Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 132 of 157
CVE-2005-0974P4HIGHCVSS 7.2v10.0v10.0.1+28 more2005-05-12
CVE-2005-0974 [HIGH] CVE-2005-0974: Unknown vulnerability in the nfs_mount call in Mac OS X 10.3.9 and earlier allows local users to gai
Unknown vulnerability in the nfs_mount call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments.
nvd
CVE-2005-2504P4HIGHCVSS 7.2v10.4.22005-08-19
CVE-2005-2504 [HIGH] CVE-2005-2504: The System Profiler in Mac OS X 10.4.2 labels a Bluetooth device with "Requires Authentication: No"
The System Profiler in Mac OS X 10.4.2 labels a Bluetooth device with "Requires Authentication: No" even when the user has selected the "Require pairing for security" option, which could confuse users about which setting is valid.
nvd
CVE-2003-0088P4HIGHCVSS 7.2v10.2v10.2.1+2 more2003-03-03
CVE-2003-0088 [HIGH] CVE-2003-0088: TruBlueEnvironment for MacOS 10.2.3 and earlier allows local users to overwrite or create arbitrary
TruBlueEnvironment for MacOS 10.2.3 and earlier allows local users to overwrite or create arbitrary files and gain root privileges by setting a certain environment variable that is used to write debugging information.
nvd
CVE-2015-1091P4MEDIUMCVSS 4.3≤ 10.10.22015-04-10
CVE-2015-1091 [MEDIUM] CWE-200 CVE-2015-1091: The CFNetwork Session component in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not prope
The CFNetwork Session component in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not properly handle request headers during processing of redirects in HTTP responses, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
nvd
CVE-2008-0055P4HIGHCVSS 7.2v10.4.112008-03-18
CVE-2008-0055 [HIGH] CWE-362 CVE-2008-0055: Foundation in Apple Mac OS X 10.4.11 creates world-writable directories while NSFileManager copies f
Foundation in Apple Mac OS X 10.4.11 creates world-writable directories while NSFileManager copies files recursively and only modifies the permissions afterward, which allows local users to modify copied files to cause a denial of service and possibly gain privileges.
nvd
CVE-2012-3720P4MEDIUMCVSS 4.3≤ 10.7.4v10.0+71 more2012-09-20
CVE-2012-3720 [MEDIUM] CWE-255 CVE-2012-3720: Mobile Accounts in Apple Mac OS X before 10.7.5 and 10.8.x before 10.8.2 saves password hashes for e
Mobile Accounts in Apple Mac OS X before 10.7.5 and 10.8.x before 10.8.2 saves password hashes for external-account use even if external accounts are not enabled, which might allow remote attackers to determine passwords via unspecified access to a mobile account.
nvd
CVE-2007-0724P4MEDIUMCVSS 6.9v10.3.9v10.4+8 more2007-03-13
CVE-2007-0724 [MEDIUM] CVE-2007-0724: The IOKit HID interface in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 does not sufficiently limit
The IOKit HID interface in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 does not sufficiently limit access to certain controls, which allows local users to gain privileges by using HID device events to read keystrokes from the console.
nvd
CVE-2015-5943P4MEDIUMCVSS 4.3≤ 10.11.02015-10-23
CVE-2015-5943 [MEDIUM] CWE-254 CVE-2015-5943: SecurityAgent in Apple OS X before 10.11.1 does not prevent synthetic clicks from reaching keychain
SecurityAgent in Apple OS X before 10.11.1 does not prevent synthetic clicks from reaching keychain windows, which allows attackers to bypass intended access restrictions via a crafted app.
nvd
CVE-2015-3709P4MEDIUMCVSS 6.9≤ 10.10.32015-07-03
CVE-2015-3709 [MEDIUM] CWE-362 CVE-2015-3709: Race condition in kext tools in Apple OS X before 10.10.4 allows local users to bypass intended sign
Race condition in kext tools in Apple OS X before 10.10.4 allows local users to bypass intended signature requirements for kernel extensions by leveraging improper pathname validation.
nvd
CVE-2014-4438P4MEDIUMCVSS 6.9≤ 10.9.52014-10-18
CVE-2014-4438 [MEDIUM] CWE-362 CVE-2014-4438: Race condition in LoginWindow in Apple OS X before 10.10 allows physically proximate attackers to ob
Race condition in LoginWindow in Apple OS X before 10.10 allows physically proximate attackers to obtain access by leveraging an unattended workstation on which screen locking had been attempted.
nvd
CVE-2006-3497P4MEDIUMCVSS 5.1v10.3.9v10.4.72006-08-02
CVE-2006-3497 [MEDIUM] CVE-2006-3497: Unspecified vulnerability in the "compression state handling" in Bom for Apple Mac OS X 10.3.9 and 1
Unspecified vulnerability in the "compression state handling" in Bom for Apple Mac OS X 10.3.9 and 10.4.7 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Zip archive.
nvd
CVE-2007-0299P4HIGHCVSS 7.1v10.4.82007-01-17
CVE-2007-0299 [HIGH] CVE-2007-0299: Integer overflow in the byte_swap_sbin function in bsd/ufs/ufs/ufs_byte_order.c in Mac OS X 10.4.8 a
Integer overflow in the byte_swap_sbin function in bsd/ufs/ufs/ufs_byte_order.c in Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service (kernel panic) by mounting a crafted Unix File System (UFS) DMG image, which triggers an invalid pointer dereference.
nvd
CVE-2020-11765P4MEDIUMCVSS 5.5≥ 10.13.0, < 10.13.6≥ 10.14.0, < 10.14.6+3 more2020-04-14
CVE-2020-11765 [MEDIUM] CWE-125 CVE-2020-11765: An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h
An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier, leading to an out-of-bounds read.
nvd
CVE-2018-4198P4MEDIUMCVSS 5.5fixed in 10.13.52018-06-08
CVE-2018-4198 [MEDIUM] CWE-20 CVE-2018-4198: An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "UIKit" component. It allows remote attackers to cause a denial of service via a crafted text file.
nvd
CVE-2017-2417P4MEDIUMCVSS 5.5≤ 10.12.32017-04-02
CVE-2017-2417 [MEDIUM] CWE-835 CVE-2017-2417: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "CoreGraphics" component. It allows remote attackers to cause a denial of service (infinite recursion) via a crafted image.
nvd
CVE-2018-4138P4MEDIUMCVSS 5.5fixed in 10.13.42018-04-03
CVE-2018-4138 [MEDIUM] CWE-200 CVE-2018-4138: An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "NVIDIA Graphics Drivers" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvd
CVE-2021-30776P4MEDIUMCVSS 5.5≥ 10.15, ≤ 10.15.6v10.15.72021-09-08
CVE-2021-30776 [MEDIUM] CVE-2021-30776: A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur
A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-004 Catalina. Playing a malicious audio file may lead to an unexpected application termination.
nvd
CVE-2018-4141P4MEDIUMCVSS 5.5fixed in 10.13.52018-06-08
CVE-2018-4141 [MEDIUM] CWE-200 CVE-2018-4141: An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvd
CVE-2018-4159P4MEDIUMCVSS 5.5fixed in 10.13.52018-06-08
CVE-2018-4159 [MEDIUM] CWE-200 CVE-2018-4159: An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Graphics Drivers" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvd
CVE-2018-4253P4MEDIUMCVSS 5.5fixed in 10.13.52018-06-08
CVE-2018-4253 [MEDIUM] CWE-125 CVE-2018-4253: An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "AMD" component. It allows local users to bypass intended memory-read restrictions or cause a denial of service (out-of-bounds read of kernel memory) via a crafted app.
nvd