cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 140 of 157
CVE-2016-1814P4MEDIUMCVSS 5.5fixed in 10.11.52016-05-20
CVE-2016-1814 [MEDIUM] CWE-476 CVE-2016-1814: IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS before 9.2.1 allows att IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS before 9.2.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted app.
nvd
CVE-2006-1457P4LOWCVSS 2.6v10.4.62006-05-12
CVE-2006-1457 [LOW] CVE-2006-1457: Safari on Apple Mac OS X 10.4.6, when "Open `safe' files after downloading" is enabled, will automat Safari on Apple Mac OS X 10.4.6, when "Open `safe' files after downloading" is enabled, will automatically expand archives, which could allow remote attackers to overwrite arbitrary files via an archive that contains a symlink.
nvd
CVE-2017-7003P4MEDIUMCVSS 5.5fixed in 10.12.52018-04-03
CVE-2017-7003 [MEDIUM] CWE-20 CVE-2017-7003: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service (application crash) via a crafted file.
nvd
CVE-2016-4663P4MEDIUMCVSS 5.5≤ 10.12.02017-02-20
CVE-2016-4663 [MEDIUM] CWE-119 CVE-2016-4663: An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "NVIDIA Graphics Drivers" component. It allows attackers to cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2004-0743P4MEDIUMCVSS 5.0v10.2v10.2.1+12 more2004-11-23
CVE-2004-0743 [MEDIUM] CVE-2004-0743: Safari in Mac OS X before 10.3.5, after sending form data using the POST method, may re-send the dat Safari in Mac OS X before 10.3.5, after sending form data using the POST method, may re-send the data to a GET method URL if that URL is redirected after the POST data and the user uses the forward or backward buttons, which may cause an information leak.
nvd
CVE-2015-7020P4MEDIUMCVSS 5.6≤ 10.11.02015-10-23
CVE-2015-7020 [MEDIUM] CVE-2015-7020: The NVIDIA driver in the Graphics Drivers subsystem in Apple OS X before 10.11.1 allows local users The NVIDIA driver in the Graphics Drivers subsystem in Apple OS X before 10.11.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read and system crash) via unspecified vectors, a different vulnerability than CVE-2015-7019.
nvd
CVE-2015-7019P4MEDIUMCVSS 5.6≤ 10.11.02015-10-23
CVE-2015-7019 [MEDIUM] CWE-119 CVE-2015-7019: The NVIDIA driver in the Graphics Drivers subsystem in Apple OS X before 10.11.1 allows local users The NVIDIA driver in the Graphics Drivers subsystem in Apple OS X before 10.11.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read and system crash) via unspecified vectors, a different vulnerability than CVE-2015-7020.
nvd
CVE-2006-1468P4MEDIUMCVSS 5.0v10.4v10.4.1+5 more2006-06-27
CVE-2006-1468 [MEDIUM] CVE-2006-1468: Unspecified vulnerability in Apple File Protocol (AFP) server in Apple Mac OS X 10.4 up to 10.4.6 in Unspecified vulnerability in Apple File Protocol (AFP) server in Apple Mac OS X 10.4 up to 10.4.6 includes the names of restricted files and folders within search results, which might allow remote attackers to obtain sensitive information.
nvd
CVE-2016-4706P4MEDIUMCVSS 5.5≤ 10.11.62016-09-25
CVE-2016-4706 [MEDIUM] CWE-20 CVE-2016-4706: cd9660 in Apple OS X before 10.12 allows local users to cause a denial of service via unspecified ve cd9660 in Apple OS X before 10.12 allows local users to cause a denial of service via unspecified vectors.
nvd
CVE-2016-4649P4MEDIUMCVSS 5.5≤ 10.11.52016-07-22
CVE-2016-4649 [MEDIUM] CWE-476 CVE-2016-4649: Audio in Apple OS X before 10.11.6 allows local users to cause a denial of service (NULL pointer der Audio in Apple OS X before 10.11.6 allows local users to cause a denial of service (NULL pointer dereference) via unspecified vectors.
nvd
CVE-2016-7615P4MEDIUMCVSS 5.5≤ 10.12.12017-02-20
CVE-2016-7615 [MEDIUM] CVE-2016-7615: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component, which allows local users to cause a denial of service via unspecified vectors.
