cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 141 of 157
CVE-2004-0924P4MEDIUMCVSS 5.0v10.2v10.2.1+13 more2005-01-27
CVE-2004-0924 [MEDIUM] CVE-2004-0924: NetInfo Manager on Mac OS X 10.3.x through 10.3.5, after an initial root login, reports the root acc NetInfo Manager on Mac OS X 10.3.x through 10.3.5, after an initial root login, reports the root account as being disabled, even when it has not.
nvd
CVE-2012-1147P4MEDIUMCVSS 4.3v10.11.0v10.11.12012-07-03
CVE-2012-1147 [MEDIUM] CWE-20 CVE-2012-1147: readfilemap.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service readfilemap.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (file descriptor consumption) via a large number of crafted XML files.
nvd
CVE-2004-0927P4MEDIUMCVSS 5.0v10.2v10.2.1+13 more2005-01-27
CVE-2004-0927 [MEDIUM] CVE-2004-0927: ServerAdmin in Mac OS X 10.2.8 through 10.3.5 uses the same example self-signed certificate on each ServerAdmin in Mac OS X 10.2.8 through 10.3.5 uses the same example self-signed certificate on each system, which allows remote attackers to decrypt sessions.
nvd
CVE-2008-3622P4MEDIUMCVSS 4.3v10.5v10.5.1+3 more2008-09-16
CVE-2008-3622 [MEDIUM] CWE-79 CVE-2008-3622: Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac OS X 10.5 through 10.5.4 allows Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac OS X 10.5 through 10.5.4 allows remote attackers to inject arbitrary web script or HTML via an e-mail message that reaches a mailing-list archive, aka "persistent JavaScript injection."
nvd
CVE-2013-1029P4MEDIUMCVSS 4.9≤ 10.8.4v10.8.0+3 more2013-09-16
CVE-2013-1029 [MEDIUM] CWE-20 CVE-2013-1029: The kernel in Apple Mac OS X before 10.8.5 allows remote attackers to cause a denial of service (pan The kernel in Apple Mac OS X before 10.8.5 allows remote attackers to cause a denial of service (panic) via crafted IGMP packets that leverage incorrect, extraneous code in the IGMP parser.
nvd
CVE-2011-0172P4MEDIUMCVSS 4.9v10.6.0v10.6.1+5 more2011-03-23
CVE-2011-0172 [MEDIUM] CVE-2011-0172: AirPort in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to cause a denial of service (d AirPort in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to cause a denial of service (divide-by-zero error and reboot) via Wi-Fi frames on the local wireless network, a different vulnerability than CVE-2011-0162.
nvd
CVE-2015-3774P4MEDIUMCVSS 4.8≤ 10.10.42015-08-16
CVE-2015-3774 [MEDIUM] CWE-20 CVE-2015-3774: The Dictionary app in Apple OS X before 10.10.5 does not use HTTPS, which allows man-in-the-middle a The Dictionary app in Apple OS X before 10.10.5 does not use HTTPS, which allows man-in-the-middle attackers to obtain sensitive information by sniffing the network or spoof word definitions by modifying the client-server data stream.
nvd
CVE-2009-0144P4MEDIUMCVSS 4.3v10.5.6v10.5+5 more2009-05-13
CVE-2009-0144 [MEDIUM] CWE-16 CVE-2009-0144: CFNetwork in Apple Mac OS X 10.5 before 10.5.7 does not properly parse noncompliant Set-Cookie heade CFNetwork in Apple Mac OS X 10.5 before 10.5.7 does not properly parse noncompliant Set-Cookie headers, which allows remote attackers to obtain sensitive information by sniffing the network for "secure cookies" that are sent over unencrypted HTTP connections.
nvd
CVE-2011-3447P4MEDIUMCVSS 4.3v10.7.0v10.7.1+1 more2012-02-02
CVE-2011-3447 [MEDIUM] CWE-200 CVE-2011-3447: CFNetwork in Apple Mac OS X 10.7.x before 10.7.3 does not properly construct request headers during CFNetwork in Apple Mac OS X 10.7.x before 10.7.3 does not properly construct request headers during parsing of URLs, which allows remote attackers to obtain sensitive information via a malformed URL.
nvd
CVE-2006-1452P4MEDIUMCVSS 4.6v10.4v10.4.1+5 more2006-05-12
CVE-2006-1452 [MEDIUM] CVE-2006-1452: Stack-based buffer overflow in Preview in Apple Mac OS 10.4 up to 10.4.6 allows local users to execu Stack-based buffer overflow in Preview in Apple Mac OS 10.4 up to 10.4.6 allows local users to execute arbitrary code via a deep directory hierarchy.
