cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 16 of 157
CVE-2016-4658P3CRITICALCVSS 9.8fixed in 10.122016-09-25
CVE-2016-4658 [CRITICAL] CWE-119 CVE-2016-4658: xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 1 xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and memory corruption) via a crafted XML document.
nvd
CVE-2020-9864P3CRITICALCVSS 9.8fixed in 10.15.62020-10-16
CVE-2020-9864 [CRITICAL] CVE-2020-9864: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15. A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.6. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2005-1307P4HIGHCVSS 7.2PoCv10.3.62005-05-17
CVE-2005-1307 [HIGH] CVE-2005-1307: The (1) stopserver.sh and (2) startserver.sh scripts in Adobe Version Cue on Mac OS X uses the curre The (1) stopserver.sh and (2) startserver.sh scripts in Adobe Version Cue on Mac OS X uses the current working directory to find and execute the productname.sh script, which allows local users to execute arbitrary code by copying and calling the scripts from a user-controlled directory.
nvd
CVE-2021-30833P3MEDIUMCVSS 5.5≥ 10.15, < 10.15.7v10.15.72021-10-28
CVE-2021-30833 [MEDIUM] CVE-2021-30833: This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.0.1. Unpacki This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.0.1. Unpacking a maliciously crafted archive may allow an attacker to write arbitrary files.
nvd
CVE-2016-4629P3CRITICALCVSS 9.8≤ 10.11.52016-07-22
CVE-2016-4629 [CRITICAL] CWE-119 CVE-2016-4629: ImageIO in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a de ImageIO in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted xStride and yStride values in an EXR image.
nvd
CVE-2016-1800P3HIGHCVSS 8.8≤ 10.11.42016-05-20
CVE-2016-1800 [HIGH] CWE-20 CVE-2016-1800: Captive Network Assistant in Apple OS X before 10.11.5 mishandles a custom URL scheme, which allows Captive Network Assistant in Apple OS X before 10.11.5 mishandles a custom URL scheme, which allows user-assisted remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2006-1985P4MEDIUMCVSS 5.1PoCv10.3v10.3.1+15 more2006-04-21
CVE-2006-1985 [MEDIUM] CWE-119 CVE-2006-1985: Heap-based buffer overflow in BOM BOMArchiveHelper 10.4 (6.3) Build 312, as used in Mac OS X 10.4.6 Heap-based buffer overflow in BOM BOMArchiveHelper 10.4 (6.3) Build 312, as used in Mac OS X 10.4.6 and earlier, allows user-assisted attackers to execute arbitrary code via a crafted archive (such as ZIP) that contains long path names, which triggers an error in the BOMStackPop function.
nvd
CVE-2016-1761P3CRITICALCVSS 9.8≤ 10.11.32016-03-24
CVE-2016-1761 [CRITICAL] CWE-119 CVE-2016-1761: libxml2 in Apple iOS before 9.3, OS X before 10.11.4, and watchOS before 2.2 allows remote attackers libxml2 in Apple iOS before 9.3, OS X before 10.11.4, and watchOS before 2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document.
nvd
CVE-2019-8676P3HIGHCVSS 8.8fixed in 10.14.62019-12-18
CVE-2019-8676 [HIGH] CWE-787 CVE-2019-8676: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8669P3HIGHCVSS 8.8fixed in 10.14.62019-12-18
CVE-2019-8669 [HIGH] CWE-787 CVE-2019-8669: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8684P3HIGHCVSS 8.8fixed in 10.14.62019-12-18
CVE-2019-8684 [HIGH] CWE-787 CVE-2019-8684: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8696P3HIGHCVSS 8.8fixed in 10.14.62020-10-27
CVE-2019-8696 [HIGH] CWE-120 CVE-2019-8696: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Mo A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra. An attacker in a privileged network position may be able to execute arbitrary code.
nvd
CVE-2019-8675P3HIGHCVSS 8.8fixed in 10.14.62020-10-27
CVE-2019-8675 [HIGH] CWE-120 CVE-2019-8675: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Mo A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra. An attacker in a privileged network position may be able to execute arbitrary code.
nvd
CVE-2016-4694P3CRITICALCVSS 9.1≤ 10.11.62016-09-25
CVE-2016-4694 [CRITICAL] CWE-284 CVE-2016-4694: The Apache HTTP Server in Apple OS X before 10.12 and OS X Server before 5.2 follows RFC 3875 sectio The Apache HTTP Server in Apple OS X before 10.12 and OS X Server before 5.2 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted CGI client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy ser
nvd
CVE-2008-2830P4HIGHCVSS 7.2PoCv10.4v10.52008-06-23
CVE-2008-2830 [HIGH] CWE-264 CVE-2008-2830: Open Scripting Architecture in Apple Mac OS X 10.4.11 and 10.5.4, and some other 10.4 and 10.5 versi Open Scripting Architecture in Apple Mac OS X 10.4.11 and 10.5.4, and some other 10.4 and 10.5 versions, does not properly restrict the loading of scripting addition plugins, which allows local users to gain privileges via scripting addition commands to a privileged application, as originally demonstrated by an osascript tell command to ARDAgent.
nvd
CVE-2017-13878P4HIGHCVSS 7.1PoCfixed in 10.13.22017-12-25
CVE-2017-13878 [HIGH] CWE-125 CVE-2017-13878: An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graphics Driver" component. It allows local users to bypass intended memory-read restrictions or cause a denial of service (out-of-bounds read and system crash).
nvd
CVE-2017-2518P3CRITICALCVSS 9.8fixed in 10.12.52017-05-22
CVE-2017-2518 [CRITICAL] CWE-416 CVE-2017-2518: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via
nvd
CVE-2021-1788P3HIGHCVSS 8.8≥ 10.14, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-04-02
CVE-2021-1788 [HIGH] CWE-416 CVE-2021-1788: A use after free issue was addressed with improved memory management. This issue is fixed in macOS B A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4, Safari 14.0.3. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2002-0659P4MEDIUMCVSS 5.0PoCv10.0v10.0.1+9 more2002-08-12
CVE-2002-0659 [MEDIUM] CVE-2002-0659: The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encodings.
nvd
CVE-2022-26748P3HIGHCVSS 8.8fixed in 10.15.7v10.15.72022-05-26
CVE-2022-26748 [HIGH] CWE-787 CVE-2022-26748: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Se An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
Apple macOS vulnerabilities | cvebase