Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 120 of 157
CVE-2018-4104P4MEDIUMCVSS 5.5fixed in 10.13.42018-04-03
CVE-2018-4104 [MEDIUM] CWE-200 CVE-2018-4104: An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4
An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvd
CVE-2021-30768P4MEDIUMCVSS 5.5≥ 10.15, ≤ 10.15.6v10.15.72021-09-08
CVE-2021-30768 [MEDIUM] CVE-2021-30768: A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur
A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-004 Catalina. A sandboxed process may be able to circumvent sandbox restrictions.
nvd
CVE-2020-9944P4MEDIUMCVSS 5.5fixed in 11.1≥ 10.14, < 10.14.6+3 more2020-12-08
CVE-2020-9944 [MEDIUM] CWE-125 CVE-2020-9944: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, tvOS 14.0, iOS 14.0 and iPadOS 14.0. An application may be able to read restricted memory.
nvd
CVE-2018-4413P4MEDIUMCVSS 5.5fixed in 10.14.12019-04-03
CVE-2018-4413 [MEDIUM] CWE-119 CVE-2018-4413: A memory initialization issue was addressed with improved memory handling. This issue affected versi
A memory initialization issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1, macOS Mojave 10.14.1, tvOS 12.1, watchOS 5.1.
nvd
CVE-2021-30791P4MEDIUMCVSS 5.5≥ 10.14.0, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-09-08
CVE-2021-30791 [MEDIUM] CWE-125 CVE-2021-30791: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 14.7,
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 14.7, macOS Big Sur 11.5. Processing a maliciously crafted file may disclose user information.
nvd
CVE-2021-30723P4MEDIUMCVSS 5.5≥ 10.14.0, ≤ 10.14.5≥ 10.15, ≤ 10.15.6+2 more2021-09-08
CVE-2021-30723 [MEDIUM] CVE-2021-30723: An information disclosure issue was addressed with improved state management. This issue is fixed in
An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted USD file may disclose memory contents.
nvd
CVE-2021-30746P4MEDIUMCVSS 5.5v10.14.0v10.14.1+13 more2021-09-08
CVE-2021-30746 [MEDIUM] CWE-125 CVE-2021-30746: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted USD file may disclose memory contents.
nvd
CVE-2014-4417P4MEDIUMCVSS 5.0≤ 10.9.52014-10-18
CVE-2014-4417 [MEDIUM] CWE-20 CVE-2014-4417: Safari in Apple OS X before 10.10 allows remote attackers to cause a denial of service (universal Pu
Safari in Apple OS X before 10.10 allows remote attackers to cause a denial of service (universal Push Notification outage) via a web site that triggers an uncaught SafariNotificationAgent exception by providing a crafted Push Notification.
nvd
CVE-2021-30691P4MEDIUMCVSS 5.5≥ 10.14, ≤ 10.14.5≥ 10.15, ≤ 10.15.6+2 more2021-09-08
CVE-2021-30691 [MEDIUM] CVE-2021-30691: An information disclosure issue was addressed with improved state management. This issue is fixed in
An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted USD file may disclose memory contents.
nvd
CVE-2021-30694P4MEDIUMCVSS 5.5≥ 10.14, ≤ 10.14.5≥ 10.15, ≤ 10.15.6+2 more2021-09-08
CVE-2021-30694 [MEDIUM] CVE-2021-30694: An information disclosure issue was addressed with improved state management. This issue is fixed in
An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted USD file may disclose memory contents.
nvd
CVE-2021-30692P4MEDIUMCVSS 5.5≥ 10.14, ≤ 10.14.5≥ 10.15, ≤ 10.15.6+2 more2021-09-08
CVE-2021-30692 [MEDIUM] CVE-2021-30692: An information disclosure issue was addressed with improved state management. This issue is fixed in
An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted USD file may disclose memory contents.
nvd
CVE-2018-4399P4MEDIUMCVSS 5.5fixed in 10.142019-04-03
CVE-2018-4399 [MEDIUM] CWE-20 CVE-2018-4399: An access issue existed with privileged API calls. This issue was addressed with additional restrict
An access issue existed with privileged API calls. This issue was addressed with additional restrictions. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
nvd
CVE-2019-8794P4MEDIUMCVSS 5.5fixed in 10.15.12019-12-18
CVE-2019-8794 [MEDIUM] CWE-20 CVE-2019-8794: A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.2 a
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to read restricted memory.
nvd
CVE-2020-10006P4MEDIUMCVSS 5.5fixed in 11.0.12020-12-08
CVE-2020-10006 [MEDIUM] CVE-2020-10006: This issue was addressed with improved entitlements. This issue is fixed in macOS Big Sur 11.0.1. A
This issue was addressed with improved entitlements. This issue is fixed in macOS Big Sur 11.0.1. A malicious application may be able to access restricted files.
nvd
CVE-2021-30709P4MEDIUMCVSS 5.5≥ 10.14, ≤ 10.14.5≥ 10.15, ≤ 10.15.6+2 more2021-09-08
CVE-2021-30709 [MEDIUM] CVE-2021-30709: This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.4, Security U
This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted USD file may disclose memory contents.
nvd
CVE-2022-26728P4MEDIUMCVSS 5.5≥ 10.15, < 10.15.7v10.15.72022-05-26
CVE-2022-26728 [MEDIUM] CVE-2022-26728: This issue was addressed with improved entitlements. This issue is fixed in Security Update 2022-004
This issue was addressed with improved entitlements. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. A malicious application may be able to access restricted files.
nvd
CVE-2021-30685P4MEDIUMCVSS 5.5≥ 10.15, ≤ 10.15.6v10.15.72021-09-08
CVE-2021-30685 [MEDIUM] CVE-2021-30685: This issue was addressed with improved checks. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS
This issue was addressed with improved checks. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. Parsing a maliciously crafted audio file may lead to disclosure of user information.
nvd
CVE-2020-9809P4MEDIUMCVSS 5.5fixed in 10.15.52020-06-09
CVE-2020-9809 [MEDIUM] CVE-2020-9809: An information disclosure issue was addressed with improved state management. This issue is fixed in
An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A malicious application may be able to determine kernel memory layout.
nvd
CVE-2019-8705P4MEDIUMCVSS 5.5fixed in 10.152019-12-18
CVE-2019-8705 [MEDIUM] CWE-787 CVE-2019-8705: A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Catal
A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15, tvOS 13. Processing a maliciously crafted movie may result in the disclosure of process memory.
nvd
CVE-2021-30850P4MEDIUMCVSS 5.5≥ 10.15, ≤ 10.15.6v10.15.72021-10-19
CVE-2021-30850 [MEDIUM] CVE-2021-30850: An access issue was addressed with improved access restrictions. This issue is fixed in Security Upd
An access issue was addressed with improved access restrictions. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6, tvOS 15. A user may gain access to protected parts of the file system.
nvd