cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 19 of 157
CVE-2016-4609P3CRITICALCVSS 9.8fixed in 10.11.62016-07-22
CVE-2016-4609 [CRITICAL] CVE-2016-4609: libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud befo libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4607, CVE-2016-460
nvd
CVE-2016-4607P3CRITICALCVSS 9.8fixed in 10.11.62016-07-22
CVE-2016-4607 [CRITICAL] CWE-119 CVE-2016-4607: libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud befo libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4608, CVE-
nvd
CVE-2007-0746P3CRITICALCVSS 10.0v10.3.9v10.4+9 more2007-04-24
CVE-2007-0746 [CRITICAL] CVE-2007-0746: Heap-based buffer overflow in the VideoConference framework in Apple Mac OS X 10.3.9 through 10.4.9 Heap-based buffer overflow in the VideoConference framework in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attackers to execute arbitrary code via a "crafted SIP packet when initializing an audio/video conference".
nvd
CVE-2020-3878P3HIGHCVSS 7.8≥ 10.13, < 10.13.6≥ 10.14, < 10.14.6+3 more2020-02-27
CVE-2020-3878 [HIGH] CWE-125 CVE-2020-3878: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.5 An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2019-6203P3CRITICALCVSS 9.8fixed in 10.14.42020-04-17
CVE-2019-6203 [CRITICAL] CVE-2019-6203: A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS M A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2. An attacker in a privileged network position may be able to intercept network traffic.
nvd
CVE-2020-8285P3HIGHCVSS 7.5fixed in 10.14.6≥ 10.15, < 10.15.7+2 more2020-12-14
CVE-2020-8285 [HIGH] CWE-674 CVE-2020-8285: curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.
nvd
CVE-2009-2193P3CRITICALCVSS 10.0v10.5v10.5.0+7 more2009-08-06
CVE-2009-2193 [CRITICAL] CWE-119 CVE-2009-2193: Buffer overflow in the kernel in Apple Mac OS X 10.5 before 10.5.8 allows remote attackers to execut Buffer overflow in the kernel in Apple Mac OS X 10.5 before 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via a crafted AppleTalk response packet.
nvd
CVE-2017-2519P3CRITICALCVSS 9.8fixed in 10.12.52017-05-22
CVE-2017-2519 [CRITICAL] CVE-2017-2519: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a craf
nvd
CVE-2014-8817P3CRITICALCVSS 10.0≤ 10.10.12015-01-30
CVE-2014-8817 [CRITICAL] CWE-19 CVE-2014-8817: coresymbolicationd in CoreSymbolication in Apple OS X before 10.10.2 does not verify that expected d coresymbolicationd in CoreSymbolication in Apple OS X before 10.10.2 does not verify that expected data types are present in XPC messages, which allows attackers to execute arbitrary code in a privileged context via a crafted app, as demonstrated by lack of verification of xpc_dictionary_get_value API return values during handling of a (1) match_mmap
nvd
CVE-2017-2489P4MEDIUMCVSS 5.5PoC≤ 10.12.32017-04-02
CVE-2017-2489 [MEDIUM] CWE-200 CVE-2017-2489: An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to obtain sensitive information from kernel memory via a crafted app.
nvd
CVE-2018-4310P3CRITICALCVSS 10.0fixed in 10.142019-04-03
CVE-2018-4310 [CRITICAL] CWE-269 CVE-2018-4310: An access issue was addressed with additional sandbox restrictions. This issue affected versions pri An access issue was addressed with additional sandbox restrictions. This issue affected versions prior to iOS 12, macOS Mojave 10.14.
nvd
CVE-2014-4461P3CRITICALCVSS 9.3≤ 10.10.1v10.8.5+2 more2014-11-18
CVE-2014-4461 [CRITICAL] CWE-20 CVE-2014-4461: The kernel in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly validate IOSharedDa The kernel in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly validate IOSharedDataQueue object metadata, which allows attackers to execute arbitrary code in a privileged context via a crafted application.
nvd
CVE-2019-8716P3CRITICALCVSS 9.8fixed in 10.15.12020-10-27
CVE-2019-8716 [CRITICAL] CWE-787 CVE-2019-8716: A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006. An application may be able to execute arbitrary code with system privileges.
nvd
CVE-2019-15126P4LOWCVSS 3.1PoCfixed in 10.15.12020-02-05
CVE-2019-15126 [LOW] CWE-367 CVE-2019-15126: An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic, a different vulnerability than C
nvd
CVE-2016-1950P3HIGHCVSS 8.8≤ 10.11.32016-03-13
CVE-2016-1950 [HIGH] CWE-119 CVE-2016-1950: Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code via crafted ASN.1 data in an X.509 certificate.
nvd
CVE-2019-8527P3CRITICALCVSS 9.1fixed in 10.14.42019-12-18
CVE-2019-8527 [CRITICAL] CWE-120 CVE-2019-8527: A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 12.2, macO A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2014-9495P3HIGHCVSS 8.8≤ 10.11.32015-01-10
CVE-2014-9495 [HIGH] CWE-119 CVE-2014-9495: Heap-based buffer overflow in the png_combine_row function in libpng before 1.5.21 and 1.6.x before Heap-based buffer overflow in the png_combine_row function in libpng before 1.5.21 and 1.6.x before 1.6.16, when running on 64-bit systems, might allow context-dependent attackers to execute arbitrary code via a "very wide interlaced" PNG image.
nvd
CVE-2016-4448P3CRITICALCVSS 9.8fixed in 10.11.62016-06-09
CVE-2016-4448 [CRITICAL] CWE-134 CVE-2016-4448: Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
nvd
CVE-2017-11103P3HIGHCVSS 8.1fixed in 10.13.12017-07-13
CVE-2017-11103 [HIGH] CWE-345 CVE-2017-11103: Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks becaus Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the encrypted version stored in 'enc_part' instead of the unencrypted version sto
nvd
CVE-2020-9920P3CRITICALCVSS 9.1fixed in 10.15.62020-10-22
CVE-2020-9920 [CRITICAL] CWE-22 CVE-2020-9920: A path handling issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iP A path handling issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, watchOS 6.2.8. A malicious mail server may overwrite arbitrary mail files.
nvd
Apple macOS vulnerabilities | cvebase