Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 21 of 157
CVE-2019-6211P3HIGHCVSS 8.8fixed in 10.14.32019-03-05
CVE-2019-6211 [HIGH] CWE-787 CVE-2019-6211: A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 1
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2015-7110P4MEDIUMCVSS 6.9PoC≤ 10.11.12015-12-11
CVE-2015-7110 [MEDIUM] CWE-119 CVE-2015-7110: The Disk Images component in Apple OS X before 10.11.2 and tvOS before 9.1 allows local users to gai
The Disk Images component in Apple OS X before 10.11.2 and tvOS before 9.1 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted disk image.
nvd
CVE-2014-1377P3CRITICALCVSS 10.0≤ 10.9.3v10.8.0+8 more2014-07-01
CVE-2014-1377 [CRITICAL] CVE-2014-1377: Array index error in IOAcceleratorFamily in Apple OS X before 10.9.4 allows attackers to execute arb
Array index error in IOAcceleratorFamily in Apple OS X before 10.9.4 allows attackers to execute arbitrary code via a crafted application.
nvd
CVE-2015-8659P3CRITICALCVSS 10.0≤ 10.11.32016-01-12
CVE-2015-8659 [CRITICAL] CWE-119 CVE-2015-8659: The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unk
The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free bug.
nvd
CVE-2014-1358P3CRITICALCVSS 10.0v10.9v10.9.1+2 more2014-07-01
CVE-2014-1358 [CRITICAL] CWE-189 CVE-2014-1358: Integer overflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before
Integer overflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 allows attackers to execute arbitrary code via a crafted application.
nvd
CVE-2014-4487P3CRITICALCVSS 10.0≤ 10.10.12015-01-30
CVE-2014-4487 [CRITICAL] CWE-119 CVE-2014-4487: Buffer overflow in IOHIDFamily in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV be
Buffer overflow in IOHIDFamily in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2017-7154P4MEDIUMCVSS 6.6PoCfixed in 10.13.22017-12-27
CVE-2017-7154 [MEDIUM] CWE-20 CVE-2017-7154: An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. The issue involves the "Kernel" component. It allows local users to bypass intended memory-read restrictions or cause a denial of service (system crash).
nvd
CVE-2017-7062P3CRITICALCVSS 9.8≤ 10.12.52017-07-20
CVE-2017-7062 [CRITICAL] CWE-119 CVE-2017-7062: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Contacts" component. A buffer overflow allows remote attackers to execute arbitrary code or cause a denial of service (application crash).
nvd
CVE-2007-0467P4MEDIUMCVSS 6.2PoCv10.4.82007-01-31
CVE-2007-0467 [MEDIUM] CVE-2007-0467: crashdump in Apple Mac OS X 10.4.8 allows local users in the admin group to modify arbitrary files o
crashdump in Apple Mac OS X 10.4.8 allows local users in the admin group to modify arbitrary files or gain privileges via a symlink attack on application logs in /Library/Logs/CrashReporter/.
nvd
CVE-2016-4598P3CRITICALCVSS 9.8≤ 10.11.52016-07-22
CVE-2016-4598 [CRITICAL] CWE-119 CVE-2016-4598: QuickTime in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a
QuickTime in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted image.
nvd
CVE-2020-9918P3CRITICALCVSS 9.8fixed in 10.15.62020-10-16
CVE-2020-9918 [CRITICAL] CWE-125 CVE-2020-9918: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Cat
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2009-0946P3HIGHCVSS 7.5≥ 10.6.0, ≤ 10.6.4v10.4.11+1 more2009-04-17
CVE-2009-0946 [HIGH] CWE-190 CVE-2009-0946: Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary
Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.
nvd
CVE-2017-2509P4MEDIUMCVSS 5.5PoC≤ 10.12.42017-05-22
CVE-2017-2509 [MEDIUM] CVE-2017-2509: An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvd
CVE-2016-4631P3HIGHCVSS 8.8fixed in 10.11.62016-07-22
CVE-2016-4631 [HIGH] CWE-119 CVE-2016-4631: ImageIO in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2
ImageIO in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted TIFF file.
nvd
CVE-2014-4381P3CRITICALCVSS 9.3≤ 10.9.42014-09-18
CVE-2014-4381 [CRITICAL] CWE-119 CVE-2014-4381: Libnotify in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking on write operatio
Libnotify in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking on write operations, which allows attackers to execute arbitrary code as root via a crafted application.
nvd
CVE-2016-4637P3HIGHCVSS 8.8fixed in 10.11.62016-07-22
CVE-2016-4637 [HIGH] CWE-119 CVE-2016-4637: CoreGraphics in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2
CoreGraphics in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted BMP image.
nvd
CVE-2015-0973P3HIGHCVSS 8.8≤ 10.11.32015-01-18
CVE-2015-0973 [HIGH] CVE-2015-0973: Buffer overflow in the png_read_IDAT_data function in pngrutil.c in libpng before 1.5.21 and 1.6.x b
Buffer overflow in the png_read_IDAT_data function in pngrutil.c in libpng before 1.5.21 and 1.6.x before 1.6.16 allows context-dependent attackers to execute arbitrary code via IDAT data with a large width, a different vulnerability than CVE-2014-9495.
nvd
CVE-2015-3691P3CRITICALCVSS 9.3≤ 10.10.32015-07-03
CVE-2015-3691 [CRITICAL] CWE-284 CVE-2015-3691: The Monitor Control Command Set kernel extension in the Display Drivers subsystem in Apple OS X befo
The Monitor Control Command Set kernel extension in the Display Drivers subsystem in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context via a crafted app that leverages control of a function pointer.
nvd
CVE-2016-7608P4MEDIUMCVSS 5.5PoC≤ 10.12.12017-02-20
CVE-2016-7608 [MEDIUM] CWE-200 CVE-2016-7608: An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "IOFireWireFamily" component, which allows local users to obtain sensitive information from kernel memory via unspecified vectors.
nvd
CVE-2014-8837P3CRITICALCVSS 9.3≤ 10.10.12015-01-30
CVE-2014-8837 [CRITICAL] CVE-2014-8837: Multiple unspecified vulnerabilities in the Bluetooth driver in Apple OS X before 10.10.2 allow atta
Multiple unspecified vulnerabilities in the Bluetooth driver in Apple OS X before 10.10.2 allow attackers to execute arbitrary code in a privileged context via a crafted app.
nvd