Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 131 of 157
CVE-2016-7761P4MEDIUMCVSS 5.5≤ 10.12.12017-02-20
CVE-2016-7761 [MEDIUM] CWE-200 CVE-2016-7761: An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "WiFi" component, which allows local users to obtain sensitive network-configuration information by leveraging global storage.
nvd
CVE-2019-8522P4MEDIUMCVSS 5.5fixed in 10.14.42019-12-18
CVE-2019-8522 [MEDIUM] CWE-306 CVE-2019-8522: A logic issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.1
A logic issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.4. An encrypted volume may be unmounted and remounted by a different user without prompting for the password.
nvd
CVE-2022-32823P4MEDIUMCVSS 5.5v10.15.72022-09-23
CVE-2022-32823 [MEDIUM] CWE-665 CVE-2022-32823: A memory initialization issue was addressed with improved memory handling. This issue is fixed in iO
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be able to leak sensitive user information.
nvd
CVE-2015-1148P4MEDIUMCVSS 5.0≤ 10.10.22015-04-10
CVE-2015-1148 [MEDIUM] CWE-200 CVE-2015-1148: Screen Sharing in Apple OS X before 10.10.3 stores the password of a user in a log file, which might
Screen Sharing in Apple OS X before 10.10.3 stores the password of a user in a log file, which might allow context-dependent attackers to obtain sensitive information by reading this file.
nvd
CVE-2015-7761P4MEDIUMCVSS 5.0≤ 10.10.52015-10-09
CVE-2015-7761 [MEDIUM] CVE-2015-7761: Mail in Apple OS X before 10.11 does not properly recognize user preferences, which allows attackers
Mail in Apple OS X before 10.11 does not properly recognize user preferences, which allows attackers to obtain sensitive information via an unspecified action during the printing of an e-mail message, a different vulnerability than CVE-2015-7760.
nvd
CVE-2013-5167P4MEDIUMCVSS 5.0≤ 10.8.5v10.8.0+5 more2013-10-24
CVE-2013-5167 [MEDIUM] CWE-16 CVE-2013-5167: CFNetwork in Apple Mac OS X before 10.9 does not properly support Safari's deletion of session cooki
CFNetwork in Apple Mac OS X before 10.9 does not properly support Safari's deletion of session cookies in response to a reset operation, which makes it easier for remote web servers to track users via Set-Cookie HTTP headers.
nvd
CVE-2013-5178P4MEDIUMCVSS 5.0≤ 10.8.5v10.8.0+5 more2013-10-24
CVE-2013-5178 [MEDIUM] CWE-264 CVE-2013-5178: LaunchServices in Apple Mac OS X before 10.9 does not properly restrict Unicode characters in filena
LaunchServices in Apple Mac OS X before 10.9 does not properly restrict Unicode characters in filenames, which allows context-dependent attackers to spoof file extensions via a crafted character sequence.
nvd
CVE-2020-8284P4LOWCVSS 3.7≥ 10.14.0, < 10.14.6≥ 10.15, < 10.15.7+2 more2020-12-14
CVE-2020-8284 [LOW] CWE-200 CVE-2020-8284: A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting ba
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.
nvd
CVE-2015-7116P4MEDIUMCVSS 4.3≤ 10.11.02016-01-10
CVE-2015-7116 [MEDIUM] CVE-2015-7116: libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to
libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted XML document, a different vulnerability than CVE-2015-7115.
nvd
CVE-2015-7115P4MEDIUMCVSS 4.3≤ 10.11.02016-01-10
CVE-2015-7115 [MEDIUM] CWE-119 CVE-2015-7115: libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to
libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted XML document, a different vulnerability than CVE-2015-7116.
nvd
CVE-2015-7043P4MEDIUMCVSS 4.3≤ 10.11.12015-12-11
CVE-2015-7043 [MEDIUM] CVE-2015-7043: The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 all
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to cause a denial of service via a crafted app, a different vulnerability than CVE-2015-7040, CVE-2015-7041, and CVE-2015-7042.
