cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 149 of 157
CVE-2016-4670P4LOWCVSS 3.3≤ 10.12.02017-02-20
CVE-2016-4670 [LOW] CWE-255 CVE-2016-4670: An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. The issue involves the "Security" component. It allows local users to discover lengths of arbitrary passwords by reading a log.
nvd
CVE-2007-4679P4LOWCVSS 2.6≥ 10.4, ≤ 10.4.102007-11-15
CVE-2007-4679 [LOW] CWE-264 CVE-2007-4679: CFFTP in CFNetwork for Apple Mac OS X 10.4 through 10.4.10 allows remote FTP servers to force client CFFTP in CFNetwork for Apple Mac OS X 10.4 through 10.4.10 allows remote FTP servers to force clients to connect to other hosts via crafted responses to FTP PASV commands.
nvd
CVE-2015-7094P4LOWCVSS 2.6≤ 10.11.12015-12-11
CVE-2015-7094 [LOW] CWE-20 CVE-2015-7094: CFNetwork HTTPProtocol in Apple iOS before 9.2 and OS X before 10.11.2 allows man-in-the-middle atta CFNetwork HTTPProtocol in Apple iOS before 9.2 and OS X before 10.11.2 allows man-in-the-middle attackers to bypass the HSTS protection mechanism via a crafted URL.
nvd
CVE-2009-2194P4MEDIUMCVSS 4.9v10.5.6v10.5+7 more2009-08-06
CVE-2009-2194 [MEDIUM] CVE-2009-2194: Apple Mac OS X 10.5 before 10.5.8 does not properly share file descriptors over local sockets, which Apple Mac OS X 10.5 before 10.5.8 does not properly share file descriptors over local sockets, which allows local users to cause a denial of service (system crash) by placing file descriptors in messages sent to a socket that has no receiver, related to a "synchronization issue."
nvd
CVE-2007-0743P4MEDIUMCVSS 4.9v10.3.9v10.4+9 more2007-04-24
CVE-2007-0743 [MEDIUM] CVE-2007-0743: URLMount in Apple Mac OS X 10.3.9 through 10.4.9 passes the username and password credentials for mo URLMount in Apple Mac OS X 10.3.9 through 10.4.9 passes the username and password credentials for mounting filesystems on SMB servers as command line arguments to the mount_sub command, which may allow local users to obtain sensitive information by listing the process.
nvd
CVE-2008-4219P4MEDIUMCVSS 4.9≤ 10.5.5v10.5+4 more2008-12-17
CVE-2008-4219 [MEDIUM] CWE-399 CVE-2008-4219: The kernel in Apple Mac OS X before 10.5.6 allows local users to cause a denial of service (infinite The kernel in Apple Mac OS X before 10.5.6 allows local users to cause a denial of service (infinite loop and system halt) by running an application that is dynamically linked to libraries on an NFS server, related to occurrence of an exception in this application.
nvd
CVE-2008-2312P4MEDIUMCVSS 4.9v10.4.112008-09-16
CVE-2008-2312 [MEDIUM] CWE-255 CVE-2008-2312: Network Preferences in Apple Mac OS X 10.4.11 stores PPP passwords in cleartext in a world-readable Network Preferences in Apple Mac OS X 10.4.11 stores PPP passwords in cleartext in a world-readable file, which allows local users to obtain sensitive information by reading this file.
nvd
CVE-2011-3435P4LOWCVSS 2.1v10.7.0v10.7.12011-10-14
CVE-2011-3435 [LOW] CWE-255 CVE-2011-3435: Open Directory in Apple Mac OS X 10.7 before 10.7.2 allows local users to read the password data of Open Directory in Apple Mac OS X 10.7 before 10.7.2 allows local users to read the password data of arbitrary users via unspecified vectors.
nvd
CVE-2003-0518P4MEDIUMCVSS 4.6v10.2v10.2.1+5 more2003-08-18
CVE-2003-0518 [MEDIUM] CVE-2003-0518: The screen saver in MacOS X allows users with physical access to cause the screen saver to crash and The screen saver in MacOS X allows users with physical access to cause the screen saver to crash and gain access to the underlying session via a large number of characters in the password field, possibly triggering a buffer overflow.
