Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 152 of 157
CVE-2015-5884P4LOWCVSS 3.3≤ 10.10.52015-10-09
CVE-2015-5884 [LOW] CWE-200 CVE-2015-5884: The Mail Drop feature in Mail in Apple OS X before 10.11 mishandles encryption parameters for attach
The Mail Drop feature in Mail in Apple OS X before 10.11 mishandles encryption parameters for attachments, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during transmission of an S/MIME e-mail message with a large attachment.
nvd
CVE-2016-7624P4LOWCVSS 3.3≤ 10.12.12017-02-20
CVE-2016-7624 [LOW] CWE-200 CVE-2016-7624: An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "IOAcceleratorFamily" component. It allows local users to obtain sensitive kernel memory-layout information via unspecified vectors.
nvd
CVE-2016-7620P4LOWCVSS 3.3≤ 10.12.12017-02-20
CVE-2016-7620 [LOW] CWE-200 CVE-2016-7620: An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "IOSurface" component. It allows local users to obtain sensitive kernel memory-layout information via unspecified vectors.
nvd
CVE-2016-4645P4LOWCVSS 3.3≤ 10.11.52016-07-22
CVE-2016-4645 [LOW] CWE-200 CVE-2016-4645: CFNetwork in Apple OS X before 10.11.6 uses weak permissions for web-browser cookies, which allows l
CFNetwork in Apple OS X before 10.11.6 uses weak permissions for web-browser cookies, which allows local users to obtain sensitive information via unspecified vectors.
nvd
CVE-2016-7625P4LOWCVSS 3.3≤ 10.12.12017-02-20
CVE-2016-7625 [LOW] CWE-200 CVE-2016-7625: An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "IOKit" component. It allows local users to obtain sensitive kernel memory-layout information via unspecified vectors.
nvd
CVE-2019-8730P4LOWCVSS 3.3fixed in 10.152019-12-18
CVE-2019-8730 [LOW] CWE-200 CVE-2019-8730: The contents of locked notes sometimes appeared in search results. This issue was addressed with imp
The contents of locked notes sometimes appeared in search results. This issue was addressed with improved data cleanup. This issue is fixed in macOS Catalina 10.15. A local user may be able to view a user’s locked notes.
nvd
CVE-2016-7714P4LOWCVSS 3.3≤ 10.12.12017-02-20
CVE-2016-7714 [LOW] CWE-200 CVE-2016-7714: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "IOKit" component. It allows local users to obtain sensitive kernel memory-layout information via unspecified vectors.
nvd
CVE-2017-13801P4LOWCVSS 3.3≤ 10.13.02017-11-13
CVE-2017-13801 [LOW] CWE-200 CVE-2017-13801: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Dictionary Widget" component. It allows attackers to read local files if pasted text is used in a search.
nvd
CVE-2006-4390P4LOWCVSS 2.6v10.3.9v10.4+7 more2006-10-03
CVE-2006-4390 [LOW] CVE-2006-4390: CFNetwork in Apple Mac OS X 10.4 through 10.4.7 and 10.3.9 allows remote SSL sites to appear as trus
CFNetwork in Apple Mac OS X 10.4 through 10.4.7 and 10.3.9 allows remote SSL sites to appear as trusted sites by using encryption without authentication, which can cause the lock icon in Safari to be displayed even when the site's identity cannot be trusted.
nvd
CVE-2006-4399P4LOWCVSS 2.1v10.4v10.4.1+6 more2006-10-03
CVE-2006-4399 [LOW] CVE-2006-4399: User interface inconsistency in Workgroup Manager in Apple Mac OS X 10.4 through 10.4.7 appears to a
User interface inconsistency in Workgroup Manager in Apple Mac OS X 10.4 through 10.4.7 appears to allow administrators to change the authentication type from crypt to ShadowHash passwords for accounts in a NetInfo parent, when such an operation is not actually supported, which could result in less secure password management than intended.
nvd
CVE-2004-0515P4MEDIUMCVSS 4.6v10.3v10.3.1+2 more2004-08-18
CVE-2004-0515 [MEDIUM] CVE-2004-0515: Unknown vulnerability in LoginWindow for Mac OS X 10.3.4, related to "handling of console log files.
