cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 133 of 157
CVE-2017-7119P4MEDIUMCVSS 5.5≤ 10.12.62017-10-23
CVE-2017-7119 [MEDIUM] CWE-20 CVE-2017-7119: An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involve An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "IOFireWireFamily" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvd
CVE-2017-7045P4MEDIUMCVSS 5.5≤ 10.12.52017-07-20
CVE-2017-7045 [MEDIUM] CWE-20 CVE-2017-7045: An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvd
CVE-2017-7067P4MEDIUMCVSS 5.5≤ 10.12.52017-07-20
CVE-2017-7067 [MEDIUM] CVE-2017-7067: An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvd
CVE-2017-7036P4MEDIUMCVSS 5.5≤ 10.12.52017-07-20
CVE-2017-7036 [MEDIUM] CWE-125 CVE-2017-7036: An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvd
CVE-2017-13842P4MEDIUMCVSS 5.5≤ 10.13.02017-11-13
CVE-2017-13842 [MEDIUM] CWE-200 CVE-2017-13842: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvd
CVE-2017-13841P4MEDIUMCVSS 5.5≤ 10.13.02017-11-13
CVE-2017-13841 [MEDIUM] CWE-200 CVE-2017-13841: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvd
CVE-2017-13836P4MEDIUMCVSS 5.5≤ 10.13.02017-11-13
CVE-2017-13836 [MEDIUM] CWE-200 CVE-2017-13836: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvd
CVE-2017-13821P4MEDIUMCVSS 5.5≤ 10.13.02017-11-13
CVE-2017-13821 [MEDIUM] CWE-200 CVE-2017-13821: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "CFString" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvd
CVE-2017-13822P4MEDIUMCVSS 5.5≤ 10.13.02017-11-13
CVE-2017-13822 [MEDIUM] CWE-200 CVE-2017-13822: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Quick Look" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvd
CVE-2017-13823P4MEDIUMCVSS 5.5≤ 10.13.02017-11-13
CVE-2017-13823 [MEDIUM] CWE-200 CVE-2017-13823: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "QuickTime" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvd
CVE-2017-13840P4MEDIUMCVSS 5.5≤ 10.13.02017-11-13
CVE-2017-13840 [MEDIUM] CWE-200 CVE-2017-13840: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvd
CVE-2017-13818P4MEDIUMCVSS 5.5≤ 10.13.02017-11-13
CVE-2017-13818 [MEDIUM] CWE-200 CVE-2017-13818: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvd
CVE-2018-4396P4MEDIUMCVSS 5.5fixed in 10.142019-04-03
CVE-2018-4396 [MEDIUM] CWE-20 CVE-2018-4396: A validation issue was addressed with improved input sanitization. This issue affected versions prio A validation issue was addressed with improved input sanitization. This issue affected versions prior to macOS Mojave 10.14.
nvd
CVE-2018-4418P4MEDIUMCVSS 5.5fixed in 10.142019-04-03
CVE-2018-4418 [MEDIUM] CWE-20 CVE-2018-4418: A validation issue was addressed with improved input sanitization. This issue affected versions prio A validation issue was addressed with improved input sanitization. This issue affected versions prior to macOS Mojave 10.14.
nvd
CVE-2015-5523P4MEDIUMCVSS 4.3≤ 10.6.82015-08-11
CVE-2015-5523 [MEDIUM] CWE-119 CVE-2015-5523: The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial o The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving multiple whitespace characters before an empty href, which triggers a large memory allocation.
nvd
CVE-2005-3702P4MEDIUMCVSS 5.0v10.3.9v10.4.32005-12-01
CVE-2005-3702 [MEDIUM] CVE-2005-3702: Safari in Mac OS X and OS X Server 10.3.9 and 10.4.3 allows remote attackers to cause files to be do Safari in Mac OS X and OS X Server 10.3.9 and 10.4.3 allows remote attackers to cause files to be downloaded to locations outside the download directory via a long file name.
nvd
CVE-2018-4417P4MEDIUMCVSS 5.5fixed in 10.142019-04-03
CVE-2018-4417 [MEDIUM] CWE-20 CVE-2018-4417: A validation issue was addressed with improved input sanitization. This issue affected versions prio A validation issue was addressed with improved input sanitization. This issue affected versions prior to macOS Mojave 10.14.
nvd
CVE-2017-6990P4MEDIUMCVSS 5.5≤ 10.12.42017-05-22
CVE-2017-6990 [MEDIUM] CVE-2017-6990: An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "HFS" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvd
CVE-2020-29615P4MEDIUMCVSS 5.5≥ 10.14, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-04-02
CVE-2020-29615 [MEDIUM] CWE-125 CVE-2020-29615: An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 7 An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 7.2, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. Processing a maliciously crafted image may lead to a denial of service.
nvd
CVE-2018-4462P4MEDIUMCVSS 5.5fixed in 10.14.22019-04-03
CVE-2018-4462 [MEDIUM] CWE-20 CVE-2018-4462: A validation issue was addressed with improved input sanitization. This issue affected versions prio A validation issue was addressed with improved input sanitization. This issue affected versions prior to macOS Mojave 10.14.2.
nvd
Apple macOS vulnerabilities | cvebase