cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 30 of 157
CVE-2021-30980P3HIGHCVSS 7.8≥ 10.15, < 10.15.7v10.15.72021-08-24
CVE-2021-30980 [HIGH] CWE-416 CVE-2021-30980: A use after free issue was addressed with improved memory management. This issue is fixed in macOS B A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2020-10017P3HIGHCVSS 7.8fixed in 11.0.12020-12-08
CVE-2020-10017 [HIGH] CWE-787 CVE-2020-10017: An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Bi An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. Processing a maliciously crafted audio file may lead to arbitrary code execution.
nvd
CVE-2018-4115P3CRITICALCVSS 9.8fixed in 10.13.42018-04-03
CVE-2018-4115 [CRITICAL] CWE-281 CVE-2018-4115: An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves CFPreferences in the "System Preferences" component. It allows attackers to bypass intended access restrictions by leveraging incorrect configuration-profil
nvd
CVE-2016-9840P3HIGHCVSS 8.8≥ 10.0.0, < 10.13.02017-05-23
CVE-2016-9840 [HIGH] CVE-2016-9840: inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by lever inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
nvd
CVE-2021-30792P3HIGHCVSS 7.8≥ 10.14.0, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-09-08
CVE-2021-30792 [HIGH] CWE-787 CVE-2021-30792: An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.7 An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2021-30881P3HIGHCVSS 7.8fixed in 10.15.7v10.15.72021-08-24
CVE-2021-30881 [HIGH] CWE-20 CVE-2021-30881: An input validation issue was addressed with improved memory handling. This issue is fixed in iOS 15 An input validation issue was addressed with improved memory handling. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, tvOS 15.1, watchOS 8.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. Unpacking a maliciously crafted archive may lead to arbitrary code execution.
nvd
CVE-2021-30743P3HIGHCVSS 7.8v10.15v10.15.1+6 more2021-09-08
CVE-2021-30743 [HIGH] CWE-787 CVE-2021-30743: An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.5 An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, Security Update 2021-003 Catalina, tvOS 14.5, macOS Big Sur 11.3. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2022-22613P3HIGHCVSS 7.8≥ 10.15, < 10.15.7v10.15.72022-03-18
CVE-2022-22613 [HIGH] CWE-787 CVE-2022-22613: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvO An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, Security Update 2022-003 Catalina, watchOS 8.5, macOS Monterey 12.3. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2015-7111P3CRITICALCVSS 9.3≤ 10.11.12015-12-11
CVE-2015-7111 [CRITICAL] CWE-119 CVE-2015-7111: The IOHIDFamily API in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS befor The IOHIDFamily API in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2015-7112.
nvd
CVE-2018-4108P3CRITICALCVSS 9.8fixed in 10.13.42018-04-03
CVE-2018-4108 [CRITICAL] CWE-20 CVE-2018-4108: An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Disk Management" component. It allows attackers to trigger truncation of an APFS volume password via an unspecified injection.
nvd
CVE-2007-4689P3CRITICALCVSS 10.0v10.4.1v10.4.2+8 more2007-11-15
CVE-2007-4689 [CRITICAL] CWE-399 CVE-2007-4689: Double free vulnerability in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows Double free vulnerability in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (system shutdown) or execute arbitrary code via crafted IPV6 packets.
nvd
CVE-2018-4189P3CRITICALCVSS 9.8≥ 10.13.0, < 10.13.32019-01-11
CVE-2018-4189 [CRITICAL] CWE-119 CVE-2018-4189: In iOS before 11.2.5, macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Securit In iOS before 11.2.5, macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, watchOS before 4.2.2, and tvOS before 11.2.5, a memory corruption issue exists and was addressed with improved memory handling.
nvd
CVE-2007-5862P3CRITICALCVSS 9.4v10.4v10.4.1+10 more2007-12-18
CVE-2007-5862 [CRITICAL] CWE-287 CVE-2007-5862: Java in Mac OS X 10.4 through 10.4.11 allows remote attackers to bypass Keychain access controls and Java in Mac OS X 10.4 through 10.4.11 allows remote attackers to bypass Keychain access controls and add or delete arbitrary Keychain items via a crafted Java applet.
nvd
CVE-2017-2402P3CRITICALCVSS 9.8≤ 10.12.32017-04-02
CVE-2017-2402 [CRITICAL] CVE-2017-2402: An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves mishandling of profile uninstall actions in the "MCX Client" component when a profile has multiple payloads. It allows remote attackers to bypass intended access restrictions by leveraging Active Directory certificate trust that should not have remained.
nvd
CVE-2020-27897P3HIGHCVSS 7.8≥ 10.14, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-04-02
CVE-2020-27897 [HIGH] CWE-787 CVE-2020-27897: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in mac An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2018-4353P3CRITICALCVSS 9.8fixed in 10.142019-04-03
CVE-2018-4353 [CRITICAL] CWE-20 CVE-2018-4353: A configuration issue was addressed with additional restrictions. This issue affected versions prior A configuration issue was addressed with additional restrictions. This issue affected versions prior to macOS Mojave 10.14.
nvd
CVE-2022-22582P3MEDIUMCVSS 5.5v10.15.72023-02-27
CVE-2022-22582 [MEDIUM] CWE-59 CVE-2022-22582: A validation issue existed in the handling of symlinks. This issue was addressed with improved valid A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Security Update 2022-003 Catalina, macOS Big Sur 11.6.5, macOS Monterey 12.3. A local user may be able to write arbitrary files.
nvd
CVE-2019-8531P3CRITICALCVSS 9.8fixed in 10.14.42020-10-27
CVE-2019-8531 [CRITICAL] CWE-295 CVE-2019-8531: A validation issue existed in Trust Anchor Management. This issue was addressed with improved valida A validation issue existed in Trust Anchor Management. This issue was addressed with improved validation. This issue is fixed in watchOS 5.2, macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, iOS 12.2. An untrusted radius server certificate may be trusted.
nvd
CVE-2007-0647P4HIGHCVSS 7.1PoCv10.3.92007-02-01
CVE-2007-0647 [HIGH] CVE-2007-0647: Format string vulnerability in Help Viewer 3.0.0 allows remote user-assisted attackers to cause a de Format string vulnerability in Help Viewer 3.0.0 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling the NSBeginAlertSheet Apple AppKit function.
nvd
CVE-2009-2188P3CRITICALCVSS 9.3v10.5.6v10.5+7 more2009-08-06
CVE-2009-2188 [CRITICAL] CWE-119 CVE-2009-2188: Buffer overflow in ImageIO in Apple Mac OS X 10.5 before 10.5.8, and Safari before 4.0.3, allows rem Buffer overflow in ImageIO in Apple Mac OS X 10.5 before 10.5.8, and Safari before 4.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image with crafted EXIF metadata.
nvd
Apple macOS vulnerabilities | cvebase