cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 128 of 157
CVE-2015-3807P4MEDIUMCVSS 4.3≤ 10.10.4≤ 10.11.12015-08-17
CVE-2015-3807 [MEDIUM] CWE-119 CVE-2015-3807: libxml2 in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to obtain sensitiv libxml2 in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (memory corruption) via a crafted XML document.
nvd
CVE-2005-1335P4HIGHCVSS 7.2v10.3.92005-05-04
CVE-2005-1335 [HIGH] CVE-2005-1335: Unknown vulnerability in Mac OS X 10.3.9 allows local users to gain privileges via (1) chfn, (2) chp Unknown vulnerability in Mac OS X 10.3.9 allows local users to gain privileges via (1) chfn, (2) chpass, and (3) chsh, which "use external helper programs in an insecure manner."
nvd
CVE-2015-3710P4MEDIUMCVSS 4.3≤ 10.10.32015-07-03
CVE-2015-3710 [MEDIUM] CWE-254 CVE-2015-3710: Mail in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to trigger a refresh op Mail in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to trigger a refresh operation, and consequently cause a visit to an arbitrary web site, via a crafted HTML e-mail message.
nvd
CVE-2001-1411P4HIGHCVSS 7.2v10.4.92003-11-17
CVE-2001-1411 [HIGH] CVE-2001-1411: Format string vulnerability in gm4 (aka m4) on Mac OS X may allow local users to gain privileges if Format string vulnerability in gm4 (aka m4) on Mac OS X may allow local users to gain privileges if gm4 is called by setuid programs.
nvd
CVE-2005-1722P4HIGHCVSS 7.2v10.4v10.4.12005-06-16
CVE-2005-1722 [HIGH] CVE-2005-1722: Unknown vulnerability in the CoreGraphics Window Server for Mac OS X 10.4.x up to 10.4.1 allows loca Unknown vulnerability in the CoreGraphics Window Server for Mac OS X 10.4.x up to 10.4.1 allows local users to inject arbitrary commands into root sessions.
nvd
CVE-2008-1517P4HIGHCVSS 7.2v10.5v10.5.0+6 more2009-05-13
CVE-2008-1517 [HIGH] CWE-20 CVE-2008-1517: Array index error in the xnu (Mach) kernel in Apple Mac OS X 10.5 before 10.5.7 allows local users t Array index error in the xnu (Mach) kernel in Apple Mac OS X 10.5 before 10.5.7 allows local users to gain privileges or cause a denial of service (system shutdown) via unspecified vectors related to workqueues.
nvd
CVE-2005-0972P4HIGHCVSS 7.2v10.0v10.0.1+27 more2005-05-12
CVE-2005-0972 [HIGH] CVE-2005-0972: Integer overflow in the searchfs system call in Mac OS X 10.3.9 and earlier allows local users to ex Integer overflow in the searchfs system call in Mac OS X 10.3.9 and earlier allows local users to execute arbitrary code via crafted parameters.
nvd
CVE-2007-4686P4HIGHCVSS 7.2v10.4.1v10.4.2+8 more2007-11-15
CVE-2007-4686 [HIGH] CWE-189 CVE-2007-4686: Integer signedness error in the ttioctl function in bsd/kern/tty.c in the xnu kernel in Apple Mac OS Integer signedness error in the ttioctl function in bsd/kern/tty.c in the xnu kernel in Apple Mac OS X 10.4 through 10.4.10 allows local users to cause a denial of service (system shutdown) or gain privileges via a crafted TIOCSETD ioctl request.
nvd
CVE-2005-2519P4HIGHCVSS 7.2v10.3.92005-08-19
CVE-2005-2519 [HIGH] CVE-2005-2519: slpd in Directory Services in Mac OS X 10.3.9 creates insecure temporary files as root, which allows slpd in Directory Services in Mac OS X 10.3.9 creates insecure temporary files as root, which allows local users to gain privileges.
