cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 156 of 157
CVE-2006-0382P4LOWCVSS 2.1v10.4.52006-02-14
CVE-2006-0382 [LOW] CVE-2006-0382: Apple Mac OS X 10.4.5 and allows local users to cause a denial of service (crash) via an undocumente Apple Mac OS X 10.4.5 and allows local users to cause a denial of service (crash) via an undocumented system call.
nvd
CVE-2004-1087P4LOWCVSS 2.1v10.2v10.2.1+14 more2004-12-02
CVE-2004-1087 [LOW] CVE-2004-1087: Terminal for Apple Mac OS X 10.3.6 may indicate that "Secure Keyboard Entry" is enabled even when it Terminal for Apple Mac OS X 10.3.6 may indicate that "Secure Keyboard Entry" is enabled even when it is not, which could result in a false sense of security for the user.
nvd
CVE-2015-5901P4LOWCVSS 2.1≤ 10.10.52015-10-09
CVE-2015-5901 [LOW] CWE-200 CVE-2015-5901: The Secure Empty Trash feature in Finder in Apple OS X before 10.11 improperly deletes Trash files, The Secure Empty Trash feature in Finder in Apple OS X before 10.11 improperly deletes Trash files, which might allow local users to obtain sensitive information by reading storage media, as demonstrated by reading a flash drive.
nvd
CVE-2014-4499P4LOWCVSS 2.1≤ 10.10.12015-01-30
CVE-2014-4499 [LOW] CWE-200 CVE-2014-4499: The App Store process in CommerceKit Framework in Apple OS X before 10.10.2 places Apple ID credenti The App Store process in CommerceKit Framework in Apple OS X before 10.10.2 places Apple ID credentials in App Store logs, which allows local users to obtain sensitive information by reading a file.
nvd
CVE-2009-0014P4LOWCVSS 2.1v10.5.62009-02-13
CVE-2009-0014 [LOW] CWE-264 CVE-2009-0014: Folder Manager in Apple Mac OS X 10.5.6 uses insecure default permissions when recreating a Download Folder Manager in Apple Mac OS X 10.5.6 uses insecure default permissions when recreating a Downloads folder after it has been deleted, which allows local users to bypass intended access restrictions and read the Downloads folder.
nvd
CVE-2013-5191P4LOWCVSS 2.1≤ 10.8.5v10.8.0+5 more2013-10-24
CVE-2013-5191 [LOW] CWE-264 CVE-2013-5191: The syslog implementation in Apple Mac OS X before 10.9 allows local users to obtain sensitive infor The syslog implementation in Apple Mac OS X before 10.9 allows local users to obtain sensitive information by leveraging access to the Guest account and reading console-log messages from previous Guest sessions.
nvd
CVE-2015-5863P4LOWCVSS 2.1≤ 10.10.52015-09-18
CVE-2015-5863 [LOW] CWE-200 CVE-2015-5863: IOStorageFamily in Apple iOS before 9 does not properly initialize an unspecified data structure, wh IOStorageFamily in Apple iOS before 9 does not properly initialize an unspecified data structure, which allows local users to obtain sensitive information from kernel memory via unknown vectors.
nvd
CVE-2013-1030P4LOWCVSS 2.1≤ 10.8.4v10.8.0+3 more2013-09-16
CVE-2013-1030 [LOW] CWE-200 CVE-2013-1030: mdmclient in Mobile Device Management in Apple Mac OS X before 10.8.5 places a password on the comma mdmclient in Mobile Device Management in Apple Mac OS X before 10.8.5 places a password on the command line, which allows local users to obtain sensitive information by listing the process.
nvd
CVE-2004-1081P4LOWCVSS 2.1v10.2v10.2.1+14 more2004-12-02
CVE-2004-1081 [LOW] CVE-2004-1081: The Application Framework (AppKit) for Apple Mac OS X 10.2.8 and 10.3.6 does not properly restrict a The Application Framework (AppKit) for Apple Mac OS X 10.2.8 and 10.3.6 does not properly restrict access to a secure text input field, which allows local users to read keyboard input from other applications within the same window session.
nvd
CVE-2004-1085P4LOWCVSS 2.1v10.2v10.2.1+14 more2004-12-02
CVE-2004-1085 [LOW] CVE-2004-1085: Human Interface Toolbox (HIToolBox) for Apple Mac 0S X 10.3.6 allows local users to exit application Human Interface Toolbox (HIToolBox) for Apple Mac 0S X 10.3.6 allows local users to exit applications via the force-quit key combination, even when the system is running in kiosk mode.
