Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 146 of 157
CVE-2014-1355P4MEDIUMCVSS 4.9v10.9v10.9.1+2 more2014-07-01
CVE-2014-1355 [MEDIUM] CVE-2014-1355: The IOKit implementation in the kernel in Apple iOS before 7.1.2 and Apple TV before 6.1.2, and in I
The IOKit implementation in the kernel in Apple iOS before 7.1.2 and Apple TV before 6.1.2, and in IOReporting in Apple OS X before 10.9.4, allows local users to cause a denial of service (NULL pointer dereference and reboot) via crafted API arguments.
nvd
CVE-2015-5902P4MEDIUMCVSS 4.9≤ 10.10.52015-10-09
CVE-2015-5902 [MEDIUM] CVE-2015-5902: The debugging feature in the kernel in Apple OS X before 10.11 mismanages state, which allows local
The debugging feature in the kernel in Apple OS X before 10.11 mismanages state, which allows local users to cause a denial of service via unspecified vectors.
nvd
CVE-2013-5192P4MEDIUMCVSS 4.9≤ 10.8.5v10.8.0+5 more2013-10-24
CVE-2013-5192 [MEDIUM] CWE-20 CVE-2013-5192: The USB hub controller in Apple Mac OS X before 10.9 allows local users to cause a denial of service
The USB hub controller in Apple Mac OS X before 10.9 allows local users to cause a denial of service (system crash) via a request with a crafted (1) port or (2) port number.
nvd
CVE-2013-5177P4MEDIUMCVSS 4.9≤ 10.8.5v10.8.0+5 more2013-10-24
CVE-2013-5177 [MEDIUM] CWE-189 CVE-2013-5177: The kernel in Apple Mac OS X before 10.9 allows local users to cause a denial of service (panic) via
The kernel in Apple Mac OS X before 10.9 allows local users to cause a denial of service (panic) via an invalid iovec structure.
nvd
CVE-2010-1794P4MEDIUMCVSS 4.9v10.6.02010-08-02
CVE-2010-1794 [MEDIUM] CWE-264 CVE-2010-1794: The webdav_mount function in webdav_vfsops.c in the WebDAV kernel extension (aka webdav_fs.kext) for
The webdav_mount function in webdav_vfsops.c in the WebDAV kernel extension (aka webdav_fs.kext) for Mac OS X 10.6 allows local users to cause a denial of service (panic) via a mount request with a large integer in the pa_socket_namelen field.
nvd
CVE-2006-0393P4MEDIUMCVSS 4.0v10.4.72006-08-03
CVE-2006-0393 [MEDIUM] CVE-2006-0393: OpenSSH in Apple Mac OS X 10.4.7 allows remote attackers to cause a denial of service or determine a
OpenSSH in Apple Mac OS X 10.4.7 allows remote attackers to cause a denial of service or determine account existence by attempting to log in using an invalid user, which causes the server to hang.
nvd
CVE-2005-2521P4MEDIUMCVSS 4.6v10.3.92005-08-19
CVE-2005-2521 [MEDIUM] CVE-2005-2521: Buffer overflow in traceroute in Mac OS X 10.3.9 allows local users to execute arbitrary code via un
Buffer overflow in traceroute in Mac OS X 10.3.9 allows local users to execute arbitrary code via unknown vectors.
nvd
CVE-2007-0739P4MEDIUMCVSS 4.6v10.4v10.4.1+8 more2007-04-24
CVE-2007-0739 [MEDIUM] CVE-2007-0739: The Login Window in Apple Mac OS X 10.4 through 10.4.9 displays the software update window beneath t
The Login Window in Apple Mac OS X 10.4 through 10.4.9 displays the software update window beneath the loginwindow authentication dialog in certain circumstances related to running scheduled tasks, which allows local users to bypass authentication controls.
nvd
CVE-2005-3700P4MEDIUMCVSS 4.6v10.3.9v10.4.32005-12-01
CVE-2005-3700 [MEDIUM] CVE-2005-3700: Unknown vulnerability in iodbcadmintool in the ODBC Administrator utility in Mac OS X and OS X Serve
Unknown vulnerability in iodbcadmintool in the ODBC Administrator utility in Mac OS X and OS X Server 10.3.9 and 10.4.3 allows local users to execute arbitrary code via unknown attack vectors.
nvd
CVE-2008-1572P4MEDIUMCVSS 4.6v10.4.112008-06-02
CVE-2008-1572 [MEDIUM] CWE-264 CVE-2008-1572: Image Capture in Apple Mac OS X before 10.5 does not properly use temporary files, which allows loca
Image Capture in Apple Mac OS X before 10.5 does not properly use temporary files, which allows local users to overwrite arbitrary files, and display images that are being resized by this application.
