cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 130 of 157
CVE-2018-4351P4MEDIUMCVSS 5.5fixed in 10.142019-04-03
CVE-2018-4351 [MEDIUM] CWE-665 CVE-2018-4351: A memory initialization issue was addressed with improved memory handling. This issue affected versi A memory initialization issue was addressed with improved memory handling. This issue affected versions prior to macOS Mojave 10.14.
nvd
CVE-2021-1778P4MEDIUMCVSS 5.5≥ 10.14, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-04-02
CVE-2021-1778 [MEDIUM] CWE-125 CVE-2021-1778: An out-of-bounds read issue existed in the curl. This issue was addressed with improved bounds check An out-of-bounds read issue existed in the curl. This issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to a denial of service.
nvd
CVE-2018-4324P4MEDIUMCVSS 5.5fixed in 10.142019-04-03
CVE-2018-4324 [MEDIUM] CWE-732 CVE-2018-4324: A permissions issue existed in the handling of the Apple ID. This issue was addressed with improved A permissions issue existed in the handling of the Apple ID. This issue was addressed with improved access controls. This issue affected versions prior to macOS Mojave 10.14.
nvd
CVE-2019-8589P4MEDIUMCVSS 5.5fixed in 10.14.52019-12-18
CVE-2019-8589 [MEDIUM] CVE-2019-8589: This issue was addressed with improved checks. This issue is fixed in macOS Mojave 10.14.5. A malici This issue was addressed with improved checks. This issue is fixed in macOS Mojave 10.14.5. A malicious application may bypass Gatekeeper checks.
nvd
CVE-2015-5840P4MEDIUMCVSS 5.0≤ 10.10.52015-09-18
CVE-2015-5840 [MEDIUM] CWE-119 CVE-2015-5840: The checkint division routines in removefile in Apple iOS before 9 allow attackers to cause a denial The checkint division routines in removefile in Apple iOS before 9 allow attackers to cause a denial of service (overflow fault and app crash) via crafted data.
nvd
CVE-2012-0651P4MEDIUMCVSS 5.0v10.6.82012-05-11
CVE-2012-0651 [MEDIUM] CWE-200 CVE-2012-0651: The directory server in Directory Service in Apple Mac OS X 10.6.8 allows remote attackers to obtain The directory server in Directory Service in Apple Mac OS X 10.6.8 allows remote attackers to obtain sensitive information from process memory via a crafted message.
nvd
CVE-2018-4403P4MEDIUMCVSS 5.5fixed in 10.14.12019-04-03
CVE-2018-4403 [MEDIUM] CWE-200 CVE-2018-4403: This issue was addressed by removing additional entitlements. This issue affected versions prior to This issue was addressed by removing additional entitlements. This issue affected versions prior to macOS Mojave 10.14.1.
nvd
CVE-2015-1118P4MEDIUMCVSS 5.0≤ 10.10.22015-04-10
CVE-2015-1118 [MEDIUM] CVE-2015-1118: libnetcore in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attack libnetcore in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attackers to cause a denial of service (memory corruption and application crash) via a crafted configuration profile.
nvd
CVE-2006-1472P4MEDIUMCVSS 5.0v10.3.92006-08-02
CVE-2006-1472 [MEDIUM] CVE-2006-1472: Unspecified vulnerability in AFP Server in Apple Mac OS X 10.3.9 allows remote attackers to determin Unspecified vulnerability in AFP Server in Apple Mac OS X 10.3.9 allows remote attackers to determine names of unauthorized files and folders via unknown vectors related to the search results.
nvd
CVE-2020-9851P4MEDIUMCVSS 5.5fixed in 10.15.52020-06-09
CVE-2020-9851 [MEDIUM] CVE-2020-9851: An access issue was addressed with improved access restrictions. This issue is fixed in macOS Catali An access issue was addressed with improved access restrictions. This issue is fixed in macOS Catalina 10.15.5. A malicious application may be able to modify protected parts of the file system.
