Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 143 of 157
CVE-2015-5914P4MEDIUMCVSS 4.7≤ 10.10.52015-10-09
CVE-2015-5914 [MEDIUM] CVE-2015-5914: The EFI component in Apple OS X before 10.11 allows physically proximate attackers to modify firmwar
The EFI component in Apple OS X before 10.11 allows physically proximate attackers to modify firmware during the EFI update process by inserting an Apple Ethernet Thunderbolt adapter with crafted code in an Option ROM, aka a "Thunderstrike" issue. NOTE: this issue exists because of an incomplete fix for CVE-2014-4498.
nvd
CVE-2010-1373P4MEDIUMCVSS 4.3v10.6.0v10.6.1+2 more2010-06-17
CVE-2010-1373 [MEDIUM] CWE-79 CVE-2010-1373: Cross-site scripting (XSS) vulnerability in Help Viewer in Apple Mac OS X 10.6 before 10.6.4 allows
Cross-site scripting (XSS) vulnerability in Help Viewer in Apple Mac OS X 10.6 before 10.6.4 allows remote attackers to inject arbitrary web script or HTML via a crafted help: URL, related to "URL parameters in HTML content."
nvd
CVE-2013-3951P4MEDIUMCVSS 4.6≤ 10.10.4v10.8.0+4 more2013-06-05
CVE-2013-3951 [MEDIUM] CWE-20 CVE-2013-3951: sys/openbsd/stack_protector.c in libc in Apple iOS 6.1.3 and Mac OS X 10.8.x does not properly parse
sys/openbsd/stack_protector.c in libc in Apple iOS 6.1.3 and Mac OS X 10.8.x does not properly parse the Apple strings employed in the user-space stack-cookie implementation, which allows local users to bypass cookie randomization by executing a program with a call-path beginning with the stack-guard= substring, as demonstrated by an iOS untethering at
nvd
CVE-2006-1471P4MEDIUMCVSS 4.6v10.4v10.4.1+5 more2006-06-27
CVE-2006-1471 [MEDIUM] CWE-134 CVE-2006-1471: Format string vulnerability in the CF_syslog function launchd in Apple Mac OS X 10.4 up to 10.4.6 al
Format string vulnerability in the CF_syslog function launchd in Apple Mac OS X 10.4 up to 10.4.6 allows local users to execute arbitrary code via format string specifiers that are not properly handled in a syslog call in the logging facility, as demonstrated by using a crafted plist file.
nvd
CVE-2007-4696P4MEDIUMCVSS 4.3v10.4.1v10.4.2+8 more2007-11-15
CVE-2007-4696 [MEDIUM] CWE-362 CVE-2007-4696: Race condition in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to obtain i
Race condition in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to obtain information for forms from other sites via unknown vectors related to "page transitions" in Safari.
nvd
CVE-2016-1851P4MEDIUMCVSS 4.6≤ 10.11.42016-05-20
CVE-2016-1851 [MEDIUM] CVE-2016-1851: The Screen Lock feature in Apple OS X before 10.11.5 mishandles password profiles, which allows phys
The Screen Lock feature in Apple OS X before 10.11.5 mishandles password profiles, which allows physically proximate attackers to reset expired passwords in the lock-screen state via unspecified vectors.
nvd
CVE-2011-3214P4MEDIUMCVSS 4.6≤ 10.6.8v10.0+64 more2011-10-14
CVE-2011-3214 [MEDIUM] CWE-264 CVE-2011-3214: IOGraphics in Apple Mac OS X through 10.6.8 does not properly handle a locked-screen state in displa
IOGraphics in Apple Mac OS X through 10.6.8 does not properly handle a locked-screen state in display sleep mode for an Apple Cinema Display, which allows physically proximate attackers to bypass the password requirement via unspecified vectors.
nvd
CVE-2015-5897P4MEDIUMCVSS 4.6≤ 10.10.52015-10-09
CVE-2015-5897 [MEDIUM] CWE-264 CVE-2015-5897: The Address Book framework in Apple OS X before 10.11 allows local users to gain privileges by using
The Address Book framework in Apple OS X before 10.11 allows local users to gain privileges by using an environment variable to inject code into processes that rely on this framework.
nvd
CVE-2005-1726P4MEDIUMCVSS 4.6v10.4.12005-12-31
CVE-2005-1726 [MEDIUM] CVE-2005-1726: The CoreGraphics Window Server in Mac OS X 10.4.1 allows local users with console access to gain pri
The CoreGraphics Window Server in Mac OS X 10.4.1 allows local users with console access to gain privileges by "launching commands into root sessions."
