cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 153 of 157
CVE-2015-1096P4LOWCVSS 1.9≤ 10.10.22015-04-10
CVE-2015-1096 [LOW] CWE-200 CVE-2015-1096: IOHIDFamily in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attac IOHIDFamily in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attackers to obtain sensitive information about kernel memory via a crafted app.
nvd
CVE-2013-0982P4LOWCVSS 1.7v10.7.0v10.7.1+8 more2013-06-05
CVE-2013-0982 [LOW] CWE-200 CVE-2013-0982: The Private Browsing feature in CFNetwork in Apple Mac OS X before 10.8.4 does not prevent storage o The Private Browsing feature in CFNetwork in Apple Mac OS X before 10.8.4 does not prevent storage of permanent cookies upon exit from Safari, which might allow physically proximate attackers to bypass cookie-based authentication by leveraging an unattended workstation.
nvd
CVE-2006-4393P4LOWCVSS 3.7v10.4v10.4.1+6 more2006-10-03
CVE-2006-4393 [LOW] CVE-2006-4393: Unspecified vulnerability in LoginWindow in Apple Mac OS X 10.4 through 10.4.7, when Fast User Switc Unspecified vulnerability in LoginWindow in Apple Mac OS X 10.4 through 10.4.7, when Fast User Switching is enabled, allows local users to gain access to Kerberos tickets of other users.
nvd
CVE-2009-5044P4LOWCVSS 3.3≤ 10.10.42011-06-24
CVE-2009-5044 [LOW] CWE-59 CVE-2009-5044: contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 allows local users to overwrite arbi contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 allows local users to overwrite arbitrary files via a symlink attack on a pdf#####.tmp temporary file.
nvd
CVE-2014-1264P4LOWCVSS 3.3≤ 10.9.1v10.92014-02-27
CVE-2014-1264 [LOW] CWE-264 CVE-2014-1264: Finder in Apple OS X before 10.9.2 does not ensure ACL integrity after the viewing of file ACL infor Finder in Apple OS X before 10.9.2 does not ensure ACL integrity after the viewing of file ACL information, which allows local users to bypass intended access restrictions in opportunistic circumstances via standard filesystem operations on a file with a damaged ACL.
nvd
CVE-2011-3218P4LOWCVSS 2.6≤ 10.6.8v10.0+64 more2011-10-14
CVE-2011-3218 [LOW] CWE-79 CVE-2011-3218: The "Save for Web" selection in QuickTime Player in Apple Mac OS X through 10.6.8 exports HTML docum The "Save for Web" selection in QuickTime Player in Apple Mac OS X through 10.6.8 exports HTML documents that contain an http link to a script file, which allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks by spoofing the http server during local viewing of an exported document.
nvd
CVE-2008-0994P4LOWCVSS 2.6v10.5.22008-03-18
CVE-2008-0994 [LOW] CWE-200 CVE-2008-0994: Preview in Apple Mac OS X 10.5.2 uses 40-bit RC4 when saving a PDF file with encryption, which makes Preview in Apple Mac OS X 10.5.2 uses 40-bit RC4 when saving a PDF file with encryption, which makes it easier for attackers to decrypt the file via brute force methods.
nvd
CVE-2005-1330P4MEDIUMCVSS 4.9v10.3.92005-05-04
CVE-2005-1330 [MEDIUM] CWE-20 CVE-2005-1330: AppKit in Mac OS X 10.3.9 allows attackers to cause a denial of service (Cocoa application crash) vi AppKit in Mac OS X 10.3.9 allows attackers to cause a denial of service (Cocoa application crash) via a malformed TIFF image that causes the NXSeek to use an incorrect offset, leading to an unhandled exception.
nvd
CVE-2002-1269P4MEDIUMCVSS 4.6v10.2.22002-12-11
CVE-2002-1269 [MEDIUM] CVE-2002-1269: Unknown vulnerability in NetInfo Manager application in Mac OS X 10.2.2 allows local users to access Unknown vulnerability in NetInfo Manager application in Mac OS X 10.2.2 allows local users to access restricted parts of a filesystem.
nvd
CVE-2005-0975P4LOWCVSS 2.1v10.3v10.3.1+5 more2005-05-02
CVE-2005-0975 [LOW] CVE-2005-0975: Integer signedness error in the parse_machfile function in the mach-o loader (mach_loader.c) for the Integer signedness error in the parse_machfile function in the mach-o loader (mach_loader.c) for the Darwin Kernel as used in Mac OS X 10.3.7, and other versions before 10.3.9, allows local users to cause a denial of service (CPU consumption) via a crafted mach-o header.
