] CWE-787 CVE-2021-1760: A memory corruption issue was addressed with improved state management. This issue is fixed in macOS A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application could execute arbitrary code leading to compromise of user information.
nvd
CVE-2019-8530P4MEDIUMCVSS 5.5fixed in 10.14.42019-12-18
CVE-2019-8530 [MEDIUM] CVE-2019-8530: This issue was addressed with improved checks. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4 This issue was addressed with improved checks. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2. A malicious application may be able to overwrite arbitrary files.
nvd
CVE-2004-1083P4HIGHCVSS 7.5v10.2v10.2.1+14 more2004-12-03
CVE-2004-1083 [HIGH] CWE-178 CVE-2004-1083: Apache for Apple Mac OS X 10.2.8 and 10.3.6 restricts access to files in a case sensitive manner, bu Apache for Apple Mac OS X 10.2.8 and 10.3.6 restricts access to files in a case sensitive manner, but the Apple HFS+ filesystem accesses files in a case insensitive manner, which allows remote attackers to read .DS_Store files and files beginning with ".ht" using alternate capitalization.
nvd
CVE-2014-8839P4MEDIUMCVSS 5.0≤ 10.10.12015-01-30
CVE-2014-8839 [MEDIUM] CWE-200 CVE-2014-8839: Spotlight in Apple OS X before 10.10.2 does not enforce the Mail "Load remote content in messages" c Spotlight in Apple OS X before 10.10.2 does not enforce the Mail "Load remote content in messages" configuration, which allows remote attackers to discover recipient IP addresses by including an inline image in an HTML e-mail message and logging HTTP requests for this image's URL.
nvd
CVE-2018-4293P4MEDIUMCVSS 5.3fixed in 10.13.62019-04-03
CVE-2018-4293 [MEDIUM] CWE-20 CVE-2018-4293: A cookie management issue was addressed with improved checks. This issue affected versions prior to A cookie management issue was addressed with improved checks. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvd
CVE-2019-8521P4MEDIUMCVSS 5.5fixed in 10.14.42019-12-18
CVE-2019-8521 [MEDIUM] CVE-2019-8521: This issue was addressed with improved checks. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4 This issue was addressed with improved checks. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4. A malicious application may be able to overwrite arbitrary files.
nvd
CVE-2018-4321P4MEDIUMCVSS 5.3fixed in 10.142019-04-03
CVE-2018-4321 [MEDIUM] CWE-20 CVE-2018-4321: A validation issue existed in the entitlement verification. This issue was addressed with improved v A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12.
nvd
CVE-2020-9787P4MEDIUMCVSS 5.3≥ 10.15.3, < 10.15.42020-10-22
CVE-2020-9787 [MEDIUM] CVE-2020-9787: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 1 A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. Some websites may not have appeared in Safari Preferences.
nvd
CVE-2016-4635P4MEDIUMCVSS 5.3≤ 10.11.52016-07-22
CVE-2016-4635 [MEDIUM] CWE-200 CVE-2016-4635: FaceTime in Apple iOS before 9.3.3 and OS X before 10.11.6 allows man-in-the-middle attackers to spo FaceTime in Apple iOS before 9.3.3 and OS X before 10.11.6 allows man-in-the-middle attackers to spoof relayed-call termination, and obtain sensitive audio information in opportunistic circumstances, via unspecified vectors.
nvd
CVE-2014-4453P4MEDIUMCVSS 5.0≤ 10.10.0v10.0+83 more2014-11-18
CVE-2014-4453 [MEDIUM] CWE-200 CVE-2014-4453: Apple iOS before 8.1.1 and OS X before 10.10.1 include location data during establishment of a Spotl Apple iOS before 8.1.1 and OS X before 10.10.1 include location data during establishment of a Spotlight Suggestions server connection by Spotlight or Safari, which might allow remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2010-0521P4MEDIUMCVSS 5.0v10.6.0v10.6.1+1 more2010-03-30
CVE-2010-0521 [MEDIUM] CWE-287 CVE-2010-0521: Server Admin in Apple Mac OS X Server before 10.6.3 does not properly enforce authentication for dir Server Admin in Apple Mac OS X Server before 10.6.3 does not properly enforce authentication for directory binding, which allows remote attackers to obtain potentially sensitive information from Open Directory via unspecified LDAP requests.
nvd
CVE-2022-32838P4MEDIUMCVSS 5.5v10.15.72022-08-24
CVE-2022-32838 [MEDIUM] CWE-285 CVE-2022-32838: A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12 A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6. An app may be able to read arbitrary files.
nvd
CVE-2015-1352P4MEDIUMCVSS 5.0≤ 10.10.52015-03-30
CVE-2015-1352 [MEDIUM] CVE-2015-1352: The build_tablename function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP through 5.6.7 The build_tablename function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP through 5.6.7 does not validate token extraction for table names, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted name.
nvd
CVE-2003-0378P4HIGHCVSS 7.5≤ 10.22003-06-16
CVE-2003-0378 [HIGH] CVE-2003-0378: The Kerberos login authentication feature in Mac OS X, when used with an LDAPv3 server and LDAP bind The Kerberos login authentication feature in Mac OS X, when used with an LDAPv3 server and LDAP bind authentication, may send cleartext passwords to the LDAP server when the AuthenticationAuthority attribute is not set.
nvd
CVE-2021-30738P4MEDIUMCVSS 5.5≥ 10.14.0, ≤ 10.14.5v10.14.62021-09-08
CVE-2021-30738 [MEDIUM] CVE-2021-30738: A malicious application may be able to overwrite arbitrary files. This issue is fixed in macOS Big S A malicious application may be able to overwrite arbitrary files. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-004 Mojave. An issue with path validation logic for hardlinks was addressed with improved path sanitization.
nvd
CVE-2005-1474P4HIGHCVSS 7.5v10.4v10.4.12005-06-13
CVE-2005-1474 [HIGH] CVE-2005-1474: Dashboard in Apple Mac OS X 10.4.1 allows remote attackers to install widgets via Safari without pro Dashboard in Apple Mac OS X 10.4.1 allows remote attackers to install widgets via Safari without prompting the user, a different vulnerability than CVE-2005-1933.
nvd
CVE-2019-8708P4MEDIUMCVSS 5.5fixed in 10.152020-10-27
CVE-2019-8708 [MEDIUM] CVE-2019-8708: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15. A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, macOS Catalina 10.15, iOS 13. A local user may be able to check for the existence of arbitrary files.
nvd
CVE-2021-1797P4MEDIUMCVSS 5.5fixed in 10.14.6≥ 10.15, < 10.15.7+2 more2021-04-02
CVE-2021-1797 [MEDIUM] CVE-2021-1797: The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.2, The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A local user may be able to read arbitrary files.
nvd