Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
277
Exploited in wild
28
Severity breakdown
CRITICAL302HIGH1409MEDIUM1236LOW192

Vulnerabilities

Page 142 of 157
CVE-2007-0355HIGHCVSS 7.2PoCv10.4.82007-01-19
CVE-2007-0355 [HIGH] CWE-119 CVE-2007-0355: Buffer overflow in the Apple Minimal SLP v2 Service Agent (slpd) in Mac OS X 10.4.11 and earlier, in Buffer overflow in the Apple Minimal SLP v2 Service Agent (slpd) in Mac OS X 10.4.11 and earlier, including 10.4.8, allows local users, and possibly remote attackers, to gain privileges and possibly execute arbitrary code via a registration request with an invalid attr-list field.
nvd
CVE-2007-0342HIGHCVSS 7.5PoCv10.4.82007-01-18
CVE-2007-0342 [HIGH] CVE-2007-0342: WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null deref WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and application crash) via a TD element with a large number in the ROWSPAN attribute, as demonstrated by a crash of OmniWeb 5.5.3 on Mac OS X 10.4.8, a different vulnerability than CVE-2006-2019.
nvd
CVE-2007-0318HIGHCVSS 7.8v10.4.82007-01-18
CVE-2007-0318 [HIGH] CVE-2007-0318: The do_hfs_truncate function in Mac OS X 10.4.8 allows context-dependent attackers to cause a denial The do_hfs_truncate function in Mac OS X 10.4.8 allows context-dependent attackers to cause a denial of service (kernel panic) via a crafted HFS+ filesystem in a DMG image, which causes an access of an invalid vnode structure during file removal.
nvd
CVE-2007-0345MEDIUMCVSS 6.8v10.4.82007-01-18
CVE-2007-0345 [MEDIUM] CVE-2007-0345: The (1) Activity Monitor.app/Contents/Resources/pmTool, (2) Keychain Access.app/Contents/Resources/k The (1) Activity Monitor.app/Contents/Resources/pmTool, (2) Keychain Access.app/Contents/Resources/kcproxy, and (3) ODBC Administrator.app/Contents/Resources/iodbcadmintool programs in /Applications/Utilities/ in Mac OS X 10.4.8 have weak permissions (writable by admin group), which allows local admin users to gain root privileges by modifying a program and t
nvd
CVE-2007-0299HIGHCVSS 7.1v10.4.82007-01-17
CVE-2007-0299 [HIGH] CVE-2007-0299: Integer overflow in the byte_swap_sbin function in bsd/ufs/ufs/ufs_byte_order.c in Mac OS X 10.4.8 a Integer overflow in the byte_swap_sbin function in bsd/ufs/ufs/ufs_byte_order.c in Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service (kernel panic) by mounting a crafted Unix File System (UFS) DMG image, which triggers an invalid pointer dereference.
nvd
CVE-2007-0267MEDIUMCVSS 6.6PoCv10.4.82007-01-17
CVE-2007-0267 [MEDIUM] CWE-399 CVE-2007-0267: The ufs_lookup function in the Mac OS X 10.4.8 and FreeBSD 6.1 kernels allows local users to cause a The ufs_lookup function in the Mac OS X 10.4.8 and FreeBSD 6.1 kernels allows local users to cause a denial of service (kernel panic) and possibly corrupt other filesystems by mounting a crafted UNIX File System (UFS) DMG image that contains a corrupted directory entry (struct direct), related to the ufs_dirbad function. NOTE: a third party states tha
nvd
CVE-2007-0236CRITICALCVSS 10.0PoCv10.4.82007-01-16
CVE-2007-0236 [CRITICAL] CWE-119 CVE-2007-0236: Double free vulnerability in the _ATPsndrsp function in Apple Mac OS X 10.4.8, and possibly other ve Double free vulnerability in the _ATPsndrsp function in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to cause a denial of service (kernel panic) and possibly execute arbitrary code via a crafted AppleTalk request that triggers a heap-based buffer overflow.
nvd
CVE-2007-0229HIGHCVSS 7.2PoCv10.4.82007-01-13
CVE-2007-0229 [HIGH] CVE-2007-0229: Integer overflow in the ffs_mountfs function in Mac OS X 10.4.8 and FreeBSD 6.1 allows local users t Integer overflow in the ffs_mountfs function in Mac OS X 10.4.8 and FreeBSD 6.1 allows local users to cause a denial of service (panic) and possibly gain privileges via a crafted DMG image that causes "allocation of a negative size buffer" leading to a heap-based buffer overflow, a related issue to CVE-2006-5679. NOTE: a third party states that this issue does
nvd
CVE-2007-0197MEDIUMCVSS 6.8PoCv10.4.6v10.4.82007-01-11
CVE-2007-0197 [MEDIUM] CWE-20 CVE-2007-0197: Finder 10.4.6 on Apple Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of se Finder 10.4.6 on Apple Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a long volume name in a DMG disk image, which results in memory corruption.
nvd
CVE-2007-0117CRITICALCVSS 10.0PoCv10.4.82007-01-09
CVE-2007-0117 [CRITICAL] CVE-2007-0117: DiskManagementTool in the DiskManagement.framework 92.29 on Mac OS X 10.4.8 does not properly valida DiskManagementTool in the DiskManagement.framework 92.29 on Mac OS X 10.4.8 does not properly validate Bill of Materials (BOM) files, which allows attackers to gain privileges via a BOM file under /Library/Receipts/, which triggers arbitrary file permission changes upon execution of a diskutil permission repair operation.
