Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
277
Exploited in wild
28
Severity breakdown
CRITICAL302HIGH1409MEDIUM1236LOW192

Vulnerabilities

Page 139 of 157
CVE-2007-4688MEDIUMCVSS 5.0v10.4.1v10.4.2+8 more2007-11-15
CVE-2007-4688 [MEDIUM] CWE-200 CVE-2007-4688: The Networking component in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to obtain al The Networking component in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to obtain all addresses for a host, including link-local addresses, via a Node Information Query.
nvd
CVE-2007-4694MEDIUMCVSS 4.3v10.4.1v10.4.2+8 more2007-11-15
CVE-2007-4694 [MEDIUM] CWE-264 CVE-2007-4694: Safari in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to access local content via fi Safari in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to access local content via file:// URLs.
nvd
CVE-2007-4696MEDIUMCVSS 4.3v10.4.1v10.4.2+8 more2007-11-15
CVE-2007-4696 [MEDIUM] CWE-362 CVE-2007-4696: Race condition in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to obtain i Race condition in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to obtain information for forms from other sites via unknown vectors related to "page transitions" in Safari.
nvd
CVE-2007-4697MEDIUMCVSS 6.8v10.4.1v10.4.2+8 more2007-11-15
CVE-2007-4697 [MEDIUM] CVE-2007-4697: Unspecified vulnerability in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers Unspecified vulnerability in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via unknown vectors related to browser history, which triggers memory corruption.
nvd
CVE-2007-4681MEDIUMCVSS 6.9v10.3.9v10.4+11 more2007-11-15
CVE-2007-4681 [MEDIUM] CWE-119 CVE-2007-4681: Buffer overflow in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 allows local use Buffer overflow in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted directory hierarchy.
nvd
CVE-2007-4701LOWCVSS 2.1v10.4.1v10.4.2+8 more2007-11-15
CVE-2007-4701 [LOW] CWE-264 CVE-2007-4701: WebKit on Apple Mac OS X 10.4 through 10.4.10 does not create temporary files securely when Safari i WebKit on Apple Mac OS X 10.4 through 10.4.10 does not create temporary files securely when Safari is previewing a PDF file, which allows local users to read the contents of that file.
nvd
CVE-2007-4679LOWCVSS 2.6≥ 10.4, ≤ 10.4.102007-11-15
CVE-2007-4679 [LOW] CWE-264 CVE-2007-4679: CFFTP in CFNetwork for Apple Mac OS X 10.4 through 10.4.10 allows remote FTP servers to force client CFFTP in CFNetwork for Apple Mac OS X 10.4 through 10.4.10 allows remote FTP servers to force clients to connect to other hosts via crafted responses to FTP PASV commands.
nvd
CVE-2007-3751CRITICALCVSS 9.3v10.3.9v10.4.10+1 more2007-11-07
CVE-2007-3751 [CRITICAL] CVE-2007-3751: Unspecified vulnerability in QuickTime for Java in Apple QuickTime before 7.3 allows remote attacker Unspecified vulnerability in QuickTime for Java in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via untrusted Java applets that gain privileges via unspecified vectors.
nvd
CVE-2007-4675CRITICALCVSS 9.3v10.3.9v10.4.10+1 more2007-11-07
CVE-2007-4675 [CRITICAL] CWE-119 CVE-2007-4675: Heap-based buffer overflow in the QuickTime VR extension 7.2.0.240 in QuickTime.qts in Apple QuickTi Heap-based buffer overflow in the QuickTime VR extension 7.2.0.240 in QuickTime.qts in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via a QTVR (QuickTime Virtual Reality) movie file containing a large size field in the atom header of a panorama sample atom.
nvd
CVE-2007-4676CRITICALCVSS 9.3v10.3.9v10.4.10+1 more2007-11-07
CVE-2007-4676 [CRITICAL] CWE-119 CVE-2007-4676: Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrar Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via malformed elements when parsing (1) Poly type (0x0070 through 0x0074) and (2) PackBitsRgn field (0x0099) opcodes in a PICT image.
nvd
CVE-2007-4677CRITICALCVSS 9.3v10.3.9v10.4.10+1 more2007-11-07
CVE-2007-4677 [CRITICAL] CWE-119 CVE-2007-4677: Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrar Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via an invalid color table size when parsing the color table atom (CTAB) in a movie file, related to the CTAB RGB values.
