cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 148 of 157
CVE-2008-2308P4MEDIUMCVSS 4.6v10.4.1v10.4.2+11 more2008-07-01
CVE-2008-2308 [MEDIUM] CWE-264 CVE-2008-2308: Unspecified vulnerability in Alias Manager in Apple Mac OS X 10.5.1 and earlier on Intel platforms a Unspecified vulnerability in Alias Manager in Apple Mac OS X 10.5.1 and earlier on Intel platforms allows local users to gain privileges or cause a denial of service (memory corruption and application crash) by resolving an alias that contains crafted AFP volume mount information.
nvd
CVE-2020-9792P4MEDIUMCVSS 4.6fixed in 10.15.52020-06-09
CVE-2020-9792 [MEDIUM] CWE-20 CVE-2020-9792: A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.5 a A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5. A USB device may be able to cause a denial of service.
nvd
CVE-2010-0545P4MEDIUMCVSS 4.4v10.5.8v10.6.0+3 more2010-06-17
CVE-2010-0545 [MEDIUM] CWE-264 CVE-2010-0545: The Finder in DesktopServices in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, does not set the exp The Finder in DesktopServices in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, does not set the expected file ownerships during an "Apply to enclosed items" action, which allows local users to bypass intended access restrictions via normal filesystem operations.
nvd
CVE-2015-1099P4MEDIUMCVSS 4.0≤ 10.10.22015-04-10
CVE-2015-1099 [MEDIUM] CWE-362 CVE-2015-1099: Race condition in the setreuid system-call implementation in the kernel in Apple iOS before 8.3, App Race condition in the setreuid system-call implementation in the kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attackers to cause a denial of service via a crafted app.
nvd
CVE-2010-1382P4LOWCVSS 3.5v10.5.8v10.6.0+3 more2010-06-17
CVE-2010-1382 [LOW] CWE-79 CVE-2010-1382: Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac OS X 10.5.8, and 10.6 before 10 Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, allows remote authenticated users to inject arbitrary web script or HTML via crafted Wiki content, related to lack of a charset field.
nvd
CVE-2014-1257P4LOWCVSS 3.6≤ 10.8.5v10.8.0+5 more2014-02-27
CVE-2014-1257 [LOW] CWE-264 CVE-2014-1257: CFNetwork in Apple OS X through 10.8.5 does not remove session cookies upon a Safari reset action, w CFNetwork in Apple OS X through 10.8.5 does not remove session cookies upon a Safari reset action, which allows physically proximate attackers to bypass intended access restrictions by leveraging an unattended workstation.
nvd
CVE-2015-3778P4LOWCVSS 3.3≤ 10.10.42015-08-16
CVE-2015-3778 [LOW] CWE-200 CVE-2015-3778: bootp in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to obtain potentiall bootp in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to obtain potentially sensitive information about MAC addresses seen in previous Wi-Fi sessions by sniffing an 802.11 network for DNAv4 broadcast traffic.
nvd
CVE-2016-1773P4LOWCVSS 3.3≤ 10.11.32016-03-24
CVE-2016-1773 [LOW] CWE-264 CVE-2016-1773: The code-signing subsystem in Apple OS X before 10.11.4 does not properly verify file ownership, whi The code-signing subsystem in Apple OS X before 10.11.4 does not properly verify file ownership, which allows local users to determine the existence of arbitrary files via unspecified vectors.
nvd
CVE-2014-1380P4LOWCVSS 2.6v10.9v10.9.1+2 more2014-07-01
CVE-2014-1380 [LOW] CWE-264 CVE-2014-1380: The Security - Keychain component in Apple OS X before 10.9.4 does not properly implement keystroke The Security - Keychain component in Apple OS X before 10.9.4 does not properly implement keystroke observers, which allows physically proximate attackers to bypass the screen-lock protection mechanism, and enter characters into an arbitrary window under the lock window, via keyboard input.
nvd
CVE-2009-0015P4MEDIUMCVSS 4.9v10.5.62009-02-13
CVE-2009-0015 [MEDIUM] CWE-255 CVE-2009-0015: Unspecified vulnerability in fseventsd in the FSEvents framework in Apple Mac OS X 10.5.6 allows loc Unspecified vulnerability in fseventsd in the FSEvents framework in Apple Mac OS X 10.5.6 allows local users to obtain sensitive information (filesystem activities and directory names) via unknown vectors related to "credential management."
