Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 144 of 157
CVE-2011-3224P4LOWCVSS 2.6≤ 10.6.8v10.0+64 more2011-10-14
CVE-2011-3224 [LOW] CVE-2011-3224: The User Documentation component in Apple Mac OS X through 10.6.8 uses http sessions for updates to
The User Documentation component in Apple Mac OS X through 10.6.8 uses http sessions for updates to App Store help information, which allows man-in-the-middle attackers to execute arbitrary code by spoofing the http server.
nvd
CVE-2004-0085P4MEDIUMCVSS 5.0v10.1.5v10.2.82004-03-03
CVE-2004-0085 [MEDIUM] CVE-2004-0085: Unknown vulnerability in the Mail application for Mac OS X 10.1.5 and 10.2.8 with unknown impact, a
Unknown vulnerability in the Mail application for Mac OS X 10.1.5 and 10.2.8 with unknown impact, a different vulnerability than CVE-2004-0086.
nvd
CVE-2002-1267P4MEDIUMCVSS 5.0v10.2.22002-12-11
CVE-2002-1267 [MEDIUM] CVE-2002-1267: Mac OS X 10.2.2 allows remote attackers to cause a denial of service by accessing the CUPS Printing
Mac OS X 10.2.2 allows remote attackers to cause a denial of service by accessing the CUPS Printing Web Administration utility, aka "CUPS Printing Web Administration is Remotely Accessible."
nvd
CVE-2004-0428P4MEDIUMCVSS 5.0v10.2v10.2.1+11 more2004-05-03
CVE-2004-0428 [MEDIUM] CVE-2004-0428: Unknown vulnerability in CoreFoundation in Mac OS X 10.3.3 and Mac OS X 10.3.3 Server, related to "t
Unknown vulnerability in CoreFoundation in Mac OS X 10.3.3 and Mac OS X 10.3.3 Server, related to "the handling of an environment variable," has unknown attack vectors and unknown impact.
nvd
CVE-2005-2745P4MEDIUMCVSS 5.0v10.3.92005-10-26
CVE-2005-2745 [MEDIUM] CVE-2005-2745: Mail.app in Mail for Apple Mac OS X 10.3.9, when using Kerberos 5 for SMTP authentication, can inclu
Mail.app in Mail for Apple Mac OS X 10.3.9, when using Kerberos 5 for SMTP authentication, can include uninitialized memory in a message, which might allow remote attackers to obtain sensitive information.
nvd
CVE-2010-4008P4MEDIUMCVSS 4.3fixed in 10.6.72010-11-17
CVE-2010-4008 [MEDIUM] CWE-119 CVE-2010-4008: libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, an
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.
nvd
CVE-2015-5747P4MEDIUMCVSS 4.9≤ 10.10.42015-08-17
CVE-2015-5747 [MEDIUM] CWE-399 CVE-2015-5747: The fasttrap driver in the kernel in Apple OS X before 10.10.5 allows local users to cause a denial
The fasttrap driver in the kernel in Apple OS X before 10.10.5 allows local users to cause a denial of service (resource consumption) via unspecified vectors.
nvd
CVE-2015-1141P4MEDIUMCVSS 4.9≤ 10.10.22015-04-10
CVE-2015-1141 [MEDIUM] CVE-2015-1141: The mach_vm_read functionality in the kernel in Apple OS X before 10.10.3 allows local users to caus
The mach_vm_read functionality in the kernel in Apple OS X before 10.10.3 allows local users to cause a denial of service (system crash) via unspecified vectors.
nvd
CVE-2014-8832P4MEDIUMCVSS 4.9≤ 10.10.12015-01-30
CVE-2014-8832 [MEDIUM] CWE-200 CVE-2014-8832: The indexing functionality in Spotlight in Apple OS X before 10.10.2 writes memory contents to an ex
The indexing functionality in Spotlight in Apple OS X before 10.10.2 writes memory contents to an external hard drive, which allows local users to obtain sensitive information by reading from this drive.
nvd
CVE-2013-5176P4MEDIUMCVSS 4.9≤ 10.8.5v10.8.0+5 more2013-10-24
CVE-2013-5176 [MEDIUM] CWE-189 CVE-2013-5176: The kernel in Apple Mac OS X before 10.9 does not properly handle integer values during unspecified
The kernel in Apple Mac OS X before 10.9 does not properly handle integer values during unspecified tty device operations, which allows local users to cause a denial of service (system hang) by triggering a truncation error.
