Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 26 of 157
CVE-2018-4259P3CRITICALCVSS 9.8fixed in 10.13.62019-04-03
CVE-2018-4259 [CRITICAL] CWE-119 CVE-2018-4259: Multiple memory corruption issues were addressed with improved memory handling. This issue affected
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to macOS High Sierra 10.13.6.
nvd
CVE-2018-4287P3CRITICALCVSS 9.8fixed in 10.13.62019-04-03
CVE-2018-4287 [CRITICAL] CWE-119 CVE-2018-4287: Multiple memory corruption issues were addressed with improved memory handling. This issue affected
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to macOS High Sierra 10.13.6.
nvd
CVE-2008-3638P3CRITICALCVSS 9.3v10.5.4v10.5.52008-09-26
CVE-2008-3638 [CRITICAL] CWE-94 CVE-2008-3638: Java on Apple Mac OS X 10.5.4 and 10.5.5 does not prevent applets from accessing file:// URLs, which
Java on Apple Mac OS X 10.5.4 and 10.5.5 does not prevent applets from accessing file:// URLs, which allows remote attackers to execute arbitrary programs.
nvd
CVE-2014-9862P3HIGHCVSS 7.8≤ 10.11.52016-07-22
CVE-2014-9862 [HIGH] CWE-190 CVE-2014-9862: Integer signedness error in bspatch.c in bspatch in bsdiff, as used in Apple OS X before 10.11.6 and
Integer signedness error in bspatch.c in bspatch in bsdiff, as used in Apple OS X before 10.11.6 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via a crafted patch file.
nvd
CVE-2017-2423P3CRITICALCVSS 9.8≤ 10.12.32017-04-02
CVE-2017-2423 [CRITICAL] CWE-347 CVE-2017-2423: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. The issue involves the "Security" component. It allows remote attackers to bypass intended access restrictions by leveraging a successful result from a SecKeyRawVerify API call with an empty signature.
nvd
CVE-2021-1882P3CRITICALCVSS 9.8≥ 10.15, ≤ 10.15.5v10.15.6+1 more2021-09-08
CVE-2021-1882 [CRITICAL] CWE-787 CVE-2021-1882: A memory corruption issue was addressed with improved validation. This issue is fixed in Security Up
A memory corruption issue was addressed with improved validation. This issue is fixed in Security Update 2021-002 Catalina, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. An application may be able to gain elevated privileges.
nvd
CVE-2006-3498P3CRITICALCVSS 10.0v10.3.9v10.4.72006-08-02
CVE-2006-3498 [CRITICAL] CVE-2006-3498: Stack-based buffer overflow in bootpd in the DHCP component for Apple Mac OS X 10.3.9 and 10.4.7 all
Stack-based buffer overflow in bootpd in the DHCP component for Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to execute arbitrary code via a crafted BOOTP request.
nvd
CVE-2018-4268P3CRITICALCVSS 9.8fixed in 10.13.62019-04-03
CVE-2018-4268 [CRITICAL] CWE-119 CVE-2018-4268: A memory corruption issue was addressed with improved memory handling. This issue affected versions
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to macOS High Sierra 10.13.6.
nvd
CVE-2018-4258P3CRITICALCVSS 9.8fixed in 10.13.52019-01-11
CVE-2018-4258 [CRITICAL] CWE-119 CVE-2018-4258: In macOS High Sierra before 10.13.5, a buffer overflow was addressed with improved bounds checking.
In macOS High Sierra before 10.13.5, a buffer overflow was addressed with improved bounds checking.
nvd
CVE-2016-7595P3HIGHCVSS 8.8≤ 10.12.12017-02-20
CVE-2016-7595 [HIGH] CWE-119 CVE-2016-7595: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "CoreText" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font.
nvd
CVE-2016-7658P3HIGHCVSS 8.8≤ 10.12.12017-02-20
CVE-2016-7658 [HIGH] CWE-119 CVE-2016-7658: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Audio" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file.
nvd
CVE-2016-7659P3HIGHCVSS 8.8≤ 10.12.12017-02-20
CVE-2016-7659 [HIGH] CWE-119 CVE-2016-7659: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Audio" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file.
nvd
CVE-2016-7588P3HIGHCVSS 8.8≤ 10.12.12017-02-20
CVE-2016-7588 [HIGH] CWE-119 CVE-2016-7588: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "CoreMedia Playback" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted MP4 file.
nvd
CVE-2016-4691P3HIGHCVSS 8.8≤ 10.12.12017-02-20
CVE-2016-4691 [HIGH] CWE-119 CVE-2016-4691: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "FontParser" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font.
nvd
CVE-2018-4150P3HIGHCVSS 7.8fixed in 10.13.42018-04-03
CVE-2018-4150 [HIGH] CWE-119 CVE-2018-4150: An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4
An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app
nvd
CVE-2008-0599P3CRITICALCVSS 9.8fixed in 10.5.42008-05-05
CVE-2008-0599 [CRITICAL] CWE-131 CVE-2008-0599: The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider
The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.
nvd
CVE-2006-6062P4MEDIUMCVSS 5.1PoCv10.4.82006-11-22
CVE-2006-6062 [MEDIUM] CVE-2006-6062: Unspecified vulnerability in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attac
Unspecified vulnerability in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a malformed UDTO HFS+ disk image, such as with "bad sectors," which triggers memory corruption.
nvd
CVE-2017-7065P3HIGHCVSS 8.8fixed in 10.12.62018-04-03
CVE-2017-7065 [HIGH] CWE-119 CVE-2017-7065: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. The issue involves the "Wi-Fi" component. It allows remote attackers to execute arbitrary code (on the Wi-Fi chip) or cause a denial of service (memory corruption) by leveraging proximity for 802.11.
nvd
CVE-2005-2713P4MEDIUMCVSS 6.8PoCv10.3v10.3.1+14 more2005-12-31
CVE-2005-2713 [MEDIUM] CVE-2005-2713: passwd in Directory Services in Mac OS X 10.3.x before 10.3.9 and 10.4.x before 10.4.5 allows local
passwd in Directory Services in Mac OS X 10.3.x before 10.3.9 and 10.4.x before 10.4.5 allows local users to create arbitrary world-writable files as root by specifying an alternate file in the password database option.
nvd
CVE-2007-2401P4MEDIUMCVSS 4.3PoCv10.3.9v10.4.92007-06-25
CVE-2007-2401 [MEDIUM] CWE-79 CVE-2007-2401: CRLF injection vulnerability in WebCore in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone befor
CRLF injection vulnerability in WebCore in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1, allows remote attackers to inject arbitrary HTTP headers via LF characters in an XMLHttpRequest request, which are not filtered when serializing headers via the setRequestHeader function. NOTE: this issue can be leveraged for cross-site scriptin
nvd