nvd
CVE-2007-1661MEDIUMCVSS 6.4v10.4.112007-11-07
CVE-2007-1661 [MEDIUM] CVE-2007-1661: Perl-Compatible Regular Expression (PCRE) library before 7.3 backtracks too far when matching certai Perl-Compatible Regular Expression (PCRE) library before 7.3 backtracks too far when matching certain input bytes against some regex patterns in non-UTF-8 mode, which allows context-dependent attackers to obtain sensitive information or cause a denial of service (crash), as demonstrated by the "\X?\d" and "\P{L}?\d" patterns.
nvd
CVE-2007-2404MEDIUMCVSS 5.0v10.3v10.3.1+19 more2007-08-03
CVE-2007-2404 [MEDIUM] CVE-2007-2404: CRLF injection vulnerability in CFNetwork on Apple Mac OS X 10.3.9 and 10.4.10 before 20070731 allow CRLF injection vulnerability in CFNetwork on Apple Mac OS X 10.3.9 and 10.4.10 before 20070731 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in an unspecified context. NOTE: this can be leveraged for cross-site scripting (XSS) attacks.
nvd
CVE-2007-3744MEDIUMCVSS 5.8v10.4v10.4.1+9 more2007-08-03
CVE-2007-3744 [MEDIUM] CWE-119 CVE-2007-3744: Heap-based buffer overflow in the UPnP IGD (Internet Gateway Device Standardized Device Control Prot Heap-based buffer overflow in the UPnP IGD (Internet Gateway Device Standardized Device Control Protocol) implementation in mDNSResponder on Apple Mac OS X 10.4.10 before 20070731 allows network-adjacent remote attackers to execute arbitrary code via a crafted packet.
nvd
CVE-2007-3828CRITICALCVSS 10.0v10.4v10.4.1+9 more2007-07-17
CVE-2007-3828 [CRITICAL] CVE-2007-3828: Unspecified vulnerability in mDNSResponder in Apple Mac OS X allows remote attackers to execute arbi Unspecified vulnerability in mDNSResponder in Apple Mac OS X allows remote attackers to execute arbitrary code via unspecified vectors, a related issue to CVE-2007-2386.
nvd
CVE-2007-3798CRITICALCVSS 9.8PoC≥ 10.0.0, < 10.4.112007-07-16
CVE-2007-3798 [CRITICAL] CWE-252 CVE-2007-3798: Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote atta Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value.
nvd
CVE-2007-2399CRITICALCVSS 9.3v10.3.9v10.4.92007-06-25
CVE-2007-2399 [CRITICAL] CVE-2007-2399: WebKit in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1 performs an "invalid type WebKit in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1 performs an "invalid type conversion", which allows remote attackers to execute arbitrary code via unspecified frame sets that trigger memory corruption.
nvd
CVE-2007-2401MEDIUMCVSS 4.3PoCv10.3.9v10.4.92007-06-25
CVE-2007-2401 [MEDIUM] CWE-79 CVE-2007-2401: CRLF injection vulnerability in WebCore in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone befor CRLF injection vulnerability in WebCore in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1, allows remote attackers to inject arbitrary HTTP headers via LF characters in an XMLHttpRequest request, which are not filtered when serializing headers via the setRequestHeader function. NOTE: this issue can be leveraged for cross-site scriptin
nvd
CVE-2007-0750CRITICALCVSS 9.3v10.4v10.4.1+8 more2007-05-24
CVE-2007-0750 [CRITICAL] CVE-2007-0750: Integer overflow in CoreGraphics in Apple Mac OS X 10.4 up to 10.4.9 allows remote user-assisted att Integer overflow in CoreGraphics in Apple Mac OS X 10.4 up to 10.4.9 allows remote user-assisted attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted PDF file.
nvd
CVE-2007-2386CRITICALCVSS 9.4PoCv10.4v10.4.1+7 more2007-05-24
CVE-2007-2386 [CRITICAL] CVE-2007-2386: Buffer overflow in mDNSResponder in Apple Mac OS X 10.4 up to 10.4.9 allows remote attackers to caus Buffer overflow in mDNSResponder in Apple Mac OS X 10.4 up to 10.4.9 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted UPnP Internet Gateway Device (IGD) packet.
nvd