cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 25 of 157
CVE-2018-4085P3HIGHCVSS 8.8fixed in 10.13.32018-04-03
CVE-2018-4085 [HIGH] CWE-119 CVE-2018-4085: An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13 An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "QuartzCore" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) vi
nvd
CVE-2021-30935P3HIGHCVSS 8.8≤ 10.15.7v10.15.72021-08-24
CVE-2021-30935 [HIGH] CVE-2021-30935: A logic issue was addressed with improved validation. This issue is fixed in Security Update 2021-00 A logic issue was addressed with improved validation. This issue is fixed in Security Update 2021-008 Catalina, macOS Big Sur 11.6.2. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2021-30835P3HIGHCVSS 7.8≥ 10.15, ≤ 10.15.6v10.15.72021-10-19
CVE-2021-30835 [HIGH] CVE-2021-30835: This issue was addressed with improved checks. This issue is fixed in Security Update 2021-005 Catal This issue was addressed with improved checks. This issue is fixed in Security Update 2021-005 Catalina, iTunes 12.12 for Windows, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2007-4708P3CRITICALCVSS 9.3v10.4.112007-12-19
CVE-2007-4708 [CRITICAL] CWE-134 CVE-2007-4708: Format string vulnerability in Address Book in Apple Mac OS X 10.4.11 allows remote attackers to exe Format string vulnerability in Address Book in Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary code via the URL handler.
nvd
CVE-2014-1314P3CRITICALCVSS 10.0≤ 10.9.2v10.9+7 more2014-04-23
CVE-2014-1314 [CRITICAL] CWE-264 CVE-2014-1314: WindowServer in Apple OS X through 10.9.2 does not prevent session creation by a sandboxed applicati WindowServer in Apple OS X through 10.9.2 does not prevent session creation by a sandboxed application, which allows attackers to bypass the sandbox protection mechanism and execute arbitrary code via a crafted application.
nvd
CVE-2017-2513P3CRITICALCVSS 9.8≤ 10.12.42017-05-22
CVE-2017-2513 [CRITICAL] CWE-416 CVE-2017-2513: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "SQLite" component. A use-after-free vulnerability allows remote attackers to execute arbitrary code or cause a denial of service (application cra
nvd
CVE-2014-1373P3CRITICALCVSS 10.0≤ 10.9.3v10.8.0+8 more2014-07-01
CVE-2014-1373 [CRITICAL] CWE-264 CVE-2014-1373: Intel Graphics Driver in Apple OS X before 10.9.4 does not properly restrict an unspecified OpenGL A Intel Graphics Driver in Apple OS X before 10.9.4 does not properly restrict an unspecified OpenGL API call, which allows attackers to execute arbitrary code via a crafted application.
nvd
CVE-2016-4614P3CRITICALCVSS 9.8fixed in 10.11.62016-07-22
CVE-2016-4614 [CRITICAL] CWE-787 CVE-2016-4614: libxml2 in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud befo libxml2 in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4615, CVE-
nvd
CVE-2016-4616P3CRITICALCVSS 9.8fixed in 10.11.62016-07-22
CVE-2016-4616 [CRITICAL] CVE-2016-4616: libxml2 in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud befo libxml2 in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4614, CVE-2016-461
nvd
CVE-2016-4615P3CRITICALCVSS 9.8fixed in 10.11.62016-07-22
CVE-2016-4615 [CRITICAL] CVE-2016-4615: libxml2 in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud befo libxml2 in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4614, CVE-2016-461
nvd
CVE-2009-2820P4MEDIUMCVSS 4.3PoC≤ 10.6.1v10.0+57 more2009-11-10
CVE-2009-2820 [MEDIUM] CWE-79 CVE-2009-2820: The web interface in CUPS before 1.4.2, as used on Apple Mac OS X before 10.6.2 and other platforms, The web interface in CUPS before 1.4.2, as used on Apple Mac OS X before 10.6.2 and other platforms, does not properly handle (1) HTTP headers and (2) HTML templates, which allows remote attackers to conduct cross-site scripting (XSS) attacks and HTTP response splitting attacks via vectors related to (a) the product's web interface, (b) the configurati
nvd
CVE-2007-6427P3CRITICALCVSS 9.3fixed in 10.4.11≥ 10.5.0, < 10.5.22008-01-18
CVE-2007-6427 [CRITICAL] CVE-2007-6427: The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arb The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte swapping and heap corruption within multiple functions, a different vulnerability than CVE-2007-4990.
nvd
CVE-2015-2301P3HIGHCVSS 7.5≤ 10.10.42015-03-30
CVE-2015-2301 [HIGH] CWE-416 CVE-2015-2301: Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5. Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5.22 and 5.6.x before 5.6.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an attempted renaming of a Phar archive to the name of an existing file.
nvd
CVE-2021-30919P3HIGHCVSS 7.8fixed in 10.15.7v10.15.72021-08-24
CVE-2021-30919 [HIGH] CWE-787 CVE-2021-30919: An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 15.1 An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, iOS 14.8.1 and iPadOS 14.8.1, tvOS 15.1, watchOS 8.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. Processing a maliciously crafted PDF may lead to arbitrary code execution.
nvd
CVE-2017-2428P3CRITICALCVSS 9.8≤ 10.12.32017-04-02
CVE-2017-2428 [CRITICAL] CVE-2017-2428: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves nghttp2 before 1.17.0 in the "HTTPProtocol" component. It allows remote HTTP/2 servers to have an unspecified impact via unknown vectors.
nvd
CVE-2014-4402P3CRITICALCVSS 9.3v10.9v10.9.1+3 more2014-09-19
CVE-2014-4402 [CRITICAL] CWE-119 CVE-2014-4402: An unspecified IOAcceleratorFamily function in Apple OS X before 10.9.5 lacks proper bounds checking An unspecified IOAcceleratorFamily function in Apple OS X before 10.9.5 lacks proper bounds checking on read operations, which allows attackers to execute arbitrary code in a privileged context via a crafted application.
nvd
CVE-2015-4024P3MEDIUMCVSS 5.0≤ 10.10.42015-06-09
CVE-2015-4024 [MEDIUM] CWE-399 CVE-2015-4024: Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in P Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote attackers to cause a denial of service (CPU consumption) via crafted form data that triggers an improper order-of-growth outcome.
nvd
CVE-2018-4288P3CRITICALCVSS 9.8fixed in 10.13.62019-04-03
CVE-2018-4288 [CRITICAL] CWE-119 CVE-2018-4288: Multiple memory corruption issues were addressed with improved memory handling. This issue affected Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to macOS High Sierra 10.13.6.
nvd
CVE-2018-4291P3CRITICALCVSS 9.8fixed in 10.13.62019-04-03
CVE-2018-4291 [CRITICAL] CWE-119 CVE-2018-4291: Multiple memory corruption issues were addressed with improved memory handling. This issue affected Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to macOS High Sierra 10.13.6.
nvd
CVE-2018-4286P3CRITICALCVSS 9.8fixed in 10.13.62019-04-03
CVE-2018-4286 [CRITICAL] CWE-119 CVE-2018-4286: Multiple memory corruption issues were addressed with improved memory handling. This issue affected Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to macOS High Sierra 10.13.6.
nvd
Apple macOS vulnerabilities | cvebase