cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 111 of 157
CVE-2007-4697P4MEDIUMCVSS 6.8v10.4.1v10.4.2+8 more2007-11-15
CVE-2007-4697 [MEDIUM] CVE-2007-4697: Unspecified vulnerability in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers Unspecified vulnerability in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via unknown vectors related to browser history, which triggers memory corruption.
nvd
CVE-2014-1263P4MEDIUMCVSS 4.3≤ 10.9.1v10.92014-02-27
CVE-2014-1263 [MEDIUM] CWE-310 CVE-2014-1263: curl and libcurl 7.27.0 through 7.35.0, when using the SecureTransport/Darwinssl backend, as used in curl and libcurl 7.27.0 through 7.35.0, when using the SecureTransport/Darwinssl backend, as used in in Apple OS X 10.9.x before 10.9.2, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate when accessing a URL that uses a numerical IP address, which allows ma
nvd
CVE-2010-0056P4MEDIUMCVSS 6.8v10.5.82010-03-30
CVE-2010-0056 [MEDIUM] CWE-119 CVE-2010-0056: Buffer overflow in Cocoa spell checking in AppKit in Apple Mac OS X 10.5.8 allows user-assisted remo Buffer overflow in Cocoa spell checking in AppKit in Apple Mac OS X 10.5.8 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted document.
nvd
CVE-2014-4378P4MEDIUMCVSS 5.8≤ 10.9.42014-09-18
CVE-2014-4378 [MEDIUM] CWE-119 CVE-2014-4378: CoreGraphics in Apple iOS before 8 and Apple TV before 7 allows remote attackers to obtain sensitive CoreGraphics in Apple iOS before 8 and Apple TV before 7 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted PDF document.
nvd
CVE-2011-0186P4MEDIUMCVSS 4.3fixed in 10.6.72011-03-23
CVE-2011-0186 [MEDIUM] CWE-787 CVE-2011-0186: QuickTime in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code or cause QuickTime in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted JPEG2000 image.
nvd
CVE-2015-5900P4HIGHCVSS 7.1≤ 10.10.52015-10-09
CVE-2015-5900 [HIGH] CWE-254 CVE-2015-5900: The protected range register in the EFI component in Apple OS X before 10.11 has an incorrect value, The protected range register in the EFI component in Apple OS X before 10.11 has an incorrect value, which allows attackers to cause a denial of service (boot failure) via a crafted app that writes to an unintended address.
nvd
CVE-2017-2450P4HIGHCVSS 7.1≤ 10.12.32017-04-02
CVE-2017-2450 [HIGH] CWE-125 CVE-2017-2450: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "CoreText" component. It allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via
nvd
CVE-2010-1374P4MEDIUMCVSS 4.3v10.5.8v10.6.0+3 more2010-06-17
CVE-2010-1374 [MEDIUM] CWE-22 CVE-2010-1374: Directory traversal vulnerability in iChat in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, when AI Directory traversal vulnerability in iChat in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, when AIM is used, allows remote attackers to create arbitrary files via directory traversal sequences in an inline image-transfer operation.
nvd
CVE-2017-2439P4HIGHCVSS 7.1≤ 10.12.32017-04-02
CVE-2017-2439 [HIGH] CWE-125 CVE-2017-2439: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "FontParser" component. It allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) v
nvd
CVE-2009-2839P4MEDIUMCVSS 6.8v10.5.82009-11-10
CVE-2009-2839 [MEDIUM] CWE-399 CVE-2009-2839: Screen Sharing in Apple Mac OS X 10.5.8 allows remote VNC servers to execute arbitrary code or cause Screen Sharing in Apple Mac OS X 10.5.8 allows remote VNC servers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.
nvd
CVE-2007-0729P4HIGHCVSS 7.2v10.0v10.0.1+38 more2007-04-24
CVE-2007-0729 [HIGH] CWE-264 CVE-2007-0729: Apple File Protocol (AFP) Client in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the Apple File Protocol (AFP) Client in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment before executing commands, which allows local users to gain privileges by setting unspecified environment variables.
nvd
CVE-2013-5172P4HIGHCVSS 7.1≤ 10.8.5v10.8.0+5 more2013-10-24
CVE-2013-5172 [HIGH] CWE-189 CVE-2013-5172: The kernel in Apple Mac OS X before 10.9 does not properly determine the output length for SHA-2 dig The kernel in Apple Mac OS X before 10.9 does not properly determine the output length for SHA-2 digest function calls, which allows context-dependent attackers to cause a denial of service (panic) by triggering a digest operation, as demonstrated by an IPSec connection.
nvd
CVE-2017-13820P4HIGHCVSS 7.1≤ 10.13.02017-11-13
CVE-2017-13820 [HIGH] CWE-119 CVE-2017-13820: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "ATS" component. It allows remote attackers to obtain sensitive information from process memory or cause a denial of service (memory corruption) via a crafted font.
nvd
CVE-2007-4680P4MEDIUMCVSS 6.8v10.4.1v10.4.2+7 more2007-11-15
CVE-2007-4680 [MEDIUM] CWE-287 CVE-2007-4680: CFNetwork in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 does not properly validate certificates, CFNetwork in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 does not properly validate certificates, which allows remote attackers to spoof trusted SSL certificates via a man-in-the-middle attack.
nvd
CVE-2015-1137P4HIGHCVSS 7.2fixed in 10.10.32015-04-10
CVE-2015-1137 [HIGH] CVE-2015-1137: The NVIDIA graphics driver in Apple OS X before 10.10.3 allows local users to gain privileges or cau The NVIDIA graphics driver in Apple OS X before 10.10.3 allows local users to gain privileges or cause a denial of service (NULL pointer dereference) via an unspecified IOService userclient type.
nvd
CVE-2007-4269P4HIGHCVSS 7.2v10.4v10.4.1+9 more2007-11-15
CVE-2007-4269 [HIGH] CWE-189 CVE-2007-4269: Integer overflow in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows local use Integer overflow in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows local users to execute arbitrary code via a crafted AppleTalk Session Protocol (ASP) message on an AppleTalk socket, which triggers a heap-based buffer overflow.
nvd
CVE-2006-4887P4HIGHCVSS 7.2≤ 10.2.82006-09-19
CVE-2006-4887 [HIGH] CVE-2006-4887: Apple Remote Desktop (ARD) for Mac OS X 10.2.8 and later does not drop privileges on the remote mach Apple Remote Desktop (ARD) for Mac OS X 10.2.8 and later does not drop privileges on the remote machine while installing certain applications, which allows local users to bypass authentication and gain privileges by selecting the icon during installation. NOTE: it could be argued that the issue is not in Remote Desktop itself, but in applications that are insta
nvd
CVE-2015-7500P4MEDIUMCVSS 5.0≤ 10.11.32015-12-15
CVE-2015-7500 [MEDIUM] CWE-119 CVE-2015-7500: The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect entities boundaries and start tags.
nvd
CVE-2007-5860P4HIGHCVSS 7.2v10.5.12007-12-19
CVE-2007-5860 [HIGH] CVE-2007-5860: Unspecified vulnerability in Spin Tracer in Apple Mac OS X 10.5.1 allows local users to execute arbi Unspecified vulnerability in Spin Tracer in Apple Mac OS X 10.5.1 allows local users to execute arbitrary code via unspecified output files, involving an "insecure file operation."
nvd
CVE-2015-3803P4HIGHCVSS 7.2≤ 10.10.42015-08-17
CVE-2015-3803 [HIGH] CWE-20 CVE-2015-3803: Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism via a crafted multi-architecture executable file.
nvd
Apple macOS vulnerabilities | cvebase