Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 22 of 157
CVE-2020-9883P3HIGHCVSS 7.8≥ 10.13, < 10.13.6≥ 10.14, < 10.14.6+3 more2020-10-22
CVE-2020-9883 [HIGH] CWE-120 CVE-2020-9883: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2022-32847P3CRITICALCVSS 9.1v10.15.72022-09-23
CVE-2022-32847 [CRITICAL] CWE-119 CVE-2022-32847: This issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, macO
This issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2021-39537P3HIGHCVSS 8.8v10.12.62021-09-20
CVE-2021-39537 [HIGH] CWE-787 CVE-2021-39537: An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buf
An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.
nvd
CVE-2012-6151P4MEDIUMCVSS 4.3PoCv10.11.02013-12-13
CVE-2012-6151 [MEDIUM] CWE-399 CVE-2012-6151: Net-SNMP 5.7.1 and earlier, when AgentX is registering to handle a MIB and processing GETNEXT reques
Net-SNMP 5.7.1 and earlier, when AgentX is registering to handle a MIB and processing GETNEXT requests, allows remote attackers to cause a denial of service (crash or infinite loop, CPU consumption, and hang) by causing the AgentX subagent to timeout.
nvd
CVE-2017-2485P3HIGHCVSS 8.8≤ 10.12.32017-04-02
CVE-2017-2485 [HIGH] CWE-416 CVE-2017-2485: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Security" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a craf
nvd
CVE-2014-4393P3CRITICALCVSS 10.0v10.8.5v10.9+4 more2014-09-19
CVE-2014-4393 [CRITICAL] CWE-119 CVE-2014-4393: Buffer overflow in the shader compiler in the Intel Graphics Driver subsystem in Apple OS X before 1
Buffer overflow in the shader compiler in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted GLSL shader.
nvd
CVE-2016-4688P3HIGHCVSS 8.8fixed in 10.12.12017-02-20
CVE-2016-4688 [HIGH] CWE-119 CVE-2016-4688: An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "FontParser" component. It allows remote attackers to execute arbitrary code or cause a denial of service (buffer overfl
nvd
CVE-2017-2381P3HIGHCVSS 8.8≤ 10.12.32017-04-02
CVE-2017-2381 [HIGH] CVE-2017-2381: An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "sudo" component. It allows remote authenticated users to gain privileges by leveraging membership in the admin group on a network directory server.
nvd
CVE-2019-8745P3HIGHCVSS 8.8fixed in 10.152019-12-18
CVE-2019-8745 [HIGH] CWE-119 CVE-2019-8745: A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina
A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15, tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing a maliciously crafted text file may lead to arbitrary code execution.
nvd
CVE-2007-0229P4HIGHCVSS 7.2PoCv10.4.82007-01-13
CVE-2007-0229 [HIGH] CVE-2007-0229: Integer overflow in the ffs_mountfs function in Mac OS X 10.4.8 and FreeBSD 6.1 allows local users t
Integer overflow in the ffs_mountfs function in Mac OS X 10.4.8 and FreeBSD 6.1 allows local users to cause a denial of service (panic) and possibly gain privileges via a crafted DMG image that causes "allocation of a negative size buffer" leading to a heap-based buffer overflow, a related issue to CVE-2006-5679. NOTE: a third party states that this issue does
nvd
CVE-2019-8585P3HIGHCVSS 8.8fixed in 10.14.52019-12-18
CVE-2019-8585 [HIGH] CWE-125 CVE-2019-8585: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.3,
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. Processing a maliciously crafted movie file may lead to arbitrary code execution.
nvd
CVE-2009-1238P4HIGHCVSS 7.2PoC≤ 10.5.6v10.0+53 more2009-04-02
CVE-2009-1238 [HIGH] CWE-362 CVE-2009-1238: Race condition in the HFS vfs sysctl interface in XNU 1228.8.20 and earlier on Apple Mac OS X 10.5.6
Race condition in the HFS vfs sysctl interface in XNU 1228.8.20 and earlier on Apple Mac OS X 10.5.6 and earlier allows local users to cause a denial of service (kernel memory corruption) by simultaneously executing the same HFS_SET_PKG_EXTENSIONS code path in multiple threads, which is problematic because of lack of mutex locking for an unspecified glo
nvd
CVE-2020-27920P3HIGHCVSS 8.8fixed in 11.0.1fixed in 11.1.02021-04-02
CVE-2020-27920 [HIGH] CWE-416 CVE-2020-27920: A use after free issue was addressed with improved memory management. This issue is fixed in macOS B
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, watchOS 7.1, tvOS 14.2. Processing maliciously crafted web content may lead to code execution.
nvd
CVE-2014-1376P3CRITICALCVSS 10.0≤ 10.9.3v10.8.0+8 more2014-07-01
CVE-2014-1376 [CRITICAL] CWE-264 CVE-2014-1376: Intel Compute in Apple OS X before 10.9.4 does not properly restrict an unspecified OpenCL API call,
Intel Compute in Apple OS X before 10.9.4 does not properly restrict an unspecified OpenCL API call, which allows attackers to execute arbitrary code via a crafted application.
nvd
CVE-2019-8826P3HIGHCVSS 8.8fixed in 10.152020-10-27
CVE-2019-8826 [HIGH] CWE-787 CVE-2019-8826: A memory corruption issue was addressed with improved state management. This issue is fixed in macOS
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2020-29633P3HIGHCVSS 8.8≥ 10.14, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-04-02
CVE-2020-29633 [HIGH] CVE-2020-29633: An authentication issue was addressed with improved state management. This issue is fixed in macOS B
An authentication issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. An attacker in a privileged network position may be able to bypass authentication policy.
nvd
CVE-2014-1356P3CRITICALCVSS 10.0v10.9v10.9.1+2 more2014-07-01
CVE-2014-1356 [CRITICAL] CWE-119 CVE-2014-1356: Heap-based buffer overflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple
Heap-based buffer overflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 allows attackers to execute arbitrary code via a crafted application that sends IPC messages.
nvd
CVE-2021-30717P3HIGHCVSS 8.1≥ 10.14, ≤ 10.14.5≥ 10.15, ≤ 10.15.6+2 more2021-09-08
CVE-2021-30717 [HIGH] CWE-787 CVE-2021-30717: A memory corruption issue was addressed with improved state management. This issue is fixed in macOS
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. An attacker in a privileged network position may be able to execute arbitrary code.
nvd
CVE-2020-9999P3HIGHCVSS 7.8fixed in 11.0.12020-12-08
CVE-2020-9999 [HIGH] CWE-787 CVE-2020-9999: A memory corruption issue was addressed with improved state management. This issue is fixed in macOS
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, iTunes for Windows 12.10.9. Processing a maliciously crafted text file may lead to arbitrary code execution.
nvd
CVE-2015-1066P3CRITICALCVSS 10.0≤ 10.10.22015-03-12
CVE-2015-1066 [CRITICAL] CWE-189 CVE-2015-1066: Off-by-one error in IOAcceleratorFamily in Apple OS X through 10.10.2 allows attackers to execute ar
Off-by-one error in IOAcceleratorFamily in Apple OS X through 10.10.2 allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd