cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 154 of 157
CVE-2005-3782P4LOWCVSS 2.1v10.4.3v10.4.4+2 more2005-12-31
CVE-2005-3782 [LOW] CVE-2005-3782: Mac OS X 10.4.3 up to 10.4.6, when loginwindow uses the "Name and password" setting, and the "Show t Mac OS X 10.4.3 up to 10.4.6, when loginwindow uses the "Name and password" setting, and the "Show the Restart, Sleep, and Shut Down buttons" option is disabled, allows users with physical access to bypass login and reboot the system by entering ">restart", ">power", or ">shutdown" sequences after the username.
nvd
CVE-2014-4460P4LOWCVSS 2.1≤ 10.10.1v10.0+84 more2014-11-18
CVE-2014-4460 [LOW] CWE-200 CVE-2014-4460: CFNetwork in Apple iOS before 8.1.1 and OS X before 10.10.1 does not properly clear the browsing cac CFNetwork in Apple iOS before 8.1.1 and OS X before 10.10.1 does not properly clear the browsing cache upon a transition out of private-browsing mode, which makes it easier for physically proximate attackers to obtain sensitive information by reading cache files.
nvd
CVE-2006-1981P4LOWCVSS 2.1v10.4.52006-04-21
CVE-2006-1981 [LOW] CVE-2006-1981: Unspecified vulnerability in Java InputMethods on Mac OS X 10.4.5 may cause InputMethods to send inp Unspecified vulnerability in Java InputMethods on Mac OS X 10.4.5 may cause InputMethods to send input events for secure fields to the wrong text field, which might reveal the password to others who can view the screen.
nvd
CVE-2013-3952P4LOWCVSS 2.1v10.8.0v10.8.1+3 more2013-06-05
CVE-2013-3952 [LOW] CWE-264 CVE-2013-3952: The fill_pipeinfo function in bsd/kern/sys_pipe.c in the XNU kernel in Apple Mac OS X 10.8.x allows The fill_pipeinfo function in bsd/kern/sys_pipe.c in the XNU kernel in Apple Mac OS X 10.8.x allows local users to defeat the KASLR protection mechanism via the PROC_PIDFDPIPEINFO option to the proc_info system call for a kernel pipe handle.
nvd
CVE-2015-5854P4LOWCVSS 2.1≤ 10.10.52015-10-09
CVE-2015-5854 [LOW] CWE-200 CVE-2015-5854: The backup implementation in Time Machine in Apple OS X before 10.11 allows local users to obtain ac The backup implementation in Time Machine in Apple OS X before 10.11 allows local users to obtain access to keychain items via unspecified vectors.
nvd
CVE-2014-1378P4LOWCVSS 2.1v10.9v10.9.1+2 more2014-07-01
CVE-2014-1378 [LOW] CWE-264 CVE-2014-1378: IOGraphicsFamily in Apple OS X before 10.9.4 allows local users to bypass the ASLR protection mechan IOGraphicsFamily in Apple OS X before 10.9.4 allows local users to bypass the ASLR protection mechanism by leveraging read access to a kernel pointer in an IOKit object.
nvd
CVE-2015-5893P4LOWCVSS 2.1≤ 10.10.52015-10-09
CVE-2015-5893 [LOW] CWE-200 CVE-2015-5893: SMBClient in SMB in Apple OS X before 10.11 allows local users to obtain sensitive kernel memory-lay SMBClient in SMB in Apple OS X before 10.11 allows local users to obtain sensitive kernel memory-layout information via unspecified vectors.
nvd
CVE-2015-1142P4LOWCVSS 2.1≤ 10.10.22015-04-10
CVE-2015-1142 [LOW] CWE-20 CVE-2015-1142: LaunchServices in Apple OS X before 10.10.3 allows local users to cause a denial of service (Finder LaunchServices in Apple OS X before 10.10.3 allows local users to cause a denial of service (Finder crash) via crafted localization data.
nvd
CVE-2015-5864P4LOWCVSS 2.1≤ 10.10.52015-10-09
CVE-2015-5864 [LOW] CWE-200 CVE-2015-5864: IOAudioFamily in Apple OS X before 10.11 allows local users to obtain sensitive kernel memory-layout IOAudioFamily in Apple OS X before 10.11 allows local users to obtain sensitive kernel memory-layout information via unspecified vectors.
nvd
CVE-2005-2751P4LOWCVSS 2.1v10.4v10.4.1+1 more2005-11-01
CVE-2005-2751 [LOW] CVE-2005-2751: memberd in Mac OS X 10.4 up to 10.4.2, in certain situations, does not quickly synchronize access co memberd in Mac OS X 10.4 up to 10.4.2, in certain situations, does not quickly synchronize access control checks with changes in group membership, which could allow users to access files and other resources after they have been removed from a group.
