Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
277
Exploited in wild
28
Severity breakdown
CRITICAL302HIGH1409MEDIUM1236LOW192
Vulnerabilities
Page 28 of 157
CVE-2019-8645MEDIUMCVSS 6.5fixed in 10.14.42020-10-27
CVE-2019-8645 [MEDIUM] CVE-2019-8645: An issue existed in the handling of encrypted Mail. This issue was addressed with improved isolation
An issue existed in the handling of encrypted Mail. This issue was addressed with improved isolation of MIME in Mail. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra. An attacker in a privileged network position may be able to intercept the contents of S/MIME-encrypted e-mail.
nvd
CVE-2019-8528MEDIUMCVSS 6.7≥ 10.13.6, < 10.14.42020-10-27
CVE-2019-8528 [MEDIUM] CWE-416 CVE-2019-8528: A use after free issue was addressed with improved memory management. This issue is fixed in watchOS
A use after free issue was addressed with improved memory management. This issue is fixed in watchOS 5.2, macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, iOS 12.2. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2019-8538MEDIUMCVSS 5.5≥ 10.14.3, < 10.14.42020-10-27
CVE-2019-8538 [MEDIUM] CVE-2019-8538: A denial of service issue was addressed with improved validation. This issue is fixed in watchOS 5.2
A denial of service issue was addressed with improved validation. This issue is fixed in watchOS 5.2, macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, iOS 12.2. Processing a maliciously crafted vcf file may lead to a denial of service.
nvd
CVE-2019-8582MEDIUMCVSS 5.5fixed in 10.14.52020-10-27
CVE-2019-8582 [MEDIUM] CWE-125 CVE-2019-8582: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iCloud for
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iCloud for Windows 7.12, tvOS 12.3, iTunes 12.9.5 for Windows, macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, iOS 12.3. Processing a maliciously crafted font may result in the disclosure of process memory.
nvd
CVE-2020-9857MEDIUMCVSS 4.3fixed in 10.15.52020-10-27
CVE-2020-9857 [MEDIUM] CVE-2020-9857: An issue existed in the parsing of URLs. This issue was addressed with improved input validation. Th
An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.5, Security Update 2020-003 Mojave, Security Update 2020-003 High Sierra. A malicious website may be able to exfiltrate autofilled data in Safari.
nvd
CVE-2019-8642LOWCVSS 3.3fixed in 10.14.42020-10-27
CVE-2019-8642 [LOW] CWE-295 CVE-2019-8642: An issue existed in the handling of S-MIME certificates. This issue was addressed with improved vali
An issue existed in the handling of S-MIME certificates. This issue was addressed with improved validation of S-MIME certificates. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra. Processing a maliciously crafted mail message may lead to S/MIME signature spoofing.
nvd
CVE-2019-8777LOWCVSS 2.4fixed in 10.14.42020-10-27
CVE-2019-8777 [LOW] CWE-276 CVE-2019-8777: A lock screen issue allowed access to contacts on a locked device. This issue was addressed with imp
A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra. A local attacker may be able to view contacts from the lock screen.
nvd
CVE-2019-8799LOWCVSS 2.4fixed in 10.152020-10-27
CVE-2019-8799 [LOW] CVE-2019-8799: This issue was resolved by replacing device names with a random identifier. This issue is fixed in i
This issue was resolved by replacing device names with a random identifier. This issue is fixed in iOS 13.1 and iPadOS 13.1, macOS Catalina 10.15, watchOS 6, tvOS 13. An attacker in physical proximity may be able to passively observe device names in AWDL communications.
nvd
CVE-2019-8856LOWCVSS 3.3fixed in 10.15.22020-10-27
CVE-2019-8856 [LOW] CVE-2019-8856: An API issue existed in the handling of outgoing phone calls initiated with Siri. This issue was add
An API issue existed in the handling of outgoing phone calls initiated with Siri. This issue was addressed with improved state handling. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. Calls made using Siri may be initiated using the wrong cellular
nvd
CVE-2019-8809LOWCVSS 3.3fixed in 10.152020-10-27
CVE-2019-8809 [LOW] CVE-2019-8809: A validation issue was addressed with improved logic. This issue is fixed in macOS Catalina 10.15, i
A validation issue was addressed with improved logic. This issue is fixed in macOS Catalina 10.15, iOS 13.1 and iPadOS 13.1, tvOS 13, watchOS 6, iOS 13. A local app may be able to read a persistent account identifier.
nvd
CVE-2020-9786LOWCVSS 3.3fixed in 10.15.42020-10-27
CVE-2020-9786 [LOW] CVE-2020-9786: This issue was addressed with improved checks This issue is fixed in macOS Catalina 10.15.4, Securit
This issue was addressed with improved checks This issue is fixed in macOS Catalina 10.15.4, Security Update 2020-002 Mojave, Security Update 2020-002 High Sierra. An application may be able to trigger a sysdiagnose.
nvd
CVE-2019-8842LOWCVSS 3.3fixed in 10.15.22020-10-27
CVE-2019-8842 [LOW] CWE-120 CVE-2019-8842: A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina
A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. In certain configurations, a remote attacker may be able to submit arbitrary print jobs.
nvd
CVE-2020-9868CRITICALCVSS 9.1fixed in 10.15.62020-10-22
CVE-2020-9868 [CRITICAL] CWE-295 CVE-2020-9868: A certificate validation issue existed when processing administrator added certificates. This issue
A certificate validation issue existed when processing administrator added certificates. This issue was addressed with improved certificate validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. An attacker may have been able to impersonate a trusted website using shared key material for an ad
nvd
CVE-2020-9898CRITICALCVSS 9.8≥ 10.13.6, < 10.15.62020-10-22
CVE-2020-9898 [CRITICAL] CVE-2020-9898: This issue was addressed with improved entitlements. This issue is fixed in iOS 13.6 and iPadOS 13.6
This issue was addressed with improved entitlements. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6. A sandboxed process may be able to circumvent sandbox restrictions.
nvd
CVE-2020-9906CRITICALCVSS 9.1≥ 10.13, < 10.13.6≥ 10.14, < 10.14.6+3 more2020-10-22
CVE-2020-9906 [CRITICAL] CWE-20 CVE-2020-9906: A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 1
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, watchOS 6.2.8. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2020-9920CRITICALCVSS 9.1fixed in 10.15.62020-10-22
CVE-2020-9920 [CRITICAL] CWE-22 CVE-2020-9920: A path handling issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iP
A path handling issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, watchOS 6.2.8. A malicious mail server may overwrite arbitrary mail files.
nvd
CVE-2020-9882HIGHCVSS 7.8≥ 10.14.6, < 10.15.62020-10-22
CVE-2020-9882 [HIGH] CWE-120 CVE-2020-9882: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, watchOS 6.2.8. Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution.
nvd
CVE-2020-9940HIGHCVSS 7.8fixed in 10.15.62020-10-22
CVE-2020-9940 [HIGH] CWE-120 CVE-2020-9940: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8. Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution.
nvd
CVE-2020-9854HIGHCVSS 7.8fixed in 10.15.52020-10-22
CVE-2020-9854 [HIGH] CVE-2020-9854: A logic issue was addressed with improved validation. This issue is fixed in iOS 13.5 and iPadOS 13.
A logic issue was addressed with improved validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5. An application may be able to gain elevated privileges.
nvd
CVE-2020-9980HIGHCVSS 7.8fixed in 10.15.62020-10-22
CVE-2020-9980 [HIGH] CWE-787 CVE-2020-9980: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. Processing a maliciously crafted font file may lead to arbitrary code execution.
nvd