cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 115 of 157
CVE-2009-0011P4HIGHCVSS 7.2v10.5.62009-02-13
CVE-2009-0011 [HIGH] CWE-264 CVE-2009-0011: Certificate Assistant in Apple Mac OS X 10.5.6 allows local users to overwrite arbitrary files via u Certificate Assistant in Apple Mac OS X 10.5.6 allows local users to overwrite arbitrary files via unknown vectors related to an "insecure file operation" on a temporary file.
nvd
CVE-2015-3764P4MEDIUMCVSS 4.3≤ 10.10.42015-08-16
CVE-2015-3764 [MEDIUM] CWE-200 CVE-2015-3764: Notification Center in Apple OS X before 10.10.5 does not properly remove dismissed notifications, w Notification Center in Apple OS X before 10.10.5 does not properly remove dismissed notifications, which allows attackers to read arbitrary notifications via a crafted app.
nvd
CVE-2014-4426P4MEDIUMCVSS 4.3≤ 10.9.52014-10-18
CVE-2014-4426 [MEDIUM] CWE-200 CVE-2014-4426: AFP File Server in Apple OS X before 10.10 allows remote attackers to discover the network addresses AFP File Server in Apple OS X before 10.10 allows remote attackers to discover the network addresses of all interfaces via an unspecified command to one interface.
nvd
CVE-2016-4639P4HIGHCVSS 7.0≤ 10.11.52016-07-22
CVE-2016-4639 [HIGH] CVE-2016-4639: Login Window in Apple OS X before 10.11.6 does not properly initialize memory, which allows local us Login Window in Apple OS X before 10.11.6 does not properly initialize memory, which allows local users to cause a denial of service via unspecified vectors.
nvd
CVE-2011-1783P4MEDIUMCVSS 4.3fixed in 10.7.32011-06-06
CVE-2011-1783 [MEDIUM] CVE-2011-1783: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6 The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is enabled, allows remote attackers to cause a denial of service (infinite loop and memory consumption) in opportunistic circumstances by requesting data.
nvd
CVE-2015-3716P4MEDIUMCVSS 4.4≤ 10.10.32015-07-03
CVE-2015-3716 [MEDIUM] CWE-77 CVE-2015-3716: Spotlight in Apple OS X before 10.10.4 allows attackers to execute arbitrary commands via a crafted Spotlight in Apple OS X before 10.10.4 allows attackers to execute arbitrary commands via a crafted name of a photo file within the local photo library.
nvd
CVE-2009-2196P4MEDIUMCVSS 5.0v10.4.v10.5.7+1 more2009-08-12
CVE-2009-2196 [MEDIUM] CVE-2009-2196: Unspecified vulnerability in Apple Safari 4 before 4.0.3 allows remote web servers to place an arbit Unspecified vulnerability in Apple Safari 4 before 4.0.3 allows remote web servers to place an arbitrary web site in the Top Sites view, and possibly conduct phishing attacks, via unknown vectors.
nvd
CVE-2020-9810P4MEDIUMCVSS 6.8≥ 10.15.4, < 10.15.52020-10-22
CVE-2020-9810 [MEDIUM] CVE-2020-9810: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15. A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.5. A person with physical access to a Mac may be able to bypass Login Window.
nvd
CVE-2004-0112P4MEDIUMCVSS 5.0v10.3.32004-11-23
CVE-2004-0112 [MEDIUM] CWE-125 CVE-2004-0112: The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.
nvd
CVE-2020-10014P4MEDIUMCVSS 6.3≥ 10.14, < 10.14.6≥ 10.15, < 10.15.7+2 more2020-12-08
CVE-2020-10014 [MEDIUM] CWE-22 CVE-2020-10014: A parsing issue in the handling of directory paths was addressed with improved path validation. This A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Big Sur 11.0.1. A malicious application may be able to break out of its sandbox.