Unknown vulnerability in LoginWindow for Mac OS X 10.3.4, related to "handling of console log files."
nvd
CVE-2004-0516P4MEDIUMCVSS 4.6v10.3v10.3.1+2 more2004-08-18
CVE-2004-0516 [MEDIUM] CVE-2004-0516: Unknown vulnerability in Mac OS X 10.3.4, related to "package installation scripts," a different vul
Unknown vulnerability in Mac OS X 10.3.4, related to "package installation scripts," a different vulnerability than CVE-2004-0517.
nvd
CVE-2003-1008P4MEDIUMCVSS 4.6v10.2.8v10.3.22004-03-29
CVE-2003-1008 [MEDIUM] CVE-2003-1008: Unknown vulnerability in Mac OS X 10.2.8 and 10.3.2 allows local users to bypass the screen saver lo
Unknown vulnerability in Mac OS X 10.2.8 and 10.3.2 allows local users to bypass the screen saver login window and write a text clipping to the desktop or another application.
nvd
CVE-2003-0883P4MEDIUMCVSS 4.6v10.32003-11-03
CVE-2003-0883 [MEDIUM] CVE-2003-0883: The System Preferences capability in Mac OS X before 10.3 allows local users to access secure Prefer
The System Preferences capability in Mac OS X before 10.3 allows local users to access secure Preference Panes for a short period after an administrator has authenticated to the system.
nvd
CVE-2015-5875P4LOWCVSS 2.1≤ 10.10.52015-10-09
CVE-2015-5875 [LOW] CWE-79 CVE-2015-5875: Cross-site scripting (XSS) vulnerability in Notes in Apple OS X before 10.11 allows local users to i
Cross-site scripting (XSS) vulnerability in Notes in Apple OS X before 10.11 allows local users to inject arbitrary web script or HTML via crafted text.
nvd
CVE-2005-2520P4LOWCVSS 2.1v10.4v10.4.1+1 more2005-08-19
CVE-2005-2520 [LOW] CVE-2005-2520: The password assistant in Mac OS X 10.4 to 10.4.2, when used to create multiple accounts from the sa
The password assistant in Mac OS X 10.4 to 10.4.2, when used to create multiple accounts from the same process, does not reset the suggested password list when the assistant is displayed, which allows attackers to view recently used passwords.
nvd
CVE-2014-4431P4LOWCVSS 2.1≤ 10.9.52014-10-18
CVE-2014-4431 [LOW] CWE-264 CVE-2014-4431: Dock in Apple OS X before 10.10 does not properly manage the screen-lock state, which allows physica
Dock in Apple OS X before 10.10 does not properly manage the screen-lock state, which allows physically proximate attackers to view windows by leveraging an unattended workstation.
nvd
CVE-2012-0657P4LOWCVSS 2.1≤ 10.7.3v10.0+68 more2012-05-11
CVE-2012-0657 [LOW] CWE-264 CVE-2012-0657: Quartz Composer in Apple Mac OS X before 10.7.4, when the RSS Visualizer screensaver is enabled, all
Quartz Composer in Apple Mac OS X before 10.7.4, when the RSS Visualizer screensaver is enabled, allows physically proximate attackers to bypass screen locking and launch a Safari process via unspecified vectors.
nvd
CVE-2011-3215P4LOWCVSS 2.1≤ 10.7.1v10.0+66 more2011-10-14
CVE-2011-3215 [LOW] CWE-264 CVE-2011-3215: The kernel in Apple Mac OS X before 10.7.2 does not properly prevent FireWire DMA in the absence of
The kernel in Apple Mac OS X before 10.7.2 does not properly prevent FireWire DMA in the absence of a login, which allows physically proximate attackers to bypass intended access restrictions and discover a password by making a DMA request in the (1) loginwindow, (2) boot, or (3) shutdown state.
nvd
CVE-2015-5748P4LOWCVSS 2.1≤ 10.10.42015-08-17
CVE-2015-5748 [LOW] CWE-17 CVE-2015-5748: The kernel in Apple OS X before 10.10.5 does not properly mount HFS volumes, which allows local user
The kernel in Apple OS X before 10.10.5 does not properly mount HFS volumes, which allows local users to cause a denial of service via a crafted volume.
nvd