cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 137 of 157
CVE-2015-3720P4MEDIUMCVSS 4.3≤ 10.10.32015-07-03
CVE-2015-3720 [MEDIUM] CWE-200 CVE-2015-3720: The kernel in Apple OS X before 10.10.4 does not properly manage memory in kernel-extension APIs, wh The kernel in Apple OS X before 10.10.4 does not properly manage memory in kernel-extension APIs, which allows attackers to obtain sensitive memory-layout information via a crafted app.
nvd
CVE-2019-8769P4MEDIUMCVSS 4.3fixed in 10.152019-12-18
CVE-2019-8769 [MEDIUM] CVE-2019-8769: An issue existed in the drawing of web page elements. The issue was addressed with improved logic. T An issue existed in the drawing of web page elements. The issue was addressed with improved logic. This issue is fixed in iOS 13.1 and iPadOS 13.1, macOS Catalina 10.15. Visiting a maliciously crafted website may reveal browsing history.
nvd
CVE-2006-3506P4MEDIUMCVSS 4.6v10.4.72006-08-21
CVE-2006-3506 [MEDIUM] CVE-2006-3506: Buffer overflow in the Xsan Filesystem driver on Mac OS X 10.4.7 and OS X Server 10.4.7 allows local Buffer overflow in the Xsan Filesystem driver on Mac OS X 10.4.7 and OS X Server 10.4.7 allows local users with Xsan write access, to execute arbitrary code via unspecified vectors related to "processing a path name."
nvd
CVE-2004-0886P4MEDIUMCVSS 5.0v10.2v10.2.1+14 more2005-01-27
CVE-2004-0886 [MEDIUM] CVE-2004-0886: Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect malloc calls.
nvd
CVE-2020-9945P4MEDIUMCVSS 4.3fixed in 11.0.12020-12-08
CVE-2020-9945 [MEDIUM] CWE-1021 CVE-2020-9945: A spoofing issue existed in the handling of URLs. This issue was addressed with improved input valid A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, Safari 14.0.1. Visiting a malicious website may lead to address bar spoofing.
nvd
CVE-2017-13786P4MEDIUMCVSS 4.6≤ 10.13.02017-11-13
CVE-2017-13786 [MEDIUM] CVE-2017-13786: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "APFS" component. It does not properly restrict the DMA mapping time of FileVault decryption buffers, which allows attackers to read cleartext APFS data via a crafted Thunderbolt adapter.
nvd
CVE-2020-9978P4MEDIUMCVSS 4.5≥ 10.14, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-04-02
CVE-2020-9978 [MEDIUM] CVE-2020-9978: This issue was addressed with improved setting propagation. This issue is fixed in macOS Big Sur 11. This issue was addressed with improved setting propagation. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.0, iOS 14.0 and iPadOS 14.0. An attacker in a privileged network position may be able to unexpectedly alter application state.
nvd
CVE-2013-5190P4MEDIUMCVSS 4.3≤ 10.8.5v10.8.0+5 more2013-10-24
CVE-2013-5190 [MEDIUM] CWE-264 CVE-2013-5190: Smart Card Services in Apple Mac OS X before 10.9 does not properly implement certificate-revocation Smart Card Services in Apple Mac OS X before 10.9 does not properly implement certificate-revocation checks, which allows remote attackers to cause a denial of service (Smart Card usage outage) by interfering with the revocation-check procedure.
nvd
CVE-2014-8838P4MEDIUMCVSS 4.3≤ 10.10.12015-01-30
CVE-2014-8838 [MEDIUM] CWE-264 CVE-2014-8838: The Security component in Apple OS X before 10.10.2 does not properly process cached information abo The Security component in Apple OS X before 10.10.2 does not properly process cached information about app certificates, which allows attackers to bypass the Gatekeeper protection mechanism by leveraging access to a revoked Developer ID certificate for signing a crafted app.
