Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 114 of 157
CVE-2017-7143P4MEDIUMCVSS 5.5≤ 10.12.62017-10-23
CVE-2017-7143 [MEDIUM] CWE-319 CVE-2017-7143: An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involve
An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "Captive Network Assistant" component. It allows remote attackers to discover cleartext passwords in opportunistic circumstances by sniffing the network during use of the captive portal browser, which has a UI error that can lead to cleartext tran
nvd
CVE-2021-30929P4MEDIUMCVSS 5.5v10.15.72021-08-24
CVE-2021-30929 [MEDIUM] CWE-787 CVE-2021-30929: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in mac
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.1, iOS 15.2 and iPadOS 15.2, macOS Big Sur 11.6.2, Security Update 2021-008 Catalina. Processing a maliciously crafted USD file may disclose memory contents.
nvd
CVE-2012-3721P4MEDIUMCVSS 5.0≤ 10.7.4v10.0+69 more2012-09-20
CVE-2012-3721 [MEDIUM] CWE-287 CVE-2012-3721: Profile Manager in Apple Mac OS X before 10.7.5 does not properly perform authentication for the Dev
Profile Manager in Apple Mac OS X before 10.7.5 does not properly perform authentication for the Device Management private interface, which allows attackers to enumerate managed devices via unspecified vectors.
nvd
CVE-2015-7045P4MEDIUMCVSS 5.0≤ 10.11.12015-12-11
CVE-2015-7045 [MEDIUM] CWE-17 CVE-2015-7045: Keychain Access in Apple OS X before 10.11.2 and tvOS before 9.1 improperly interacts with Keychain
Keychain Access in Apple OS X before 10.11.2 and tvOS before 9.1 improperly interacts with Keychain Agent, which allows attackers to spoof the Keychain Server via unspecified vectors.
nvd
CVE-2005-3712P4MEDIUMCVSS 6.5v10.4v10.4.1+4 more2005-12-31
CVE-2005-3712 [MEDIUM] CWE-119 CVE-2005-3712: Heap-based buffer overflow in rsync in Mac OS X 10.4 through 10.4.5 allows remote authenticated user
Heap-based buffer overflow in rsync in Mac OS X 10.4 through 10.4.5 allows remote authenticated users to execute arbitrary code via long extended attributes.
nvd
CVE-2010-1844P4HIGHCVSS 7.1v10.6.0v10.6.1+3 more2010-11-16
CVE-2010-1844 [HIGH] CWE-20 CVE-2010-1844: Unspecified vulnerability in Image Capture in Apple Mac OS X 10.6.x before 10.6.5 allows remote atta
Unspecified vulnerability in Image Capture in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to cause a denial of service (memory consumption and system crash) via a crafted image.
nvd
CVE-2008-1573P4HIGHCVSS 7.1≤ 10.5.2v10.4.11+2 more2008-06-02
CVE-2008-1573 [HIGH] CWE-119 CVE-2008-1573: The BMP and GIF image decoding engine in ImageIO in Apple Mac OS X before 10.5.3 allows remote attac
The BMP and GIF image decoding engine in ImageIO in Apple Mac OS X before 10.5.3 allows remote attackers to obtain sensitive information (memory contents) via a crafted (1) BMP or (2) GIF image, which causes an out-of-bounds read.
nvd
CVE-2008-2310P4MEDIUMCVSS 6.8≤ 10.5.3v10.4.1+13 more2008-07-01
CVE-2008-2310 [MEDIUM] CWE-134 CVE-2008-2310: Format string vulnerability in c++filt in Apple Mac OS X 10.5 before 10.5.4 allows user-assisted att
Format string vulnerability in c++filt in Apple Mac OS X 10.5 before 10.5.4 allows user-assisted attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string in (1) C++ or (2) Java source code.
nvd
CVE-2011-2834P4MEDIUMCVSS 6.8fixed in 10.7.42011-09-19
CVE-2011-2834 [MEDIUM] CWE-415 CVE-2011-2834: Double free vulnerability in libxml2, as used in Google Chrome before 14.0.835.163, allows remote at
Double free vulnerability in libxml2, as used in Google Chrome before 14.0.835.163, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
nvd
CVE-2016-4682P4HIGHCVSS 7.1≤ 10.12.02017-02-20
CVE-2016-4682 [HIGH] CWE-125 CVE-2016-4682: An issue was discovered in certain Apple products. macOS before 10.12 is affected. macOS before 10.1
An issue was discovered in certain Apple products. macOS before 10.12 is affected. macOS before 10.12.1 is affected. The issue involves the "ImageIO" component. It allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted SGI file.
