cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 142 of 157
CVE-2006-1984P4MEDIUMCVSS 5.0≤ 10.4.5v10.3+14 more2006-04-21
CVE-2006-1984 [MEDIUM] CVE-2006-1984: Unspecified vulnerability in the _cg_TIFFSetField function in Mac OS X 10.4.6 and earlier, as used i Unspecified vulnerability in the _cg_TIFFSetField function in Mac OS X 10.4.6 and earlier, as used in applications that use ImageIO or AppKit, allows remote attackers to cause a denial of service (application crash) via a crafted TIFF image that triggers a null dereference.
nvd
CVE-2013-5229P4LOWCVSS 3.7≤ 10.8.52015-11-14
CVE-2013-5229 [LOW] CWE-254 CVE-2013-5229: The Remote Desktop full-screen feature in Apple OS X before 10.9 and Apple Remote Desktop before 3.7 The Remote Desktop full-screen feature in Apple OS X before 10.9 and Apple Remote Desktop before 3.7 sends dialog-box text to a connected remote host upon being woken from sleep, which allows physically proximate attackers to bypass intended access restrictions by entering a command in this box.
nvd
CVE-2006-6292P4MEDIUMCVSS 5.7v10.4.82006-12-05
CVE-2006-6292 [MEDIUM] CVE-2006-6292: Apple Airport Extreme firmware 0.1.27 in Mac OS X 10.4.8 on Mac mini, MacBook, and MacBook Pro with Apple Airport Extreme firmware 0.1.27 in Mac OS X 10.4.8 on Mac mini, MacBook, and MacBook Pro with Core Duo hardware allows remote attackers to cause a denial of service (out-of-bounds memory access and kernel panic) and have possibly other security-related impact via certain beacon frames.
nvd
CVE-2005-0127P4MEDIUMCVSS 5.0v10.3.72005-05-02
CVE-2005-0127 [MEDIUM] CVE-2005-0127: Mail in Mac OS X 10.3.7, when generating a Message-ID header, generates a GUUID that includes inform Mail in Mac OS X 10.3.7, when generating a Message-ID header, generates a GUUID that includes information that identifies the Ethernet hardware being used, which allows remote attackers to link mail messages to a particular machine.
nvd
CVE-2016-7605P4MEDIUMCVSS 5.5≤ 10.12.12017-02-20
CVE-2016-7605 [MEDIUM] CWE-476 CVE-2016-7605: An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Bluetooth" component. It allows attackers to cause a denial of service (NULL pointer dereference) via a crafted app.
nvd
CVE-2017-7074P4MEDIUMCVSS 5.5≤ 10.12.62017-10-23
CVE-2017-7074 [MEDIUM] CWE-20 CVE-2017-7074: An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involve An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "AppSandbox" component. It allows attackers to cause a denial of service via a crafted app.
nvd
CVE-2004-0744P4MEDIUMCVSS 5.0v10.2v10.2.1+12 more2004-11-23
CVE-2004-0744 [MEDIUM] CVE-2004-0744: The TCP/IP Networking component in Mac OS X before 10.3.5 allows remote attackers to cause a denial The TCP/IP Networking component in Mac OS X before 10.3.5 allows remote attackers to cause a denial of service (memory and resource consumption) via a "Rose Attack" that involves sending a subset of small IP fragments that do not form a complete, larger packet.
nvd
CVE-2016-7603P4MEDIUMCVSS 5.5≤ 10.12.12017-02-20
CVE-2016-7603 [MEDIUM] CWE-476 CVE-2016-7603: An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "CoreStorage" component. It allows local users to cause a denial of service (NULL pointer dereference) via unspecified vectors.
nvd
CVE-2016-7604P4MEDIUMCVSS 5.5≤ 10.12.12017-02-20
CVE-2016-7604 [MEDIUM] CWE-476 CVE-2016-7604: An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "CoreCapture" component. It allows local users to cause a denial of service (NULL pointer dereference) via unspecified vectors.
nvd
CVE-2003-1005P4MEDIUMCVSS 5.0v10.2.8v10.3.22003-12-31
CVE-2003-1005 [MEDIUM] CVE-2003-1005: The PKI functionality in Mac OS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of ser The PKI functionality in Mac OS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (service crash) via malformed ASN.1 sequences.