nvd
CVE-2005-2515P4MEDIUMCVSS 4.6v10.4.22005-08-19
CVE-2005-2515 [MEDIUM] CVE-2005-2515: Quartz Composer Screen Saver in Mac OS X 10.4.2 allows local users to access links from the RSS Visu Quartz Composer Screen Saver in Mac OS X 10.4.2 allows local users to access links from the RSS Visualizer even when a password is required.
nvd
CVE-2006-4387P4MEDIUMCVSS 4.6v10.4v10.4.1+6 more2006-10-03
CVE-2006-4387 [MEDIUM] CVE-2006-4387: Apple Mac OS X 10.4 through 10.4.7, when the administrator clears the "Allow user to administer this Apple Mac OS X 10.4 through 10.4.7, when the administrator clears the "Allow user to administer this computer" checkbox in System Preferences for a user, does not remove the user's account from the appserveradm or appserverusr groups, which still allows the user to manage WebObjects applications.
nvd
CVE-2005-1473P4MEDIUMCVSS 4.6v10.4.12005-06-13
CVE-2005-1473 [MEDIUM] CVE-2005-1473: SecurityAgent in Apple Mac OS X 10.4.1 allows attackers with physical access to bypass the locked sc SecurityAgent in Apple Mac OS X 10.4.1 allows attackers with physical access to bypass the locked screensaver and launch background applications by opening a URL from a text input field.
nvd
CVE-2005-0712P4MEDIUMCVSS 4.6v10.1v10.2+1 more2005-05-02
CVE-2005-0712 [MEDIUM] CVE-2005-0712: Mac OS X before 10.3.8 users world-writable permissions for certain directories, which may allow loc Mac OS X before 10.3.8 users world-writable permissions for certain directories, which may allow local users to gain privileges, possibly via the receipt cache or ColorSync profiles.
nvd
CVE-2008-0990P4MEDIUMCVSS 4.4v10.4.112008-03-18
CVE-2008-0990 [MEDIUM] CWE-200 CVE-2008-0990: notifyd in Apple Mac OS X 10.4.11 does not verify that Mach port death notifications have originated notifyd in Apple Mac OS X 10.4.11 does not verify that Mach port death notifications have originated from the kernel, which allows local users to cause a denial of service via spoofed death notifications that prevent other applications from receiving notifications.
nvd
CVE-2006-0391P4LOWCVSS 1.7v10.3.1v10.3.3+10 more2006-03-03
CVE-2006-0391 [LOW] CVE-2006-0391: Directory traversal vulnerability in the BOM framework in Mac OS X 10.x before 10.3.9 and 10.4 befor Directory traversal vulnerability in the BOM framework in Mac OS X 10.x before 10.3.9 and 10.4 before 10.4.5 allows user-assisted attackers to overwrite or create arbitrary files via an archive that is handled by BOMArchiveHelper.
nvd
CVE-2017-2426P4LOWCVSS 3.3≤ 10.12.32017-04-02
CVE-2017-2426 [LOW] CWE-200 CVE-2017-2426: An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "iBooks" component. It allows remote attackers to obtain sensitive information from local files via a file: URL in an iBooks file.
nvd
CVE-2016-1796P4LOWCVSS 3.3≤ 10.11.42016-05-20
CVE-2016-1796 [LOW] CWE-200 CVE-2016-1796: Apple Type Services (ATS) in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel m Apple Type Services (ATS) in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information or cause a denial of service (out-of-bounds memory access) via a crafted app.
nvd
CVE-2016-4715P4LOWCVSS 3.3≤ 10.11.62016-09-25
CVE-2016-4715 [LOW] CWE-200 CVE-2016-4715: The Date & Time Pref Pane component in Apple OS X before 10.12 mishandles the .GlobalPreferences fil The Date & Time Pref Pane component in Apple OS X before 10.12 mishandles the .GlobalPreferences file, which allows attackers to discover a user's location via a crafted app.
nvd
CVE-2016-1791P4LOWCVSS 3.3≤ 10.11.42016-05-20
CVE-2016-1791 [LOW] CWE-200 CVE-2016-1791: The AMD subsystem in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-la The AMD subsystem in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.
nvd
CVE-2019-8502P4LOWCVSS 3.3fixed in 10.14.42019-12-18
CVE-2019-8502 [LOW] CWE-20 CVE-2019-8502: An API issue existed in the handling of dictation requests. This issue was addressed with improved v An API issue existed in the handling of dictation requests. This issue was addressed with improved validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to initiate a Dictation request without user authorization.
nvd
Apple macOS vulnerabilities | cvebase