cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 139 of 157
CVE-2010-3796P4MEDIUMCVSS 4.3v10.5.8v10.6.0+4 more2010-11-16
CVE-2010-3796 [MEDIUM] CWE-200 CVE-2010-3796: Safari RSS in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not block Java applets in an RSS f Safari RSS in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not block Java applets in an RSS feed, which allows remote attackers to obtain sensitive information via a feed: URL containing an applet that performs DOM modifications.
nvd
CVE-2006-1220P4MEDIUMCVSS 4.6v10.0v10.0.1+34 more2006-03-14
CVE-2006-1220 [MEDIUM] CVE-2006-1220: Integer overflow in the mach_msg_send function in the kernel for Mac OS X might allow local users to Integer overflow in the mach_msg_send function in the kernel for Mac OS X might allow local users to execute arbitrary code via unknown attack vectors related to a large message header size, which leads to a heap-based buffer overflow.
nvd
CVE-2014-4432P4MEDIUMCVSS 4.7≤ 10.9.52014-10-18
CVE-2014-4432 [MEDIUM] CWE-310 CVE-2014-4432: fdesetup in Apple OS X before 10.10 does not properly display the encryption status in between a set fdesetup in Apple OS X before 10.10 does not properly display the encryption status in between a setting-update action and a reboot action, which might make it easier for physically proximate attackers to obtain cleartext data by leveraging ignorance of the reboot requirement.
nvd
CVE-2005-0969P4MEDIUMCVSS 4.6v10.0v10.0.1+27 more2005-05-12
CVE-2005-0969 [MEDIUM] CVE-2005-0969: Heap-based buffer overflow in the syscall emulation functionality in Mac OS X before 10.3.9 allows l Heap-based buffer overflow in the syscall emulation functionality in Mac OS X before 10.3.9 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via crafted parameters.
nvd
CVE-2019-8550P4MEDIUMCVSS 4.3fixed in 10.12.6≥ 10.13, < 10.13.6+3 more2019-12-18
CVE-2019-8550 [MEDIUM] CWE-459 CVE-2019-8550: An issue existed in the pausing of FaceTime video. The issue was resolved with improved logic. This An issue existed in the pausing of FaceTime video. The issue was resolved with improved logic. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, watchOS 5.2. A user’s video may not be paused in a FaceTime call if they exit the FaceTime app while the call is ringing.
nvd
CVE-2019-8670P4MEDIUMCVSS 4.3fixed in 10.14.62019-12-18
CVE-2019-8670 [MEDIUM] CWE-20 CVE-2019-8670: An inconsistent user interface issue was addressed with improved state management. This issue is fix An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.6, Safari 12.1.2. Visiting a malicious website may lead to address bar spoofing.
nvd
CVE-2013-5185P4MEDIUMCVSS 4.3≤ 10.8.5v10.8.0+5 more2013-10-24
CVE-2013-5185 [MEDIUM] CWE-310 CVE-2013-5185: The ldapsearch command-line program in OpenLDAP in Apple Mac OS X before 10.9 does not properly proc The ldapsearch command-line program in OpenLDAP in Apple Mac OS X before 10.9 does not properly process the minssf configuration setting, which allows remote attackers to obtain sensitive information by leveraging unintended weak encryption and sniffing the network.
nvd
CVE-2015-5894P4MEDIUMCVSS 4.3≤ 10.10.52015-10-09
CVE-2015-5894 [MEDIUM] CWE-17 CVE-2015-5894: The X.509 certificate-trust implementation in Apple OS X before 10.11 does not recognize that the kS The X.509 certificate-trust implementation in Apple OS X before 10.11 does not recognize that the kSecRevocationRequirePositiveResponse flag implies a revocation-checking requirement, which makes it easier for man-in-the-middle attackers to spoof endpoints by leveraging access to a revoked certificate.
nvd
CVE-2020-9857P4MEDIUMCVSS 4.3fixed in 10.15.52020-10-27
CVE-2020-9857 [MEDIUM] CVE-2020-9857: An issue existed in the parsing of URLs. This issue was addressed with improved input validation. Th An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.5, Security Update 2020-003 Mojave, Security Update 2020-003 High Sierra. A malicious website may be able to exfiltrate autofilled data in Safari.
