cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 3 of 157
CVE-2011-1752P2MEDIUMCVSS 5.0Exploitedfixed in 10.7.32011-06-06
CVE-2011-1752 [MEDIUM] CWE-476 CVE-2011-1752: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17 The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request for a baselined WebDAV resource, as exploited in the wild in May 2011.
nvd
CVE-2015-0235P2CRITICALCVSS 10.0PoCfixed in 10.11.12015-01-28
CVE-2015-0235 [CRITICAL] CWE-787 CVE-2015-0235: Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x ve Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."
nvd
CVE-2014-8517P2HIGHCVSS 7.5PoCv10.8.5v10.9.5+2 more2014-11-17
CVE-2014-8517 [HIGH] CWE-77 CVE-2014-8517: The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 thr The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 through 6.1.5 allows remote attackers to execute arbitrary commands via a | (pipe) character at the end of an HTTP redirect.
nvd
CVE-2008-0226P2HIGHCVSS 7.5PoCv10.5.42008-01-10
CVE-2008-0226 [HIGH] CWE-119 CVE-2008-0226: Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code via (1) the ProcessOldClientHello function in handshake.cpp or (2) "input_buffer& operator>>" in yassl_imp.cpp.
nvd
CVE-2007-3798P2CRITICALCVSS 9.8PoC≥ 10.0.0, < 10.4.112007-07-16
CVE-2007-3798 [CRITICAL] CWE-252 CVE-2007-3798: Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote atta Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value.
nvd
CVE-2010-1205P2CRITICALCVSS 9.8PoC≥ 10.6.0, < 10.6.42010-06-30
CVE-2010-1205 [CRITICAL] CWE-120 CVE-2010-1205: Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.
nvd
CVE-2016-0801P2CRITICALCVSS 9.8PoC≤ 10.11.32016-02-07
CVE-2016-0801 [CRITICAL] CWE-20 CVE-2016-0801: The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6. The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted wireless control message packets, aka internal bug 25662029.
nvd
CVE-2016-4071P2CRITICALCVSS 9.8PoC≤ 10.11.42016-05-20
CVE-2016-4071 [CRITICAL] CWE-20 CVE-2016-4071: Format string vulnerability in the php_snmp_error function in ext/snmp/snmp.c in PHP before 5.5.34, Format string vulnerability in the php_snmp_error function in ext/snmp/snmp.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to execute arbitrary code via format string specifiers in an SNMP::get call.
nvd
CVE-2017-13872P2HIGHCVSS 8.1PoCv10.13.0v10.13.12017-11-29
CVE-2017-13872 [HIGH] CWE-287 CVE-2017-13872: An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The issue involves the "Directory Utility" component. It allows attackers to obtain administrator access without a password via certain interactions involving entry of the root user name.
nvd
CVE-2019-8660P2CRITICALCVSS 9.8PoCfixed in 10.14.62019-12-18
CVE-2019-8660 [CRITICAL] CWE-787 CVE-2019-8660: A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 1 A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
nvd
CVE-2013-6420P2HIGHCVSS 7.5PoC≤ 10.9.12013-12-17
CVE-2013-6420 [HIGH] CWE-119 CVE-2013-6420: The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not properly parse (1) notBefore and (2) notAfter timestamps in X.509 certificates, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate that is not
nvd
CVE-2015-7007P2HIGHCVSS 7.5PoC≤ 10.11.02015-10-23
CVE-2015-7007 [HIGH] CVE-2015-7007: Script Editor in Apple OS X before 10.11.1 allows remote attackers to bypass an intended user-confir Script Editor in Apple OS X before 10.11.1 allows remote attackers to bypass an intended user-confirmation requirement for AppleScript execution via unspecified vectors.
nvd
CVE-2019-8689P2HIGHCVSS 8.8PoCfixed in 10.14.62019-12-18
CVE-2019-8689 [HIGH] CWE-787 CVE-2019-8689: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8672P2HIGHCVSS 8.8PoCfixed in 10.14.62019-12-18
CVE-2019-8672 [HIGH] CWE-787 CVE-2019-8672: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2014-8146P2HIGHCVSS 7.5PoC≤ 10.10.42015-05-25
CVE-2014-8146 [HIGH] CWE-119 CVE-2014-8146: The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implemen The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 does not properly track directionally isolated pieces of text, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly execute arbitrary
nvd
CVE-2003-0466P3CRITICALCVSS 9.8PoCv10.2.62003-08-27
CVE-2003-0466 [CRITICAL] CWE-193 CVE-2003-0466: Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may al Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU
nvd
CVE-2019-8641P2CRITICALCVSS 9.8PoCfixed in 10.14.62019-12-18
CVE-2019-8641 [CRITICAL] CWE-125 CVE-2019-8641: An out-of-bounds read was addressed with improved input validation. An out-of-bounds read was addressed with improved input validation.
nvd
CVE-2019-8661P2CRITICALCVSS 9.8PoCfixed in 10.14.62019-12-18
CVE-2019-8661 [CRITICAL] CWE-416 CVE-2019-8661: A use after free issue was addressed with improved memory management. This issue is fixed in macOS M A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.6. A remote attacker may be able to cause arbitrary code execution.
nvd
CVE-2008-3529P2CRITICALCVSS 10.0PoCfixed in 10.5.7v10.5.72008-09-12
CVE-2008-3529 [CRITICAL] CWE-119 CVE-2008-3529: Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7 Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name.
nvd
CVE-2017-2523P2CRITICALCVSS 9.8PoCfixed in 10.12.52017-05-22
CVE-2017-2523 [CRITICAL] CWE-119 CVE-2017-2523: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "Foundation" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash
nvd
Apple macOS vulnerabilities | cvebase