Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 157 of 157
CVE-2019-8777P4LOWCVSS 2.4fixed in 10.14.42020-10-27
CVE-2019-8777 [LOW] CWE-276 CVE-2019-8777: A lock screen issue allowed access to contacts on a locked device. This issue was addressed with imp
A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra. A local attacker may be able to view contacts from the lock screen.
nvd
CVE-2006-1439P4LOWCVSS 2.1v10.4.62006-05-12
CVE-2006-1439 [LOW] CWE-200 CVE-2006-1439: NSSecureTextField in AppKit in Apple Mac OS X 10.4.6 does not re-enable secure event input under cer
NSSecureTextField in AppKit in Apple Mac OS X 10.4.6 does not re-enable secure event input under certain circumstances, which could allow other applications in the window session to monitor input characters and keyboard events.
nvd
CVE-2005-2749P4LOWCVSS 2.1v10.4v10.4.1+1 more2005-11-01
CVE-2005-2749 [LOW] CVE-2005-2749: Unspecified vulnerability in the Finder Get Info window for Mac OS X 10.4 up to 10.4.2 causes Finder
Unspecified vulnerability in the Finder Get Info window for Mac OS X 10.4 up to 10.4.2 causes Finder to misrepresent file and group ownership information. NOTE: it is not clear whether this issue satisfies the CVE definition of a vulnerability.
nvd
CVE-2005-2512P4LOWCVSS 2.1v10.4v10.4.1+1 more2005-08-19
CVE-2005-2512 [LOW] CVE-2005-2512: Mail.app in Mac OS 10.4.2 and earlier, when printing or forwarding an HTML message, loads remote ima
Mail.app in Mac OS 10.4.2 and earlier, when printing or forwarding an HTML message, loads remote images even when the user's preferences state otherwise, which could result in a privacy leak.
nvd
CVE-2014-4403P4LOWCVSS 2.1v10.9v10.9.1+3 more2014-09-19
CVE-2014-4403 [LOW] CWE-200 CVE-2014-4403: The kernel in Apple OS X before 10.9.5 allows local users to obtain sensitive address information an
The kernel in Apple OS X before 10.9.5 allows local users to obtain sensitive address information and bypass the ASLR protection mechanism by leveraging predictability of the location of the CPU Global Descriptor Table.
nvd
CVE-2011-3216P4LOWCVSS 2.1≤ 10.7.1v10.0+66 more2011-10-14
CVE-2011-3216 [LOW] CWE-264 CVE-2011-3216: The kernel in Apple Mac OS X before 10.7.2 does not properly implement the sticky bit for directorie
The kernel in Apple Mac OS X before 10.7.2 does not properly implement the sticky bit for directories, which might allow local users to bypass intended permissions and delete files via an unlink system call.
nvd
CVE-2007-4701P4LOWCVSS 2.1v10.4.1v10.4.2+8 more2007-11-15
CVE-2007-4701 [LOW] CWE-264 CVE-2007-4701: WebKit on Apple Mac OS X 10.4 through 10.4.10 does not create temporary files securely when Safari i
WebKit on Apple Mac OS X 10.4 through 10.4.10 does not create temporary files securely when Safari is previewing a PDF file, which allows local users to read the contents of that file.
nvd
CVE-2015-5842P4LOWCVSS 2.1≤ 10.10.52015-09-18
CVE-2015-5842 [LOW] CWE-200 CVE-2015-5842: XNU in the kernel in Apple iOS before 9 does not properly initialize an unspecified data structure,
XNU in the kernel in Apple iOS before 9 does not properly initialize an unspecified data structure, which allows local users to obtain sensitive memory-layout information via unknown vectors.
nvd
CVE-2011-0178P4LOWCVSS 2.1≤ 10.6.6v10.6.0+5 more2011-03-23
CVE-2011-0178 [LOW] CWE-200 CVE-2011-0178: The FSFindFolder API in CarbonCore in Apple Mac OS X before 10.6.7 provides a world-readable directo
The FSFindFolder API in CarbonCore in Apple Mac OS X before 10.6.7 provides a world-readable directory in response to a call with the kTemporaryFolderType flag, which allows local users to obtain potentially sensitive information by accessing this directory.
nvd
CVE-2002-1270P4LOWCVSS 2.1v10.2.22002-12-11
CVE-2002-1270 [LOW] CVE-2002-1270: Mac OS X 10.2.2 allows local users to read files that only allow write access via the map_fd() Mach
Mac OS X 10.2.2 allows local users to read files that only allow write access via the map_fd() Mach system call.
