cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 150 of 157
CVE-2019-8856P4LOWCVSS 3.3fixed in 10.15.22020-10-27
CVE-2019-8856 [LOW] CVE-2019-8856: An API issue existed in the handling of outgoing phone calls initiated with Siri. This issue was add An API issue existed in the handling of outgoing phone calls initiated with Siri. This issue was addressed with improved state handling. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. Calls made using Siri may be initiated using the wrong cellular
nvd
CVE-2016-1862P4LOWCVSS 3.3≤ 10.11.42016-06-19
CVE-2016-1862 [LOW] CVE-2016-1862: Intel Graphics Driver in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memor Intel Graphics Driver in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app, a different vulnerability than CVE-2016-1860.
nvd
CVE-2016-1860P4LOWCVSS 3.3≤ 10.11.42016-06-19
CVE-2016-1860 [LOW] CWE-200 CVE-2016-1860: Intel Graphics Driver in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memor Intel Graphics Driver in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app, a different vulnerability than CVE-2016-1862.
nvd
CVE-2013-1031P4LOWCVSS 3.3≤ 10.8.4v10.8.0+3 more2013-09-16
CVE-2013-1031 [LOW] CWE-264 CVE-2013-1031: Power Management in Apple Mac OS X before 10.8.5 does not properly perform locking upon occurrences Power Management in Apple Mac OS X before 10.8.5 does not properly perform locking upon occurrences of a power assertion, which allows physically proximate attackers to bypass intended access restrictions by visiting an unattended workstation on which a locking failure had prevented the startup of the screen saver.
nvd
CVE-2010-0546P4LOWCVSS 3.3v10.5.8v10.6.0+3 more2010-06-17
CVE-2010-0546 [LOW] CWE-59 CVE-2010-0546: Folder Manager in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, allows local users to delete arbitr Folder Manager in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, allows local users to delete arbitrary folders via a symlink attack in conjunction with an unmount operation on a crafted volume, related to the Cleanup At Startup folder.
nvd
CVE-2013-5171P4LOWCVSS 3.3≤ 10.8.5v10.8.0+5 more2013-10-24
CVE-2013-5171 [LOW] CWE-264 CVE-2013-5171: CoreGraphics in Apple Mac OS X before 10.9 allows local users to bypass secure input mode and log an CoreGraphics in Apple Mac OS X before 10.9 allows local users to bypass secure input mode and log an arbitrary application's keystrokes via a hotkey event registration.
nvd
CVE-2014-1321P4LOWCVSS 3.3v10.9v10.9.1+1 more2014-04-23
CVE-2014-1321 [LOW] CWE-264 CVE-2014-1321: Power Management in Apple OS X 10.9.x through 10.9.2 allows physically proximate attackers to bypass Power Management in Apple OS X 10.9.x through 10.9.2 allows physically proximate attackers to bypass an intended transition into the locked-screen state by touching (1) a key or (2) the trackpad during a lid-close action.
nvd
CVE-2022-22656P4LOWCVSS 3.3≥ 10.15, < 10.15.7v10.15.72022-03-18
CVE-2022-22656 [LOW] CWE-287 CVE-2022-22656: An authentication issue was addressed with improved state management. This issue is fixed in macOS B An authentication issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. A local attacker may be able to view the previous logged in user’s desktop from the fast user switching screen.
nvd
CVE-2003-0913P4MEDIUMCVSS 4.6v10.32003-12-01
CVE-2003-0913 [MEDIUM] CVE-2003-0913: Unknown vulnerability in the Terminal application for Mac OS X 10.3 (Client and Server) may allow "u Unknown vulnerability in the Terminal application for Mac OS X 10.3 (Client and Server) may allow "unauthorized access."
nvd
CVE-2002-1266P4MEDIUMCVSS 4.6v10.2.22002-12-11
CVE-2002-1266 [MEDIUM] CVE-2002-1266: Mac OS X 10.2.2 allows local users to gain privileges by mounting a disk image file that was created Mac OS X 10.2.2 allows local users to gain privileges by mounting a disk image file that was created on another system, aka "Local User Privilege Elevation via Disk Image File."
