Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
277
Exploited in wild
28
Severity breakdown
CRITICAL302HIGH1409MEDIUM1236LOW192

Vulnerabilities

Page 122 of 157
CVE-2010-3791MEDIUMCVSS 6.8v10.6.0v10.6.1+3 more2010-11-16
CVE-2010-3791 [MEDIUM] CWE-119 CVE-2010-3791: Buffer overflow in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execu Buffer overflow in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG movie file.
nvd
CVE-2010-3790MEDIUMCVSS 6.8v10.6.0v10.6.1+3 more2010-11-16
CVE-2010-3790 [MEDIUM] CWE-119 CVE-2010-3790: QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code o QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file that causes an image sample transformation to scale a sprite outside a buffer boundary.
nvd
CVE-2010-1845MEDIUMCVSS 6.8v10.5.8v10.6.0+4 more2010-11-16
CVE-2010-1845 [MEDIUM] CWE-20 CVE-2010-1845: ImageIO in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitra ImageIO in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted PSD image.
nvd
CVE-2010-3785MEDIUMCVSS 6.8v10.5.8v10.6.0+4 more2010-11-16
CVE-2010-3785 [MEDIUM] CWE-119 CVE-2010-3785: Buffer overflow in QuickLook in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attacke Buffer overflow in QuickLook in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Office document.
nvd
CVE-2010-3795MEDIUMCVSS 6.8v10.6.0v10.6.1+3 more2010-11-16
CVE-2010-3795 [MEDIUM] CWE-119 CVE-2010-3795: QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during proc QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during processing of GIF image data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted GIF file.
nvd
CVE-2010-3787MEDIUMCVSS 6.8v10.6.0v10.6.1+3 more2010-11-16
CVE-2010-3787 [MEDIUM] CWE-119 CVE-2010-3787: Heap-based buffer overflow in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attacke Heap-based buffer overflow in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JP2 image.
nvd
CVE-2010-4010MEDIUMCVSS 6.8v10.5.82010-11-16
CVE-2010-4010 [MEDIUM] CWE-189 CVE-2010-4010: Integer signedness error in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 allows remote attacke Integer signedness error in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary code via a crafted embedded Compact Font Format (CFF) font in a document.
nvd
CVE-2010-3798MEDIUMCVSS 6.8v10.6.0v10.6.1+3 more2010-11-16
CVE-2010-3798 [MEDIUM] CWE-119 CVE-2010-3798: Heap-based buffer overflow in xar in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to Heap-based buffer overflow in xar in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted xar archive.
nvd
CVE-2010-3789MEDIUMCVSS 6.8v10.6.0v10.6.1+3 more2010-11-16
CVE-2010-3789 [MEDIUM] CWE-119 CVE-2010-3789: QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code o QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted AVI file.
nvd
CVE-2010-1847MEDIUMCVSS 4.9v10.6.0v10.6.1+3 more2010-11-16
CVE-2010-1847 [MEDIUM] CWE-399 CVE-2010-1847: The kernel in Apple Mac OS X 10.6.x before 10.6.5 does not properly perform memory management associ The kernel in Apple Mac OS X 10.6.x before 10.6.5 does not properly perform memory management associated with terminal devices, which allows local users to cause a denial of service (system crash) via unspecified vectors.
nvd
CVE-2010-3794MEDIUMCVSS 6.8v10.6.0v10.6.1+3 more2010-11-16
CVE-2010-3794 [MEDIUM] CWE-119 CVE-2010-3794: QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during proc QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during processing of FlashPix image data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FlashPix file.
nvd
CVE-2010-1841CRITICALCVSS 9.3v10.5.8v10.6.0+4 more2010-11-15
CVE-2010-1841 [CRITICAL] CWE-20 CVE-2010-1841: Disk Images in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arb Disk Images in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted UDIF image.
nvd
CVE-2010-1378CRITICALCVSS 9.8≥ 10.6.0, < 10.6.52010-11-15
CVE-2010-1378 [CRITICAL] CWE-295 CVE-2010-1378: OpenSSL in Apple Mac OS X 10.6.x before 10.6.5 does not properly perform arithmetic, which allows re OpenSSL in Apple Mac OS X 10.6.x before 10.6.5 does not properly perform arithmetic, which allows remote attackers to bypass X.509 certificate authentication via an arbitrary certificate issued by a legitimate Certification Authority.
nvd
CVE-2010-1842CRITICALCVSS 9.3v10.6.0v10.6.1+3 more2010-11-15
CVE-2010-1842 [CRITICAL] CWE-119 CVE-2010-1842: Buffer overflow in AppKit in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute Buffer overflow in AppKit in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a bidirectional text string with ellipsis truncation.
nvd
CVE-2010-1840HIGHCVSS 7.5PoCv10.5.8v10.6.0+4 more2010-11-15
CVE-2010-1840 [HIGH] CWE-119 CVE-2010-1840: Stack-based buffer overflow in the password-validation functionality in Directory Services in Apple Stack-based buffer overflow in the password-validation functionality in Directory Services in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2010-1836MEDIUMCVSS 6.8v10.5.8v10.6.0+4 more2010-11-15
CVE-2010-1836 [MEDIUM] CWE-119 CVE-2010-1836: Stack-based buffer overflow in CoreGraphics in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows Stack-based buffer overflow in CoreGraphics in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.
nvd
CVE-2010-1803MEDIUMCVSS 4.3v10.6.0v10.6.1+3 more2010-11-15
CVE-2010-1803 [MEDIUM] CVE-2010-1803: Time Machine in Apple Mac OS X 10.6.x before 10.6.5 does not verify the unique identifier of its rem Time Machine in Apple Mac OS X 10.6.x before 10.6.5 does not verify the unique identifier of its remote AFP volume, which allows remote attackers to obtain sensitive information by spoofing this volume.
nvd
CVE-2010-1828MEDIUMCVSS 5.0v10.5.8v10.6.0+4 more2010-11-15
CVE-2010-1828 [MEDIUM] CWE-20 CVE-2010-1828: AFP Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to cause a deni AFP Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon restart) via crafted reconnect authentication packets.
nvd
CVE-2010-1834MEDIUMCVSS 5.8v10.6.0v10.6.1+3 more2010-11-15
CVE-2010-1834 [MEDIUM] CWE-20 CVE-2010-1834: CFNetwork in Apple Mac OS X 10.6.x before 10.6.5 does not properly validate the domains of cookies, CFNetwork in Apple Mac OS X 10.6.x before 10.6.5 does not properly validate the domains of cookies, which makes it easier for remote web servers to track users by setting a cookie that is associated with a partial IP address.
nvd
CVE-2010-1831MEDIUMCVSS 6.8v10.5.8v10.6.0+4 more2010-11-15
CVE-2010-1831 [MEDIUM] CWE-119 CVE-2010-1831: Buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allow Buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code via a long name of an embedded font in a document.
nvd