nvd
CVE-2015-6987P4LOWCVSS 2.1≤ 10.11.02015-10-23
CVE-2015-6987 [LOW] CWE-20 CVE-2015-6987: The File Bookmark component in Apple OS X before 10.11.1 allows local users to cause a denial of ser
The File Bookmark component in Apple OS X before 10.11.1 allows local users to cause a denial of service (application crash) via crafted bookmark metadata in a folder.
nvd
CVE-2005-1472P4LOWCVSS 2.1v10.4.12005-05-19
CVE-2005-1472 [LOW] CVE-2005-1472: Certain system calls in Apple Mac OS X 10.4.1 do not properly enforce the permissions of certain dir
Certain system calls in Apple Mac OS X 10.4.1 do not properly enforce the permissions of certain directories without the POSIX read bit set, but with the execute bits set for group or other, which allows local users to list files in otherwise restricted directories.
nvd
CVE-2008-0038P4LOWCVSS 1.9v10.5v10.5.12008-02-12
CVE-2008-0038 [LOW] CWE-264 CVE-2008-0038: Launch Services in Apple Mac OS X 10.5 through 10.5.1 allows an uninstalled application to be launch
Launch Services in Apple Mac OS X 10.5 through 10.5.1 allows an uninstalled application to be launched if it is in a Time Machine backup, which might allow local users to bypass intended security restrictions or exploit vulnerabilities in the application.
nvd
CVE-2008-0996P4LOWCVSS 1.7v10.5.22008-03-18
CVE-2008-0996 [LOW] CWE-200 CVE-2008-0996: The Printing component in Apple Mac OS X 10.5.2 might save authentication credentials to disk when s
The Printing component in Apple Mac OS X 10.5.2 might save authentication credentials to disk when starting a job on an authenticated print queue, which might allow local users to obtain the credentials.
nvd
CVE-2008-3619P4LOWCVSS 2.1v10.5v10.5.1+3 more2008-09-16
CVE-2008-3619 [LOW] CWE-264 CVE-2008-3619: Time Machine in Apple Mac OS X 10.5 through 10.5.4 uses weak permissions for Time Machine Backup log
Time Machine in Apple Mac OS X 10.5 through 10.5.4 uses weak permissions for Time Machine Backup log files, which allows local users to obtain sensitive information by reading these files.
nvd
CVE-2006-3499P4LOWCVSS 2.1v10.3.92006-08-03
CVE-2006-3499 [LOW] CVE-2006-3499: The dynamic linker (dyld) in Apple Mac OS X 10.3.9 allows local users to obtain sensitive informatio
The dynamic linker (dyld) in Apple Mac OS X 10.3.9 allows local users to obtain sensitive information via unspecified dynamic linker options that affect the use of standard error (stderr) by privileged applications.
nvd
CVE-2011-0197P4LOWCVSS 2.1v10.5.8v10.6.0+7 more2011-06-24
CVE-2011-0197 [LOW] CWE-200 CVE-2011-0197: App Store in Apple Mac OS X before 10.6.8 creates a log entry containing a user's AppleID password,
App Store in Apple Mac OS X before 10.6.8 creates a log entry containing a user's AppleID password, which might allow local users to obtain sensitive information by reading a log file, as demonstrated by a log file that has non-default permissions.
nvd
CVE-2007-0751P4LOWCVSS 2.1v10.3v10.3.1+18 more2007-05-24
CVE-2007-0751 [LOW] CVE-2007-0751: A cleanup script in crontabs in Apple Mac OS X 10.3.9 and 10.4.9 might delete filesystems that have
A cleanup script in crontabs in Apple Mac OS X 10.3.9 and 10.4.9 might delete filesystems that have been mounted in /tmp, which might allow local users to cause a denial of service, related to the find command.
nvd
CVE-2008-1578P4LOWCVSS 2.1v10.4.11v10.5+2 more2008-06-02
CVE-2008-1578 [LOW] CWE-200 CVE-2008-1578: The sso_util program in Single Sign-On in Apple Mac OS X before 10.5.3 places passwords on the comma
The sso_util program in Single Sign-On in Apple Mac OS X before 10.5.3 places passwords on the command line, which allows local users to obtain sensitive information by listing the process.
nvd
← Previous157 / 157