nvd
CVE-2006-0401P4MEDIUMCVSS 4.6v10.4.52006-04-05
CVE-2006-0401 [MEDIUM] CVE-2006-0401: Unspecified vulnerability in Mac OS X before 10.4.6, when running on an Intel-based computer, allows
Unspecified vulnerability in Mac OS X before 10.4.6, when running on an Intel-based computer, allows attackers with physical access to bypass the firmware password and log on in Single User Mode via unspecified vectors.
nvd
CVE-2011-0260P4MEDIUMCVSS 4.6v10.7.0v10.7.12011-10-14
CVE-2011-0260 [MEDIUM] CWE-264 CVE-2011-0260: The CoreProcesses component in Apple Mac OS X 10.7 before 10.7.2 does not prevent a system window fr
The CoreProcesses component in Apple Mac OS X 10.7 before 10.7.2 does not prevent a system window from receiving keystrokes in the locked-screen state, which might allow physically proximate attackers to bypass intended access restrictions by typing into this window.
nvd
CVE-2008-2324P4MEDIUMCVSS 4.6v10.4.112008-08-04
CVE-2008-2324 [MEDIUM] CWE-264 CVE-2008-2324: The Repair Permissions tool in Disk Utility in Apple Mac OS X 10.4.11 adds the setuid bit to the ema
The Repair Permissions tool in Disk Utility in Apple Mac OS X 10.4.11 adds the setuid bit to the emacs executable file, which allows local users to gain privileges by executing commands within emacs.
nvd
CVE-2007-0737P4MEDIUMCVSS 4.6v10.3.9v10.4+9 more2007-04-24
CVE-2007-0737 [MEDIUM] CVE-2007-0737: The Login Window in Apple Mac OS X 10.3.9 through 10.4.9 does not properly check certain environment
The Login Window in Apple Mac OS X 10.3.9 through 10.4.9 does not properly check certain environment variables, which allows local users to gain privileges via unspecified vectors.
nvd
CVE-2008-2313P4MEDIUMCVSS 4.6v10.4.1v10.4.2+13 more2008-07-01
CVE-2008-2313 [MEDIUM] CWE-264 CVE-2008-2313: Apple Mac OS X before 10.5 uses weak permissions for the User Template directory, which allows local
Apple Mac OS X before 10.5 uses weak permissions for the User Template directory, which allows local users to gain privileges by inserting a Trojan horse file into this directory.
nvd
CVE-2020-9804P4MEDIUMCVSS 4.6fixed in 10.15.52020-06-09
CVE-2020-9804 [MEDIUM] CVE-2020-9804: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.5. Inserting a USB device that sends invalid messages may cause a kernel panic.
nvd
CVE-2009-0149P4MEDIUMCVSS 4.4v10.4.11v10.5.0+6 more2009-05-13
CVE-2009-0149 [MEDIUM] CWE-94 CVE-2009-0149: Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows local users to gain privileges or cause a denia
Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows local users to gain privileges or cause a denial of service (application crash) by attempting to mount a crafted sparse disk image that triggers memory corruption.
nvd
CVE-2013-1776P4MEDIUMCVSS 4.4≤ 10.10.42013-04-08
CVE-2013-1776 [MEDIUM] CWE-264 CVE-2013-1776: sudo 1.3.5 through 1.7.10 and 1.8.0 through 1.8.5, when the tty_tickets option is enabled, does not
sudo 1.3.5 through 1.7.10 and 1.8.0 through 1.8.5, when the tty_tickets option is enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to connecting to the standard input, output, and error file descriptors of another termi
nvd
CVE-2013-2777P4MEDIUMCVSS 4.4≤ 10.10.42013-04-08
CVE-2013-2777 [MEDIUM] CVE-2013-2777: sudo before 1.7.10p5 and 1.8.x before 1.8.6p6, when the tty_tickets option is enabled, does not prop
sudo before 1.7.10p5 and 1.8.x before 1.8.6p6, when the tty_tickets option is enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to a session without a controlling terminal device and connecting to the standard input, output, an
nvd
CVE-2007-0728P4MEDIUMCVSS 4.4v10.3.9v10.4+8 more2007-03-13
CVE-2007-0728 [MEDIUM] CVE-2007-0728: Unspecified vulnerability in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 creates files insecurely
Unspecified vulnerability in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 creates files insecurely while initializing a USB printer, which allows local users to create or overwrite arbitrary files.
nvd