Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 17 of 157
CVE-2009-0138P3CRITICALCVSS 10.0v10.5.62009-02-13
CVE-2009-0138 [CRITICAL] CWE-287 CVE-2009-0138: servermgrd (Server Manager) in Apple Mac OS X 10.5.6 does not properly validate authentication crede
servermgrd (Server Manager) in Apple Mac OS X 10.5.6 does not properly validate authentication credentials, which allows remote attackers to modify the system configuration.
nvd
CVE-2017-2520P3CRITICALCVSS 9.8fixed in 10.12.52017-05-22
CVE-2017-2520 [CRITICAL] CWE-787 CVE-2017-2520: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via
nvd
CVE-2007-3876P4MEDIUMCVSS 6.6PoCv10.4.112007-12-19
CVE-2007-3876 [MEDIUM] CWE-119 CVE-2007-3876: Stack-based buffer overflow in SMB in Apple Mac OS X 10.4.11 allows local users to execute arbitrary
Stack-based buffer overflow in SMB in Apple Mac OS X 10.4.11 allows local users to execute arbitrary code via (1) a long workgroup (-W) option to mount_smbfs or (2) an unspecified manipulation of the command line to smbutil.
nvd
CVE-2021-30655P3CRITICALCVSS 9.8≥ 10.15, ≤ 10.15.5v10.15.6+1 more2021-09-08
CVE-2021-30655 [CRITICAL] CVE-2021-30655: An application may be able to execute arbitrary code with system privileges. This issue is fixed in
An application may be able to execute arbitrary code with system privileges. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. The issue was addressed with improved permissions logic.
nvd
CVE-2018-12015P3HIGHCVSS 7.5fixed in 10.14.42018-06-07
CVE-2018-12015 [HIGH] CWE-59 CVE-2018-12015: In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traver
In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.
nvd
CVE-2022-22630P3CRITICALCVSS 9.8v10.15.72023-06-23
CVE-2022-22630 [CRITICAL] CWE-416 CVE-2022-22630: A use after free issue was addressed with improved memory management. This issue is fixed in macOS B
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.6.6, macOS Monterey 12.3, Security Update 2022-004 Catalina. A remote user may cause an unexpected app termination or arbitrary code execution
nvd
CVE-2016-4073P3CRITICALCVSS 9.8≤ 10.11.32016-05-20
CVE-2016-4073 [CRITICAL] CWE-119 CVE-2016-4073: Multiple integer overflows in the mbfl_strcut function in ext/mbstring/libmbfl/mbfl/mbfilter.c in PH
Multiple integer overflows in the mbfl_strcut function in ext/mbstring/libmbfl/mbfl/mbfilter.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted mb_strcut call.
nvd
CVE-2020-9856P4MEDIUMCVSS 5.3PoC≥ 10.13, < 10.13.6≥ 10.14, < 10.14.6+3 more2020-06-09
CVE-2020-9856 [MEDIUM] CVE-2020-9856: This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.5. An app
This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.5. An application may be able to gain elevated privileges.
nvd
CVE-2005-1333P4MEDIUMCVSS 5.0PoCv10.3.92005-05-04
CVE-2005-1333 [MEDIUM] CVE-2005-1333: Directory traversal vulnerability in the Bluetooth file and object exchange (OBEX) services in Mac O
Directory traversal vulnerability in the Bluetooth file and object exchange (OBEX) services in Mac OS X 10.3.9 allows remote attackers to read arbitrary files.
nvd
CVE-2020-9789P3HIGHCVSS 8.8fixed in 10.15.52020-06-09
CVE-2020-9789 [HIGH] CWE-787 CVE-2020-9789: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2020-9790P3HIGHCVSS 8.8fixed in 10.15.52020-06-09
CVE-2020-9790 [HIGH] CWE-787 CVE-2020-9790: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2019-8685P3HIGHCVSS 8.8fixed in 10.14.62019-12-18
CVE-2019-8685 [HIGH] CWE-787 CVE-2019-8685: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8830P3HIGHCVSS 8.8fixed in 10.15.22020-10-27
CVE-2019-8830 [HIGH] CWE-125 CVE-2019-8830: An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 13.3
An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, iOS 13.3 and iPadOS 13.3, iOS 12.4.4, watchOS 5.3.4. Processing malicious video via FaceTime may lead to arbitrary code execution.
nvd
CVE-2019-8688P3HIGHCVSS 8.8fixed in 10.14.62019-12-18
CVE-2019-8688 [HIGH] CWE-787 CVE-2019-8688: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2021-30799P3HIGHCVSS 8.8≥ 10.14, ≤ 10.14.6≥ 10.15, < 10.15.7+3 more2021-09-08
CVE-2021-30799 [HIGH] CWE-787 CVE-2021-30799: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8683P3HIGHCVSS 8.8fixed in 10.14.62019-12-18
CVE-2019-8683 [HIGH] CWE-787 CVE-2019-8683: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8673P3HIGHCVSS 8.8fixed in 10.14.62019-12-18
CVE-2019-8673 [HIGH] CWE-787 CVE-2019-8673: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8678P3HIGHCVSS 8.8fixed in 10.14.62019-12-18
CVE-2019-8678 [HIGH] CWE-787 CVE-2019-8678: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2020-3846P3HIGHCVSS 8.8fixed in 10.15.32020-02-27
CVE-2020-3846 [HIGH] CWE-20 CVE-2020-3846: A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 13.3.1 and
A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code executi
nvd
CVE-2014-1359P3CRITICALCVSS 10.0v10.9v10.9.1+2 more2014-07-01
CVE-2014-1359 [CRITICAL] CWE-189 CVE-2014-1359: Integer underflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV befor
Integer underflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 allows attackers to execute arbitrary code via a crafted application.
nvd