Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 127 of 157
CVE-2019-8546P4MEDIUMCVSS 5.5fixed in 10.14.42019-12-18
CVE-2019-8546 [MEDIUM] CVE-2019-8546: An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 12.2,
An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, watchOS 5.2. A local user may be able to view sensitive user information.
nvd
CVE-2020-9772P4MEDIUMCVSS 5.5fixed in 10.15.42020-10-22
CVE-2020-9772 [MEDIUM] CVE-2020-9772: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 1
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. A sandboxed process may be able to circumvent sandbox restrictions.
nvd
CVE-2020-9913P4MEDIUMCVSS 5.5fixed in 10.15.62020-10-16
CVE-2020-9913 [MEDIUM] CVE-2020-9913: This issue was addressed with improved data protection. This issue is fixed in macOS Catalina 10.15.
This issue was addressed with improved data protection. This issue is fixed in macOS Catalina 10.15.6. A local user may be able to leak sensitive user information.
nvd
CVE-2017-13810P4MEDIUMCVSS 5.5≤ 10.13.02017-11-13
CVE-2017-13810 [MEDIUM] CWE-200 CVE-2017-13810: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows local users to obtain sensitive information by leveraging an error in packet counters.
nvd
CVE-2017-13817P4MEDIUMCVSS 5.5≤ 10.13.02017-11-13
CVE-2017-13817 [MEDIUM] CWE-125 CVE-2017-13817: An out-of-bounds read issue was discovered in certain Apple products. macOS before 10.13.1 is affect
An out-of-bounds read issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows local users to bypass intended memory-read restrictions.
nvd
CVE-2021-30811P4MEDIUMCVSS 5.5≥ 10.14.0, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-10-19
CVE-2021-30811 [MEDIUM] CVE-2021-30811: This issue was addressed with improved checks. This issue is fixed in iOS 15 and iPadOS 15, watchOS
This issue was addressed with improved checks. This issue is fixed in iOS 15 and iPadOS 15, watchOS 8. A local attacker may be able to read sensitive information.
nvd
CVE-2018-4256P4MEDIUMCVSS 5.5fixed in 10.13.52019-01-11
CVE-2018-4256 [MEDIUM] CWE-125 CVE-2018-4256: In macOS High Sierra before 10.13.5, an out-of-bounds read was addressed with improved input validat
In macOS High Sierra before 10.13.5, an out-of-bounds read was addressed with improved input validation.
nvd
CVE-2018-4255P4MEDIUMCVSS 5.5fixed in 10.13.52019-01-11
CVE-2018-4255 [MEDIUM] CWE-125 CVE-2018-4255: In macOS High Sierra before 10.13.5, an out-of-bounds read was addressed with improved input validat
In macOS High Sierra before 10.13.5, an out-of-bounds read was addressed with improved input validation.
nvd
CVE-2020-9833P4MEDIUMCVSS 5.5fixed in 10.15.52020-06-09
CVE-2020-9833 [MEDIUM] CWE-665 CVE-2020-9833: A memory initialization issue was addressed with improved memory handling. This issue is fixed in ma
A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.5. A local user may be able to read kernel memory.
nvd
CVE-2019-8692P4MEDIUMCVSS 5.5fixed in 10.14.62019-12-18
CVE-2019-8692 [MEDIUM] CWE-125 CVE-2019-8692: A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Moja
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Mojave 10.14.6. An application may be able to read restricted memory.
nvd
CVE-2017-13839P4MEDIUMCVSS 5.5v10.13.02018-04-03
CVE-2017-13839 [MEDIUM] CWE-200 CVE-2017-13839: An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involve
An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "Spotlight" component. It allows local users to see results for other users' files.
nvd
CVE-2018-4178P4MEDIUMCVSS 5.5fixed in 10.13.42019-04-03
CVE-2018-4178 [MEDIUM] CWE-732 CVE-2018-4178: A permissions issue existed in which execute permission was incorrectly granted. This issue was addr
A permissions issue existed in which execute permission was incorrectly granted. This issue was addressed with improved permission validation. This issue affected versions prior to macOS High Sierra 10.13.4.
nvd
CVE-2008-3617P4MEDIUMCVSS 5.0v10.5v10.5.1+3 more2008-09-16
CVE-2008-3617 [MEDIUM] CWE-255 CVE-2008-3617: Remote Management and Screen Sharing in Apple Mac OS X 10.5 through 10.5.4, when used to set a passw
Remote Management and Screen Sharing in Apple Mac OS X 10.5 through 10.5.4, when used to set a password for a VNC viewer, displays additional input characters beyond the maximum password length, which might make it easier for attackers to guess passwords that the user believed were longer.
nvd
CVE-2022-32849P4MEDIUMCVSS 5.5fixed in 10.15.7v10.15.72022-09-23
CVE-2022-32849 [MEDIUM] CWE-200 CVE-2022-32849: An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed i
An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be able to access sensitive user information.
nvd
CVE-2019-8702P4MEDIUMCVSS 5.5fixed in 10.14.6≥ 10.12, < 10.12.6+3 more2021-12-23
CVE-2019-8702 [MEDIUM] CWE-668 CVE-2019-8702: This issue was addressed with a new entitlement. This issue is fixed in macOS Mojave 10.14.6, Securi
This issue was addressed with a new entitlement. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra, iOS 12.4, tvOS 12.4. A local user may be able to read a persistent account identifier.
nvd
CVE-2015-5915P4MEDIUMCVSS 5.0≤ 10.10.52015-10-09
CVE-2015-5915 [MEDIUM] CWE-17 CVE-2015-5915: Apple OS X before 10.11 does not ensure that the keychain's lock state is displayed correctly, which
Apple OS X before 10.11 does not ensure that the keychain's lock state is displayed correctly, which has unspecified impact and attack vectors.
nvd
CVE-2013-5182P4MEDIUMCVSS 5.0≤ 10.8.5v10.8.0+5 more2013-10-24
CVE-2013-5182 [MEDIUM] CWE-310 CVE-2013-5182: Mail in Apple Mac OS X before 10.9 allows remote attackers to spoof the existence of a cryptographic
Mail in Apple Mac OS X before 10.9 allows remote attackers to spoof the existence of a cryptographic signature for an e-mail message by using the multipart/signed content type within an unsigned message.
nvd
CVE-2017-7083P4MEDIUMCVSS 4.9≤ 10.12.62017-10-23
CVE-2017-7083 [MEDIUM] CWE-20 CVE-2017-7083: An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is
An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "CFNetwork Proxies" component. It allows remote attackers to cause a denial of service.
nvd
CVE-2016-4748P4MEDIUMCVSS 5.3≤ 10.11.62016-09-25
CVE-2016-4748 [MEDIUM] CWE-254 CVE-2016-4748: Perl in Apple OS X before 10.12 allows local users to bypass the taint-mode protection mechanism via
Perl in Apple OS X before 10.12 allows local users to bypass the taint-mode protection mechanism via a crafted environment variable.
nvd
CVE-2013-0990P4MEDIUMCVSS 4.9v10.7.0v10.7.1+8 more2013-06-05
CVE-2013-0990 [MEDIUM] CWE-264 CVE-2013-0990: SMB in Apple Mac OS X before 10.8.4, when file sharing is enabled, allows remote authenticated users
SMB in Apple Mac OS X before 10.8.4, when file sharing is enabled, allows remote authenticated users to create or modify files outside of a shared directory via unspecified vectors.
nvd