nvd
CVE-2004-0088P4LOWCVSS 2.1v10.2.82004-03-03
CVE-2004-0088 [LOW] CVE-2004-0088: The System Configuration subsystem in Mac OS 10.2.8 allows local users to modify network settings, a The System Configuration subsystem in Mac OS 10.2.8 allows local users to modify network settings, a different vulnerability than CVE-2004-0087.
nvd
CVE-2009-0013P4LOWCVSS 2.1v10.4.11v10.5.62009-02-13
CVE-2009-0013 [LOW] CWE-255 CVE-2009-0013: dscl in DS Tools in Apple Mac OS X 10.4.11 and 10.5.6 requires that passwords must be provided as co dscl in DS Tools in Apple Mac OS X 10.4.11 and 10.5.6 requires that passwords must be provided as command line arguments, which allows local users to gain privileges by listing process information.
nvd
CVE-2013-5173P4LOWCVSS 2.1≤ 10.8.5v10.8.0+5 more2013-10-24
CVE-2013-5173 [LOW] CWE-310 CVE-2013-5173: The random-number generator in the kernel in Apple Mac OS X before 10.9 provides lengthy exclusive a The random-number generator in the kernel in Apple Mac OS X before 10.9 provides lengthy exclusive access for processing of large requests, which allows local users to cause a denial of service (temporary generator outage) via an application that requires many random numbers.
nvd
CVE-2005-0715P4LOWCVSS 2.1v10.3v10.3.1+7 more2005-03-21
CVE-2005-0715 [LOW] CVE-2005-0715: AFP Server in Mac OS X before 10.3.8 uses insecure permissions for "Drop Boxes," which allows local AFP Server in Mac OS X before 10.3.8 uses insecure permissions for "Drop Boxes," which allows local users to read the contents of a Drop Box.
nvd
CVE-2014-1317P4LOWCVSS 2.1v10.9v10.9.1+2 more2014-07-01
CVE-2014-1317 [LOW] CWE-200 CVE-2014-1317: iBooks Commerce in Apple OS X before 10.9.4 places Apple ID credentials in the iBooks log, which all iBooks Commerce in Apple OS X before 10.9.4 places Apple ID credentials in the iBooks log, which allows local users to obtain sensitive information by reading this file.
nvd
CVE-2013-0985P4LOWCVSS 2.1≤ 10.8.3v10.8.0+2 more2013-06-05
CVE-2013-0985 [LOW] CWE-287 CVE-2013-0985: Disk Management in Apple Mac OS X before 10.8.4 does not properly authenticate attempts to disable F Disk Management in Apple Mac OS X before 10.8.4 does not properly authenticate attempts to disable FileVault, which allows local users to cause a denial of service (loss of encryption functionality) via an unspecified command line.
nvd
CVE-2013-5169P4LOWCVSS 1.9≤ 10.8.5v10.8.0+5 more2013-10-24
CVE-2013-5169 [LOW] CWE-264 CVE-2013-5169: CoreGraphics in Apple Mac OS X before 10.9, when display-sleep mode is used, does not ensure that sc CoreGraphics in Apple Mac OS X before 10.9, when display-sleep mode is used, does not ensure that screen locking blocks the visibility of all windows, which allows physically proximate attackers to obtain sensitive information by reading the screen.
nvd
CVE-2009-0142P4LOWCVSS 1.9v10.5.62009-02-12
CVE-2009-0142 [LOW] CWE-362 CVE-2009-0142: Race condition in AFP Server in Apple Mac OS X 10.5.6 allows local users to cause a denial of servic Race condition in AFP Server in Apple Mac OS X 10.5.6 allows local users to cause a denial of service (infinite loop) via unspecified vectors related to "file enumeration logic."
nvd
CVE-2006-0386P4LOWCVSS 1.7v10.3v10.3.1+14 more2006-03-03
CVE-2006-0386 [LOW] CVE-2006-0386: FileVault in Mac OS X 10.4.5 and earlier does not properly mount user directories when creating a Fi FileVault in Mac OS X 10.4.5 and earlier does not properly mount user directories when creating a FileVault image, which allows local users to access protected files when FileVault is enabled.
nvd
CVE-2001-0806P4LOWCVSS 3.6v10.0v10.0.1+4 more2001-12-06
CVE-2001-0806 [LOW] CVE-2001-0806: Apple MacOS X 10.0 and 10.1 allow a local user to read and write to a user's desktop folder via inse Apple MacOS X 10.0 and 10.1 allow a local user to read and write to a user's desktop folder via insecure default permissions for the Desktop when it is created in some languages.
nvd
Apple macOS vulnerabilities | cvebase