cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 155 of 157
CVE-2015-3785P4LOWCVSS 1.9≤ 10.10.52015-10-09
CVE-2015-3785 [LOW] CVE-2015-3785: The Telephony component in Apple OS X before 10.11, when the Continuity feature is enabled, allows l The Telephony component in Apple OS X before 10.11, when the Continuity feature is enabled, allows local users to bypass intended telephone-call restrictions via unspecified vectors.
nvd
CVE-2008-2329P4LOWCVSS 1.9v10.5v10.5.1+3 more2008-09-16
CVE-2008-2329 [LOW] CWE-200 CVE-2008-2329: Directory Services in Apple Mac OS X 10.5 through 10.5.4, when Active Directory is used, allows atta Directory Services in Apple Mac OS X 10.5 through 10.5.4, when Active Directory is used, allows attackers to enumerate user names via wildcard characters in the Login Window.
nvd
CVE-2006-3356P4LOWCVSS 2.6≤ 10.4.72006-07-06
CVE-2006-3356 [LOW] CVE-2006-3356: The TIFFFetchAnyArray function in ImageIO in Apple OS X 10.4.7 and earlier allows remote user-assist The TIFFFetchAnyArray function in ImageIO in Apple OS X 10.4.7 and earlier allows remote user-assisted attackers to cause a denial of service (application crash) via an invalid tag value in a TIFF image, possibly triggering a null dereference. NOTE: This is a different issue than CVE-2006-1469.
nvd
CVE-2005-2517P4LOWCVSS 2.6v10.3.9v10.4.22005-08-19
CVE-2005-2517 [LOW] CVE-2005-2517: Safari in Mac OS X 10.3.9 and 10.4.2 submits forms from an XSL formatted page to the next page that Safari in Mac OS X 10.3.9 and 10.4.2 submits forms from an XSL formatted page to the next page that is browsed by the user, which causes form data to be sent to the wrong site.
nvd
CVE-2017-7082P4LOWCVSS 2.4≤ 10.12.62017-10-23
CVE-2017-7082 [LOW] CWE-200 CVE-2017-7082: An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involve An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "Screen Lock" component. It allows physically proximate attackers to read Application Firewall prompts.
nvd
CVE-2019-8799P4LOWCVSS 2.4fixed in 10.152020-10-27
CVE-2019-8799 [LOW] CVE-2019-8799: This issue was resolved by replacing device names with a random identifier. This issue is fixed in i This issue was resolved by replacing device names with a random identifier. This issue is fixed in iOS 13.1 and iPadOS 13.1, macOS Catalina 10.15, watchOS 6, tvOS 13. An attacker in physical proximity may be able to passively observe device names in AWDL communications.
nvd
CVE-2021-30915P4LOWCVSS 2.4fixed in 10.15.7v10.15.72021-08-24
CVE-2021-30915 [LOW] CVE-2021-30915: A logic issue was addressed with improved state management. This issue is fixed in iOS 15.1 and iPad A logic issue was addressed with improved state management. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, tvOS 15.1, watchOS 8.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. A person with physical access to an iOS device may be able to determine characteristics of a user's password in a secure text entry field.
nvd
CVE-2006-6127P4LOWCVSS 2.1v10.4.82006-11-27
CVE-2006-6127 [LOW] CVE-2006-6127: Apple Mac OS X kernel allows local users to cause a denial of service via a process that uses kevent Apple Mac OS X kernel allows local users to cause a denial of service via a process that uses kevent to register a queue and an event, then fork a child process that uses kevent to register an event for the same queue as the parent.
nvd
CVE-2004-0923P4LOWCVSS 2.1v10.2v10.2.1+13 more2005-01-27
CVE-2004-0923 [LOW] CVE-2004-0923: CUPS 1.1.20 and earlier records authentication information for a device URI in the error_log file, w CUPS 1.1.20 and earlier records authentication information for a device URI in the error_log file, which allows local users to obtain user names and passwords.
nvd
CVE-2013-7127P4LOWCVSS 2.1v10.7.5v10.8.52013-12-17
CVE-2013-7127 [LOW] CWE-310 CVE-2013-7127: Apple Safari 6.0.5 on Mac OS X 10.7.5 and 10.8.5 stores cleartext credentials in LastSession.plist, Apple Safari 6.0.5 on Mac OS X 10.7.5 and 10.8.5 stores cleartext credentials in LastSession.plist, which allows local users to obtain sensitive information by reading this file.
