Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 145 of 157
CVE-2008-4214P4MEDIUMCVSS 4.6v10.4.11v10.5.52008-10-10
CVE-2008-4214 [MEDIUM] CWE-264 CVE-2008-4214: Unspecified vulnerability in Script Editor in Mac OS X 10.4.11 and 10.5.5 allows local users to caus
Unspecified vulnerability in Script Editor in Mac OS X 10.4.11 and 10.5.5 allows local users to cause the scripting dictionary to be written to arbitrary locations, related to an "insecure file operation" on temporary files.
nvd
CVE-2019-8906P4MEDIUMCVSS 4.4fixed in 10.14.42019-02-18
CVE-2019-8906 [MEDIUM] CWE-125 CVE-2019-8906: do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is mis
do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused.
nvd
CVE-2010-4754P4MEDIUMCVSS 4.0≤ 10.6.72011-03-02
CVE-2010-4754 [MEDIUM] CVE-2010-4754: The glob implementation in libc in FreeBSD 7.3 and 8.1, NetBSD 5.0.2, and OpenBSD 4.7, and Libsystem
The glob implementation in libc in FreeBSD 7.3 and 8.1, NetBSD 5.0.2, and OpenBSD 4.7, and Libsystem in Apple Mac OS X before 10.6.8, allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a
nvd
CVE-2013-2776P4MEDIUMCVSS 4.4≤ 10.10.42013-04-08
CVE-2013-2776 [MEDIUM] CVE-2013-2776: sudo 1.3.5 through 1.7.10p5 and 1.8.0 through 1.8.6p6, when running on systems without /proc or the
sudo 1.3.5 through 1.7.10p5 and 1.8.0 through 1.8.6p6, when running on systems without /proc or the sysctl function with the tty_tickets option enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to connecting to the standard inpu
nvd
CVE-2009-0150P4MEDIUMCVSS 4.4v10.5.0v10.5.1+5 more2009-05-13
CVE-2009-0150 [MEDIUM] CWE-119 CVE-2009-0150: Stack-based buffer overflow in Apple Mac OS X 10.5 before 10.5.7 allows local users to gain privileg
Stack-based buffer overflow in Apple Mac OS X 10.5 before 10.5.7 allows local users to gain privileges or cause a denial of service (application crash) by attempting to mount a crafted sparse disk image.
nvd
CVE-2008-2314P4MEDIUMCVSS 4.4v10.4.1v10.4.2+13 more2008-07-01
CVE-2008-2314 [MEDIUM] CWE-264 CVE-2008-2314: Dock in Apple Mac OS X 10.5 before 10.5.4, when Exposé hot corners is enabled, allows physically pro
Dock in Apple Mac OS X 10.5 before 10.5.4, when Exposé hot corners is enabled, allows physically proximate attackers to gain access to a locked session in (1) sleep mode or (2) screen saver mode via unspecified vectors.
nvd
CVE-2016-4739P4LOWCVSS 3.7≤ 10.11.62016-09-25
CVE-2016-4739 [LOW] CWE-200 CVE-2016-4739: mDNSResponder in Apple OS X before 10.12, when VMnet.framework is used, arranges for a DNS proxy to
mDNSResponder in Apple OS X before 10.12, when VMnet.framework is used, arranges for a DNS proxy to listen on all interfaces, which allows remote attackers to obtain sensitive information by sending a DNS query to an unintended interface.
nvd
CVE-2016-7577P4LOWCVSS 3.7≤ 10.12.02017-02-20
CVE-2016-7577 [LOW] CWE-200 CVE-2016-7577: An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. The issue involves the "FaceTime" component, which allows remote attackers to trigger memory corruption and obtain audio data from a call that appeared to have ended.
nvd
CVE-2017-13852P4LOWCVSS 3.3fixed in 10.13.12017-11-13
CVE-2017-13852 [LOW] CWE-200 CVE-2017-13852: An issue was discovered in certain Apple products. iOS before 11.1 is affected. macOS before 10.13.1
An issue was discovered in certain Apple products. iOS before 11.1 is affected. macOS before 10.13.1 is affected. tvOS before 11.1 is affected. watchOS before 4.1 is affected. The issue involves the "Kernel" component. It allows attackers to monitor arbitrary apps via a crafted app that accesses process information at a high rate.
nvd
CVE-2015-7046P4LOWCVSS 2.6≤ 10.11.12015-12-11
CVE-2015-7046 [LOW] CWE-200 CVE-2015-7046: The Sandbox feature in xnu in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchO
The Sandbox feature in xnu in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 does not properly implement privilege separation, which allows attackers to bypass the ASLR protection mechanism via a crafted app with root privileges.
