Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 123 of 157
CVE-2004-0081P4MEDIUMCVSS 5.0v10.3.32004-11-23
CVE-2004-0081 [MEDIUM] CVE-2004-0081: OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote atta
OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.
nvd
CVE-2010-1830P4MEDIUMCVSS 5.0v10.5.8v10.6.0+4 more2010-11-15
CVE-2010-1830 [MEDIUM] CVE-2010-1830: AFP Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 generates different error messages depe
AFP Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 generates different error messages depending on whether a share exists, which allows remote attackers to enumerate valid share names via unspecified vectors.
nvd
CVE-2014-1316P4MEDIUMCVSS 5.0≤ 10.9.2v10.9+1 more2014-04-23
CVE-2014-1316 [MEDIUM] CWE-20 CVE-2014-1316: Heimdal, as used in Apple OS X through 10.9.2, allows remote attackers to cause a denial of service
Heimdal, as used in Apple OS X through 10.9.2, allows remote attackers to cause a denial of service (abort and daemon exit) via ASN.1 data encountered in the Kerberos 5 protocol.
nvd
CVE-2005-1343P4HIGHCVSS 7.2v10.3.92005-05-03
CVE-2005-1343 [HIGH] CVE-2005-1343: Stack-based buffer overflow in the VPN daemon (vpnd) for Mac OS X before 10.3.9 allows local users t
Stack-based buffer overflow in the VPN daemon (vpnd) for Mac OS X before 10.3.9 allows local users to execute arbitrary code via a long -i (Server_id) argument.
nvd
CVE-2007-5857P4MEDIUMCVSS 6.4v10.5.12007-12-19
CVE-2007-5857 [MEDIUM] CWE-264 CVE-2007-5857: Quick Look in Apple Mac OS X 10.5.1 does not prevent a movie from accessing URLs when the movie file
Quick Look in Apple Mac OS X 10.5.1 does not prevent a movie from accessing URLs when the movie file is previewed or if an icon is created, which might allow remote attackers to obtain sensitive information via HREFTrack.
nvd
CVE-2017-2409P4HIGHCVSS 7.1≤ 10.12.32017-04-02
CVE-2017-2409 [HIGH] CWE-125 CVE-2017-2409: An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Menus" component. It allows attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted app.
nvd
CVE-2013-0969P4MEDIUMCVSS 4.9v10.8.0v10.8.1+1 more2013-03-15
CVE-2013-0969 [MEDIUM] CWE-264 CVE-2013-0969: Login Window in Apple Mac OS X before 10.8.3 does not prevent application launching with the VoiceOv
Login Window in Apple Mac OS X before 10.8.3 does not prevent application launching with the VoiceOver feature, which allows physically proximate attackers to bypass authentication and make arbitrary System Preferences changes via unspecified use of the keyboard.
nvd
CVE-2004-0822P4HIGHCVSS 7.2v10.2.8v10.3.4+1 more2004-09-07
CVE-2004-0822 [HIGH] CVE-2004-0822: Buffer overflow in The Core Foundation framework (CoreFoundation.framework) in Mac OS X 10.2.8, 10.3
Buffer overflow in The Core Foundation framework (CoreFoundation.framework) in Mac OS X 10.2.8, 10.3.4, and 10.3.5 allows local users to execute arbitrary code via a certain environment variable.
nvd
CVE-2006-3509P4HIGHCVSS 7.2v10.4.72006-09-21
CVE-2006-3509 [HIGH] CVE-2006-3509: Integer overflow in the API for the AirPort wireless driver on Apple Mac OS X 10.4.7 might allow phy
Integer overflow in the API for the AirPort wireless driver on Apple Mac OS X 10.4.7 might allow physically proximate attackers to cause a denial of service (crash) or execute arbitrary code in third-party wireless software that uses the API via crafted frames.
nvd
CVE-2007-1661P4MEDIUMCVSS 6.4v10.4.112007-11-07
CVE-2007-1661 [MEDIUM] CVE-2007-1661: Perl-Compatible Regular Expression (PCRE) library before 7.3 backtracks too far when matching certai
Perl-Compatible Regular Expression (PCRE) library before 7.3 backtracks too far when matching certain input bytes against some regex patterns in non-UTF-8 mode, which allows context-dependent attackers to obtain sensitive information or cause a denial of service (crash), as demonstrated by the "\X?\d" and "\P{L}?\d" patterns.
