cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 15 of 157
CVE-2022-26775P3CRITICALCVSS 9.8≥ 10.15, < 10.15.7v10.15.72022-05-26
CVE-2022-26775 [CRITICAL] CWE-190 CVE-2022-26775: An integer overflow was addressed with improved input validation. This issue is fixed in Security Up An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4. An attacker may be able to cause unexpected application termination or arbitrary code execution.
nvd
CVE-2015-4026P3HIGHCVSS 7.5≤ 10.10.42015-06-09
CVE-2015-4026 [HIGH] CVE-2015-4026: The pcntl_exec implementation in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 trun The pcntl_exec implementation in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character, which might allow remote attackers to bypass intended extension restrictions and execute files with unexpected names via a crafted first argument. NOTE: this vulnerability exists because of an incomplete fix fo
nvd
CVE-2019-8601P3HIGHCVSS 8.8fixed in 10.14.52019-12-18
CVE-2019-8601 [HIGH] CWE-190 CVE-2019-8601: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2021-30937P3HIGHCVSS 7.8≥ 10.15, ≤ 10.15.7v10.15.72021-08-24
CVE-2021-30937 [HIGH] CWE-787 CVE-2021-30937: A memory corruption vulnerability was addressed with improved locking. This issue is fixed in macOS A memory corruption vulnerability was addressed with improved locking. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2013-1775P4MEDIUMCVSS 6.9PoC≤ 10.10.42013-03-05
CVE-2013-1775 [MEDIUM] CWE-264 CVE-2013-1775: sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximat sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypass intended time restrictions and retain privileges without re-authenticating by setting the system clock and sudo user timestamp to the epoch.
nvd
CVE-2016-4702P3CRITICALCVSS 9.8fixed in 10.12.02016-09-25
CVE-2016-4702 [CRITICAL] CWE-119 CVE-2016-4702: Audio in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote Audio in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2006-6173P4HIGHCVSS 7.2PoC≤ 10.4.62006-11-30
CVE-2006-6173 [HIGH] CVE-2006-6173: Buffer overflow in the shared_region_make_private_np function in vm/vm_unix.c in Mac OS X 10.4.6 and Buffer overflow in the shared_region_make_private_np function in vm/vm_unix.c in Mac OS X 10.4.6 and earlier allows local users to execute arbitrary code via (1) a small range count, which causes insufficient memory allocation, or (2) a large number of ranges in the shared_region_make_private_np_args parameter.
nvd
CVE-2015-7077P4HIGHCVSS 7.2PoC≤ 10.11.12015-12-11
CVE-2015-7077 [HIGH] CWE-119 CVE-2015-7077: The Intel Graphics Driver component in Apple OS X before 10.11.2 allows local users to gain privileg The Intel Graphics Driver component in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial of service (out-of-bounds memory access) via unspecified vectors.
nvd
CVE-2015-7106P4HIGHCVSS 7.2PoC≤ 10.11.12015-12-11
CVE-2015-7106 [HIGH] CWE-119 CVE-2015-7106: The Intel Graphics Driver component in Apple OS X before 10.11.2 allows local users to gain privileg The Intel Graphics Driver component in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2009-1235P4HIGHCVSS 7.2PoC≤ 10.5.6v10.0+53 more2009-04-02
CVE-2009-1235 [HIGH] CWE-264 CVE-2009-1235: XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interactio XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space and the HFS IOCTL handler, which allows local users to overwrite kernel memory and gain privileges by attaching an HFS+ disk image and performing certain steps involving HFS_GET_BOOT_INFO fcntl calls.
nvd
CVE-2007-0753P4HIGHCVSS 7.2PoCv10.3v10.3.1+18 more2007-05-24
CVE-2007-0753 [HIGH] CWE-134 CVE-2007-0753: Format string vulnerability in the VPN daemon (vpnd) in Apple Mac OS X 10.3.9 and 10.4.9 allows loca Format string vulnerability in the VPN daemon (vpnd) in Apple Mac OS X 10.3.9 and 10.4.9 allows local users to execute arbitrary code via the -i parameter.
nvd
CVE-2007-0752P4HIGHCVSS 7.2PoCv10.4.82007-05-24
CVE-2007-0752 [HIGH] CVE-2007-0752: The PPP daemon (pppd) in Apple Mac OS X 10.4.8 checks ownership of the stdin file descriptor to dete The PPP daemon (pppd) in Apple Mac OS X 10.4.8 checks ownership of the stdin file descriptor to determine if the invoker has sufficient privileges, which allows local users to load arbitrary plugins and gain root privileges by bypassing this check.
nvd
CVE-2013-5135P3HIGHCVSS 7.5≤ 10.8.5v10.8.0+5 more2013-10-24
CVE-2013-5135 [HIGH] CWE-134 CVE-2013-5135: Format string vulnerability in Screen Sharing Server in Apple Mac OS X before 10.9 and Apple Remote Format string vulnerability in Screen Sharing Server in Apple Mac OS X before 10.9 and Apple Remote Desktop before 3.5.4 allows remote attackers to execute arbitrary code via format string specifiers in a VNC username.
nvd
CVE-2022-32787P3HIGHCVSS 8.8v10.15.72022-09-23
CVE-2022-32787 [HIGH] CWE-787 CVE-2022-32787: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2017-13865P4MEDIUMCVSS 5.5PoCfixed in 10.13.22017-12-25
CVE-2017-13865 [MEDIUM] CWE-200 CVE-2017-13865: An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvd
CVE-2006-0396P4MEDIUMCVSS 5.1PoCv10.4v10.4.1+4 more2006-03-14
CVE-2006-0396 [MEDIUM] CVE-2006-0396: Buffer overflow in Mail in Apple Mac OS X 10.4 up to 10.4.5, when patched with Security Update 2006- Buffer overflow in Mail in Apple Mac OS X 10.4 up to 10.4.5, when patched with Security Update 2006-001, allows remote attackers to execute arbitrary code via a long Real Name value in an e-mail attachment sent in AppleDouble format, which triggers the overflow when the user double-clicks on an attachment.
nvd
CVE-2018-4090P4MEDIUMCVSS 5.5PoCfixed in 10.13.32018-04-03
CVE-2018-4090 [MEDIUM] CWE-200 CVE-2018-4090: An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13 An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvd
CVE-2019-6208P4MEDIUMCVSS 5.5PoCfixed in 10.14.32019-03-05
CVE-2019-6208 [MEDIUM] CWE-665 CVE-2019-6208: A memory initialization issue was addressed with improved memory handling. This issue is fixed in iO A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A malicious application may cause unexpected changes in memory shared between processes.
nvd
CVE-2021-30793P3CRITICALCVSS 9.8v10.14v10.14.0+14 more2021-09-08
CVE-2021-30793 [CRITICAL] CVE-2021-30793: A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11. A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2020-9906P3CRITICALCVSS 9.1≥ 10.13, < 10.13.6≥ 10.14, < 10.14.6+3 more2020-10-22
CVE-2020-9906 [CRITICAL] CWE-20 CVE-2020-9906: A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 1 A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, watchOS 6.2.8. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.
nvd
Apple macOS vulnerabilities | cvebase