nvd
CVE-2016-1745P4MEDIUMCVSS 5.5≤ 10.11.32016-03-24
CVE-2016-1745 [MEDIUM] CVE-2016-1745: IOFireWireFamily in Apple OS X before 10.11.4 allows local users to cause a denial of service (NULL IOFireWireFamily in Apple OS X before 10.11.4 allows local users to cause a denial of service (NULL pointer dereference) via unspecified vectors.
nvd
CVE-2005-2525P4MEDIUMCVSS 5.0v10.3.9v10.4.22005-08-19
CVE-2005-2525 [MEDIUM] CVE-2005-2525: CUPS in Mac OS X 10.3.9 and 10.4.2 does not properly close file descriptors when handling multiple s CUPS in Mac OS X 10.3.9 and 10.4.2 does not properly close file descriptors when handling multiple simultaneous print jobs, which allows remote attackers to cause a denial of service (printing halt).
nvd
CVE-2006-4409P4MEDIUMCVSS 5.0v10.4v10.4.1+7 more2006-11-30
CVE-2006-4409 [MEDIUM] CVE-2006-4409: The Online Certificate Status Protocol (OCSP) service in the Security Framework in Apple Mac OS X 10 The Online Certificate Status Protocol (OCSP) service in the Security Framework in Apple Mac OS X 10.4 through 10.4.8 retrieve certificate revocation lists (CRL) when an HTTP proxy is in use, which could cause the system to accept certificates that have been revoked.
nvd
CVE-2008-1036P4MEDIUMCVSS 4.3v10.4.11v10.5+2 more2008-06-02
CVE-2008-1036 [MEDIUM] CWE-79 CVE-2008-1036: The International Components for Unicode (ICU) library in Apple Mac OS X before 10.5.3, Red Hat Ente The International Components for Unicode (ICU) library in Apple Mac OS X before 10.5.3, Red Hat Enterprise Linux 5, and other operating systems omits some invalid character sequences during conversion of some character encodings, which might allow remote attackers to conduct cross-site scripting (XSS) attacks.
nvd
CVE-2002-2326P4MEDIUMCVSS 5.0v10.0v10.0.1+9 more2002-12-31
CVE-2002-2326 [MEDIUM] CWE-310 CVE-2002-2326: The default configuration of Mail.app in Mac OS X 10.0 through 10.0.4 and 10.1 through 10.1.5 sends The default configuration of Mail.app in Mac OS X 10.0 through 10.0.4 and 10.1 through 10.1.5 sends iDisk authentication credentials in cleartext when connecting to Mac.com, which could allow remote attackers to obtain passwords by sniffing network traffic.
nvd
CVE-2003-0882P4MEDIUMCVSS 5.0≤ 10.32003-11-03
CVE-2003-0882 [MEDIUM] CVE-2003-0882: Mac OS X before 10.3 initializes the TCP timestamp with a constant number, which allows remote attac Mac OS X before 10.3 initializes the TCP timestamp with a constant number, which allows remote attackers to determine the system's uptime via the ID field in a TCP packet.
nvd
CVE-2004-0925P4MEDIUMCVSS 5.0v10.3v10.3.1+4 more2005-01-27
CVE-2004-0925 [MEDIUM] CVE-2004-0925: Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not properly clear the user Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not properly clear the username between authentication attempts, which allows users with the longest username to prevent other valid users from being able to authenticate.
nvd
CVE-2005-2524P4MEDIUMCVSS 5.0v10.3.92005-10-26
CVE-2005-2524 [MEDIUM] CVE-2005-2524: Safari after 2.0 in Apple Mac OS X 10.3.9 allows remote attackers to bypass domain restrictions via Safari after 2.0 in Apple Mac OS X 10.3.9 allows remote attackers to bypass domain restrictions via crafted web archives that cause Safari to render them as if they came from a different site.
nvd
CVE-2010-0525P4MEDIUMCVSS 5.0≤ 10.6.2v10.5.0+10 more2010-03-30
CVE-2010-0525 [MEDIUM] CWE-310 CVE-2010-0525: Mail in Apple Mac OS X before 10.6.3 does not properly enforce the key usage extension during proces Mail in Apple Mac OS X before 10.6.3 does not properly enforce the key usage extension during processing of a keychain that specifies multiple certificates for an e-mail recipient, which might make it easier for remote attackers to obtain sensitive information via a brute-force attack on a weakly encrypted e-mail message.
nvd
Apple macOS vulnerabilities | cvebase