nvd
CVE-2015-7995P4MEDIUMCVSS 5.0≤ 10.11.22015-11-17
CVE-2015-7995 [MEDIUM] CVE-2015-7995: The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to a "type confusion" issue.
nvd
CVE-2019-8855P4MEDIUMCVSS 6.3fixed in 10.152020-10-27
CVE-2019-8855 [MEDIUM] CVE-2019-8855: An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Cat An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Catalina 10.15. A malicious application may be able to access restricted files.
nvd
CVE-2016-7636P4MEDIUMCVSS 5.9≤ 10.12.12017-02-20
CVE-2016-7636 [MEDIUM] CWE-20 CVE-2016-7636: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Security" component, which allows man-in-the-middle attackers to cause a denial of service (application crash) via vectors related to OCSP responder URLs.
nvd
CVE-2020-9939P4MEDIUMCVSS 6.4fixed in 10.15.62020-10-22
CVE-2020-9939 [MEDIUM] CWE-367 CVE-2020-9939: This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.6. A loca This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.6. A local user may be able to load unsigned kernel extensions.
nvd
CVE-2014-3707P4MEDIUMCVSS 4.3v10.10.0v10.10.1+3 more2014-11-15
CVE-2014-3707 [MEDIUM] CWE-200 CVE-2014-3707: The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COP The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out-of-bounds read that allows remote web servers to read sensitive memory information.
nvd
CVE-2014-8151P4MEDIUMCVSS 5.8≤ 10.10.42015-01-15
CVE-2014-8151 [MEDIUM] CVE-2014-8151: The darwinssl_connect_step1 function in lib/vtls/curl_darwinssl.c in libcurl 7.31.0 through 7.39.0, The darwinssl_connect_step1 function in lib/vtls/curl_darwinssl.c in libcurl 7.31.0 through 7.39.0, when using the DarwinSSL (aka SecureTransport) back-end for TLS, does not check if a cached TLS session validated the certificate when reusing the session, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.
nvd
CVE-2020-11759P4MEDIUMCVSS 5.5≥ 10.13.0, < 10.13.6≥ 10.14.0, < 10.14.6+3 more2020-04-14
CVE-2020-11759 [MEDIUM] CWE-190 CVE-2020-11759: An issue was discovered in OpenEXR before 2.4.1. Because of integer overflows in CompositeDeepScanLi An issue was discovered in OpenEXR before 2.4.1. Because of integer overflows in CompositeDeepScanLine::Data::handleDeepFrameBuffer and readSampleCountForLineBlock, an attacker can write to an out-of-bounds pointer.
nvd
CVE-2004-0485P4MEDIUMCVSS 5.0v10.2.8v10.3.32004-07-07
CVE-2004-0485 [MEDIUM] CVE-2004-0485: The default protocol helper for the disk: URI on Mac OS X 10.3.3 and 10.2.8 allows remote attackers The default protocol helper for the disk: URI on Mac OS X 10.3.3 and 10.2.8 allows remote attackers to write arbitrary files by causing a disk image file (.dmg) to be mounted as a disk volume.
nvd
CVE-2020-27896P4MEDIUMCVSS 5.5≥ 10.14.0, < 10.14.6≥ 10.15.0, < 10.15.7+2 more2020-12-08
CVE-2020-27896 [MEDIUM] CWE-22 CVE-2020-27896: A path handling issue was addressed with improved validation. This issue is fixed in macOS Big Sur 1 A path handling issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.0.1. A remote attacker may be able to modify the file system.
nvd
CVE-2019-8582P4MEDIUMCVSS 5.5fixed in 10.14.52020-10-27
CVE-2019-8582 [MEDIUM] CWE-125 CVE-2019-8582: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iCloud for An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iCloud for Windows 7.12, tvOS 12.3, iTunes 12.9.5 for Windows, macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, iOS 12.3. Processing a maliciously crafted font may result in the disclosure of process memory.
nvd
Apple macOS vulnerabilities | cvebase