nvd
CVE-2005-2746P4MEDIUMCVSS 5.0v10.3.9v10.4.22005-10-26
CVE-2005-2746 [MEDIUM] CVE-2005-2746: Mail.app in Mail for Apple Mac OS X 10.3.9 and 10.4.2 includes message contents when using auto-repl
Mail.app in Mail for Apple Mac OS X 10.3.9 and 10.4.2 includes message contents when using auto-reply rules, which could cause Mail.app to include decrypted message contents for encrypted messages.
nvd
CVE-2003-1007P4MEDIUMCVSS 5.0v10.2.8v10.3.22004-03-29
CVE-2003-1007 [MEDIUM] CVE-2003-1007: AppleFileServer (AFS) in Apple Mac OS X 10.2.8 and 10.3.2 does not properly handle certain malformed
AppleFileServer (AFS) in Apple Mac OS X 10.2.8 and 10.3.2 does not properly handle certain malformed requests, with unknown impact.
nvd
CVE-2005-2506P4MEDIUMCVSS 5.0v10.3.9v10.4.22005-08-19
CVE-2005-2506 [MEDIUM] CVE-2005-2506: Algorithmic complexity vulnerability in CoreFoundation in Mac OS X 10.3.9 and 10.4.2 allows attacker
Algorithmic complexity vulnerability in CoreFoundation in Mac OS X 10.3.9 and 10.4.2 allows attackers to cause a denial of service (CPU consumption) via crafted Gregorian dates.
nvd
CVE-2004-1123P4MEDIUMCVSS 5.0v10.2v10.2.1+14 more2005-01-10
CVE-2004-1123 [MEDIUM] CVE-2004-1123: Darwin Streaming Server 5.0.1, and possibly earlier versions, allows remote attackers to cause a den
Darwin Streaming Server 5.0.1, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) via a DESCRIBE request with a location that contains a null byte.
nvd
CVE-2004-0086P4MEDIUMCVSS 5.0v10.3.22004-03-03
CVE-2004-0086 [MEDIUM] CVE-2004-0086: Unknown vulnerability in the Mail application for Mac OS X 10.3.2 has unknown impact and attack vect
Unknown vulnerability in the Mail application for Mac OS X 10.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2004-0085.
nvd
CVE-2006-6353P4MEDIUMCVSS 5.0v10.4.82006-12-07
CVE-2006-6353 [MEDIUM] CVE-2006-6353: Multiple unspecified vulnerabilities in BOMArchiveHelper in Mac OS X allow user-assisted remote atta
Multiple unspecified vulnerabilities in BOMArchiveHelper in Mac OS X allow user-assisted remote attackers to cause a denial of service (application crash) via unspecified vectors related to (1) certain KERN_PROTECTION_FAILURE thread crashes and (2) certain KERN_INVALID_ADDRESS thread crashes, as discovered with the "iSec Partners FileP fuzzer".
nvd
CVE-2006-4403P4MEDIUMCVSS 4.0≤ 10.4.82006-11-30
CVE-2006-4403 [MEDIUM] CVE-2006-4403: The FTP server in Apple Mac OS X 10.4.8 and earlier, when FTP Access is enabled, will crash when a l
The FTP server in Apple Mac OS X 10.4.8 and earlier, when FTP Access is enabled, will crash when a login failure occurs with a valid user name, which allows remote attackers to cause a denial of service (crash) and enumerate valid usernames.
nvd
CVE-2013-3953P4MEDIUMCVSS 4.9v10.8.0v10.8.1+3 more2013-06-05
CVE-2013-3953 [MEDIUM] CWE-200 CVE-2013-3953: The mach_port_space_info function in osfmk/ipc/mach_debug.c in the XNU kernel in Apple Mac OS X 10.8
The mach_port_space_info function in osfmk/ipc/mach_debug.c in the XNU kernel in Apple Mac OS X 10.8.x does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory via a crafted call.
nvd
CVE-2015-1138P4MEDIUMCVSS 4.9≤ 10.10.22015-04-10
CVE-2015-1138 [MEDIUM] CWE-20 CVE-2015-1138: Hypervisor in Apple OS X before 10.10.3 allows local users to cause a denial of service via unspecif
Hypervisor in Apple OS X before 10.10.3 allows local users to cause a denial of service via unspecified vectors.
nvd
CVE-2014-1320P4MEDIUMCVSS 4.9≤ 10.9.2v10.9+1 more2014-04-23
CVE-2014-1320 [MEDIUM] CWE-200 CVE-2014-1320: IOKit in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 places kernel
IOKit in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 places kernel pointers into an object data structure, which makes it easier for local users to bypass the ASLR protection mechanism by reading unspecified attributes of the object.
nvd