Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 24 of 157
CVE-2014-1318P3CRITICALCVSS 10.0≤ 10.9.2v10.9+7 more2014-04-23
CVE-2014-1318 [CRITICAL] CWE-20 CVE-2014-1318: The Intel Graphics Driver in Apple OS X through 10.9.2 does not properly validate a certain pointer,
The Intel Graphics Driver in Apple OS X through 10.9.2 does not properly validate a certain pointer, which allows attackers to execute arbitrary code via a crafted application.
nvd
CVE-2015-7987P3CRITICALCVSS 9.8≥ 10.9, < 10.9.5≥ 10.10.0, < 10.10.5+1 more2016-06-26
CVE-2015-7987 [CRITICAL] CWE-119 CVE-2015-7987: Multiple buffer overflows in mDNSResponder before 625.41.2 allow remote attackers to read or write t
Multiple buffer overflows in mDNSResponder before 625.41.2 allow remote attackers to read or write to out-of-bounds memory locations via vectors involving the (1) GetValueForIPv4Addr, (2) GetValueForMACAddr, (3) rfc3110_import, or (4) CopyNSEC3ResourceRecord function.
nvd
CVE-2018-4332P3CRITICALCVSS 9.8fixed in 10.142019-04-03
CVE-2018-4332 [CRITICAL] CWE-119 CVE-2018-4332: A memory corruption issue was addressed with improved memory handling. This issue affected versions
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
nvd
CVE-2017-2516P4MEDIUMCVSS 5.0PoC≤ 10.12.42017-05-22
CVE-2017-2516 [MEDIUM] CVE-2017-2516: An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvd
CVE-2018-18313P3CRITICALCVSS 9.1fixed in 10.14.42018-12-07
CVE-2018-18313 [CRITICAL] CWE-125 CVE-2018-18313: Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure
Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process memory.
nvd
CVE-2015-3768P3CRITICALCVSS 9.3≤ 10.10.42015-08-16
CVE-2015-3768 [CRITICAL] CWE-189 CVE-2015-3768: Integer overflow in the kernel in Apple iOS before 8.4.1 and OS X before 10.10.5 allows attackers to
Integer overflow in the kernel in Apple iOS before 8.4.1 and OS X before 10.10.5 allows attackers to execute arbitrary code in a privileged context via a crafted app that makes unspecified IOKit API calls.
nvd
CVE-2019-8756P3CRITICALCVSS 9.8fixed in 10.152020-10-27
CVE-2019-8756 [CRITICAL] CWE-787 CVE-2019-8756: Multiple memory corruption issues were addressed with improved input validation. This issue is fixed
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Catalina 10.15, iOS 13, iCloud for Windows 7.14, iCloud for Windows 10.7, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, watchOS 6, iTunes 12.10.1 for Windows. Multiple issues in libxml2.
nvd
CVE-2009-1726P3CRITICALCVSS 9.3v10.5.6v10.4.11+8 more2009-08-06
CVE-2009-1726 [CRITICAL] CWE-119 CVE-2009-1726: Heap-based buffer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5 before 10.5.8 allows remo
Heap-based buffer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5 before 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted image containing an embedded ColorSync profile.
nvd
CVE-2016-4630P3HIGHCVSS 8.8≤ 10.11.52016-07-22
CVE-2016-4630 [HIGH] CWE-119 CVE-2016-4630: ImageIO in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a de
ImageIO in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted EXR image with B44 compression.
nvd
CVE-2009-0010P3CRITICALCVSS 9.3v10.4.11v10.5+7 more2009-05-13
CVE-2009-0010 [CRITICAL] CWE-189 CVE-2009-0010: Integer underflow in QuickDraw Manager in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7, and Apple Q
Integer underflow in QuickDraw Manager in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7, and Apple QuickTime before 7.6.2, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PICT image with a crafted 0x77 Poly tag and a crafted length field, which triggers a heap-based buffer overflow.
nvd
CVE-2020-36230P3HIGHCVSS 7.5≥ 10.14.0, < 10.14.6v10.14.62021-01-26
CVE-2020-36230 [HIGH] CWE-617 CVE-2020-36230: A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.50
A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, resulting in denial of service.
nvd
CVE-2010-2941P3CRITICALCVSS 9.8fixed in 10.5.8≥ 10.6.0, ≤ 10.6.42010-11-05
CVE-2010-2941 [CRITICAL] CWE-416 CVE-2010-2941: ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with
ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted IPP request.
nvd
CVE-2017-7000P3HIGHCVSS 8.8fixed in 10.12.52018-04-03
CVE-2017-7000 [HIGH] CWE-119 CVE-2017-7000: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
nvd
CVE-2016-1807P4MEDIUMCVSS 5.1PoCfixed in 10.11.52016-05-20
CVE-2016-1807 [MEDIUM] CWE-362 CVE-2016-1807: Race condition in the Disk Images subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS bef
Race condition in the Disk Images subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows local users to obtain sensitive information from kernel memory via unspecified vectors.
nvd
CVE-2009-0012P3CRITICALCVSS 10.0v10.5.62009-02-13
CVE-2009-0012 [CRITICAL] CWE-119 CVE-2009-0012: Heap-based buffer overflow in CoreText in Apple Mac OS X 10.5.6 allows remote attackers to execute a
Heap-based buffer overflow in CoreText in Apple Mac OS X 10.5.6 allows remote attackers to execute arbitrary code via a crafted Unicode string.
nvd
CVE-2003-1006P4HIGHCVSS 7.2PoCv10.0v10.0.1+21 more2004-03-29
CVE-2003-1006 [HIGH] CVE-2003-1006: Buffer overflow in cd9660.util in Apple Mac OS X 10.0 through 10.3.2 and Apple Mac OS X Server 10.0
Buffer overflow in cd9660.util in Apple Mac OS X 10.0 through 10.3.2 and Apple Mac OS X Server 10.0 through 10.3.2 may allow local users to execute arbitrary code via a long command line parameter.
nvd
CVE-2005-0716P4HIGHCVSS 7.2PoCv10.3v10.3.1+7 more2005-03-21
CVE-2005-0716 [HIGH] CVE-2005-0716: Stack-based buffer overflow in the Core Foundation Library in Mac OS X 10.3.5 and 10.3.6, and possib
Stack-based buffer overflow in the Core Foundation Library in Mac OS X 10.3.5 and 10.3.6, and possibly earlier versions, allows local users to execute arbitrary code via a long CF_CHARSET_PATH environment variable.
nvd
CVE-2003-0171P4HIGHCVSS 7.2PoCv10.0v10.0.1+14 more2003-05-05
CVE-2003-0171 [HIGH] CVE-2003-0171: DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch co
DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitrary commands by modifying the PATH to point to a directory containing a malicious touch program.
nvd
CVE-2007-0023P4MEDIUMCVSS 6.9PoCv10.4.82007-01-24
CVE-2007-0023 [MEDIUM] CVE-2007-0023: The CFUserNotificationSendRequest function in UserNotificationCenter.app in Apple Mac OS X 10.4.8, w
The CFUserNotificationSendRequest function in UserNotificationCenter.app in Apple Mac OS X 10.4.8, when used in combination with diskutil, allows local users to gain privileges via a malicious InputManager in Library/InputManagers in a user's home directory, which is executed when Cocoa applications attempt to notify the user.
nvd
CVE-2021-30939P3HIGHCVSS 7.8≥ 10.15, < 10.15.7v10.15.72021-08-24
CVE-2021-30939 [HIGH] CWE-125 CVE-2021-30939: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd