Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 134 of 157
CVE-2022-32785P4MEDIUMCVSS 5.5v10.15.72022-09-23
CVE-2022-32785 [MEDIUM] CWE-476 CVE-2022-32785: A null pointer dereference was addressed with improved validation. This issue is fixed in iOS 15.6 a
A null pointer dereference was addressed with improved validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing an image may lead to a denial-of-service.
nvd
CVE-2009-0153P4MEDIUMCVSS 4.3v10.5.0v10.5.1+5 more2009-05-13
CVE-2009-0153 [MEDIUM] CWE-79 CVE-2009-0153: International Components for Unicode (ICU) 4.0, 3.6, and other 3.x versions, as used in Apple Mac OS
International Components for Unicode (ICU) 4.0, 3.6, and other 3.x versions, as used in Apple Mac OS X 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Fedora 9 and 10, and possibly other operating systems, does not properly handle invalid byte sequences during Unicode conversion, which might allow remote att
nvd
CVE-2011-0183P4MEDIUMCVSS 5.0≤ 10.6.6v10.5.8+6 more2011-03-23
CVE-2011-0183 [MEDIUM] CWE-189 CVE-2011-0183: Libinfo in Apple Mac OS X before 10.6.7 does not properly handle an unspecified integer field in an
Libinfo in Apple Mac OS X before 10.6.7 does not properly handle an unspecified integer field in an NFS RPC packet, which allows remote attackers to cause a denial of service (lockd, statd, mountd, or portmap outage) via a crafted packet, related to an "integer truncation issue."
nvd
CVE-2019-8774P4MEDIUMCVSS 5.5fixed in 10.152020-10-27
CVE-2019-8774 [MEDIUM] CWE-20 CVE-2019-8774: A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS
A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 13.1 and iPadOS 13.1, macOS Catalina 10.15. Parsing a maliciously crafted iBooks file may lead to a persistent denial-of-service.
nvd
CVE-2007-4688P4MEDIUMCVSS 5.0v10.4.1v10.4.2+8 more2007-11-15
CVE-2007-4688 [MEDIUM] CWE-200 CVE-2007-4688: The Networking component in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to obtain al
The Networking component in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to obtain all addresses for a host, including link-local addresses, via a Node Information Query.
nvd
CVE-2016-7628P4MEDIUMCVSS 5.5≤ 10.12.12017-02-20
CVE-2016-7628 [MEDIUM] CWE-264 CVE-2016-7628: An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Assets" component, which allows local users to bypass intended permission restrictions and change a downloaded mobile asset via unspecified vectors.
nvd
CVE-2004-0518P4HIGHCVSS 7.5v10.3v10.3.1+2 more2004-08-18
CVE-2004-0518 [HIGH] CVE-2004-0518: Unknown vulnerability in AppleFileServer for Mac OS X 10.3.4, related to "the use of SSH and reporti
Unknown vulnerability in AppleFileServer for Mac OS X 10.3.4, related to "the use of SSH and reporting errors," has unknown impact and attack vectors.
nvd
CVE-2005-3704P4MEDIUMCVSS 5.0v10.4v10.4.1+2 more2005-12-01
CVE-2005-3704 [MEDIUM] CVE-2005-3704: System log server in Mac OS X and OS X Server 10.4 through 10.4.3 allows remote attackers to spoof s
System log server in Mac OS X and OS X Server 10.4 through 10.4.3 allows remote attackers to spoof syslog messages in log files by injecting various control characters such as newline (NL).
nvd
CVE-2013-7040P4MEDIUMCVSS 4.3≤ 10.10.42014-05-19
CVE-2013-7040 [MEDIUM] CVE-2013-7040: Python 2.7 before 3.4 only uses the last eight bits of the prefix to randomize hash values, which ca
Python 2.7 before 3.4 only uses the last eight bits of the prefix to randomize hash values, which causes it to compute hash values without restricting the ability to trigger hash collisions predictably and makes it easier for context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash ta
nvd
CVE-2008-2331P4MEDIUMCVSS 5.0v10.5v10.5.1+3 more2008-09-16
CVE-2008-2331 [MEDIUM] CWE-264 CVE-2008-2331: Finder in Apple Mac OS X 10.5 through 10.5.4 does not properly update permission data in the Get Inf
Finder in Apple Mac OS X 10.5 through 10.5.4 does not properly update permission data in the Get Info window after a lock operation that modifies Sharing & Permissions in a filesystem, which might allow local users to leverage weak permissions that were not intended by an administrator.
nvd
CVE-2011-0231P4MEDIUMCVSS 5.0≤ 10.7.1v10.0+66 more2011-10-14
CVE-2011-0231 [MEDIUM] CWE-200 CVE-2011-0231: CFNetwork in Apple Mac OS X before 10.7.2 does not properly follow an intended cookie-storage policy
CFNetwork in Apple Mac OS X before 10.7.2 does not properly follow an intended cookie-storage policy, which makes it easier for remote web servers to track users via a cookie, related to a "synchronization issue."
nvd
CVE-2008-4224P4HIGHCVSS 7.1≤ 10.5.5v10.4.11+5 more2008-12-17
CVE-2008-4224 [HIGH] CWE-20 CVE-2008-4224: UDF in Apple Mac OS X before 10.5.6 allows user-assisted attackers to cause a denial of service (sys
UDF in Apple Mac OS X before 10.5.6 allows user-assisted attackers to cause a denial of service (system crash) via a malformed UDF volume in a crafted ISO file.
nvd
CVE-2007-4678P4HIGHCVSS 7.1v10.3.9v10.4+10 more2007-11-15
CVE-2007-4678 [HIGH] CVE-2007-4678: AppleRAID in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 allows attackers to cause a denial of se
AppleRAID in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 allows attackers to cause a denial of service (crash) via a crafted striped disk image, which triggers a NULL pointer dereference when it is mounted.
nvd
CVE-2005-1260P4MEDIUMCVSS 5.0fixed in 10.4.112005-05-19
CVE-2005-1260 [MEDIUM] CWE-400 CVE-2005-1260: bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bz
bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (a.k.a "decompression bomb").
nvd
CVE-2014-4439P4MEDIUMCVSS 4.3≤ 10.9.52014-10-18
CVE-2014-4439 [MEDIUM] CWE-200 CVE-2014-4439: Mail in Apple OS X before 10.10 does not properly recognize the removal of a recipient address from
Mail in Apple OS X before 10.10 does not properly recognize the removal of a recipient address from a message, which makes it easier for remote attackers to obtain sensitive information in opportunistic circumstances by reading a message intended exclusively for other recipients.
nvd
CVE-2013-0967P4MEDIUMCVSS 4.3v10.7.0v10.7.1+7 more2013-03-15
CVE-2013-0967 [MEDIUM] CVE-2013-0967: CoreTypes in Apple Mac OS X before 10.8.3 includes JNLP files in the list of safe file types, which
CoreTypes in Apple Mac OS X before 10.8.3 includes JNLP files in the list of safe file types, which allows remote attackers to bypass a Java plug-in disabled setting, and trigger the launch of Java Web Start applications, via a crafted web site.
nvd
CVE-2015-7058P4MEDIUMCVSS 4.3≤ 10.11.12015-12-11
CVE-2015-7058 [MEDIUM] CWE-200 CVE-2015-7058: Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 improperly validate keychain item ACL
Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 improperly validate keychain item ACLs, which allows attackers to obtain access to keychain items via a crafted app.
nvd
CVE-2015-3782P4MEDIUMCVSS 4.3≤ 10.10.42015-08-16
CVE-2015-3782 [MEDIUM] CWE-200 CVE-2015-3782: CloudKit in Apple iOS before 8.4.1 and OS X before 10.10.5 allows attackers to access an iCloud user
CloudKit in Apple iOS before 8.4.1 and OS X before 10.10.5 allows attackers to access an iCloud user record associated with a previous user's login session via a crafted app.
nvd
CVE-2015-3766P4MEDIUMCVSS 4.3≤ 10.10.42015-08-16
CVE-2015-3766 [MEDIUM] CWE-200 CVE-2015-3766: The kernel in Apple iOS before 8.4.1 and OS X before 10.10.5 does not properly restrict the mach_por
The kernel in Apple iOS before 8.4.1 and OS X before 10.10.5 does not properly restrict the mach_port_space_info interface, which allows attackers to obtain sensitive memory-layout information via a crafted app.
nvd
CVE-2015-5859P4MEDIUMCVSS 4.3≤ 10.10.42015-11-22
CVE-2015-5859 [MEDIUM] CWE-200 CVE-2015-5859: The CFNetwork HTTPProtocol component in Apple iOS before 9 and OS X before 10.11 does not properly r
The CFNetwork HTTPProtocol component in Apple iOS before 9 and OS X before 10.11 does not properly recognize the HSTS preload list during a Safari private-browsing session, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.
nvd