nvd
CVE-2015-7041P4MEDIUMCVSS 4.3≤ 10.11.12015-12-11
CVE-2015-7041 [MEDIUM] CVE-2015-7041: The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 all
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to cause a denial of service via a crafted app, a different vulnerability than CVE-2015-7040, CVE-2015-7042, and CVE-2015-7043.
nvd
CVE-2015-7042P4MEDIUMCVSS 4.3≤ 10.11.12015-12-11
CVE-2015-7042 [MEDIUM] CVE-2015-7042: The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 all
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to cause a denial of service via a crafted app, a different vulnerability than CVE-2015-7040, CVE-2015-7041, and CVE-2015-7043.
nvd
CVE-2015-7040P4MEDIUMCVSS 4.3≤ 10.11.12015-12-11
CVE-2015-7040 [MEDIUM] CVE-2015-7040: The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 all
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to cause a denial of service via a crafted app, a different vulnerability than CVE-2015-7041, CVE-2015-7042, and CVE-2015-7043.
nvd
CVE-2015-5782P4MEDIUMCVSS 4.3≤ 10.10.42015-08-17
CVE-2015-5782 [MEDIUM] CWE-200 CVE-2015-5782: ImageIO in Apple iOS before 8.4.1 and OS X before 10.10.5 does not properly initialize an unspecifie
ImageIO in Apple iOS before 8.4.1 and OS X before 10.10.5 does not properly initialize an unspecified data structure, which allows remote attackers to obtain sensitive information from process memory via a crafted TIFF image.
nvd
CVE-2015-5781P4MEDIUMCVSS 4.3≤ 10.10.42015-08-17
CVE-2015-5781 [MEDIUM] CWE-200 CVE-2015-5781: ImageIO in Apple iOS before 8.4.1 and OS X before 10.10.5 does not properly initialize an unspecifie
ImageIO in Apple iOS before 8.4.1 and OS X before 10.10.5 does not properly initialize an unspecified data structure, which allows remote attackers to obtain sensitive information from process memory via a crafted PNG image.
nvd
CVE-2015-3781P4MEDIUMCVSS 4.3≤ 10.10.42015-08-16
CVE-2015-3781 [MEDIUM] CWE-79 CVE-2015-3781: Cross-site scripting (XSS) vulnerability in Quick Look in Apple OS X before 10.10.5 allows remote at
Cross-site scripting (XSS) vulnerability in Quick Look in Apple OS X before 10.10.5 allows remote attackers to inject arbitrary web script or HTML via a previously visited web site that is rendered during a Quick Look search.
nvd
CVE-2001-1447P4HIGHCVSS 7.2v10.0v10.0.1+4 more2001-10-17
CVE-2001-1447 [HIGH] CVE-2001-1447: NetInfo Manager for Mac OS X 10.0 through 10.1 allows local users to gain root privileges by opening
NetInfo Manager for Mac OS X 10.0 through 10.1 allows local users to gain root privileges by opening applications using the (1) "recent items" and (2) "services" menus, which causes the applications to run with root privileges.
nvd
CVE-2018-4092P4MEDIUMCVSS 4.7fixed in 10.13.32018-04-03
CVE-2018-4092 [MEDIUM] CWE-362 CVE-2018-4092: An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "Kernel" component. A race condition allows attackers to bypass intended memory-read restrictions via a crafted app.
nvd
CVE-2004-0821P4HIGHCVSS 7.2v10.2.8v10.3.4+1 more2004-12-31
CVE-2004-0821 [HIGH] CVE-2004-0821: The CFPlugIn in Core Foundation framework in Mac OS X allows user supplied libraries to be loaded, w
The CFPlugIn in Core Foundation framework in Mac OS X allows user supplied libraries to be loaded, which could allow local users to gain privileges.
nvd