nvd
CVE-2009-2825P4MEDIUMCVSS 4.3≤ 10.6.1v10.0+57 more2009-11-10
CVE-2009-2825 [MEDIUM] CVE-2009-2825: Certificate Assistant in Apple Mac OS X before 10.6.2 does not properly handle a '\0' character in a Certificate Assistant in Apple Mac OS X before 10.6.2 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408
nvd
CVE-2022-26688P4MEDIUMCVSS 4.4≥ 10.15, < 10.15.7v10.15.72022-05-26
CVE-2022-26688 [MEDIUM] CWE-59 CVE-2022-26688: An issue in the handling of symlinks was addressed with improved validation. This issue is fixed in An issue in the handling of symlinks was addressed with improved validation. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. A malicious app with root privileges may be able to modify the contents of system files.
nvd
CVE-2016-7609P4MEDIUMCVSS 6.2≤ 10.12.12017-02-20
CVE-2016-7609 [MEDIUM] CWE-476 CVE-2016-7609: An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "AppleGraphicsPowerManagement" component. It allows local users to cause a denial of service (NULL pointer dereference) via unspecified vectors.
nvd
CVE-2006-3503P4MEDIUMCVSS 5.1v10.4.72006-08-03
CVE-2006-3503 [MEDIUM] CVE-2006-3503: Integer overflow in ImageIO in Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denia Integer overflow in ImageIO in Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malformed GIF image.
nvd
CVE-2006-3501P4MEDIUMCVSS 5.1v10.4.72006-08-03
CVE-2006-3501 [MEDIUM] CVE-2006-3501: Integer overflow in ImageIO for Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a deni Integer overflow in ImageIO for Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Radiance image.
nvd
CVE-2008-1579P4MEDIUMCVSS 5.0v10.4.11v10.5+2 more2008-06-02
CVE-2008-1579 [MEDIUM] CWE-200 CVE-2008-1579: Wiki Server in Apple Mac OS X 10.5 before 10.5.3 allows remote attackers to obtain sensitive informa Wiki Server in Apple Mac OS X 10.5 before 10.5.3 allows remote attackers to obtain sensitive information (user names) by reading the error message produced upon access to a nonexistent blog.
nvd
CVE-2014-4373P4MEDIUMCVSS 5.5≤ 10.9.52014-09-18
CVE-2014-4373 [MEDIUM] CVE-2014-4373: The IntelAccelerator driver in the IOAcceleratorFamily subsystem in Apple iOS before 8 and Apple TV The IntelAccelerator driver in the IOAcceleratorFamily subsystem in Apple iOS before 8 and Apple TV before 7 allows attackers to cause a denial of service (NULL pointer dereference and device restart) via a crafted application.
nvd
CVE-2006-1446P4MEDIUMCVSS 5.0v10.3.9v10.4.62006-05-12
CVE-2006-1446 [MEDIUM] CVE-2006-1446: Keychain in Apple Mac OS X 10.3.9 and 10.4.6 might allow an application to bypass a locked Keychain Keychain in Apple Mac OS X 10.3.9 and 10.4.6 might allow an application to bypass a locked Keychain by first obtaining a reference to the Keychain when it is unlocked, then reusing that reference after the Keychain has been locked.
nvd
CVE-2018-4400P4MEDIUMCVSS 5.5fixed in 10.14.12019-04-03
CVE-2018-4400 [MEDIUM] CWE-20 CVE-2018-4400: A validation issue was addressed with improved logic. This issue affected versions prior to iOS 12.1 A validation issue was addressed with improved logic. This issue affected versions prior to iOS 12.1, macOS Mojave 10.14.1, watchOS 5.1.
nvd
CVE-2019-8538P4MEDIUMCVSS 5.5≥ 10.14.3, < 10.14.42020-10-27
CVE-2019-8538 [MEDIUM] CVE-2019-8538: A denial of service issue was addressed with improved validation. This issue is fixed in watchOS 5.2 A denial of service issue was addressed with improved validation. This issue is fixed in watchOS 5.2, macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, iOS 12.2. Processing a maliciously crafted vcf file may lead to a denial of service.
nvd
CVE-2005-1043P4MEDIUMCVSS 5.0v10.3.9v10.4+1 more2005-04-14
CVE-2005-1043 [MEDIUM] CVE-2005-1043: exif.c in PHP before 4.3.11 allows remote attackers to cause a denial of service (memory consumption exif.c in PHP before 4.3.11 allows remote attackers to cause a denial of service (memory consumption and crash) via an EXIF header with a large IFD nesting level, which causes significant stack recursion.
nvd
Apple macOS vulnerabilities | cvebase