nvd
CVE-2007-0747P4HIGHCVSS 7.2v10.3.9v10.4+9 more2007-04-24
CVE-2007-0747 [HIGH] CVE-2007-0747: load_webdav in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when mou
load_webdav in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when mounting a WebDAV filesystem, which allows local users to gain privileges by setting unspecified environment variables.
nvd
CVE-2017-13831P4HIGHCVSS 7.1≤ 10.13.02017-11-13
CVE-2017-13831 [HIGH] CWE-200 CVE-2017-13831: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "ImageIO" component. It allows remote attackers to obtain sensitive information or cause a denial of service via a crafted image.
nvd
CVE-2017-13850P4HIGHCVSS 7.1fixed in 10.12.62018-04-03
CVE-2017-13850 [HIGH] CWE-119 CVE-2017-13850: An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Font Importer" component. It allows remote attackers to cause a denial of service (memory corruption) or obtain sensitive information from process memory via a crafted font.
nvd
CVE-2006-1443P4MEDIUMCVSS 6.5v10.3.9v10.4.62006-05-12
CVE-2006-1443 [MEDIUM] CVE-2006-1443: Integer underflow in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 allows context-dependent att
Integer underflow in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 allows context-dependent attackers to execute arbitrary code via unspecified vectors involving conversions from string to file system representation within (1) CFStringGetFileSystemRepresentation or (2) getFileSystemRepresentation:maxLength:withPath in NSFileManager, and possibly other si
nvd
CVE-2006-1448P4MEDIUMCVSS 6.5v10.3.9v10.4.62006-05-12
CVE-2006-1448 [MEDIUM] CVE-2006-1448: Finder in Apple Mac OS X 10.3.9 and 10.4.6 allows user-assisted attackers to execute arbitrary code
Finder in Apple Mac OS X 10.3.9 and 10.4.6 allows user-assisted attackers to execute arbitrary code by tricking a user into launching an Internet Location item that appears to use a safe URL scheme, but which actually has a different and more risky scheme.
nvd
CVE-2007-0744P4HIGHCVSS 7.2v10.3.9v10.4+9 more2007-04-24
CVE-2007-0744 [HIGH] CVE-2007-0744: SMB in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when executing c
SMB in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when executing commands, which allows local users to gain privileges by setting unspecified environment variables.
nvd
CVE-2009-0151P4HIGHCVSS 7.2v10.5.6v10.5+7 more2009-08-06
CVE-2009-0151 [HIGH] CVE-2009-0151: The screen saver in Dock in Apple Mac OS X 10.5 before 10.5.8 does not prevent four-finger Multi-Tou
The screen saver in Dock in Apple Mac OS X 10.5 before 10.5.8 does not prevent four-finger Multi-Touch gestures, which allows physically proximate attackers to bypass locking and "manage applications or use Expose" via unspecified vectors.
nvd
CVE-2015-5888P4HIGHCVSS 7.2≤ 10.10.52015-10-09
CVE-2015-5888 [HIGH] CWE-264 CVE-2015-5888: The Install Framework Legacy component in Apple OS X before 10.11 allows local users to obtain root
The Install Framework Legacy component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors involving a privileged executable file.
nvd
CVE-2008-4218P4HIGHCVSS 7.2≤ 10.5.5v10.5+4 more2008-12-17
CVE-2008-4218 [HIGH] CWE-189 CVE-2008-4218: Multiple integer overflows in the kernel in Apple Mac OS X before 10.5.6 on Intel platforms allow lo
Multiple integer overflows in the kernel in Apple Mac OS X before 10.5.6 on Intel platforms allow local users to gain privileges via a crafted call to (1) i386_set_ldt or (2) i386_get_ldt.
nvd
CVE-2008-1027P4MEDIUMCVSS 4.3v10.4.11v10.5+2 more2008-06-02
CVE-2008-1027 [MEDIUM] CWE-264 CVE-2008-1027: Apple Filing Protocol (AFP) Server in Apple Mac OS X before 10.5.3 does not verify that requested fi
Apple Filing Protocol (AFP) Server in Apple Mac OS X before 10.5.3 does not verify that requested files and directories are inside shared folders, which allows remote attackers to read arbitrary files via unspecified AFP traffic.
nvd