Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 119 of 157
CVE-2017-7070P4MEDIUMCVSS 6.8fixed in 10.12.42018-04-03
CVE-2017-7070 [MEDIUM] CVE-2017-7070: An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Kernel" component. It allows physically proximate attackers to bypass the screen-locking protection mechanism that should have been in place upon closing the lid.
nvd
CVE-2016-7585P4MEDIUMCVSS 6.8≤ 10.12.32017-04-02
CVE-2016-7585 [MEDIUM] CWE-310 CVE-2016-7585: An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves mishandling of DMA in the "EFI" component. It allows physically proximate attackers to discover the FileVault 2 encryption password via a crafted Thunderbolt adapter.
nvd
CVE-2014-3565P4MEDIUMCVSS 5.0v10.11.02014-10-07
CVE-2014-3565 [MEDIUM] CWE-399 CVE-2014-3565: snmplib/mib.c in net-snmp 5.7.0 and earlier, when the -OQ option is used, allows remote attackers to
snmplib/mib.c in net-snmp 5.7.0 and earlier, when the -OQ option is used, allows remote attackers to cause a denial of service (snmptrapd crash) via a crafted SNMP trap message, which triggers a conversion to the variable type designated in the MIB file, as demonstrated by a NULL type in an ifMtu trap message.
nvd
CVE-2010-1802P4MEDIUMCVSS 6.4v10.5.8v10.6.42010-08-25
CVE-2010-1802 [MEDIUM] CWE-287 CVE-2010-1802: libsecurity in Apple Mac OS X 10.5.8 and 10.6.4 does not properly perform comparisons to domain-name
libsecurity in Apple Mac OS X 10.5.8 and 10.6.4 does not properly perform comparisons to domain-name strings in X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a certificate associated with a similar domain name, as demonstrated by use of a www.example.con certificate to spoof www.example.com.
nvd
CVE-2022-26755P4MEDIUMCVSS 6.3fixed in 10.15.7v10.15.72022-05-26
CVE-2022-26755 [MEDIUM] CVE-2022-26755: This issue was addressed with improved environment sanitization. This issue is fixed in Security Upd
This issue was addressed with improved environment sanitization. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. A malicious application may be able to break out of its sandbox.
nvd
CVE-2016-1833P4MEDIUMCVSS 5.5fixed in 10.11.52016-05-20
CVE-2016-1833 [MEDIUM] CWE-125 CVE-2016-1833: The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before
The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
nvd
CVE-2017-13819P4MEDIUMCVSS 6.1≤ 10.13.02017-11-13
CVE-2017-13819 [MEDIUM] CWE-79 CVE-2017-13819: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "HelpViewer" component. A cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML by bypassing the Same Origin Policy for quarantined HTML documents.
nvd
CVE-2008-3611P4MEDIUMCVSS 6.3v10.4.112008-09-16
CVE-2008-3611 [MEDIUM] CWE-287 CVE-2008-3611: Login Window in Apple Mac OS X 10.4.11 does not clear the current password when a user makes a passw
Login Window in Apple Mac OS X 10.4.11 does not clear the current password when a user makes a password-change attempt that is denied by policy, which allows opportunistic, physically proximate attackers to bypass authentication and change this user's password by later entering an acceptable new password on the same login screen.
nvd
CVE-2015-1546P4MEDIUMCVSS 5.0v10.10.22015-02-12
CVE-2015-1546 [MEDIUM] CVE-2015-1546: Double free vulnerability in the get_vrFilter function in servers/slapd/filter.c in OpenLDAP 2.4.40
Double free vulnerability in the get_vrFilter function in servers/slapd/filter.c in OpenLDAP 2.4.40 allows remote attackers to cause a denial of service (crash) via a crafted search query with a matched values control.
nvd
CVE-2016-7600P4MEDIUMCVSS 6.2≤ 10.12.12017-02-20
CVE-2016-7600 [MEDIUM] CWE-200 CVE-2016-7600: An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "OpenPAM" component, which allows local users to obtain sensitive information by leveraging mishandling of failed PAM authentication by a sandboxed app.
nvd
CVE-2010-1834P4MEDIUMCVSS 5.8v10.6.0v10.6.1+3 more2010-11-15
CVE-2010-1834 [MEDIUM] CWE-20 CVE-2010-1834: CFNetwork in Apple Mac OS X 10.6.x before 10.6.5 does not properly validate the domains of cookies,
CFNetwork in Apple Mac OS X 10.6.x before 10.6.5 does not properly validate the domains of cookies, which makes it easier for remote web servers to track users by setting a cookie that is associated with a partial IP address.
nvd
CVE-2018-4084P4MEDIUMCVSS 5.5fixed in 10.13.32018-04-03
CVE-2018-4084 [MEDIUM] CWE-200 CVE-2018-4084: An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue involves the "Wi-Fi" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvd
CVE-2020-11762P4MEDIUMCVSS 5.5fixed in 10.15.6≥ 10.13.0, < 10.13.6+3 more2020-04-14
CVE-2020-11762 [MEDIUM] CWE-125 CVE-2020-11762: An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read and write in DwaComp
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read and write in DwaCompressor::uncompress in ImfDwaCompressor.cpp when handling the UNKNOWN compression case.
nvd
CVE-2020-11764P4MEDIUMCVSS 5.5≥ 10.13.0, < 10.13.6≥ 10.14.0, < 10.14.6+3 more2020-04-14
CVE-2020-11764 [MEDIUM] CWE-787 CVE-2020-11764: An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuf
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuffer in ImfMisc.cpp.
nvd
CVE-2021-30913P4MEDIUMCVSS 5.5≥ 10.15, < 10.15.7v10.15.72021-08-24
CVE-2021-30913 [MEDIUM] CVE-2021-30913: The issue was addressed with improved permissions logic. This issue is fixed in macOS Monterey 12.0.
The issue was addressed with improved permissions logic. This issue is fixed in macOS Monterey 12.0.1, macOS Big Sur 11.6.1. An unprivileged application may be able to edit NVRAM variables.
nvd
CVE-2019-6231P4MEDIUMCVSS 5.5fixed in 10.14.32019-03-05
CVE-2019-6231 [MEDIUM] CWE-125 CVE-2019-6231: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to read restricted memory.
nvd
CVE-2019-8761P4MEDIUMCVSS 5.5fixed in 10.152020-10-27
CVE-2019-8761 [MEDIUM] CVE-2019-8761: This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.1, Securi
This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, macOS Catalina 10.15. Parsing a maliciously crafted text file may lead to disclosure of user information.
nvd
CVE-2020-27937P4MEDIUMCVSS 5.5fixed in 11.2.0fixed in 11.0.12021-04-02
CVE-2020-27937 [MEDIUM] CVE-2020-27937: A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, macOS Big Sur 11.0.1. A malicious application may be able to access private information.
nvd
CVE-2018-4251P4MEDIUMCVSS 5.5fixed in 10.13.52018-06-08
CVE-2018-4251 [MEDIUM] CWE-732 CVE-2018-4251: An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Firmware" component. It allows attackers to modify the EFI flash-memory region that a crafted app that has root access.
nvd
CVE-2021-1810P4MEDIUMCVSS 5.5≥ 10.15, ≤ 10.15.5v10.15.6+1 more2021-09-08
CVE-2021-1810 [MEDIUM] CVE-2021-1810: A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks.
nvd