cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 129 of 157
CVE-2017-7173P4MEDIUMCVSS 5.5fixed in 10.13.22018-04-03
CVE-2017-7173 [MEDIUM] CWE-200 CVE-2017-7173: An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvd
CVE-2005-1331P4MEDIUMCVSS 5.1v10.3v10.3.1+8 more2005-05-04
CVE-2005-1331 [MEDIUM] CVE-2005-1331: The AppleScript Editor in Mac OS X 10.3.9 does not properly display script code for an applescript: The AppleScript Editor in Mac OS X 10.3.9 does not properly display script code for an applescript: URI, which can result in code that is different than the actual code that would be run, which could allow remote attackers to trick users into executing malicious code via certain URI characters such as NULL, control characters, and homographs.
nvd
CVE-2010-1379P4MEDIUMCVSS 5.0v10.6.0v10.6.1+2 more2010-06-17
CVE-2010-1379 [MEDIUM] CWE-20 CVE-2010-1379: Printer Setup in Apple Mac OS X 10.6 before 10.6.4 does not properly interpret character encoding, w Printer Setup in Apple Mac OS X 10.6 before 10.6.4 does not properly interpret character encoding, which allows remote attackers to cause a denial of service (printing failure) by deploying a printing device that has a Unicode character in its printing-service name.
nvd
CVE-2017-13782P4MEDIUMCVSS 5.5≤ 10.13.02017-11-13
CVE-2017-13782 [MEDIUM] CWE-200 CVE-2017-13782: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a /dev/dtracehelper attack involving the dtrace_dif_variable and dtrace_getarg functions.
nvd
CVE-2010-1828P4MEDIUMCVSS 5.0v10.5.8v10.6.0+4 more2010-11-15
CVE-2010-1828 [MEDIUM] CWE-20 CVE-2010-1828: AFP Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to cause a deni AFP Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon restart) via crafted reconnect authentication packets.
nvd
CVE-2017-6974P4MEDIUMCVSS 5.5v10.12.32017-04-02
CVE-2017-6974 [MEDIUM] CWE-20 CVE-2017-6974: An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the system-installation subsystem of the "System Integrity Protection" component. It allows attackers to modify the contents of a protected disk location via a crafted app.
nvd
CVE-2017-2540P4MEDIUMCVSS 5.5≤ 10.12.42017-05-22
CVE-2017-2540 [MEDIUM] CWE-20 CVE-2017-2540: An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "WindowServer" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvd
CVE-2018-4176P4MEDIUMCVSS 5.5fixed in 10.13.42018-04-03
CVE-2018-4176 [MEDIUM] CWE-20 CVE-2018-4176: An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Disk Images" component. It allows attackers to trigger an app launch upon mounting a crafted disk image.
nvd
CVE-2016-4752P4MEDIUMCVSS 5.5≤ 10.11.62016-09-25
CVE-2016-4752 [MEDIUM] CWE-200 CVE-2016-4752: The SecKeyDeriveFromPassword function in Apple OS X before 10.12 does not use the CF_RETURNS_RETAINE The SecKeyDeriveFromPassword function in Apple OS X before 10.12 does not use the CF_RETURNS_RETAINED keyword, which allows attackers to obtain sensitive information from process memory by triggering key derivation.
nvd
CVE-2008-0050P4MEDIUMCVSS 5.0v10.4.112008-03-18
CVE-2008-0050 [MEDIUM] CWE-200 CVE-2008-0050: CFNetwork in Apple Mac OS X 10.4.11 allows remote HTTPS proxy servers to spoof secure websites via d CFNetwork in Apple Mac OS X 10.4.11 allows remote HTTPS proxy servers to spoof secure websites via data in a 502 Bad Gateway error.
nvd
CVE-2018-4390P4MEDIUMCVSS 5.5≥ 10.13, < 10.13.12020-10-27
CVE-2018-4390 [MEDIUM] CVE-2018-4390: An inconsistent user interface issue was addressed with improved state management. This issue is fix An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan, watchOS 4.3, iOS 12.1. Processing a maliciously crafted text message may lead to UI spoofing.
nvd
CVE-2018-4391P4MEDIUMCVSS 5.5≥ 10.13, < 10.13.12020-10-27
CVE-2018-4391 [MEDIUM] CVE-2018-4391: An inconsistent user interface issue was addressed with improved state management. This issue is fix An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan, watchOS 4.3, iOS 12.1. Processing a maliciously crafted text message may lead to UI spoofing.
nvd
CVE-2019-8817P4MEDIUMCVSS 5.5fixed in 10.15.12019-12-18
CVE-2019-8817 [MEDIUM] CWE-20 CVE-2019-8817: A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Cata A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.1. An application may be able to read restricted memory.
nvd
CVE-2019-8693P4MEDIUMCVSS 5.5fixed in 10.14.62019-12-18
CVE-2019-8693 [MEDIUM] CWE-125 CVE-2019-8693: A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Moja A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Mojave 10.14.6. An application may be able to read restricted memory.
nvd
CVE-2021-1773P4MEDIUMCVSS 5.5≥ 10.14, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-04-02
CVE-2021-1773 [MEDIUM] CVE-2021-1773: A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11. A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to a denial of service.
nvd
CVE-2021-1766P4MEDIUMCVSS 5.5≥ 10.14, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-04-02
CVE-2021-1766 [MEDIUM] CVE-2021-1766: This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security U This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to a denial of service.
nvd
CVE-2018-4355P4MEDIUMCVSS 5.5fixed in 10.142019-04-03
CVE-2018-4355 [MEDIUM] CWE-200 CVE-2018-4355: A configuration issue was addressed with additional restrictions. This issue affected versions prior A configuration issue was addressed with additional restrictions. This issue affected versions prior to iOS 12, macOS Mojave 10.14.
nvd
CVE-2018-4346P4MEDIUMCVSS 5.5fixed in 10.142019-04-03
CVE-2018-4346 [MEDIUM] CWE-20 CVE-2018-4346: A validation issue existed which allowed local file access. This was addressed with input sanitizati A validation issue existed which allowed local file access. This was addressed with input sanitization. This issue affected versions prior to macOS Mojave 10.14.
nvd
CVE-2018-4333P4MEDIUMCVSS 5.5fixed in 10.142019-04-03
CVE-2018-4333 [MEDIUM] CWE-20 CVE-2018-4333: A validation issue was addressed with improved input sanitization. This issue affected versions prio A validation issue was addressed with improved input sanitization. This issue affected versions prior to iOS 12, macOS Mojave 10.14.
nvd
CVE-2018-4308P4MEDIUMCVSS 5.5fixed in 10.142019-04-03
CVE-2018-4308 [MEDIUM] CWE-125 CVE-2018-4308: An out-of-bounds read was addressed with improved bounds checking. This issue affected versions prio An out-of-bounds read was addressed with improved bounds checking. This issue affected versions prior to macOS Mojave 10.14.
nvd
Apple macOS vulnerabilities | cvebase