cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 27 of 157
CVE-2019-6200P3HIGHCVSS 8.8fixed in 10.14.32019-03-05
CVE-2019-6200 [HIGH] CWE-125 CVE-2019-6200: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.1. An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3. An attacker in a privileged network position may be able to execute arbitrary code.
nvd
CVE-2019-9506P3HIGHCVSS 8.1v10.12.6v10.13.6+1 more2019-08-14
CVE-2019-9506 [HIGH] CWE-310 CVE-2019-9506: The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encrypti The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.
nvd
CVE-2008-4217P3CRITICALCVSS 9.3≤ 10.5.5v10.4.11+5 more2008-12-17
CVE-2008-4217 [CRITICAL] CWE-189 CVE-2008-4217: Integer signedness error in BOM in Apple Mac OS X before 10.5.6 allows remote attackers to execute a Integer signedness error in BOM in Apple Mac OS X before 10.5.6 allows remote attackers to execute arbitrary code via the headers in a crafted CPIO archive, leading to a stack-based buffer overflow.
nvd
CVE-2008-2305P3CRITICALCVSS 9.3v10.4.11v10.5+4 more2008-09-16
CVE-2008-2305 [CRITICAL] CWE-119 CVE-2008-2305: Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.4.11 and 10.5 through 1 Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows remote attackers to execute arbitrary code via a document containing a crafted font, related to "PostScript font names."
nvd
CVE-2022-26757P3HIGHCVSS 7.8fixed in 10.15.7v10.15.72022-05-26
CVE-2022-26757 [HIGH] CWE-416 CVE-2022-26757: A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15 A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 Catalina, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2007-2390P3CRITICALCVSS 10.0v10.3.9v10.4.92007-05-24
CVE-2007-2390 [CRITICAL] CVE-2007-2390: Buffer overflow in iChat in Apple Mac OS X 10.3.9 and 10.4.9 allows remote attackers to cause a deni Buffer overflow in iChat in Apple Mac OS X 10.3.9 and 10.4.9 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted UPnP Internet Gateway Device (IGD) packet.
nvd
CVE-2019-8604P3HIGHCVSS 8.8fixed in 10.14.52019-12-18
CVE-2019-8604 [HIGH] CWE-787 CVE-2019-8604: A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.5. An application may be able to execute arbitrary code with system privileges.
nvd
CVE-2021-30847P3HIGHCVSS 7.8≥ 10.15, ≤ 10.15.6v10.15.72021-10-19
CVE-2021-30847 [HIGH] CVE-2021-30847: This issue was addressed with improved checks. This issue is fixed in watchOS 8, macOS Big Sur 11.6, This issue was addressed with improved checks. This issue is fixed in watchOS 8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, iTunes 12.12 for Windows. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2009-0846P3CRITICALCVSS 10.0fixed in 10.5.72009-04-09
CVE-2009-0846 [CRITICAL] CWE-824 CVE-2009-0846: The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime de The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer.
nvd
CVE-2015-5887P3CRITICALCVSS 10.0≤ 10.10.52015-10-09
CVE-2015-5887 [CRITICAL] CWE-17 CVE-2015-5887: The TLS Handshake Protocol implementation in Secure Transport in Apple OS X before 10.11 accepts a C The TLS Handshake Protocol implementation in Secure Transport in Apple OS X before 10.11 accepts a Certificate Request message within a session in which no Server Key Exchange message has been sent, which allows remote attackers to have an unspecified impact via crafted TLS data.
nvd
CVE-2021-30981P3HIGHCVSS 7.8≥ 10.15, < 10.15.7v10.15.72021-08-24
CVE-2021-30981 [HIGH] CWE-120 CVE-2021-30981: A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Monterey A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.1, Security Update 2021-008 Catalina, macOS Big Sur 11.6.2. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2021-1772P3HIGHCVSS 7.8≥ 10.14, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-04-02
CVE-2021-1772 [HIGH] CWE-787 CVE-2021-1772: A stack overflow was addressed with improved input validation. This issue is fixed in macOS Big Sur A stack overflow was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted text file may lead to arbitrary code execution.
nvd
CVE-2022-26751P3HIGHCVSS 7.8fixed in 10.15.7v10.15.72022-05-26
CVE-2022-26751 [HIGH] CWE-787 CVE-2022-26751: A memory corruption issue was addressed with improved input validation. This issue is fixed in iTune A memory corruption issue was addressed with improved input validation. This issue is fixed in iTunes 12.12.4 for Windows, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 Catalina, macOS Big Sur 11.6.6, macOS Monterey 12.4. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2018-4229P3CRITICALCVSS 10.0fixed in 10.13.52018-06-08
CVE-2018-4229 [CRITICAL] CVE-2018-4229: An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Grand Central Dispatch" component. It allows attackers to bypass a sandbox protection mechanism by leveraging the misparsing of entitlement plists.
nvd
CVE-2021-30917P3HIGHCVSS 7.8fixed in 10.15.7v10.15.72021-08-24
CVE-2021-30917 [HIGH] CWE-20 CVE-2021-30917: A memory corruption issue existed in the processing of ICC profiles. This issue was addressed with i A memory corruption issue existed in the processing of ICC profiles. This issue was addressed with improved input validation. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, iOS 14.8.1 and iPadOS 14.8.1, tvOS 15.1, watchOS 8.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. Processing a maliciously crafted image may le
nvd
CVE-2021-30942P3HIGHCVSS 7.8≥ 10.15, < 10.15.7v10.15.72021-08-24
CVE-2021-30942 [HIGH] CWE-787 CVE-2021-30942: Description: A memory corruption issue in the processing of ICC profiles was addressed with improved Description: A memory corruption issue in the processing of ICC profiles was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2021-30926P3HIGHCVSS 7.8≥ 10.15, < 10.15.17v10.15.72021-08-24
CVE-2021-30926 [HIGH] CWE-787 CVE-2021-30926: Description: A memory corruption issue in the processing of ICC profiles was addressed with improved Description: A memory corruption issue in the processing of ICC profiles was addressed with improved input validation. This issue is fixed in macOS Monterey 12.1, watchOS 8.3, iOS 15.2 and iPadOS 15.2, tvOS 15.2. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2019-8547P3CRITICALCVSS 9.8≥ 10.12.6, < 10.14.5≥ 10.14.3, < 10.14.42020-10-27
CVE-2019-8547 [CRITICAL] CWE-125 CVE-2019-8547: An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, watchOS 5.2, macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra
nvd
CVE-2018-4091P3CRITICALCVSS 10.0fixed in 10.13.32018-04-03
CVE-2018-4091 [CRITICAL] CVE-2018-4091: An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue involves the "Sandbox" component. It allows bypass of a sandbox protection mechanism.
nvd
CVE-2020-3847P3CRITICALCVSS 9.8fixed in 10.15.32020-04-01
CVE-2020-3847 [CRITICAL] CWE-20 CVE-2020-3847: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Cat An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able to leak memory.
nvd
Apple macOS vulnerabilities | cvebase