nvd
CVE-2006-6900CRITICALCVSS 10.0v10.42006-12-31
CVE-2006-6900 [CRITICAL] CVE-2006-6900: Unspecified vulnerability in the Bluetooth stack in Apple Mac OS 10.4 has unknown impact and attack Unspecified vulnerability in the Bluetooth stack in Apple Mac OS 10.4 has unknown impact and attack vectors, related to an "implementation bug."
nvd
CVE-2006-6906HIGHCVSS 7.2≤ 10.4.72006-12-31
CVE-2006-6906 [HIGH] CVE-2006-6906: Unspecified vulnerability in the Bluetooth stack on Mac OS 10.4.7 and earlier has unknown impact and Unspecified vulnerability in the Bluetooth stack on Mac OS 10.4.7 and earlier has unknown impact and local attack vectors, related to "Mach Exception Handling", a different issue than CVE-2006-6900.
nvd
CVE-2006-6652CRITICALCVSS 9.0PoCv10.0v10.0.1+39 more2006-12-20
CVE-2006-6652 [CRITICAL] CWE-119 CVE-2006-6652: Buffer overflow in the glob implementation (glob.c) in libc in NetBSD-current before 20050914, NetBS Buffer overflow in the glob implementation (glob.c) in libc in NetBSD-current before 20050914, NetBSD 2.* and 3.* before 20061203, and Apple Mac OS X before 2007-004, as used by the FTP daemon and tnftpd, allows remote authenticated users to execute arbitrary code via a long pathname that results from path expansion.
nvd
CVE-2006-5681LOWCVSS 2.6v10.4v10.4.1+7 more2006-12-20
CVE-2006-5681 [LOW] CVE-2006-5681: QuickTime for Java on Mac OS X 10.4 through 10.4.8, when used with Quartz Composer, allows remote at QuickTime for Java on Mac OS X 10.4 through 10.4.8, when used with Quartz Composer, allows remote attackers to obtain sensitive information (screen images) via a Java applet that accesses images that are being rendered by other embedded QuickTime objects.
nvd
CVE-2006-6353MEDIUMCVSS 5.0v10.4.82006-12-07
CVE-2006-6353 [MEDIUM] CVE-2006-6353: Multiple unspecified vulnerabilities in BOMArchiveHelper in Mac OS X allow user-assisted remote atta Multiple unspecified vulnerabilities in BOMArchiveHelper in Mac OS X allow user-assisted remote attackers to cause a denial of service (application crash) via unspecified vectors related to (1) certain KERN_PROTECTION_FAILURE thread crashes and (2) certain KERN_INVALID_ADDRESS thread crashes, as discovered with the "iSec Partners FileP fuzzer".
nvd
CVE-2006-6292MEDIUMCVSS 5.7v10.4.82006-12-05
CVE-2006-6292 [MEDIUM] CVE-2006-6292: Apple Airport Extreme firmware 0.1.27 in Mac OS X 10.4.8 on Mac mini, MacBook, and MacBook Pro with Apple Airport Extreme firmware 0.1.27 in Mac OS X 10.4.8 on Mac mini, MacBook, and MacBook Pro with Core Duo hardware allows remote attackers to cause a denial of service (out-of-bounds memory access and kernel panic) and have possibly other security-related impact via certain beacon frames.
nvd
CVE-2006-4404CRITICALCVSS 10.0≤ 10.4.82006-11-30
CVE-2006-4404 [CRITICAL] CVE-2006-4404: The Installer application in Apple Mac OS X 10.4.8 and earlier, when used by a user with Admin crede The Installer application in Apple Mac OS X 10.4.8 and earlier, when used by a user with Admin credentials, does not authenticate the user before installing certain software requiring system privileges.
nvd
CVE-2006-6173HIGHCVSS 7.2PoC≤ 10.4.62006-11-30
CVE-2006-6173 [HIGH] CVE-2006-6173: Buffer overflow in the shared_region_make_private_np function in vm/vm_unix.c in Mac OS X 10.4.6 and Buffer overflow in the shared_region_make_private_np function in vm/vm_unix.c in Mac OS X 10.4.6 and earlier allows local users to execute arbitrary code via (1) a small range count, which causes insufficient memory allocation, or (2) a large number of ranges in the shared_region_make_private_np_args parameter.
nvd
CVE-2006-4411HIGHCVSS 7.2v10.3v10.3.1+17 more2006-11-30
CVE-2006-4411 [HIGH] CVE-2006-4411: The VPN service in Apple Mac OS X 10.3.x through 10.3.9 and 10.4.x through 10.4.8 does not properly The VPN service in Apple Mac OS X 10.3.x through 10.3.9 and 10.4.x through 10.4.8 does not properly clean the environment when executing commands, which allows local users to gain privileges via unspecified vectors.
nvd
CVE-2006-4410HIGHCVSS 7.5v10.3.9v10.4+6 more2006-11-30
CVE-2006-4410 [HIGH] CVE-2006-4410: The Security Framework in Apple Mac OS X 10.3.9, and 10.4.x before 10.4.7, does not properly search The Security Framework in Apple Mac OS X 10.3.9, and 10.4.x before 10.4.7, does not properly search certificate revocation lists (CRL), which allows remote attackers to access systems by using revoked certificates.
nvd