nvd
CVE-2013-3949P4LOWCVSS 2.1v10.8.0v10.8.1+3 more2013-06-05
CVE-2013-3949 [LOW] CWE-264 CVE-2013-3949: The posix_spawn system call in the XNU kernel in Apple Mac OS X 10.8.x does not prevent use of the _ The posix_spawn system call in the XNU kernel in Apple Mac OS X 10.8.x does not prevent use of the _POSIX_SPAWN_DISABLE_ASLR and _POSIX_SPAWN_ALLOW_DATA_EXEC flags for setuid and setgid programs, which allows local users to bypass intended access restrictions via a wrapper program that calls the posix_spawnattr_setflags function.
nvd
CVE-2005-2752P4LOWCVSS 2.1≤ 10.4.22005-11-01
CVE-2005-2752 [LOW] CVE-2005-2752: An unspecified kernel interface in Mac OS X 10.4.2 and earlier does not properly clear memory before An unspecified kernel interface in Mac OS X 10.4.2 and earlier does not properly clear memory before reusing it, which could allow attackers to obtain sensitive information, a different vulnerability than CVE-2005-1126 and CVE-2005-1406.
nvd
CVE-2005-2748P4LOWCVSS 2.1v10.3.9v10.4.22005-10-25
CVE-2005-2748 [LOW] CVE-2005-2748: The malloc function in the libSystem library in Apple Mac OS X 10.3.9 and 10.4.2 allows local users The malloc function in the libSystem library in Apple Mac OS X 10.3.9 and 10.4.2 allows local users to overwrite arbitrary files by setting the MallocLogFile environment variable to the target file before running a setuid application.
nvd
CVE-2015-1146P4LOWCVSS 1.9fixed in 10.10.32015-04-10
CVE-2015-1146 [LOW] CVE-2015-1146: The Code Signing implementation in Apple OS X before 10.10.3 does not properly validate signatures, The Code Signing implementation in Apple OS X before 10.10.3 does not properly validate signatures, which allows local users to bypass intended access restrictions via a crafted bundle, a different vulnerability than CVE-2015-1145.
nvd
CVE-2015-1145P4LOWCVSS 1.9fixed in 10.10.32015-04-10
CVE-2015-1145 [LOW] CWE-310 CVE-2015-1145: The Code Signing implementation in Apple OS X before 10.10.3 does not properly validate signatures, The Code Signing implementation in Apple OS X before 10.10.3 does not properly validate signatures, which allows local users to bypass intended access restrictions via a crafted bundle, a different vulnerability than CVE-2015-1146.
nvd
CVE-2013-5187P4LOWCVSS 1.9≤ 10.8.5v10.8.0+5 more2013-10-24
CVE-2013-5187 [LOW] CWE-264 CVE-2013-5187: The Screen Lock implementation in Apple Mac OS X before 10.9 does not immediately accept Keychain St The Screen Lock implementation in Apple Mac OS X before 10.9 does not immediately accept Keychain Status menu Lock Screen commands, and instead incorrectly relies on a certain timeout setting, which allows physically proximate attackers to obtain sensitive information by reading a screen that should have transitioned into the locked state.
nvd
CVE-2005-1430P4LOWCVSS 3.6v10.0v10.0.1+28 more2005-05-03
CVE-2005-1430 [LOW] CVE-2005-1430: Mac OS X 10.3.x and earlier uses insecure permissions for a pseudo terminal tty (pty) that is manage Mac OS X 10.3.x and earlier uses insecure permissions for a pseudo terminal tty (pty) that is managed by a non-setuid program, which allows local users to read or modify sessions of other users.
nvd
CVE-2008-0995P4LOWCVSS 2.6v10.5.22008-03-18
CVE-2008-0995 [LOW] CWE-200 CVE-2008-0995: The Printing component in Apple Mac OS X 10.5.2 uses 40-bit RC4 when printing to an encrypted PDF fi The Printing component in Apple Mac OS X 10.5.2 uses 40-bit RC4 when printing to an encrypted PDF file, which makes it easier for attackers to decrypt the file via brute force methods.
nvd
CVE-2019-8757P4LOWCVSS 2.5fixed in 10.152019-12-18
CVE-2019-8757 [LOW] CWE-362 CVE-2019-8757: A race condition existed when reading and writing user preferences. This was addressed with improved A race condition existed when reading and writing user preferences. This was addressed with improved state handling. This issue is fixed in macOS Catalina 10.15. The "Share Mac Analytics" setting may not be disabled when a user deselects the switch to share analytics.
nvd
CVE-2006-3495P4LOWCVSS 2.1v10.3.9v10.4.72006-08-02
CVE-2006-3495 [LOW] CVE-2006-3495: AFP Server in Apple Mac OS X 10.3.9 and 10.4.7 stores reconnect keys in a world-readable file, which AFP Server in Apple Mac OS X 10.3.9 and 10.4.7 stores reconnect keys in a world-readable file, which allows local users to obtain the keys and access files and folders of other users.
nvd
Apple macOS vulnerabilities | cvebase