nvd
CVE-2014-8827P4LOWCVSS 2.1≤ 10.10.12015-01-30
CVE-2014-8827 [LOW] CWE-284 CVE-2014-8827: LoginWindow in Apple OS X before 10.10.2 does not transition to the lock-screen state immediately up LoginWindow in Apple OS X before 10.10.2 does not transition to the lock-screen state immediately upon being woken from sleep, which allows physically proximate attackers to obtain sensitive information by reading the screen.
nvd
CVE-2015-7067P4LOWCVSS 2.1≤ 10.11.12015-12-11
CVE-2015-7067 [LOW] CVE-2015-7067: IOThunderboltFamily in Apple OS X before 10.11.2 allows local users to cause a denial of service (NU IOThunderboltFamily in Apple OS X before 10.11.2 allows local users to cause a denial of service (NULL pointer dereference) via an unspecified userclient type.
nvd
CVE-2003-0876P4LOWCVSS 2.1v10.0v10.0.1+18 more2003-11-03
CVE-2003-0876 [LOW] CVE-2003-0876: Finder in Mac OS X 10.2.8 and earlier sets global read/write/execute permissions on directories when Finder in Mac OS X 10.2.8 and earlier sets global read/write/execute permissions on directories when they are dragged (copied) from a mounted volume such as a disk image (DMG), which could cause the directories to have less restrictive permissions than intended.
nvd
CVE-2001-1565P4LOWCVSS 2.1v10.0v10.1+5 more2001-12-31
CVE-2001-1565 [LOW] CVE-2001-1565: Point to Point Protocol daemon (pppd) in MacOS x 10.0 and 10.1 through 10.1.5 provides the username Point to Point Protocol daemon (pppd) in MacOS x 10.0 and 10.1 through 10.1.5 provides the username and password on the command line, which allows local users to obtain authentication information via the ps command.
nvd
CVE-2015-3757P4LOWCVSS 2.1≤ 10.10.42015-08-16
CVE-2015-3757 [LOW] CWE-284 CVE-2015-3757: Apple OS X before 10.10.5 does not properly restrict access to the Date & Time preferences pane, whi Apple OS X before 10.10.5 does not properly restrict access to the Date & Time preferences pane, which allows local users to spoof the time by visiting this pane.
nvd
CVE-2004-0087P4LOWCVSS 2.1v10.2.8v10.3.22004-03-03
CVE-2004-0087 [LOW] CVE-2004-0087: The System Configuration subsystem in Mac OS 10.2.8 and 10.3.2 allows local users to modify network The System Configuration subsystem in Mac OS 10.2.8 and 10.3.2 allows local users to modify network settings, a different vulnerability than CVE-2004-0088.
nvd
CVE-2014-8833P4LOWCVSS 2.1≤ 10.10.12015-01-30
CVE-2014-8833 [LOW] CWE-284 CVE-2014-8833: SpotlightIndex in Apple OS X before 10.10.2 does not properly perform deserialization during access SpotlightIndex in Apple OS X before 10.10.2 does not properly perform deserialization during access to a permission cache, which allows local users to read search results associated with other users' protected files via a Spotlight query.
nvd
CVE-2014-1375P4LOWCVSS 2.1v10.9v10.9.1+2 more2014-07-01
CVE-2014-1375 [LOW] CWE-264 CVE-2014-1375: Intel Graphics Driver in Apple OS X before 10.9.4 allows local users to bypass the ASLR protection m Intel Graphics Driver in Apple OS X before 10.9.4 allows local users to bypass the ASLR protection mechanism by leveraging read access to a kernel pointer in an IOKit object.
nvd
CVE-2012-3718P4LOWCVSS 2.1≤ 10.7.4v10.0+71 more2012-09-20
CVE-2012-3718 [LOW] CWE-200 CVE-2012-3718: Apple Mac OS X before 10.7.5 and 10.8.x before 10.8.2 allows local users to read passwords entered i Apple Mac OS X before 10.7.5 and 10.8.x before 10.8.2 allows local users to read passwords entered into Login Window (aka LoginWindow) or Screen Saver Unlock by installing an input method that intercepts keystrokes.
nvd
CVE-2005-0973P4LOWCVSS 2.1v10.0v10.0.1+28 more2005-05-12
CVE-2005-0973 [LOW] CVE-2005-0973: Unknown vulnerability in the setsockopt system call in Mac OS X 10.3.9 and earlier allows local user Unknown vulnerability in the setsockopt system call in Mac OS X 10.3.9 and earlier allows local users to cause a denial of service (memory exhaustion) via crafted arguments.
nvd
Apple macOS vulnerabilities | cvebase