cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 113 of 157
CVE-2001-1446P4HIGHCVSS 7.5v10.0v10.0.1+3 more2001-09-11
CVE-2001-1446 [HIGH] CVE-2001-1446: Find-By-Content in Mac OS X 10.0 through 10.0.4 creates world-readable index files named .FBCIndex i Find-By-Content in Mac OS X 10.0 through 10.0.4 creates world-readable index files named .FBCIndex in every directory, which allows remote attackers to learn the contents of files in web accessible directories.
nvd
CVE-2002-1372P4HIGHCVSS 7.5v10.2v10.2.22002-12-26
CVE-2002-1372 [HIGH] CWE-252 CVE-2002-1372: Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check the return values o Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check the return values of various file and socket operations, which could allow a remote attacker to cause a denial of service (resource exhaustion) by causing file descriptors to be assigned and not released, as demonstrated by fanta.
nvd
CVE-2019-8540P4MEDIUMCVSS 5.5fixed in 10.14.42019-12-18
CVE-2019-8540 [MEDIUM] CWE-665 CVE-2019-8540: A memory initialization issue was addressed with improved memory handling. This issue is fixed in iO A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to determine kernel memory layout.
nvd
CVE-2019-8656P4MEDIUMCVSS 5.5fixed in 10.14.62020-10-27
CVE-2019-8656 [MEDIUM] CVE-2019-8656: This was addressed with additional checks by Gatekeeper on files mounted through a network share. Th This was addressed with additional checks by Gatekeeper on files mounted through a network share. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra. Extracting a zip file containing a symbolic link to an endpoint in an NFS mount that is attacker controlled may bypass Gatekeeper.
nvd
CVE-2017-13804P4MEDIUMCVSS 5.5fixed in 10.13.12017-11-13
CVE-2017-13804 [MEDIUM] CWE-20 CVE-2017-13804: An issue was discovered in certain Apple products. iOS before 11.1 is affected. macOS before 10.13.1 An issue was discovered in certain Apple products. iOS before 11.1 is affected. macOS before 10.13.1 is affected. tvOS before 11.1 is affected. watchOS before 4.1 is affected. The issue involves the "StreamingZip" component. It allows remote attackers to write to unintended pathnames via a crafted ZIP archive.
nvd
CVE-2004-0167P4HIGHCVSS 7.5v10.2.8v10.3.22004-03-15
CVE-2004-0167 [HIGH] CVE-2004-0167: DiskArbitration in Mac OS X 10.2.8 and 10.3.2 does not properly initialize writeable removable media DiskArbitration in Mac OS X 10.2.8 and 10.3.2 does not properly initialize writeable removable media.
nvd
CVE-2021-30968P4MEDIUMCVSS 5.5≥ 10.15, < 10.15.7v10.15.72021-08-24
CVE-2021-30968 [MEDIUM] CWE-59 CVE-2021-30968: A validation issue related to hard link behavior was addressed with improved sandbox restrictions. T A validation issue related to hard link behavior was addressed with improved sandbox restrictions. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. A malicious application may be able to bypass certain Privacy preferences.
nvd
CVE-2003-0049P4HIGHCVSS 7.5v10.2v10.2.1+2 more2003-03-03
CVE-2003-0049 [HIGH] CVE-2003-0049: Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users b Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.
nvd
CVE-2015-5883P4MEDIUMCVSS 5.0≤ 10.10.52015-10-09
CVE-2015-5883 [MEDIUM] CWE-20 CVE-2015-5883: The bidirectional text-display and text-selection implementations in Terminal in Apple OS X before 1 The bidirectional text-display and text-selection implementations in Terminal in Apple OS X before 10.11 interpret directional override formatting characters differently, which allows remote attackers to spoof the content of a text document via a crafted character sequence.
nvd
CVE-2011-3225P4MEDIUMCVSS 5.0v10.7.0v10.7.12011-10-14
CVE-2011-3225 [MEDIUM] CWE-264 CVE-2011-3225: The SMB File Server component in Apple Mac OS X 10.7 before 10.7.2 does not prevent all guest users The SMB File Server component in Apple Mac OS X 10.7 before 10.7.2 does not prevent all guest users from accessing the share point record of a guest-restricted folder, which allows remote attackers to bypass intended browsing restrictions by leveraging access to the nobody account.