nvd
CVE-2014-4442P4MEDIUMCVSS 4.7≤ 10.9.52014-10-18
CVE-2014-4442 [MEDIUM] CWE-20 CVE-2014-4442: The kernel in Apple OS X before 10.10 allows local users to cause a denial of service (panic) via a The kernel in Apple OS X before 10.10 allows local users to cause a denial of service (panic) via a message to a system control socket.
nvd
CVE-2007-4683P4MEDIUMCVSS 4.6v10.4v10.4.0+10 more2007-11-15
CVE-2007-4683 [MEDIUM] CWE-22 CVE-2007-4683: Directory traversal vulnerability in the kernel in Apple Mac OS X 10.4 through 10.4.10 allows local Directory traversal vulnerability in the kernel in Apple Mac OS X 10.4 through 10.4.10 allows local users to bypass the chroot mechanism via a relative path when changing the current working directory.
nvd
CVE-2004-0089P4MEDIUMCVSS 4.6v10.2.8v10.3.92004-03-03
CVE-2004-0089 [MEDIUM] CVE-2004-0089: Buffer overflow in TruBlueEnvironment in Mac OS X 10.3.x and 10.2.x allows local users to gain privi Buffer overflow in TruBlueEnvironment in Mac OS X 10.3.x and 10.2.x allows local users to gain privileges via a long environment variable.
nvd
CVE-2002-1366P4MEDIUMCVSS 6.2v10.2v10.2.22002-12-26
CVE-2002-1366 [MEDIUM] CVE-2002-1366: Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows local users with lp privileges to cr Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows local users with lp privileges to create or overwrite arbitrary files via file race conditions, as demonstrated by ice-cream.
nvd
CVE-2007-5851P4LOWCVSS 3.6v10.4.112007-12-19
CVE-2007-5851 [LOW] CWE-264 CVE-2007-5851: iChat in Apple Mac OS X 10.4.11 allows network-adjacent remote attackers to automatically initiate a iChat in Apple Mac OS X 10.4.11 allows network-adjacent remote attackers to automatically initiate a video connection to another user via unknown vectors.
nvd
CVE-2014-4407P4LOWCVSS 3.3≤ 10.9.52014-09-18
CVE-2014-4407 [LOW] CWE-200 CVE-2014-4407: IOKit in Apple iOS before 8 and Apple TV before 7 does not properly initialize kernel memory, which IOKit in Apple iOS before 8 and Apple TV before 7 does not properly initialize kernel memory, which allows attackers to obtain sensitive memory-content information via an application that makes crafted IOKit function calls.
nvd
CVE-2016-1748P4LOWCVSS 3.3fixed in 10.11.42016-03-24
CVE-2016-1748 [LOW] CWE-200 CVE-2016-1748: IOHIDFamily in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 al IOHIDFamily in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.
nvd
CVE-2015-3787P4LOWCVSS 3.3≤ 10.10.42015-08-16
CVE-2015-3787 [LOW] CWE-20 CVE-2015-3787: The Bluetooth subsystem in Apple OS X before 10.10.5 allows remote attackers to cause a denial of se The Bluetooth subsystem in Apple OS X before 10.10.5 allows remote attackers to cause a denial of service via malformed Bluetooth ACL packets.
nvd
CVE-2006-0389P4LOWCVSS 2.6v10.4v10.4.1+4 more2006-03-03
CVE-2006-0389 [LOW] CVE-2006-0389: Cross-site scripting (XSS) vulnerability in Syndication (Safari RSS) in Mac OS X 10.4 through 10.4.5 Cross-site scripting (XSS) vulnerability in Syndication (Safari RSS) in Mac OS X 10.4 through 10.4.5 allows remote attackers to execute arbitrary JavaScript via unspecified vectors involving RSS feeds.
nvd
CVE-2015-5853P4LOWCVSS 3.3≤ 10.10.52015-10-09
CVE-2015-5853 [LOW] CWE-200 CVE-2015-5853: AirScan in Apple OS X before 10.11 allows man-in-the-middle attackers to obtain eSCL packet payload AirScan in Apple OS X before 10.11 allows man-in-the-middle attackers to obtain eSCL packet payload data via unspecified vectors.
nvd
Apple macOS vulnerabilities | cvebase