cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 151 of 157
CVE-2019-8642P4LOWCVSS 3.3fixed in 10.14.42020-10-27
CVE-2019-8642 [LOW] CWE-295 CVE-2019-8642: An issue existed in the handling of S-MIME certificates. This issue was addressed with improved vali An issue existed in the handling of S-MIME certificates. This issue was addressed with improved validation of S-MIME certificates. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra. Processing a maliciously crafted mail message may lead to S/MIME signature spoofing.
nvd
CVE-2019-8809P4LOWCVSS 3.3fixed in 10.152020-10-27
CVE-2019-8809 [LOW] CVE-2019-8809: A validation issue was addressed with improved logic. This issue is fixed in macOS Catalina 10.15, i A validation issue was addressed with improved logic. This issue is fixed in macOS Catalina 10.15, iOS 13.1 and iPadOS 13.1, tvOS 13, watchOS 6, iOS 13. A local app may be able to read a persistent account identifier.
nvd
CVE-2017-7138P4LOWCVSS 3.3≤ 10.12.62017-10-23
CVE-2017-7138 [LOW] CWE-200 CVE-2017-7138: An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involve An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "Directory Utility" component. It allows local users to discover the Apple ID of the computer's owner.
nvd
CVE-2006-5681P4LOWCVSS 2.6v10.4v10.4.1+7 more2006-12-20
CVE-2006-5681 [LOW] CVE-2006-5681: QuickTime for Java on Mac OS X 10.4 through 10.4.8, when used with Quartz Composer, allows remote at QuickTime for Java on Mac OS X 10.4 through 10.4.8, when used with Quartz Composer, allows remote attackers to obtain sensitive information (screen images) via a Java applet that accesses images that are being rendered by other embedded QuickTime objects.
nvd
CVE-2010-0537P4LOWCVSS 2.6v10.6.0v10.6.1+1 more2010-03-30
CVE-2010-0537 [LOW] CWE-264 CVE-2010-0537: DesktopServices in Apple Mac OS X 10.6 before 10.6.3 does not properly resolve pathnames in certain DesktopServices in Apple Mac OS X 10.6 before 10.6.3 does not properly resolve pathnames in certain circumstances involving an application's save panel, which allows user-assisted remote attackers to trigger unintended remote file copying via a crafted share name.
nvd
CVE-2005-2503P4MEDIUMCVSS 4.6v10.3.9v10.4.22005-08-19
CVE-2005-2503 [MEDIUM] CVE-2005-2503: AppKit for Mac OS X 10.3.9 and 10.4.2 allows attackers with physical access to create local accounts AppKit for Mac OS X 10.3.9 and 10.4.2 allows attackers with physical access to create local accounts by forcing a particular error to occur at the login window.
nvd
CVE-2004-0517P4MEDIUMCVSS 4.6v10.3v10.3.1+2 more2004-08-18
CVE-2004-0517 [MEDIUM] CVE-2004-0517: Unknown vulnerability in Mac OS X 10.3.4, related to "handling of process IDs during package install Unknown vulnerability in Mac OS X 10.3.4, related to "handling of process IDs during package installation," a different vulnerability than CVE-2004-0516.
nvd
CVE-2005-1338P4MEDIUMCVSS 4.6v10.3.92005-05-04
CVE-2005-1338 [MEDIUM] CVE-2005-1338: Mac OS X 10.3.9, when using an LDAP server that does not use ldap_extended_operation, may store init Mac OS X 10.3.9, when using an LDAP server that does not use ldap_extended_operation, may store initial LDAP passwords for new accounts in plaintext.
nvd
CVE-2006-1440P4LOWCVSS 2.1v10.3.9v10.4.62006-05-12
CVE-2006-1440 [LOW] CVE-2006-1440: BOM in Apple Mac OS X 10.3.9 and 10.4.6 allows attackers to overwrite arbitrary files via an archive BOM in Apple Mac OS X 10.3.9 and 10.4.6 allows attackers to overwrite arbitrary files via an archive that contains symbolic links.
