cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 12 of 157
CVE-2004-0486P3HIGHCVSS 7.6PoCv10.3v10.3.1+2 more2004-07-07
CVE-2004-0486 [HIGH] CVE-2004-0486: HelpViewer in Mac OS X 10.3.3 and 10.2.8 processes scripts that it did not initiate, which can allow HelpViewer in Mac OS X 10.3.3 and 10.2.8 processes scripts that it did not initiate, which can allow attackers to execute arbitrary code, an issue that was originally reported as a directory traversal vulnerability in the Safari web browser using the runscript parameter in a help: URI handler.
nvd
CVE-2019-8591P3HIGHCVSS 7.1PoCfixed in 10.14.52019-12-18
CVE-2019-8591 [HIGH] CWE-843 CVE-2019-8591: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.3, A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. An application may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2014-8826P3MEDIUMCVSS 5.0PoC≤ 10.10.12015-01-30
CVE-2014-8826 [MEDIUM] CWE-19 CVE-2014-8826: LaunchServices in Apple OS X before 10.10.2 does not properly handle file-type metadata, which allow LaunchServices in Apple OS X before 10.10.2 does not properly handle file-type metadata, which allows attackers to bypass the Gatekeeper protection mechanism via a crafted JAR archive.
nvd
CVE-2020-9839P3HIGHCVSS 7.0PoCfixed in 10.15.52020-06-09
CVE-2020-9839 [HIGH] CWE-362 CVE-2020-9839: A race condition was addressed with improved state handling. This issue is fixed in iOS 13.5 and iPa A race condition was addressed with improved state handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. An application may be able to gain elevated privileges.
nvd
CVE-2010-0519P3MEDIUMCVSS 6.8PoCv10.6.0v10.6.1+1 more2010-03-30
CVE-2010-0519 [MEDIUM] CWE-189 CVE-2010-0519: Integer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arb Integer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a FlashPix image with a malformed SubImage Header Stream containing a NumberOfTiles field with a large value.
nvd
CVE-2016-0778P3HIGHCVSS 8.1≥ 10.9.0, ≤ 10.9.5≥ 10.10.0, ≤ 10.10.5+1 more2016-01-14
CVE-2016-0778 [HIGH] CWE-119 CVE-2016-0778: The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5. The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection file descriptors, which allows remote servers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified othe
nvd
CVE-2015-7036P3HIGHCVSS 7.5≤ 10.10.32015-11-22
CVE-2015-7036 [HIGH] CWE-20 CVE-2015-7036: The fts3_tokenizer function in SQLite, as used in Apple iOS before 8.4 and OS X before 10.10.4, allo The fts3_tokenizer function in SQLite, as used in Apple iOS before 8.4 and OS X before 10.10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a SQL command that triggers an API call with a crafted pointer value in the second argument.
nvd
CVE-2015-6908P3MEDIUMCVSS 5.0PoC≤ 10.11.12015-09-11
CVE-2015-6908 [MEDIUM] CWE-20 CVE-2015-6908: The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote att The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd.
nvd
CVE-2015-3760P3HIGHCVSS 7.2PoC≤ 10.10.42015-08-16
CVE-2015-3760 [HIGH] CWE-20 CVE-2015-3760: dyld in Apple OS X before 10.10.5 does not properly validate pathnames in the environment, which all dyld in Apple OS X before 10.10.5 does not properly validate pathnames in the environment, which allows local users to gain privileges via unspecified vectors.
nvd
CVE-2016-4072P3CRITICALCVSS 9.8≤ 10.11.42016-05-20
CVE-2016-4072 [CRITICAL] CWE-20 CVE-2016-4072: The Phar extension in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote att The Phar extension in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to execute arbitrary code via a crafted filename, as demonstrated by mishandling of \0 characters by the phar_analyze_path function in ext/phar/phar.c.
nvd
CVE-2011-0419P3MEDIUMCVSS 4.3PoCv10.6.02011-05-16
CVE-2011-0419 [MEDIUM] CWE-770 CVE-2011-0419: Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portabl Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent attackers to cause a denial of ser
nvd
CVE-2015-5889P3HIGHCVSS 7.2PoC≤ 10.10.52015-10-09
CVE-2015-5889 [HIGH] CWE-264 CVE-2015-5889: rsh in the remote_cmds component in Apple OS X before 10.11 allows local users to obtain root privil rsh in the remote_cmds component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors involving environment variables.
nvd
CVE-2022-32839P3CRITICALCVSS 9.8v10.15.72022-08-24
CVE-2022-32839 [CRITICAL] CWE-119 CVE-2022-32839: The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.5, mac The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6, tvOS 15.6, watchOS 8.7. A remote user may cause an unexpected app termination or arbitrary code execution.
nvd
CVE-2007-4675P3CRITICALCVSS 9.3v10.3.9v10.4.10+1 more2007-11-07
CVE-2007-4675 [CRITICAL] CWE-119 CVE-2007-4675: Heap-based buffer overflow in the QuickTime VR extension 7.2.0.240 in QuickTime.qts in Apple QuickTi Heap-based buffer overflow in the QuickTime VR extension 7.2.0.240 in QuickTime.qts in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via a QTVR (QuickTime Virtual Reality) movie file containing a large size field in the atom header of a panorama sample atom.
nvd
CVE-2015-4147P3HIGHCVSS 7.5≤ 10.10.42015-06-09
CVE-2015-4147 [HIGH] CWE-19 CVE-2015-4147: The SoapClient::__call method in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6. The SoapClient::__call method in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that __default_headers is an array, which allows remote attackers to execute arbitrary code by providing crafted serialized data with an unexpected data type, related to a "type confusion" issue.
nvd
CVE-2013-5704P3MEDIUMCVSS 5.0fixed in 10.10.42014-04-15
CVE-2013-5704 [MEDIUM] CVE-2013-5704: The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHe The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such."
nvd
CVE-2011-0182P3HIGHCVSS 7.2PoC≤ 10.6.6v10.6.0+5 more2011-03-23
CVE-2011-0182 [HIGH] CWE-20 CVE-2011-0182: The i386_set_ldt system call in the kernel in Apple Mac OS X before 10.6.7 does not properly handle The i386_set_ldt system call in the kernel in Apple Mac OS X before 10.6.7 does not properly handle call gates, which allows local users to gain privileges via vectors involving the creation of a call gate entry.
nvd
CVE-2015-6988P3CRITICALCVSS 10.0≤ 10.11.02015-10-23
CVE-2015-6988 [CRITICAL] CVE-2015-6988: The kernel in Apple iOS before 9.1 and OS X before 10.11.1 does not initialize an unspecified data s The kernel in Apple iOS before 9.1 and OS X before 10.11.1 does not initialize an unspecified data structure, which allows remote attackers to execute arbitrary code via vectors involving an unknown network-connectivity requirement.
nvd
CVE-2015-7084P3HIGHCVSS 7.2PoC≤ 10.11.12015-12-11
CVE-2015-7084 [HIGH] CVE-2015-7084: The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 all The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-7083.
nvd
CVE-2018-20506P3HIGHCVSS 8.1fixed in 10.14.32019-04-03
CVE-2018-20506 [HIGH] CVE-2018-20506: SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and result SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use ca
nvd
Apple macOS vulnerabilities | cvebase