Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 138 of 157
CVE-2008-0999P4HIGHCVSS 7.1v10.5.22008-03-18
CVE-2008-0999 [HIGH] CWE-20 CVE-2008-0999: Apple Mac OS X 10.5.2 allows user-assisted attackers to cause a denial of service (crash) via a craf
Apple Mac OS X 10.5.2 allows user-assisted attackers to cause a denial of service (crash) via a crafted Universal Disc Format (UDF) disk image, which triggers a NULL pointer dereference.
nvd
CVE-2006-4408P4MEDIUMCVSS 5.0v10.4v10.4.1+7 more2006-11-30
CVE-2006-4408 [MEDIUM] CVE-2006-4408: The Security Framework in Apple Mac OS X 10.4 through 10.4.8 allows remote attackers to cause a deni
The Security Framework in Apple Mac OS X 10.4 through 10.4.8 allows remote attackers to cause a denial of service (resource consumption) via certain public key values in an X.509 certificate that requires extra resources during signature verification. NOTE: this issue may be similar to CVE-2006-2940.
nvd
CVE-2006-3504P4MEDIUMCVSS 5.1v10.4.72006-08-03
CVE-2006-3504 [MEDIUM] CVE-2006-3504: The Download Validation in LaunchServices for Apple Mac OS X 10.4.7 can identify certain HTML as "sa
The Download Validation in LaunchServices for Apple Mac OS X 10.4.7 can identify certain HTML as "safe", which could allow attackers to execute Javascript code in local context when the "Open 'safe' files after downloading" option is enabled in Safari.
nvd
CVE-2016-1865P4MEDIUMCVSS 5.5fixed in 10.11.62016-07-22
CVE-2016-1865 [MEDIUM] CWE-476 CVE-2016-1865: The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2
The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to cause a denial of service (NULL pointer dereference) via unspecified vectors.
nvd
CVE-2018-4348P4MEDIUMCVSS 5.5fixed in 10.142019-04-03
CVE-2018-4348 [MEDIUM] CWE-20 CVE-2018-4348: A validation issue was addressed with improved logic. This issue affected versions prior to macOS Mo
A validation issue was addressed with improved logic. This issue affected versions prior to macOS Mojave 10.14.
nvd
CVE-2009-0141P4MEDIUMCVSS 5.5v10.4.11v10.5.62009-02-13
CVE-2009-0141 [MEDIUM] CWE-732 CVE-2009-0141: XTerm in Apple Mac OS X 10.4.11 and 10.5.6, when used with luit, creates tty devices with insecure w
XTerm in Apple Mac OS X 10.4.11 and 10.5.6, when used with luit, creates tty devices with insecure world-writable permissions, which allows local users to write to the Xterm of another user.
nvd
CVE-2007-2404P4MEDIUMCVSS 5.0v10.3v10.3.1+19 more2007-08-03
CVE-2007-2404 [MEDIUM] CVE-2007-2404: CRLF injection vulnerability in CFNetwork on Apple Mac OS X 10.3.9 and 10.4.10 before 20070731 allow
CRLF injection vulnerability in CFNetwork on Apple Mac OS X 10.3.9 and 10.4.10 before 20070731 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in an unspecified context. NOTE: this can be leveraged for cross-site scripting (XSS) attacks.
nvd
CVE-2008-4368P4MEDIUMCVSS 5.0v10.5.4v10.5.52008-10-01
CVE-2008-4368 [MEDIUM] CWE-310 CVE-2008-4368: The default configuration of Java 1.5 on Apple Mac OS X 10.5.4 and 10.5.5 contains a jurisdiction po
The default configuration of Java 1.5 on Apple Mac OS X 10.5.4 and 10.5.5 contains a jurisdiction policy that limits Java Cryptography Extension (JCE) key sizes to 128 bits, which makes it easier for attackers to decrypt ciphertext produced by JCE.
nvd
CVE-2010-0541P4MEDIUMCVSS 4.3v10.5.8v10.6.0+3 more2010-06-17
CVE-2010-0541 [MEDIUM] CWE-79 CVE-2010-0541: Cross-site scripting (XSS) vulnerability in the WEBrick HTTP server in Ruby in Apple Mac OS X 10.5.8
Cross-site scripting (XSS) vulnerability in the WEBrick HTTP server in Ruby in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, allows remote attackers to inject arbitrary web script or HTML via a crafted URI that triggers a UTF-7 error page.