nvd
CVE-2016-4595P4MEDIUMCVSS 4.6≤ 10.11.52016-07-22
CVE-2016-4595 [MEDIUM] CWE-200 CVE-2016-4595: Safari Login AutoFill in Apple OS X before 10.11.6 allows physically proximate attackers to discover Safari Login AutoFill in Apple OS X before 10.11.6 allows physically proximate attackers to discover passwords by reading the screen during the login procedure.
nvd
CVE-2014-4425P4MEDIUMCVSS 4.6≤ 10.9.52014-10-18
CVE-2014-4425 [MEDIUM] CWE-287 CVE-2014-4425: CFPreferences in Apple OS X before 10.10 does not properly enforce the "require password after sleep CFPreferences in Apple OS X before 10.10 does not properly enforce the "require password after sleep or screen saver begins" setting, which makes it easier for physically proximate attackers to obtain access by leveraging an unattended workstation.
nvd
CVE-2013-5180P4MEDIUMCVSS 4.3≤ 10.8.5v10.8.0+5 more2013-10-24
CVE-2013-5180 [MEDIUM] CWE-310 CVE-2013-5180: The srandomdev function in Libc in Apple Mac OS X before 10.9, when the kernel random-number generat The srandomdev function in Libc in Apple Mac OS X before 10.9, when the kernel random-number generator is unavailable, produces predictable values instead of the intended random values, which makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by leveraging knowledge of these values, related to a compiler-opti
nvd
CVE-2022-22647P4MEDIUMCVSS 4.6≥ 10.15, < 10.15.7v10.15.72022-03-18
CVE-2022-22647 [MEDIUM] CVE-2022-22647: This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.5, macOS Mo This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. A person with access to a Mac may be able to bypass Login Window.
nvd
CVE-2010-0064P4MEDIUMCVSS 6.9v10.6.0v10.6.1+1 more2010-03-30
CVE-2010-0064 [MEDIUM] CWE-264 CVE-2010-0064: DesktopServices in Apple Mac OS X 10.6 before 10.6.3 preserves file ownership during an authenticate DesktopServices in Apple Mac OS X 10.6 before 10.6.3 preserves file ownership during an authenticated Finder copy, which might allow local users to bypass intended disk-quota restrictions and have unspecified other impact by copying files owned by other users.
nvd
CVE-2005-2714P4MEDIUMCVSS 6.8v10.3v10.3.1+14 more2005-12-31
CVE-2005-2714 [MEDIUM] CWE-59 CVE-2005-2714: passwd in Directory Services in Mac OS X 10.3.x before 10.3.9 and 10.4.x before 10.4.5 allows local passwd in Directory Services in Mac OS X 10.3.x before 10.3.9 and 10.4.x before 10.4.5 allows local users to overwrite arbitrary files via a symlink attack on the .pwtmp.[PID] temporary file.
nvd
CVE-2007-0345P4MEDIUMCVSS 6.8v10.4.82007-01-18
CVE-2007-0345 [MEDIUM] CVE-2007-0345: The (1) Activity Monitor.app/Contents/Resources/pmTool, (2) Keychain Access.app/Contents/Resources/k The (1) Activity Monitor.app/Contents/Resources/pmTool, (2) Keychain Access.app/Contents/Resources/kcproxy, and (3) ODBC Administrator.app/Contents/Resources/iodbcadmintool programs in /Applications/Utilities/ in Mac OS X 10.4.8 have weak permissions (writable by admin group), which allows local admin users to gain root privileges by modifying a program and t
nvd
CVE-2021-1824P4MEDIUMCVSS 4.4≥ 10.15, ≤ 10.15.5v10.15.6+1 more2021-09-08
CVE-2021-1824 [MEDIUM] CVE-2021-1824: This issue was addressed with improved entitlements. This issue is fixed in macOS Big Sur 11.3, Secu This issue was addressed with improved entitlements. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application with root privileges may be able to access private information.
nvd
CVE-2014-4444P4MEDIUMCVSS 4.4≤ 10.9.52014-10-18
CVE-2014-4444 [MEDIUM] CWE-287 CVE-2014-4444: SecurityAgent in Apple OS X before 10.10 does not ensure that a Kerberos ticket is in the cache for SecurityAgent in Apple OS X before 10.10 does not ensure that a Kerberos ticket is in the cache for the correct user, which allows local users to gain privileges in opportunistic circumstances by leveraging a Fast User Switching login.
nvd
CVE-2016-4707P4MEDIUMCVSS 4.0≤ 10.11.62016-09-25
CVE-2016-4707 [MEDIUM] CWE-19 CVE-2016-4707: CFNetwork in Apple iOS before 10 and OS X before 10.12 mishandles Local Storage deletion, which allo CFNetwork in Apple iOS before 10 and OS X before 10.12 mishandles Local Storage deletion, which allows local users to discover the visited web sites of arbitrary users via unspecified vectors.
nvd
Apple macOS vulnerabilities | cvebase