Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 117 of 157
CVE-2019-8744P4MEDIUMCVSS 5.5fixed in 10.152020-10-27
CVE-2019-8744 [MEDIUM] CWE-787 CVE-2019-8744: A memory corruption issue existed in the handling of IPv6 packets. This issue was addressed with imp
A memory corruption issue existed in the handling of IPv6 packets. This issue was addressed with improved memory management. This issue is fixed in macOS Catalina 10.15, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, watchOS 6, iOS 13. A malicious application may be able to determine kernel memory layout.
nvd
CVE-2008-0046P4MEDIUMCVSS 5.0v10.5.22008-03-18
CVE-2008-0046 [MEDIUM] CWE-264 CVE-2008-0046: The Application Firewall in Apple Mac OS X 10.5.2 has an incorrect German translation for the "Set a
The Application Firewall in Apple Mac OS X 10.5.2 has an incorrect German translation for the "Set access for specific services and applications" radio button that might cause the user to believe that the button is used to restrict access only to specific services and applications, which might allow attackers to bypass intended access restrictions.
nvd
CVE-2021-30973P4MEDIUMCVSS 5.5≥ 10.15, ≤ 10.15.7v10.15.72021-08-24
CVE-2021-30973 [MEDIUM] CWE-125 CVE-2021-30973: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Mon
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Monterey 12.1, iOS 15.2 and iPadOS 15.2, macOS Big Sur 11.6.2, Security Update 2021-008 Catalina. Processing a maliciously crafted file may disclose user information.
nvd
CVE-2021-30911P4MEDIUMCVSS 5.5fixed in 10.15.7v10.15.72021-08-24
CVE-2021-30911 [MEDIUM] CWE-125 CVE-2021-30911: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Mont
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.0.1, Security Update 2021-007 Catalina, iOS 15.1 and iPadOS 15.1, macOS Big Sur 11.6.1. Processing a maliciously crafted USD file may disclose memory contents.
nvd
CVE-2021-1846P4MEDIUMCVSS 5.5v10.15v10.15.1+6 more2021-09-08
CVE-2021-1846 [MEDIUM] CWE-125 CVE-2021-1846: Processing a maliciously crafted audio file may disclose restricted memory. This issue is fixed in S
Processing a maliciously crafted audio file may disclose restricted memory. This issue is fixed in Security Update 2021-002 Catalina, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. An out-of-bounds read was addressed with improved input validation.
nvd
CVE-2021-30686P4MEDIUMCVSS 5.5≥ 10.15, ≤ 10.15.6v10.15.72021-09-08
CVE-2021-30686 [MEDIUM] CWE-125 CVE-2021-30686: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in tvOS 14.6,
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. Processing a maliciously crafted audio file may disclose restricted memory.
nvd
CVE-2003-0049P4HIGHCVSS 7.5v10.2v10.2.1+2 more2003-03-03
CVE-2003-0049 [HIGH] CVE-2003-0049: Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users b
Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.
nvd
CVE-2020-29610P4MEDIUMCVSS 5.5≥ 10.14, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-04-02
CVE-2020-29610 [MEDIUM] CWE-125 CVE-2020-29610: An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 7
An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 7.2, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. Processing a maliciously crafted audio file may disclose restricted memory.
nvd
CVE-2019-8850P4MEDIUMCVSS 5.5fixed in 10.15.12020-10-27
CVE-2019-8850 [MEDIUM] CWE-125 CVE-2019-8850: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Cat
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15, iOS 13.1 and iPadOS 13.1, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, watchOS 6. Processing a maliciously crafted audio file may disclose restricted memory.
nvd
CVE-2019-6207P4MEDIUMCVSS 5.5fixed in 10.14.42019-12-18
CVE-2019-6207 [MEDIUM] CWE-125 CVE-2019-6207: An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to determine kernel memory layout.
nvd
CVE-2022-26746P4MEDIUMCVSS 5.5fixed in 10.15.7v10.15.72022-05-26
CVE-2022-26746 [MEDIUM] CVE-2022-26746: This issue was addressed by removing the vulnerable code. This issue is fixed in Security Update 202
This issue was addressed by removing the vulnerable code. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. A malicious application may be able to bypass Privacy preferences.
nvd
CVE-2020-3896P4MEDIUMCVSS 5.5≥ 10.13, < 10.13.6≥ 10.14, < 10.14.6+3 more2021-12-23
CVE-2020-3896 [MEDIUM] CVE-2020-3896: This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Catalina 10.1
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Catalina 10.15.4, Security Update 2020-002 Mojave, Security Update 2020-002 High Sierra. A malicious application may be able to overwrite arbitrary files.
nvd
CVE-2006-0398P4HIGHCVSS 7.5v10.4v10.4.1+4 more2006-03-14
CVE-2006-0398 [HIGH] CVE-2006-0398: Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 1
Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into opening an application that appears to be a safe file type. NOTE: due to the lack of specific information in the vendor advisory, it is not clear how CVE-2006-0397, CVE-2006-0398, and CVE-2006-0399 are different.
nvd
CVE-2006-0399P4HIGHCVSS 7.5v10.4v10.4.1+4 more2006-03-14
CVE-2006-0399 [HIGH] CVE-2006-0399: Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 1
Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into opening an application that appears to be a safe file type. NOTE: due to the lack of specific information in the vendor advisory, it is not clear how CVE-2006-0397, CVE-2006-0398, and CVE-2006-0399 are different.
nvd
CVE-2006-0397P4HIGHCVSS 7.5v10.4v10.4.1+4 more2006-03-14
CVE-2006-0397 [HIGH] CWE-94 CVE-2006-0397: Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 1
Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into opening an application that appears to be a safe file type. NOTE: due to the lack of specific information in the vendor advisory, it is not clear how CVE-2006-0397, CVE-2006-0398, and CVE-2006-0399 are different.
nvd
CVE-2018-4224P4MEDIUMCVSS 5.5fixed in 10.13.52018-06-08
CVE-2018-4224 [MEDIUM] CWE-200 CVE-2018-4224: An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "Security" component. It allows local users to bypass intended re
nvd
CVE-2007-4682P4MEDIUMCVSS 6.8≥ 10.4, ≤ 10.4.102007-11-15
CVE-2007-4682 [MEDIUM] CWE-824 CVE-2007-4682: CoreText in Apple Mac OS X 10.4 through 10.4.10 allows attackers to cause a denial of service (appli
CoreText in Apple Mac OS X 10.4 through 10.4.10 allows attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted text content that triggers an access of an uninitialized object pointer.
nvd
CVE-2014-4491P4MEDIUMCVSS 5.0≤ 10.10.12015-01-30
CVE-2014-4491 [MEDIUM] CWE-200 CVE-2014-4491: The extension APIs in the kernel in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV
The extension APIs in the kernel in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 do not prevent the presence of addresses within an OSBundleMachOHeaders key in a response, which makes it easier for attackers to bypass the ASLR protection mechanism via a crafted app.
nvd
CVE-2018-4223P4MEDIUMCVSS 5.5fixed in 10.13.52018-06-08
CVE-2018-4223 [MEDIUM] CWE-200 CVE-2018-4223: An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "Security" component. It allows local users to bypass intended restrictions on the reading of a persistent account identifier.
nvd
CVE-2019-8510P4MEDIUMCVSS 5.5fixed in 10.14.42019-12-18
CVE-2019-8510 [MEDIUM] CWE-125 CVE-2019-8510: An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to determine kernel memory layout.
nvd