nvd
CVE-2016-1764P4MEDIUMCVSS 4.3≤ 10.11.32016-03-24
CVE-2016-1764 [MEDIUM] CWE-200 CVE-2016-1764: The Content Security Policy (CSP) implementation in Messages in Apple OS X before 10.11.4 allows rem
The Content Security Policy (CSP) implementation in Messages in Apple OS X before 10.11.4 allows remote attackers to obtain sensitive information via a javascript: URL.
nvd
CVE-2015-5862P4MEDIUMCVSS 4.3≤ 10.10.52015-09-18
CVE-2015-5862 [MEDIUM] CWE-119 CVE-2015-5862: The Audio component in Apple iOS before 9 allows remote attackers to cause a denial of service (memo
The Audio component in Apple iOS before 9 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted audio file.
nvd
CVE-2011-0187P4MEDIUMCVSS 4.3fixed in 10.6.72011-03-23
CVE-2011-0187 [MEDIUM] CVE-2011-0187: The plug-in in QuickTime in Apple Mac OS X before 10.6.7 allows remote attackers to bypass the Same
The plug-in in QuickTime in Apple Mac OS X before 10.6.7 allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive video data via vectors involving a cross-site redirect.
nvd
CVE-2011-3220P4MEDIUMCVSS 4.3≤ 10.7.1v10.0+66 more2011-10-14
CVE-2011-3220 [MEDIUM] CWE-200 CVE-2011-3220: QuickTime in Apple Mac OS X before 10.7.2 does not properly process URL data handlers in movie files
QuickTime in Apple Mac OS X before 10.7.2 does not properly process URL data handlers in movie files, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted file.
nvd
CVE-2009-2840P4MEDIUMCVSS 4.9v10.5.82009-11-10
CVE-2009-2840 [MEDIUM] CVE-2009-2840: Spotlight in Apple Mac OS X 10.5.8 does not properly handle temporary files, which allows local user
Spotlight in Apple Mac OS X 10.5.8 does not properly handle temporary files, which allows local users to overwrite arbitrary files in the context of a different user's privileges via unspecified vectors.
nvd
CVE-2010-1803P4MEDIUMCVSS 4.3v10.6.0v10.6.1+3 more2010-11-15
CVE-2010-1803 [MEDIUM] CVE-2010-1803: Time Machine in Apple Mac OS X 10.6.x before 10.6.5 does not verify the unique identifier of its rem
Time Machine in Apple Mac OS X 10.6.x before 10.6.5 does not verify the unique identifier of its remote AFP volume, which allows remote attackers to obtain sensitive information by spoofing this volume.
nvd
CVE-2004-0514P4HIGHCVSS 7.2v10.3v10.3.1+2 more2004-08-18
CVE-2004-0514 [HIGH] CVE-2004-0514: Unknown vulnerability in LoginWindow for Mac OS X 10.3.4, related to "handling of directory services
Unknown vulnerability in LoginWindow for Mac OS X 10.3.4, related to "handling of directory services lookups."
nvd
CVE-2003-1011P4HIGHCVSS 7.2v10.0v10.0.1+18 more2004-03-29
CVE-2003-1011 [HIGH] CVE-2003-1011: Apple Mac OS X 10.0 through 10.2.8 allows local users with a USB keyboard to gain unauthorized acces
Apple Mac OS X 10.0 through 10.2.8 allows local users with a USB keyboard to gain unauthorized access by holding down the CTRL and C keys when the system is booting, which crashes the init process and leaves the user in a root shell.
nvd
CVE-2006-6906P4HIGHCVSS 7.2≤ 10.4.72006-12-31
CVE-2006-6906 [HIGH] CVE-2006-6906: Unspecified vulnerability in the Bluetooth stack on Mac OS 10.4.7 and earlier has unknown impact and
Unspecified vulnerability in the Bluetooth stack on Mac OS 10.4.7 and earlier has unknown impact and local attack vectors, related to "Mach Exception Handling", a different issue than CVE-2006-6900.
nvd
CVE-2007-4694P4MEDIUMCVSS 4.3v10.4.1v10.4.2+8 more2007-11-15
CVE-2007-4694 [MEDIUM] CWE-264 CVE-2007-4694: Safari in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to access local content via fi
Safari in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to access local content via file:// URLs.
nvd
CVE-2014-4436P4MEDIUMCVSS 4.3≤ 10.9.52014-10-18
CVE-2014-4436 [MEDIUM] CWE-119 CVE-2014-4436: IOHIDFamily in Apple OS X before 10.10 allows attackers to cause denial of service (out-of-bounds re
IOHIDFamily in Apple OS X before 10.10 allows attackers to cause denial of service (out-of-bounds read operation) via a crafted application.
nvd