nvd
CVE-2002-1268P4MEDIUMCVSS 4.6v10.2.22002-12-11
CVE-2002-1268 [MEDIUM] CVE-2002-1268: Mac OS X 10.2.2 allows local users to gain privileges via a mounted ISO 9600 CD, aka "User Privilege Mac OS X 10.2.2 allows local users to gain privileges via a mounted ISO 9600 CD, aka "User Privilege Elevation via Mounting an ISO 9600 CD."
nvd
CVE-2003-0880P4MEDIUMCVSS 4.6≤ 10.32003-11-03
CVE-2003-0880 [MEDIUM] CVE-2003-0880: Unknown vulnerability in Mac OS X before 10.3 allows local users to access Dock functions from behin Unknown vulnerability in Mac OS X before 10.3 allows local users to access Dock functions from behind Screen Effects when Full Keyboard Access is enabled using the Keyboard pane in System Preferences.
nvd
CVE-2005-1728P4MEDIUMCVSS 4.6v10.4v10.4.12005-06-08
CVE-2005-1728 [MEDIUM] CVE-2005-1728: MCX Client for Apple Mac OS X 10.4.x up to 10.4.1 insecurely logs Portable Home Directory credential MCX Client for Apple Mac OS X 10.4.x up to 10.4.1 insecurely logs Portable Home Directory credentials, which allows local users to obtain the credentials.
nvd
CVE-2005-2739P4LOWCVSS 2.1v10.0v10.0.1+31 more2005-11-01
CVE-2005-2739 [LOW] CVE-2005-2739: Keychain Access in Mac OS X 10.4.2 and earlier keeps a password visible even if a keychain times out Keychain Access in Mac OS X 10.4.2 and earlier keeps a password visible even if a keychain times out while the password is being viewed, which could allow attackers with physical access to obtain the password.
nvd
CVE-2008-0049P4LOWCVSS 1.9v10.4.112008-03-18
CVE-2008-0049 [LOW] CWE-264 CVE-2008-0049: AppKit in Apple Mac OS X 10.4.11 inadvertently makes an NSApplication mach port available for inter- AppKit in Apple Mac OS X 10.4.11 inadvertently makes an NSApplication mach port available for inter-process communication instead of inter-thread communication, which allows local users to execute arbitrary code via crafted messages to privileged applications.
nvd
CVE-2016-1798P4LOWCVSS 3.3≤ 10.11.42016-05-20
CVE-2016-1798 [LOW] CVE-2016-1798: Audio in Apple OS X before 10.11.5 allows attackers to cause a denial of service (NULL pointer deref Audio in Apple OS X before 10.11.5 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted app.
nvd
CVE-2016-7657P4LOWCVSS 3.3≤ 10.12.12017-02-20
CVE-2016-7657 [LOW] CWE-20 CVE-2016-7657: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "IOKit" component. It allows attackers to obtain sensitive information from kernel memory via a crafted app.
nvd
CVE-2017-2357P4LOWCVSS 3.3≤ 10.12.22017-02-20
CVE-2017-2357 [LOW] CWE-200 CVE-2017-2357: An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "IOAudioFamily" component. It allows attackers to obtain sensitive kernel memory-layout information via a crafted app.
nvd
CVE-2021-30671P4LOWCVSS 3.3≥ 10.15, ≤ 10.15.6v10.15.72021-09-08
CVE-2021-30671 [LOW] CWE-20 CVE-2021-30671: A validation issue was addressed with improved logic. This issue is fixed in macOS Big Sur 11.4, Sec A validation issue was addressed with improved logic. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina. A malicious application may be able to send unauthorized Apple events to Finder.
nvd
CVE-2020-29623P4LOWCVSS 3.3≥ 10.14, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-04-02
CVE-2020-29623 [LOW] CVE-2020-29623: "Clear History and Website Data" did not clear the history. The issue was addressed with improved da "Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. A user may be unable to fully delete browsing history.
nvd
Apple macOS vulnerabilities | cvebase