cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 28 of 157
CVE-2015-3712P3CRITICALCVSS 9.3≤ 10.10.32015-07-03
CVE-2015-3712 [CRITICAL] CWE-119 CVE-2015-3712: The NVIDIA graphics driver in Apple OS X before 10.10.4 allows attackers to execute arbitrary code i The NVIDIA graphics driver in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (out-of-bounds write) via a crafted app.
nvd
CVE-2019-7288P3CRITICALCVSS 9.8fixed in 10.14.32020-10-27
CVE-2019-7288 [CRITICAL] CVE-2019-7288: The issue was addressed with improved validation on the FaceTime server. This issue is fixed in macO The issue was addressed with improved validation on the FaceTime server. This issue is fixed in macOS Mojave 10.14.3 Supplemental Update, iOS 12.1.4. A thorough security audit of the FaceTime service uncovered an issue with Live Photos .
nvd
CVE-2019-8703P3CRITICALCVSS 9.8fixed in 10.152021-12-23
CVE-2019-8703 [CRITICAL] CVE-2019-8703: This issue was addressed with improved entitlements. This issue is fixed in watchOS 6, tvOS 13, macO This issue was addressed with improved entitlements. This issue is fixed in watchOS 6, tvOS 13, macOS Catalina 10.15, iOS 13. An application may be able to gain elevated privileges.
nvd
CVE-2018-4298P3CRITICALCVSS 9.8≥ 10.13.0, < 10.13.32019-01-11
CVE-2018-4298 [CRITICAL] CVE-2018-4298: In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 E In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, a permissions issue existed in Remote Management. This issue was addressed through improved permission validation.
nvd
CVE-2021-30690P3CRITICALCVSS 9.8≥ 10.14, ≤ 10.14.5v10.14.62021-09-08
CVE-2021-30690 [CRITICAL] CVE-2021-30690: Multiple issues in apache were addressed by updating apache to version 2.4.46. This issue is fixed i Multiple issues in apache were addressed by updating apache to version 2.4.46. This issue is fixed in Security Update 2021-004 Mojave. Multiple issues in apache.
nvd
CVE-2018-4257P3CRITICALCVSS 9.8fixed in 10.13.52019-01-11
CVE-2018-4257 [CRITICAL] CWE-119 CVE-2018-4257: In macOS High Sierra before 10.13.5, a buffer overflow was addressed with improved size validation. In macOS High Sierra before 10.13.5, a buffer overflow was addressed with improved size validation.
nvd
CVE-2022-32813P3HIGHCVSS 7.8v10.15.72022-08-24
CVE-2022-32813 [HIGH] CWE-787 CVE-2022-32813: The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.5, m The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6, tvOS 15.6, watchOS 8.7. An app with root privileges may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2006-1470P4MEDIUMCVSS 5.0PoCv10.4v10.4.1+5 more2006-06-27
CVE-2006-1470 [MEDIUM] CWE-399 CVE-2006-1470: OpenLDAP in Apple Mac OS X 10.4 up to 10.4.6 allows remote attackers to cause a denial of service (c OpenLDAP in Apple Mac OS X 10.4 up to 10.4.6 allows remote attackers to cause a denial of service (crash) via an invalid LDAP request that triggers an assert error.
nvd
CVE-2014-4390P3CRITICALCVSS 9.3v10.9v10.9.1+3 more2014-09-19
CVE-2014-4390 [CRITICAL] CWE-20 CVE-2014-4390: Bluetooth in Apple OS X before 10.9.5 does not properly validate API calls, which allows attackers t Bluetooth in Apple OS X before 10.9.5 does not properly validate API calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application.
nvd
CVE-2014-4405P3CRITICALCVSS 9.3≤ 10.10.22014-09-18
CVE-2014-4405 [CRITICAL] CVE-2014-4405: IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code i IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via an application that provides crafted key-mapping properties.
nvd
CVE-2007-2399P3CRITICALCVSS 9.3v10.3.9v10.4.92007-06-25
CVE-2007-2399 [CRITICAL] CVE-2007-2399: WebKit in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1 performs an "invalid type WebKit in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1 performs an "invalid type conversion", which allows remote attackers to execute arbitrary code via unspecified frame sets that trigger memory corruption.
nvd
CVE-2016-1841P3HIGHCVSS 8.8fixed in 10.11.52016-05-20
CVE-2016-1841 [HIGH] CWE-119 CVE-2016-1841: libxslt, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS befo libxslt, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
nvd
CVE-2016-4601P3HIGHCVSS 8.8≤ 10.11.52016-07-22
CVE-2016-4601 [HIGH] CWE-119 CVE-2016-4601: QuickTime in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a QuickTime in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted SGI image.
nvd
CVE-2016-7596P3HIGHCVSS 8.8≤ 10.12.12017-02-20
CVE-2016-7596 [HIGH] CWE-119 CVE-2016-7596: An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Bluetooth" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2016-1834P3HIGHCVSS 7.8fixed in 10.11.52016-05-20
CVE-2016-1834 [HIGH] CWE-119 CVE-2016-1834: Heap-based buffer overflow in the xmlStrncat function in libxml2 before 2.9.4, as used in Apple iOS Heap-based buffer overflow in the xmlStrncat function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document.
nvd
CVE-2016-1847P3HIGHCVSS 8.8fixed in 10.11.52016-05-20
CVE-2016-1847 [HIGH] CWE-119 CVE-2016-1847: OpenGL, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS befor OpenGL, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
nvd
CVE-2017-6983P3HIGHCVSS 8.8≤ 10.12.42017-05-22
CVE-2017-6983 [HIGH] CWE-119 CVE-2017-6983: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
nvd
CVE-2018-4194P3HIGHCVSS 8.8≥ 10.13.0, < 10.13.52019-01-11
CVE-2018-4194 [HIGH] CWE-125 CVE-2018-4194: In iOS before 11.4, iCloud for Windows before 7.5, watchOS before 4.3.1, iTunes before 12.7.5 for Wi In iOS before 11.4, iCloud for Windows before 7.5, watchOS before 4.3.1, iTunes before 12.7.5 for Windows, and macOS High Sierra before 10.13.5, an out-of-bounds read was addressed with improved input validation.
nvd
CVE-2017-7002P3HIGHCVSS 8.8fixed in 10.12.52018-04-03
CVE-2017-7002 [HIGH] CWE-119 CVE-2017-7002: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
nvd
CVE-2017-6991P3HIGHCVSS 8.8≤ 10.12.42017-05-22
CVE-2017-6991 [HIGH] CWE-119 CVE-2017-6991: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
nvd
Apple macOS vulnerabilities | cvebase