nvd
CVE-2006-6126P4LOWCVSS 2.1v10.4.82006-11-27
CVE-2006-6126 [LOW] CVE-2006-6126: Apple Mac OS X allows local users to cause a denial of service (memory corruption) via a crafted Mac Apple Mac OS X allows local users to cause a denial of service (memory corruption) via a crafted Mach-O binary with a malformed load_command data structure.
nvd
CVE-2006-1444P4LOWCVSS 2.1v10.4.62006-05-12
CVE-2006-1444 [LOW] CVE-2006-1444: CoreGraphics in Apple Mac OS X 10.4.6, when "Enable access for assistive devices" is on, allows an a CoreGraphics in Apple Mac OS X 10.4.6, when "Enable access for assistive devices" is on, allows an application to bypass restrictions for secure event input and read certain events from other applications in the same window session by using Quartz Event Services.
nvd
CVE-2005-2509P4LOWCVSS 2.1v10.0v10.0.1+31 more2005-08-19
CVE-2005-2509 [LOW] CVE-2005-2509: Unknown vulnerability in loginwindow in Mac OS X 10.4.2 and earlier, when Fast User Switching is ena Unknown vulnerability in loginwindow in Mac OS X 10.4.2 and earlier, when Fast User Switching is enabled, allows attackers to log into other accounts if they know the passwords to at least two accounts.
nvd
CVE-2011-3212P4LOWCVSS 2.1v10.7.0v10.7.12011-10-14
CVE-2011-3212 [LOW] CWE-310 CVE-2011-3212: CoreStorage in Apple Mac OS X 10.7 before 10.7.2 does not ensure that all disk data is encrypted dur CoreStorage in Apple Mac OS X 10.7 before 10.7.2 does not ensure that all disk data is encrypted during the enabling of FileVault, which makes it easier for physically proximate attackers to obtain sensitive information by reading directly from the disk device.
nvd
CVE-2015-5878P4LOWCVSS 2.1≤ 10.10.52015-10-09
CVE-2015-5878 [LOW] CWE-200 CVE-2015-5878: Notes in Apple OS X before 10.11 misparses links, which allows local users to obtain sensitive infor Notes in Apple OS X before 10.11 misparses links, which allows local users to obtain sensitive information via unspecified vectors.
nvd
CVE-2015-5870P4LOWCVSS 2.1≤ 10.10.52015-10-09
CVE-2015-5870 [LOW] CWE-200 CVE-2015-5870: The debugging interfaces in the kernel in Apple OS X before 10.11 allow local users to obtain sensit The debugging interfaces in the kernel in Apple OS X before 10.11 allow local users to obtain sensitive memory-layout information via unspecified vectors.
nvd
CVE-2013-5186P4LOWCVSS 2.1≤ 10.8.5v10.8.0+5 more2013-10-24
CVE-2013-5186 [LOW] CWE-264 CVE-2013-5186: Power Management in Apple Mac OS X before 10.9 does not properly handle the interaction between lock Power Management in Apple Mac OS X before 10.9 does not properly handle the interaction between locking and power assertions, which allows physically proximate attackers to obtain sensitive information by reading a screen that should have transitioned into the locked state.
nvd
CVE-2015-5851P4LOWCVSS 2.1≤ 10.10.52015-09-18
CVE-2015-5851 [LOW] CWE-200 CVE-2015-5851: The convenience initializer in the Multipeer Connectivity component in Apple iOS before 9 does not r The convenience initializer in the Multipeer Connectivity component in Apple iOS before 9 does not require an encrypted session, which allows local users to obtain cleartext multipeer data via an encrypted-to-unencrypted downgrade attack.
nvd
CVE-2014-8834P4LOWCVSS 2.1v10.10.0v10.10.12015-01-30
CVE-2014-8834 [LOW] CWE-200 CVE-2014-8834: UserAccountUpdater in Apple OS X 10.10 before 10.10.2 stores a PDF document's password in a printing UserAccountUpdater in Apple OS X 10.10 before 10.10.2 stores a PDF document's password in a printing preference file, which allows local users to obtain sensitive information by reading a file.
nvd
CVE-2004-0622P4LOWCVSS 2.1v10.3.4v10.4+1 more2004-12-06
CVE-2004-0622 [LOW] CVE-2004-0622: Apple Mac OS X 10.3.4, 10.4, 10.5, and possibly other versions does not properly clear memory for lo Apple Mac OS X 10.3.4, 10.4, 10.5, and possibly other versions does not properly clear memory for login (aka Loginwindow.app), Keychain, or FileVault passwords, which could allow the root user or an attacker with physical access to obtain sensitive information by reading memory.
nvd
Apple macOS vulnerabilities | cvebase