nvd
CVE-2021-30702P4MEDIUMCVSS 4.6≥ 10.14, ≤ 10.14.5≥ 10.15, ≤ 10.15.6+2 more2021-09-08
CVE-2021-30702 [MEDIUM] CWE-287 CVE-2021-30702: A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A person with physical access to a Mac may be able to bypass Login Window.
nvd
CVE-2020-3835P4MEDIUMCVSS 4.4fixed in 10.15.32020-02-27
CVE-2020-3835 [MEDIUM] CWE-59 CVE-2020-3835: A validation issue existed in the handling of symlinks. This issue was addressed with improved valid
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Catalina 10.15.3. A malicious application may be able to access restricted files.
nvd
CVE-2014-4435P4MEDIUMCVSS 4.4≤ 10.9.52014-10-18
CVE-2014-4435 [MEDIUM] CWE-287 CVE-2014-4435: The "iCloud Find My Mac" feature in Apple OS X before 10.10 does not properly enforce rate limiting
The "iCloud Find My Mac" feature in Apple OS X before 10.10 does not properly enforce rate limiting of lost-mode PIN entry, which makes it easier for physically proximate attackers to obtain access via a brute-force attack involving a series of reboots.
nvd
CVE-2015-5824P4MEDIUMCVSS 4.3≤ 10.10.52015-09-18
CVE-2015-5824 [MEDIUM] CWE-310 CVE-2015-5824: The NSURL implementation in the CFNetwork SSL component in Apple iOS before 9 does not properly veri
The NSURL implementation in the CFNetwork SSL component in Apple iOS before 9 does not properly verify X.509 certificates from SSL servers after a certificate change, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
nvd
CVE-2010-0534P4MEDIUMCVSS 4.0v10.6.0v10.6.1+1 more2010-03-30
CVE-2010-0534 [MEDIUM] CWE-264 CVE-2010-0534: Wiki Server in Apple Mac OS X 10.6 before 10.6.3 does not enforce the service access control list (S
Wiki Server in Apple Mac OS X 10.6 before 10.6.3 does not enforce the service access control list (SACL) for weblogs during weblog creation, which allows remote authenticated users to publish content via HTTP requests.
nvd
CVE-2003-0198P4MEDIUMCVSS 6.4v10.0v10.0.1+13 more2003-05-05
CVE-2003-0198 [MEDIUM] CVE-2003-0198: Mac OS X before 10.2.5 allows guest users to modify the permissions of the DropBox folder and read u
Mac OS X before 10.2.5 allows guest users to modify the permissions of the DropBox folder and read unauthorized files.
nvd
CVE-2008-3613P4MEDIUMCVSS 6.1v10.5.2v10.5.3+1 more2008-09-16
CVE-2008-3613 [MEDIUM] CWE-399 CVE-2008-3613: Finder in Apple Mac OS X 10.5.2 through 10.5.4 allows remote attackers to cause a denial of service
Finder in Apple Mac OS X 10.5.2 through 10.5.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors involving a search for a remote disk on the local network.
nvd
CVE-2006-0383P4MEDIUMCVSS 5.0v10.3v10.3.1+14 more2006-03-02
CVE-2006-0383 [MEDIUM] CVE-2006-0383: IPSec when used with VPN networks in Mac OS X 10.4 through 10.4.5 allows remote attackers to cause a
IPSec when used with VPN networks in Mac OS X 10.4 through 10.4.5 allows remote attackers to cause a denial of service (application crash) via unspecified vectors involving the "incorrect handling of error conditions".
nvd
CVE-2002-1265P4MEDIUMCVSS 5.0v10.0v10.0.1+11 more2002-11-12
CVE-2002-1265 [MEDIUM] CVE-2002-1265: The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism whe
The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism when reading data from TCP connections, which allows remote attackers to cause a denial of service (hang).
nvd
CVE-2004-0166P4MEDIUMCVSS 5.0v10.2.82004-03-15
CVE-2004-0166 [MEDIUM] CVE-2004-0166: Unknown vulnerability in Safari web browser for Mac OS X 10.2.8 related to "the display of URLs in t
Unknown vulnerability in Safari web browser for Mac OS X 10.2.8 related to "the display of URLs in the status bar."
nvd
CVE-2016-4661P4MEDIUMCVSS 5.5≤ 10.12.02017-02-20
CVE-2016-4661 [MEDIUM] CWE-20 CVE-2016-4661: An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "ntfs" component, which misparses disk images and allows attackers to cause a denial of service via a crafted app.
nvd