nvd
CVE-2005-0970P4HIGHCVSS 7.6v10.0v10.0.1+28 more2005-05-02
CVE-2005-0970 [HIGH] CWE-264 CVE-2005-0970: Mac OS X 10.3.9 and earlier allows users to install, create, and execute setuid/setgid scripts, cont Mac OS X 10.3.9 and earlier allows users to install, create, and execute setuid/setgid scripts, contrary to the intended design, which may allow attackers to conduct unauthorized activities with escalated privileges via vulnerable scripts.
nvd
CVE-2007-0734P4MEDIUMCVSS 5.4v10.3.9v10.4+9 more2007-04-10
CVE-2007-0734 [MEDIUM] CWE-119 CVE-2007-0734: fsck, as used by the AirPort Disk feature of the AirPort Extreme Base Station with 802.11n before Fi fsck, as used by the AirPort Disk feature of the AirPort Extreme Base Station with 802.11n before Firmware Update 7.1, and by Apple Mac OS X 10.3.9 through 10.4.9, does not properly enforce password protection of a USB hard drive, which allows context-dependent attackers to list arbitrary directories or execute arbitrary code, resulting from memory co
nvd
CVE-2015-1089P4MEDIUMCVSS 5.0≤ 10.10.22015-04-10
CVE-2015-1089 [MEDIUM] CWE-200 CVE-2015-1089: CFNetwork in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not properly handle cookies dur CFNetwork in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not properly handle cookies during processing of redirects in HTTP responses, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
nvd
CVE-2015-5839P4MEDIUMCVSS 5.0≤ 10.10.52015-09-18
CVE-2015-5839 [MEDIUM] CWE-254 CVE-2015-5839: dyld in Apple iOS before 9 allows attackers to bypass a code-signing protection mechanism via an app dyld in Apple iOS before 9 allows attackers to bypass a code-signing protection mechanism via an app that places a crafted signature in an executable file.
nvd
CVE-2019-8796P4MEDIUMCVSS 5.3fixed in 10.15.12020-10-27
CVE-2019-8796 [MEDIUM] CVE-2019-8796: A logic issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.1, A logic issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, iOS 12.4.3, watchOS 6.1, iOS 13.2 and iPadOS 13.2. AirDrop transfers may be unexpectedly accepted while in Everyone mode.
nvd
CVE-2017-7078P4MEDIUMCVSS 5.3≤ 10.12.62017-10-23
CVE-2017-7078 [MEDIUM] CWE-319 CVE-2017-7078: An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. The issue involves the "Mail Drafts" component. It allows remote attackers to obtain sensitive information by reading unintended cleartext transmissions.
nvd
CVE-2014-4428P4MEDIUMCVSS 5.4≤ 10.9.52014-10-18
CVE-2014-4428 [MEDIUM] CWE-310 CVE-2014-4428: Bluetooth in Apple OS X before 10.10 does not require encryption for HID Low Energy devices, which a Bluetooth in Apple OS X before 10.10 does not require encryption for HID Low Energy devices, which allows remote attackers to spoof a device by leveraging previous pairing.
nvd
CVE-2017-2390P4MEDIUMCVSS 5.5≤ 10.12.32017-04-02
CVE-2017-2390 [MEDIUM] CWE-59 CVE-2017-2390: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves symlink mishandling in the "libarchive" component. It allows local users to change arbitrary directory permissions via unspecified vectors.
nvd
CVE-2016-7619P4MEDIUMCVSS 5.5≤ 10.12.12017-02-20
CVE-2016-7619 [MEDIUM] CWE-59 CVE-2016-7619: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "libarchive" component, which allows local users to write to arbitrary files via vectors related to symlinks.
nvd
CVE-2015-1147P4MEDIUMCVSS 5.0fixed in 10.10.32015-04-10
CVE-2015-1147 [MEDIUM] CWE-200 CVE-2015-1147: Open Directory Client in Apple OS X before 10.10.3 sends unencrypted password-change requests in cer Open Directory Client in Apple OS X before 10.10.3 sends unencrypted password-change requests in certain circumstances involving missing certificates, which allows remote attackers to obtain sensitive information by sniffing the network.
nvd
Apple macOS vulnerabilities | cvebase