nvd
CVE-2005-2526P4MEDIUMCVSS 5.0v10.3.9v10.4.22005-08-19
CVE-2005-2526 [MEDIUM] CVE-2005-2526: CUPS in Mac OS X 10.3.9 and 10.4.2 allows remote attackers to cause a denial of service (CPU consump CUPS in Mac OS X 10.3.9 and 10.4.2 allows remote attackers to cause a denial of service (CPU consumption) by sending a partial IPP request and closing the connection.
nvd
CVE-2003-0804P4MEDIUMCVSS 5.0v10.2v10.2.1+6 more2003-11-17
CVE-2003-0804 [MEDIUM] CVE-2003-0804: The arplookup function in FreeBSD 5.1 and earlier, Mac OS X before 10.2.8, and possibly other BSD-ba The arplookup function in FreeBSD 5.1 and earlier, Mac OS X before 10.2.8, and possibly other BSD-based systems, allows remote attackers on a local subnet to cause a denial of service (resource starvation and panic) via a flood of spoofed ARP requests.
nvd
CVE-2003-0975P4MEDIUMCVSS 5.0v10.2.8v10.3.12003-12-15
CVE-2003-0975 [MEDIUM] CVE-2003-0975: Apple Safari 1.0 through 1.1 on Mac OS X 10.3.1 and Mac OS X 10.2.8 allows remote attackers to steal Apple Safari 1.0 through 1.1 on Mac OS X 10.3.1 and Mac OS X 10.2.8 allows remote attackers to steal user cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.
nvd
CVE-2005-2513P4MEDIUMCVSS 5.0v10.4.22005-08-19
CVE-2005-2513 [MEDIUM] CVE-2005-2513: Unknown vulnerability in HItoolbox for Mac OS X 10.4.2 allows VoiceOver services to read secure inpu Unknown vulnerability in HItoolbox for Mac OS X 10.4.2 allows VoiceOver services to read secure input fields.
nvd
CVE-2004-0922P4MEDIUMCVSS 5.0v10.2v10.2.1+13 more2005-01-27
CVE-2004-0922 [MEDIUM] CVE-2004-0922: AFP Server on Mac OS X 10.3.x to 10.3.5, under certain conditions, does not properly set the guest g AFP Server on Mac OS X 10.3.x to 10.3.5, under certain conditions, does not properly set the guest group ID, which causes AFP to change a write-only AFP Drop Box to be read-write when the Drop Box is on a share that is mounted by a guest, which allows attackers to read the Drop Box.
nvd
CVE-2018-4304P4MEDIUMCVSS 5.0fixed in 10.142019-04-03
CVE-2018-4304 [MEDIUM] CWE-20 CVE-2018-4304: A denial of service issue was addressed with improved validation. This issue affected versions prior A denial of service issue was addressed with improved validation. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
nvd
CVE-2014-1372P4MEDIUMCVSS 4.9≤ 10.9.3v10.8.0+8 more2014-07-01
CVE-2014-1372 [MEDIUM] CWE-264 CVE-2014-1372: Graphics Driver in Apple OS X before 10.9.4 does not properly restrict read operations during proces Graphics Driver in Apple OS X before 10.9.4 does not properly restrict read operations during processing of an unspecified system call, which allows local users to obtain sensitive information from kernel memory and bypass the ASLR protection mechanism via a crafted call.
nvd
CVE-2006-4396P4MEDIUMCVSS 4.6≤ 10.4.82006-11-30
CVE-2006-4396 [MEDIUM] CVE-2006-4396: The Apple Type Services (ATS) server in Mac OS X 10.4.8 and earlier does not securely create log fil The Apple Type Services (ATS) server in Mac OS X 10.4.8 and earlier does not securely create log files, which allows local users to create and modify arbitrary files via unspecified vectors, possibly relating to a symlink attack.
nvd
CVE-2011-3058P4MEDIUMCVSS 4.3fixed in 10.8.32012-03-30
CVE-2011-3058 [MEDIUM] CWE-79 CVE-2011-3058: Google Chrome before 18.0.1025.142 does not properly handle the EUC-JP encoding system, which might Google Chrome before 18.0.1025.142 does not properly handle the EUC-JP encoding system, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
nvd
CVE-2007-4695P4MEDIUMCVSS 4.3v10.4.1v10.4.2+8 more2007-11-15
CVE-2007-4695 [MEDIUM] CWE-20 CVE-2007-4695: Unspecified "input validation" vulnerability in WebCore in Apple Mac OS X 10.4 through 10.4.10 allow Unspecified "input validation" vulnerability in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to modify form field values via unknown vectors related to file uploads.
nvd
Apple macOS vulnerabilities | cvebase