Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 121 of 157
CVE-2014-1361P4MEDIUMCVSS 5.0v10.9v10.9.1+2 more2014-07-01
CVE-2014-1361 [MEDIUM] CWE-200 CVE-2014-1361: Secure Transport in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 does
Secure Transport in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 does not ensure that a DTLS message is accepted only for a DTLS connection, which allows remote attackers to obtain potentially sensitive information from uninitialized process memory by providing a DTLS message within a TLS connection.
nvd
CVE-2021-30963P4MEDIUMCVSS 5.5≥ 10.15, ≤ 10.15.7v10.15.72021-08-24
CVE-2021-30963 [MEDIUM] CWE-120 CVE-2021-30963: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Security
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Security Update 2021-008 Catalina, macOS Big Sur 11.6.2. Parsing a maliciously crafted audio file may lead to disclosure of user information.
nvd
CVE-2021-30959P4MEDIUMCVSS 5.5≥ 10.15, ≤ 10.15.7v10.15.72021-08-24
CVE-2021-30959 [MEDIUM] CWE-120 CVE-2021-30959: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Security
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Security Update 2021-008 Catalina, macOS Big Sur 11.6.2. Parsing a maliciously crafted audio file may lead to disclosure of user information.
nvd
CVE-2021-30961P4MEDIUMCVSS 5.5≥ 10.15, ≤ 10.15.7v10.15.72021-08-24
CVE-2021-30961 [MEDIUM] CWE-120 CVE-2021-30961: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Security
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Security Update 2021-008 Catalina, macOS Big Sur 11.6.2. Parsing a maliciously crafted audio file may lead to disclosure of user information.
nvd
CVE-2020-3875P4MEDIUMCVSS 5.5fixed in 10.15.32020-02-27
CVE-2020-3875 [MEDIUM] CWE-125 CVE-2020-3875: A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.3.1
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to read restricted memory.
nvd
CVE-2020-27946P4MEDIUMCVSS 5.5≥ 10.14, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-04-02
CVE-2020-27946 [MEDIUM] CVE-2020-27946: An information disclosure issue was addressed with improved state management. This issue is fixed in
An information disclosure issue was addressed with improved state management. This issue is fixed in watchOS 7.2, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. Processing a maliciously crafted font may result in the disclosure of process memory.
nvd
CVE-2016-4771P4MEDIUMCVSS 5.5≤ 10.11.62016-09-25
CVE-2016-4771 [MEDIUM] CWE-200 CVE-2016-4771: The kernel in Apple iOS before 10 and OS X before 10.12 allows local users to bypass intended file-a
The kernel in Apple iOS before 10 and OS X before 10.12 allows local users to bypass intended file-access restrictions via a crafted directory pathname.
nvd
CVE-2018-4431P4MEDIUMCVSS 5.5fixed in 10.14.22019-04-03
CVE-2018-4431 [MEDIUM] CWE-200 CVE-2018-4431: A memory initialization issue was addressed with improved memory handling. This issue affected versi
A memory initialization issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2.
nvd
CVE-2020-9831P4MEDIUMCVSS 5.5fixed in 10.15.52020-06-09
CVE-2020-9831 [MEDIUM] CWE-125 CVE-2020-9831: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Cata
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.5. A malicious application may be able to determine kernel memory layout.
nvd
CVE-2020-9832P4MEDIUMCVSS 5.5fixed in 10.15.52020-06-09
CVE-2020-9832 [MEDIUM] CWE-125 CVE-2020-9832: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Cat
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.5. A malicious application may be able to determine kernel memory layout.
nvd
CVE-2020-3866P4MEDIUMCVSS 5.5fixed in 10.15.32020-02-27
CVE-2020-3866 [MEDIUM] CVE-2020-3866: This was addressed with additional checks by Gatekeeper on files mounted through a network share. Th
This was addressed with additional checks by Gatekeeper on files mounted through a network share. This issue is fixed in macOS Catalina 10.15.3. Searching for and opening a file from an attacker controlled NFS mount may bypass Gatekeeper.
nvd
CVE-2018-4235P4MEDIUMCVSS 5.5fixed in 10.13.52018-06-08
CVE-2018-4235 [MEDIUM] CWE-74 CVE-2018-4235: An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "Messages" component. It allows local users to perform impersonation attacks via an unspecified injection.
nvd
CVE-2018-4181P4MEDIUMCVSS 5.5fixed in 10.13.52019-01-11
CVE-2018-4181 [MEDIUM] CVE-2018-4181: In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improve
In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions.
nvd
CVE-2003-0871P4HIGHCVSS 7.5v10.32003-11-03
CVE-2003-0871 [HIGH] CVE-2003-0871: Unknown vulnerability in QuickTime Java in Mac OS X v10.3 and Mac OS X Server 10.3 allows attackers
Unknown vulnerability in QuickTime Java in Mac OS X v10.3 and Mac OS X Server 10.3 allows attackers to gain "unauthorized access to a system."
nvd
CVE-2022-22648P4MEDIUMCVSS 5.5≥ 10.15, < 10.15.7v10.15.72022-03-18
CVE-2022-22648 [MEDIUM] CVE-2022-22648: This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.5, macOS Mo
This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. An application may be able to read restricted memory.
nvd
CVE-2020-10007P4MEDIUMCVSS 5.5fixed in 11.0.1≥ 10.14, < 10.14.6+3 more2020-12-08
CVE-2020-10007 [MEDIUM] CVE-2020-10007: A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1. A malicious application may be able to determine kernel memory layout.
nvd
CVE-2021-1739P4MEDIUMCVSS 5.5≥ 10.14, ≤ 10.14.5≥ 10.15, ≤ 10.15.5+4 more2021-09-08
CVE-2021-1739 [MEDIUM] CWE-22 CVE-2021-1739: A parsing issue in the handling of directory paths was addressed with improved path validation. This
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A local user may be able to modify protected parts of the file system.
nvd
CVE-2015-5831P4MEDIUMCVSS 5.0≤ 10.10.52015-09-18
CVE-2015-5831 [MEDIUM] CWE-200 CVE-2015-5831: NetworkExtension in the kernel in Apple iOS before 9 does not properly initialize an unspecified dat
NetworkExtension in the kernel in Apple iOS before 9 does not properly initialize an unspecified data structure, which allows attackers to obtain sensitive memory-layout information via a crafted app.
nvd
CVE-2020-9775P4MEDIUMCVSS 5.3≥ 10.15, < 10.15.42020-04-01
CVE-2020-9775 [MEDIUM] CWE-665 CVE-2020-9775: An issue existed in the handling of tabs displaying picture in picture video. The issue was correcte
An issue existed in the handling of tabs displaying picture in picture video. The issue was corrected with improved state handling. This issue is fixed in iOS 13.4 and iPadOS 13.4. A user's private browsing activity may be unexpectedly saved in Screen Time.
nvd
CVE-2019-8568P4MEDIUMCVSS 5.5fixed in 10.14.52019-12-18
CVE-2019-8568 [MEDIUM] CWE-59 CVE-2019-8568: A validation issue existed in the handling of symlinks. This issue was addressed with improved valid
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A local user may be able to modify protected parts of the file system.
nvd