cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 124 of 157
CVE-2007-0726P4MEDIUMCVSS 5.0v10.3.9v10.4+8 more2007-03-13
CVE-2007-0726 [MEDIUM] CVE-2007-0726: The SSH key generation process in OpenSSH in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows re The SSH key generation process in OpenSSH in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote attackers to cause a denial of service by connecting to the server before SSH has finished creating keys, which causes the keys to be regenerated and can break trust relationships that were based on the original keys.
nvd
CVE-2020-11760P4MEDIUMCVSS 5.5fixed in 10.15.6≥ 10.13.0, < 10.13.6+3 more2020-04-14
CVE-2020-11760 [MEDIUM] CWE-125 CVE-2020-11760: An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompres An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompression in rleUncompress in ImfRle.cpp.
nvd
CVE-2020-11763P4MEDIUMCVSS 5.5≥ 10.13.0, < 10.13.6≥ 10.14.0, < 10.14.6+3 more2020-04-14
CVE-2020-11763 [MEDIUM] CWE-125 CVE-2020-11763: An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and writ An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and write, as demonstrated by ImfTileOffsets.cpp.
nvd
CVE-2011-0199P4MEDIUMCVSS 5.9≥ 10.6.0, < 10.6.82011-06-24
CVE-2011-0199 [MEDIUM] CWE-295 CVE-2011-0199: The Certificate Trust Policy component in Apple Mac OS X before 10.6.8 does not perform CRL checking The Certificate Trust Policy component in Apple Mac OS X before 10.6.8 does not perform CRL checking for Extended Validation (EV) certificates that lack OCSP URLs, which might allow man-in-the-middle attackers to spoof an SSL server via a revoked certificate.
nvd
CVE-2013-1028P4MEDIUMCVSS 5.8≤ 10.8.4v10.8.0+3 more2013-09-16
CVE-2013-1028 [MEDIUM] CWE-20 CVE-2013-1028: The IPSec implementation in Apple Mac OS X before 10.8.5, when Hybrid Auth is used, does not verify The IPSec implementation in Apple Mac OS X before 10.8.5, when Hybrid Auth is used, does not verify X.509 certificates from security gateways, which allows man-in-the-middle attackers to spoof security gateways and obtain sensitive information via a crafted certificate.
nvd
CVE-2018-4338P4MEDIUMCVSS 5.5fixed in 10.142019-04-03
CVE-2018-4338 [MEDIUM] CWE-20 CVE-2018-4338: A validation issue was addressed with improved input sanitization. This issue affected versions prio A validation issue was addressed with improved input sanitization. This issue affected versions prior to macOS Mojave 10.14.
nvd
CVE-2016-1802P4MEDIUMCVSS 5.5fixed in 10.11.52016-05-20
CVE-2016-1802 [MEDIUM] CWE-200 CVE-2016-1802: CCCrypt in CommonCrypto in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watch CCCrypt in CommonCrypto in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 mishandles return values during key-length calculations, which allows attackers to obtain sensitive information via a crafted app.
nvd
CVE-2010-0205P4MEDIUMCVSS 4.3fixed in 10.6.52010-03-03
CVE-2010-0205 [MEDIUM] CWE-400 CVE-2010-0205: The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large uncompressed representation, which allows remote attackers to cause a denial of service (memory and CPU consumption, and application hang)
nvd
CVE-2013-5184P4MEDIUMCVSS 5.7≤ 10.8.5v10.8.0+5 more2013-10-24
CVE-2013-5184 [MEDIUM] CWE-399 CVE-2013-5184: The kernel in Apple Mac OS X before 10.9 does not properly check for errors during the processing of The kernel in Apple Mac OS X before 10.9 does not properly check for errors during the processing of multicast Wi-Fi packets, which allows remote attackers to cause a denial of service (system crash) by leveraging presence in an 802.11 network's coverage area.
nvd
CVE-2021-30782P4MEDIUMCVSS 5.5≥ 10.14, ≤ 10.14.5≥ 10.15, ≤ 10.15.6+2 more2021-09-08
CVE-2021-30782 [MEDIUM] CVE-2021-30782: This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.5, Security U This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. A malicious application may be able to access restricted files.
nvd
CVE-2020-10009P4MEDIUMCVSS 5.5fixed in 11.0.1≥ 10.14, < 10.14.6+3 more2020-12-08
CVE-2020-10009 [MEDIUM] CVE-2020-10009: A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11. A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1. A sandboxed process may be able to circumvent sandbox restrictions.
nvd
CVE-2017-13828P4MEDIUMCVSS 5.5≤ 10.13.02017-11-13
CVE-2017-13828 [MEDIUM] CVE-2017-13828: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Fonts" component. It allows remote attackers to spoof the user interface via crafted text.
nvd
CVE-2020-10001P4MEDIUMCVSS 5.5fixed in 11.1.02021-04-02
CVE-2020-10001 [MEDIUM] CWE-20 CVE-2020-10001: An input validation issue was addressed with improved memory handling. This issue is fixed in macOS An input validation issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may be able to read restricted memory.
nvd
CVE-2018-4093P4MEDIUMCVSS 5.5fixed in 10.13.32018-04-03
CVE-2018-4093 [MEDIUM] CWE-200 CVE-2018-4093: An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13 An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvd
CVE-2021-30950P4MEDIUMCVSS 5.5≥ 10.15, < 10.15.7v10.15.72021-08-24
CVE-2021-30950 [MEDIUM] CVE-2021-30950: A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12 A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.1, Security Update 2021-008 Catalina, macOS Big Sur 11.6.2. A malicious application may bypass Gatekeeper checks.
nvd
CVE-2016-7607P4MEDIUMCVSS 5.5≤ 10.12.12017-02-20
CVE-2016-7607 [MEDIUM] CWE-200 CVE-2016-7607: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component, which allows attackers to obtain sensitive information from kernel memory via a crafted app.
nvd
CVE-2018-4171P4MEDIUMCVSS 5.5fixed in 10.13.52018-06-08
CVE-2018-4171 [MEDIUM] CWE-200 CVE-2018-4171: An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Bluetooth" component. It allows attackers to obtain sensitive kernel memory-layout information via a crafted app that leverages device properties.
nvd
CVE-2017-6987P4MEDIUMCVSS 5.5≤ 10.12.42017-05-22
CVE-2017-6987 [MEDIUM] CWE-200 CVE-2017-6987: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvd
CVE-2020-9963P4MEDIUMCVSS 5.5fixed in 11.0.12020-12-08
CVE-2020-9963 [MEDIUM] CVE-2020-9963: The issue was addressed with improved handling of icon caches. This issue is fixed in macOS Big Sur The issue was addressed with improved handling of icon caches. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.0 and iPadOS 14.0. A malicious app may be able to determine the existence of files on the computer.
nvd
CVE-2021-30976P4MEDIUMCVSS 5.5≥ 10.15, < 10.15.7v10.15.72021-08-24
CVE-2021-30976 [MEDIUM] CVE-2021-30976: A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12 A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.1, Security Update 2021-008 Catalina, macOS Big Sur 11.6.2. A malicious application may bypass Gatekeeper checks.
nvd
Apple macOS vulnerabilities | cvebase