nvd
CVE-2008-0988P4MEDIUMCVSS 4.3v10.4.112008-03-18
CVE-2008-0988 [MEDIUM] CWE-189 CVE-2008-0988: Off-by-one error in the Libsystem strnstr API in libc on Apple Mac OS X 10.4.11 allows context-depen
Off-by-one error in the Libsystem strnstr API in libc on Apple Mac OS X 10.4.11 allows context-dependent attackers to cause a denial of service (crash) via crafted arguments that trigger a buffer over-read.
nvd
CVE-2004-0383P4HIGHCVSS 7.2v10.2.8v10.3.32004-05-04
CVE-2004-0383 [HIGH] CVE-2004-0383: Unknown vulnerability in Mail for Mac OS X 10.3.3 and 10.2.8, with unknown impact, related to "the h
Unknown vulnerability in Mail for Mac OS X 10.3.3 and 10.2.8, with unknown impact, related to "the handling of HTML-formatted email."
nvd
CVE-2004-0382P4HIGHCVSS 7.2v10.2.8v10.3.32004-05-04
CVE-2004-0382 [HIGH] CVE-2004-0382: Unknown vulnerability in the CUPS printing system in Mac OS X 10.3.3 and Mac OS X 10.2.8 with unknow
Unknown vulnerability in the CUPS printing system in Mac OS X 10.3.3 and Mac OS X 10.2.8 with unknown impact, possibly related to a configuration file setting.
nvd
CVE-2014-4430P4MEDIUMCVSS 4.7≤ 10.9.52014-10-18
CVE-2014-4430 [MEDIUM] CWE-310 CVE-2014-4430: CoreStorage in Apple OS X before 10.10 retains a volume's encryption keys upon an eject action in th
CoreStorage in Apple OS X before 10.10 retains a volume's encryption keys upon an eject action in the unlocked state, which makes it easier for physically proximate attackers to obtain cleartext data via a remount.
nvd
CVE-2005-0971P4MEDIUMCVSS 4.6v10.0v10.0.1+28 more2005-05-12
CVE-2005-0971 [MEDIUM] CVE-2005-0971: Stack-based buffer overflow in the semop system call in Mac OS X 10.3.9 and earlier allows local use
Stack-based buffer overflow in the semop system call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments.
nvd
CVE-2007-0738P4MEDIUMCVSS 4.6v10.4v10.4.1+8 more2007-04-24
CVE-2007-0738 [MEDIUM] CVE-2007-0738: The Login Window in Apple Mac OS X 10.4 through 10.4.9 does not display the screen saver authenticat
The Login Window in Apple Mac OS X 10.4 through 10.4.9 does not display the screen saver authentication dialog in certain circumstances when waking from sleep, even though the "require a password to wake the computer from sleep" option is enabled, which allows local users to bypass authentication controls.
nvd
CVE-2005-2742P4MEDIUMCVSS 4.6v10.4.22005-10-26
CVE-2005-2742 [MEDIUM] CVE-2005-2742: SecurityAgent in Apple Mac OS X 10.4.2, under certain circumstances, can cause the "Switch User..."
SecurityAgent in Apple Mac OS X 10.4.2, under certain circumstances, can cause the "Switch User..." button to appear even though the "Enable fast user switching" setting is disabled, which can allow attackers with physical access to gain access to the desktop and bypass the "Require password to wake this computer from sleep or screen saver" setting.
nvd
CVE-2015-7062P4MEDIUMCVSS 4.6≤ 10.11.12015-12-11
CVE-2015-7062 [MEDIUM] CWE-264 CVE-2015-7062: Apple OS X before 10.11.2 and tvOS before 9.1 allow local users to bypass intended configuration-pro
Apple OS X before 10.11.2 and tvOS before 9.1 allow local users to bypass intended configuration-profile installation restrictions via unspecified vectors.
nvd
CVE-2014-1265P4MEDIUMCVSS 4.6≤ 10.9.1v10.7.0+12 more2014-02-27
CVE-2014-1265 [MEDIUM] CWE-264 CVE-2014-1265: The systemsetup program in the Date and Time subsystem in Apple OS X before 10.9.2 allows local user
The systemsetup program in the Date and Time subsystem in Apple OS X before 10.9.2 allows local users to bypass intended access restrictions by changing the current time on the system clock.
nvd
CVE-2009-2835P4MEDIUMCVSS 4.6≤ 10.6.1v10.0+57 more2009-11-10
CVE-2009-2835 [MEDIUM] CWE-20 CVE-2009-2835: The kernel in Apple Mac OS X before 10.6.2 does not properly handle task state segments, which allow
The kernel in Apple Mac OS X before 10.6.2 does not properly handle task state segments, which allows local users to gain privileges, cause a denial of service (system crash), or obtain sensitive information via unspecified vectors.
nvd