nvd
CVE-2020-9885P4MEDIUMCVSS 5.5fixed in 10.15.62020-10-16
CVE-2020-9885 [MEDIUM] CWE-345 CVE-2020-9885: An issue existed in the handling of iMessage tapbacks. The issue was resolved with additional verifi An issue existed in the handling of iMessage tapbacks. The issue was resolved with additional verification. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A user that is removed from an iMessage group could rejoin the group.
nvd
CVE-2016-4648P4MEDIUMCVSS 5.5≤ 10.11.52016-07-22
CVE-2016-4648 [MEDIUM] CWE-200 CVE-2016-4648: Audio in Apple OS X before 10.11.6 allows local users to obtain sensitive kernel memory-layout infor Audio in Apple OS X before 10.11.6 allows local users to obtain sensitive kernel memory-layout information or cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2009-2808P4MEDIUMCVSS 5.4≤ 10.6.1v10.0+57 more2009-11-10
CVE-2009-2808 [MEDIUM] CWE-310 CVE-2009-2808: Help Viewer in Apple Mac OS X before 10.6.2 does not use an HTTPS connection to retrieve Apple Help Help Viewer in Apple Mac OS X before 10.6.2 does not use an HTTPS connection to retrieve Apple Help content from a web site, which allows man-in-the-middle attackers to send a crafted help:runscript link, and thereby execute arbitrary code, via a spoofed response.
nvd
CVE-2020-3839P4MEDIUMCVSS 5.5fixed in 10.15.32020-02-27
CVE-2020-3839 [MEDIUM] CWE-20 CVE-2020-3839: A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Cata A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.3. An application may be able to read restricted memory.
nvd
CVE-2016-4755P4MEDIUMCVSS 5.5≤ 10.11.62016-09-25
CVE-2016-4755 [MEDIUM] CWE-200 CVE-2016-4755: Terminal in Apple OS X before 10.12 uses weak permissions for the .bash_history and .bash_session fi Terminal in Apple OS X before 10.12 uses weak permissions for the .bash_history and .bash_session files, which allows local users to obtain sensitive information via unspecified vectors.
nvd
CVE-2019-8537P4MEDIUMCVSS 5.5fixed in 10.14.42019-12-18
CVE-2019-8537 [MEDIUM] CVE-2019-8537: An access issue was addressed with improved memory management. This issue is fixed in macOS Mojave 1 An access issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.4. A local user may be able to view a user’s locked notes.
nvd
CVE-2018-4179P4MEDIUMCVSS 5.5≥ 10.13.0, < 10.13.42019-01-11
CVE-2018-4179 [MEDIUM] CWE-200 CVE-2018-4179: In macOS High Sierra before 10.13.4, there was an issue with the handling of smartcard PINs. This is In macOS High Sierra before 10.13.4, there was an issue with the handling of smartcard PINs. This issue was addressed with additional logic.
nvd
CVE-2016-1732P4MEDIUMCVSS 5.5≤ 10.11.32016-03-24
CVE-2016-1732 [MEDIUM] CWE-119 CVE-2016-1732: AppleRAID in Apple OS X before 10.11.4 allows local users to obtain sensitive kernel memory-layout i AppleRAID in Apple OS X before 10.11.4 allows local users to obtain sensitive kernel memory-layout information or cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2011-3462P4MEDIUMCVSS 5.0≤ 10.7.2v10.7.0+1 more2012-02-02
CVE-2011-3462 [MEDIUM] CVE-2011-3462: Time Machine in Apple Mac OS X before 10.7.3 does not verify the unique identifier of its remote AFP Time Machine in Apple Mac OS X before 10.7.3 does not verify the unique identifier of its remote AFP volume or Time Capsule, which allows remote attackers to obtain sensitive information contained in new backups by spoofing this storage object, a different vulnerability than CVE-2010-1803.
nvd
CVE-2018-4342P4MEDIUMCVSS 5.5fixed in 10.14.12019-04-03
CVE-2018-4342 [MEDIUM] CWE-20 CVE-2018-4342: A configuration issue was addressed with additional restrictions. This issue affected versions prior A configuration issue was addressed with additional restrictions. This issue affected versions prior to macOS Mojave 10.14.1.
nvd
Apple macOS vulnerabilities | cvebase