nvd
CVE-2013-5181P4MEDIUMCVSS 4.3≤ 10.8.5v10.8.0+5 more2013-10-24
CVE-2013-5181 [MEDIUM] CWE-310 CVE-2013-5181: The auto-configuration feature in Mail in Apple Mac OS X before 10.9 selects plaintext authenticatio The auto-configuration feature in Mail in Apple Mac OS X before 10.9 selects plaintext authentication for unspecified servers that support CRAM-MD5 authentication, which allows remote attackers to obtain sensitive information by sniffing the network.
nvd
CVE-2009-2416P4MEDIUMCVSS 6.5fixed in 10.4.11≥ 10.5.0, < 10.5.8+1 more2009-08-11
CVE-2009-2416 [MEDIUM] CWE-416 CVE-2009-2416: Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and l Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.
nvd
CVE-2012-3723P4MEDIUMCVSS 4.6≤ 10.7.4v10.0+69 more2012-09-20
CVE-2012-3723 [MEDIUM] CWE-119 CVE-2012-3723: Apple Mac OS X before 10.7.5 does not properly handle the bNbrPorts field of a USB hub descriptor, w Apple Mac OS X before 10.7.5 does not properly handle the bNbrPorts field of a USB hub descriptor, which allows physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption and system crash) by attaching a USB device.
nvd
CVE-2013-0970P4MEDIUMCVSS 4.3v10.8.0v10.8.1+1 more2013-03-15
CVE-2013-0970 [MEDIUM] CVE-2013-0970: Messages in Apple Mac OS X before 10.8.3 allows remote attackers to bypass the FaceTime call-confirm Messages in Apple Mac OS X before 10.8.3 allows remote attackers to bypass the FaceTime call-confirmation prompt via a crafted FaceTime: URL.
nvd
CVE-2007-0720P4MEDIUMCVSS 5.0fixed in 10.4.92007-03-13
CVE-2007-0720 [MEDIUM] CVE-2007-0720: The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL connection, which prevents other requests from being accepted.
nvd
CVE-2008-0989P4MEDIUMCVSS 6.9v10.5.22008-03-18
CVE-2008-0989 [MEDIUM] CWE-134 CVE-2008-0989: Format string vulnerability in mDNSResponderHelper in Apple Mac OS X 10.5.2 allows local users to ex Format string vulnerability in mDNSResponderHelper in Apple Mac OS X 10.5.2 allows local users to execute arbitrary code via format string specifiers in the local hostname.
nvd
CVE-2017-13873P4MEDIUMCVSS 4.3fixed in 10.132018-04-03
CVE-2017-13873 [MEDIUM] CWE-200 CVE-2017-13873: An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "Kernel" component. It allows attackers to obtain sensitive network-activity information about arbitrary apps via a crafted app.
nvd
CVE-2012-1148P4MEDIUMCVSS 5.0≤ 10.11.12012-07-03
CVE-2012-1148 [MEDIUM] CWE-399 CVE-2012-1148: Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-de Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (memory consumption) via a large number of crafted XML files that cause improperly-handled reallocation failures when expanding entities.
nvd
CVE-2006-0392P4MEDIUMCVSS 5.1v10.4.72006-08-03
CVE-2006-0392 [MEDIUM] CVE-2006-0392: Buffer overflow in Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service Buffer overflow in Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Canon RAW image.
nvd
CVE-2020-11758P4MEDIUMCVSS 5.5fixed in 10.15.6≥ 10.13.0, < 10.13.6+3 more2020-04-14
CVE-2020-11758 [MEDIUM] CWE-125 CVE-2020-11758: An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read in ImfOptimizedPixel An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read in ImfOptimizedPixelReading.h.
nvd
CVE-2020-11761P4MEDIUMCVSS 5.5fixed in 10.15.6≥ 10.13.0, < 10.13.6+3 more2020-04-14
CVE-2020-11761 [MEDIUM] CWE-125 CVE-2020-11761: An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncom An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncompression, as demonstrated by FastHufDecoder::refill in ImfFastHuf.cpp.
nvd
Apple macOS vulnerabilities | cvebase