nvd
CVE-2008-0037P4MEDIUMCVSS 4.3v10.5v10.5.12008-02-12
CVE-2008-0037 [MEDIUM] CWE-264 CVE-2008-0037: X11 in Apple Mac OS X 10.5 through 10.5.1 does not properly handle when the "Allow connections from
X11 in Apple Mac OS X 10.5 through 10.5.1 does not properly handle when the "Allow connections from network client" preference is disabled, which allows remote attackers to bypass intended access restrictions and connect to the X server.
nvd
CVE-2005-0125P4HIGHCVSS 7.2v10.3.4v10.3.72005-05-02
CVE-2005-0125 [HIGH] CVE-2005-0125: The "at" commands on Mac OS X 10.3.7 and earlier do not properly drop privileges, which allows local
The "at" commands on Mac OS X 10.3.7 and earlier do not properly drop privileges, which allows local users to (1) delete arbitrary files via atrm, (2) execute arbitrary programs via the -f argument to batch, or (3) read arbitrary files via the -f argument to batch, which generates a job file that is readable by the local user.
nvd
CVE-2007-4685P4HIGHCVSS 7.2v10.4.1v10.4.2+8 more2007-11-15
CVE-2007-4685 [HIGH] CWE-264 CVE-2007-4685: The kernel in Apple Mac OS X 10.4 through 10.4.10 allows local users to gain privileges by executing
The kernel in Apple Mac OS X 10.4 through 10.4.10 allows local users to gain privileges by executing setuid or setgid programs in which the stdio, stderr, or stdout file descriptors are "in an unexpected state."
nvd
CVE-2005-2741P4HIGHCVSS 7.2v10.3.9v10.4.22005-10-26
CVE-2005-2741 [HIGH] CWE-264 CVE-2005-2741: Authorization Services in securityd for Apple Mac OS X 10.3.9 allows local users to gain privileges
Authorization Services in securityd for Apple Mac OS X 10.3.9 allows local users to gain privileges by granting themselves certain rights that should be restricted to administrators.
nvd
CVE-2019-8834P4MEDIUMCVSS 4.3fixed in 10.15.22020-10-27
CVE-2019-8834 [MEDIUM] CVE-2019-8834: A configuration issue was addressed with additional restrictions. This issue is fixed in tvOS 13.3,
A configuration issue was addressed with additional restrictions. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iCloud for Windows 10.9, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, iOS 13.3 and iPadOS 13.3, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. An attacker in a privileged network position
nvd
CVE-2010-1838P4MEDIUMCVSS 4.4v10.5.8v10.6.0+4 more2010-11-15
CVE-2010-1838 [MEDIUM] CWE-287 CVE-2010-1838: Directory Services in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not properly handle errors
Directory Services in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not properly handle errors associated with disabled mobile accounts, which allows remote attackers to bypass authentication by providing a valid account name.
nvd
CVE-2008-0998P4MEDIUMCVSS 6.9v10.4.11v10.5.22008-03-18
CVE-2008-0998 [MEDIUM] CWE-264 CVE-2008-0998: Unspecified vulnerability in NetCfgTool in the System Configuration component in Apple Mac OS X 10.4
Unspecified vulnerability in NetCfgTool in the System Configuration component in Apple Mac OS X 10.4.11 and 10.5.2 allows local users to bypass authorization and execute arbitrary code via crafted distributed objects.
nvd
CVE-2008-0051P4MEDIUMCVSS 6.9v10.4.112008-03-18
CVE-2008-0051 [MEDIUM] CWE-189 CVE-2008-0051: Integer overflow in CoreFoundation in Apple Mac OS X 10.4.11 might allow local users to execute arbi
Integer overflow in CoreFoundation in Apple Mac OS X 10.4.11 might allow local users to execute arbitrary code via crafted time zone data.
nvd
CVE-2015-1117P4MEDIUMCVSS 6.9≤ 10.10.22015-04-10
CVE-2015-1117 [MEDIUM] CWE-264 CVE-2015-1117: The (1) setreuid and (2) setregid system-call implementations in the kernel in Apple iOS before 8.3,
The (1) setreuid and (2) setregid system-call implementations in the kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 do not properly perform privilege drops, which makes it easier for attackers to execute code with unintended user or group privileges via a crafted app.
nvd
CVE-2011-2391P4MEDIUMCVSS 6.1≤ 10.9.52013-09-19
CVE-2011-2391 [MEDIUM] CWE-20 CVE-2011-2391: The IPv6 implementation in the kernel in Apple iOS before 7 allows remote attackers to cause a denia
The IPv6 implementation in the kernel in Apple iOS before 7 allows remote attackers to cause a denial of service (CPU consumption) via crafted ICMPv6 packets.
nvd