nvd
CVE-2003-0878P4LOWCVSS 2.1≤ 10.32003-11-03
CVE-2003-0878 [LOW] CVE-2003-0878: slpd daemon in Mac OS X before 10.3 allows local users to overwrite arbitrary files via a symlink at slpd daemon in Mac OS X before 10.3 allows local users to overwrite arbitrary files via a symlink attack on a temporary file, a different vulnerability than CVE-2003-0875.
nvd
CVE-2014-4371P4LOWCVSS 1.9≤ 10.9.52014-09-18
CVE-2014-4371 [LOW] CWE-665 CVE-2014-4371: The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers to obtain sensitive memory-content and memory-layout information via a crafted application, a different vulnerability than CVE-2014-4419, CVE-2014-4420, and CVE-2014-4421.
nvd
CVE-2014-4419P4LOWCVSS 1.9≤ 10.10.12014-09-18
CVE-2014-4419 [LOW] CVE-2014-4419: The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers to obtain sensitive memory-content and memory-layout information via a crafted application, a different vulnerability than CVE-2014-4371, CVE-2014-4420, and CVE-2014-4421.
nvd
CVE-2014-4420P4LOWCVSS 1.9≤ 10.10.12014-09-18
CVE-2014-4420 [LOW] CVE-2014-4420: The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers to obtain sensitive memory-content and memory-layout information via a crafted application, a different vulnerability than CVE-2014-4371, CVE-2014-4419, and CVE-2014-4421.
nvd
CVE-2014-4421P4LOWCVSS 1.9≤ 10.10.12014-09-18
CVE-2014-4421 [LOW] CVE-2014-4421: The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers to obtain sensitive memory-content and memory-layout information via a crafted application, a different vulnerability than CVE-2014-4371, CVE-2014-4419, and CVE-2014-4420.
nvd
CVE-2016-4717P4LOWCVSS 3.3≤ 10.11.62016-09-25
CVE-2016-4717 [LOW] CVE-2016-4717: The File Bookmark component in Apple OS X before 10.12 mishandles scoped-bookmark file descriptors, The File Bookmark component in Apple OS X before 10.12 mishandles scoped-bookmark file descriptors, which allows attackers to cause a denial of service via a crafted app.
nvd
CVE-2020-9986P4LOWCVSS 3.3fixed in 10.15.72020-10-22
CVE-2020-9986 [LOW] CVE-2020-9986: A file access issue existed with certain home folder files. This was addressed with improved access A file access issue existed with certain home folder files. This was addressed with improved access restrictions. This issue is fixed in macOS Catalina 10.15.7. A malicious application may be able to read sensitive location information.
nvd
CVE-2018-4470P4LOWCVSS 3.3fixed in 10.13.62019-04-03
CVE-2018-4470 [LOW] CVE-2018-4470: A privacy issue in the handling of Open Directory records was addressed with improved indexing. This A privacy issue in the handling of Open Directory records was addressed with improved indexing. This issue affected versions prior to macOS High Sierra 10.13.6.
nvd
CVE-2020-9776P4LOWCVSS 3.3fixed in 10.15.42020-04-01
CVE-2020-9776 [LOW] CVE-2020-9776: This issue was addressed with a new entitlement. This issue is fixed in macOS Catalina 10.15.4. A ma This issue was addressed with a new entitlement. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be able to access a user's call history.
nvd
CVE-2020-9786P4LOWCVSS 3.3fixed in 10.15.42020-10-27
CVE-2020-9786 [LOW] CVE-2020-9786: This issue was addressed with improved checks This issue is fixed in macOS Catalina 10.15.4, Securit This issue was addressed with improved checks This issue is fixed in macOS Catalina 10.15.4, Security Update 2020-002 Mojave, Security Update 2020-002 High Sierra. An application may be able to trigger a sysdiagnose.
nvd
CVE-2021-1771P4LOWCVSS 3.3≥ 10.14, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-04-02
CVE-2021-1771 [LOW] CVE-2021-1771: This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security U This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. A user that is removed from an iMessage group could rejoin the group.
nvd
Apple macOS vulnerabilities | cvebase