Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 112 of 157
CVE-2015-7076P4HIGHCVSS 7.2≤ 10.11.12015-12-11
CVE-2015-7076 [HIGH] CVE-2015-7076: The Intel Graphics Driver component in Apple OS X before 10.11.2 allows local users to gain privileg
The Intel Graphics Driver component in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors.
nvd
CVE-2015-3806P4HIGHCVSS 7.2≤ 10.10.42015-08-17
CVE-2015-3806 [HIGH] CWE-284 CVE-2015-3806: Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection
Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism by appending code to a crafted executable file.
nvd
CVE-2015-5945P4HIGHCVSS 7.2≤ 10.11.02015-10-23
CVE-2015-5945 [HIGH] CWE-20 CVE-2015-5945: The Sandbox subsystem in Apple OS X before 10.11.1 allows local users to gain privileges via vectors
The Sandbox subsystem in Apple OS X before 10.11.1 allows local users to gain privileges via vectors involving NVRAM parameters.
nvd
CVE-2010-0509P4HIGHCVSS 7.2≤ 10.6.2v10.5+11 more2010-03-30
CVE-2010-0509 [HIGH] CWE-264 CVE-2010-0509: SFLServer in OS Services in Apple Mac OS X before 10.6.3 allows local users to gain privileges via v
SFLServer in OS Services in Apple Mac OS X before 10.6.3 allows local users to gain privileges via vectors related to use of wheel group membership during access to the home directories of user accounts.
nvd
CVE-2008-3646P4MEDIUMCVSS 6.8v10.5.52008-10-10
CVE-2008-3646 [MEDIUM] CWE-362 CVE-2008-3646: The Postfix configuration file in Mac OS X 10.5.5 causes Postfix to be network-accessible when mail
The Postfix configuration file in Mac OS X 10.5.5 causes Postfix to be network-accessible when mail is sent from a local command-line tool, which allows remote attackers to send mail to local Mac OS X users.
nvd
CVE-2006-1473P4MEDIUMCVSS 5.0v10.3.9v10.4.72006-08-02
CVE-2006-1473 [MEDIUM] CVE-2006-1473: Integer overflow in AFP Server for Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause
Integer overflow in AFP Server for Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors.
nvd
CVE-2016-7627P4MEDIUMCVSS 6.5≤ 10.12.12017-02-20
CVE-2016-7627 [MEDIUM] CWE-476 CVE-2016-7627: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "CoreGraphics" component. It allows attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted font.
nvd
CVE-2012-0656P4MEDIUMCVSS 6.9v10.7.0v10.7.1+2 more2012-05-11
CVE-2012-0656 [MEDIUM] CWE-362 CVE-2012-0656: Race condition in LoginUIFramework in Apple Mac OS X 10.7.x before 10.7.4, when the Guest account is
Race condition in LoginUIFramework in Apple Mac OS X 10.7.x before 10.7.4, when the Guest account is enabled, allows physically proximate attackers to login to arbitrary accounts by entering the account name and no password.
nvd
CVE-2017-13907P4MEDIUMCVSS 6.8≥ 10.11, < 10.11.6≥ 10.12, ≤ 10.12.5+1 more2021-12-23
CVE-2017-13907 [MEDIUM] CVE-2017-13907: A state management issue was addressed with improved state validation. This issue is fixed in macOS
A state management issue was addressed with improved state validation. This issue is fixed in macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan. The screen lock may unexpectedly remain unlocked.
nvd
CVE-2015-7024P4MEDIUMCVSS 6.7≤ 10.11.02016-01-11
CVE-2015-7024 [MEDIUM] CVE-2015-7024: Untrusted search path vulnerability in Apple OS X before 10.11.1 allows local users to bypass intend
Untrusted search path vulnerability in Apple OS X before 10.11.1 allows local users to bypass intended Gatekeeper restrictions and gain privileges via a Trojan horse program that is loaded from an unexpected directory by an application that has a valid Apple digital signature.
nvd
CVE-2005-2522P4MEDIUMCVSS 5.1v10.4v10.4.1+1 more2005-08-19
CVE-2005-2522 [MEDIUM] CVE-2005-2522: Safari in WebKit in Mac OS X 10.4 to 10.4.2 directly accesses URLs within PDF files without the norm
Safari in WebKit in Mac OS X 10.4 to 10.4.2 directly accesses URLs within PDF files without the normal security checks, which allows remote attackers to execute arbitrary code via links in a PDF file.
nvd
CVE-2020-6616P4MEDIUMCVSS 6.5≥ 10.13.0, < 10.13.6≥ 10.14.0, < 10.14.6+3 more2020-05-08
CVE-2020-6616 [MEDIUM] CVE-2020-6616: Some Broadcom chips mishandle Bluetooth random-number generation because a low-entropy Pseudo Random
Some Broadcom chips mishandle Bluetooth random-number generation because a low-entropy Pseudo Random Number Generator (PRNG) is used in situations where a Hardware Random Number Generator (HRNG) should have been used to prevent spoofing. This affects, for example, Samsung Galaxy S8, S8+, and Note8 devices with the BCM4361 chipset. The Samsung ID is SVE-2020-1
nvd
CVE-2008-0059P4MEDIUMCVSS 5.8v10.4.112008-03-18
CVE-2008-0059 [MEDIUM] CWE-362 CVE-2008-0059: Race condition in NSXML in Foundation for Apple Mac OS X 10.4.11 allows context-dependent attackers
Race condition in NSXML in Foundation for Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via a crafted XML file, related to "error handling logic."
nvd
CVE-2021-30783P4MEDIUMCVSS 6.5≥ 10.14, ≤ 10.14.5≥ 10.15, ≤ 10.15.6+2 more2021-09-08
CVE-2021-30783 [MEDIUM] CVE-2021-30783: An access issue was addressed with improved access restrictions. This issue is fixed in macOS Big Su
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. A sandboxed process may be able to circumvent sandbox restrictions.
nvd
CVE-2017-2418P4MEDIUMCVSS 6.5≤ 10.12.32017-04-02
CVE-2017-2418 [MEDIUM] CWE-200 CVE-2017-2418: An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Hypervisor" component. It allows guest OS users to obtain sensitive information from the CR8 control register via unspecified vectors.
nvd
CVE-2010-0540P4MEDIUMCVSS 6.0v10.5.8v10.6.0+3 more2010-06-17
CVE-2010-0540 [MEDIUM] CWE-352 CVE-2010-0540: Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used o
Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for requests that change settings.
nvd
CVE-2003-0242P4HIGHCVSS 7.5fixed in 10.2.62003-06-09
CVE-2003-0242 [HIGH] CVE-2003-0242: IPSec in Mac OS X before 10.2.6 does not properly handle certain incoming security policies that mat
IPSec in Mac OS X before 10.2.6 does not properly handle certain incoming security policies that match by port, which could allow traffic that is not explicitly allowed by the policies.
nvd
CVE-2009-2474P4MEDIUMCVSS 5.8fixed in 10.6.52009-08-21
CVE-2009-2474 [MEDIUM] CVE-2009-2474: neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a d
neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
nvd
CVE-2022-0530P4MEDIUMCVSS 5.5≥ 10.15, < 10.15.7v10.15.72022-02-09
CVE-2022-0530 [MEDIUM] CVE-2022-0530: A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a loca
A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.
nvd
CVE-2018-4112P4MEDIUMCVSS 5.5fixed in 10.13.42018-04-03
CVE-2018-4112 [MEDIUM] CWE-59 CVE-2018-4112: An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "ATS" component. It allows attackers to obtain sensitive information by leveraging symlink mishandling.
nvd