nvd
CVE-2020-9935P4MEDIUMCVSS 4.3fixed in 10.15.62020-10-22
CVE-2020-9935 [MEDIUM] CVE-2020-9935: A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10 A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15.6. A user may be unexpectedly logged in to another user’s account.
nvd
CVE-2022-32781P4MEDIUMCVSS 4.4v10.15.72022-09-23
CVE-2022-32781 [MEDIUM] CWE-269 CVE-2022-32781: This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4, i This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5, Security Update 2022-005 Catalina, macOS Big Sur 11.6.8. An app with root privileges may be able to access private information.
nvd
CVE-2022-32857P4MEDIUMCVSS 4.3v10.15.72022-08-24
CVE-2022-32857 [MEDIUM] CWE-319 CVE-2022-32857: This issue was addressed by using HTTPS when sending information over the network. This issue is fix This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6, tvOS 15.6, watchOS 8.7. A user in a privileged network position can track a user’s activity.
nvd
CVE-2013-5175P4MEDIUMCVSS 6.6≤ 10.8.5v10.8.0+5 more2013-10-24
CVE-2013-5175 [MEDIUM] CWE-20 CVE-2013-5175: The kernel in Apple Mac OS X before 10.9 allows local users to obtain sensitive information or cause The kernel in Apple Mac OS X before 10.9 allows local users to obtain sensitive information or cause a denial of service (out-of-bounds read and system crash) via a crafted Mach-O file.
nvd
CVE-2006-1552P4MEDIUMCVSS 5.0v10.4v10.4.1+4 more2006-03-31
CVE-2006-1552 [MEDIUM] CWE-189 CVE-2006-1552: Integer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to cause a d Integer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to cause a denial of service (crash) via a crafted JPEG image with malformed JPEG metadata, as demonstrated using Safari, aka "Deja-Doom".
nvd
CVE-2019-8842P4LOWCVSS 3.3fixed in 10.15.22020-10-27
CVE-2019-8842 [LOW] CWE-120 CVE-2019-8842: A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. In certain configurations, a remote attacker may be able to submit arbitrary print jobs.
nvd
CVE-2010-1381P4LOWCVSS 3.5v10.5.8v10.6.0+3 more2010-06-17
CVE-2010-1381 [LOW] CVE-2010-1381: The default configuration of SMB File Server in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, enabl The default configuration of SMB File Server in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, enables support for wide links, which allows remote authenticated users to access arbitrary files via vectors involving symbolic links. NOTE: this might overlap CVE-2010-0926.
nvd
CVE-2016-4701P4MEDIUMCVSS 6.2≤ 10.11.62016-09-25
CVE-2016-4701 [MEDIUM] CWE-20 CVE-2016-4701: Application Firewall in Apple OS X before 10.12 allows local users to cause a denial of service via Application Firewall in Apple OS X before 10.12 allows local users to cause a denial of service via vectors involving a crafted SO_EXECPATH environment variable.
nvd
CVE-2015-8035P4LOWCVSS 2.6≤ 10.11.32015-11-18
CVE-2015-8035 [LOW] CWE-399 CVE-2015-8035: The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, whic The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.
nvd
CVE-2006-3496P4MEDIUMCVSS 5.0v10.3.9v10.4.72006-08-02
CVE-2006-3496 [MEDIUM] CVE-2006-3496: AFP Server in Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause denial of service (c AFP Server in Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause denial of service (crash) via an invalid AFP request that triggers an unchecked error condition.
nvd
CVE-2005-2194P4MEDIUMCVSS 5.0≤ 10.4.12005-12-31
CVE-2005-2194 [MEDIUM] CVE-2005-2194: Unspecified vulnerability in the Apple Mac OS X kernel before 10.4.2 allows remote attackers to caus Unspecified vulnerability in the Apple Mac OS X kernel before 10.4.2 allows remote attackers to cause a denial of service (kernel panic) via a crafted TCP packet, possibly related to source routing or loose source routing.
nvd
Apple macOS vulnerabilities | cvebase