Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 31 of 157
CVE-2015-3330P3MEDIUMCVSS 6.8≤ 10.10.42015-06-09
CVE-2015-3330 [MEDIUM] CWE-20 CVE-2015-3330: The php_handler function in sapi/apache2handler/sapi_apache2.c in PHP before 5.4.40, 5.5.x before 5.
The php_handler function in sapi/apache2handler/sapi_apache2.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, when the Apache HTTP Server 2.4.x is used, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via pipelined HTTP requests that result in a "deconfigured interpreter."
nvd
CVE-2010-0512P3CRITICALCVSS 9.3v10.6.0v10.6.1+1 more2010-03-30
CVE-2010-0512 [CRITICAL] CWE-264 CVE-2010-0512: The Accounts Preferences implementation in Apple Mac OS X 10.6 before 10.6.3, when a network account
The Accounts Preferences implementation in Apple Mac OS X 10.6 before 10.6.3, when a network account server is used, does not support Login Window access control that is based solely on group membership, which allows attackers to bypass intended access restrictions by entering login credentials.
nvd
CVE-2022-23308P3HIGHCVSS 7.5≥ 10.15.0, < 10.15.7v10.15.72022-02-26
CVE-2022-23308 [HIGH] CWE-416 CVE-2022-23308: valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
nvd
CVE-2016-4667P3HIGHCVSS 8.8≤ 10.12.02017-02-20
CVE-2016-4667 [HIGH] CWE-119 CVE-2016-4667: An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "ATS" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font.
nvd
CVE-2016-4600P3HIGHCVSS 8.8≤ 10.11.52016-07-22
CVE-2016-4600 [HIGH] CVE-2016-4600: QuickTime in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a
QuickTime in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted FlashPix bitmap image, a different vulnerability than CVE-2016-4596, CVE-2016-4597, and CVE-2016-4602.
nvd
CVE-2016-4596P3HIGHCVSS 8.8≤ 10.11.52016-07-22
CVE-2016-4596 [HIGH] CWE-119 CVE-2016-4596: QuickTime in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a
QuickTime in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted FlashPix bitmap image, a different vulnerability than CVE-2016-4597, CVE-2016-4600, and CVE-2016-4602.
nvd
CVE-2016-4602P3HIGHCVSS 8.8≤ 10.11.52016-07-22
CVE-2016-4602 [HIGH] CVE-2016-4602: QuickTime in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a
QuickTime in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted FlashPix bitmap image, a different vulnerability than CVE-2016-4596, CVE-2016-4597, and CVE-2016-4600.
nvd
CVE-2016-4597P3HIGHCVSS 8.8≤ 10.11.52016-07-22
CVE-2016-4597 [HIGH] CVE-2016-4597: QuickTime in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a
QuickTime in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted FlashPix bitmap image, a different vulnerability than CVE-2016-4596, CVE-2016-4600, and CVE-2016-4602.
nvd
CVE-2020-9868P3CRITICALCVSS 9.1fixed in 10.15.62020-10-22
CVE-2020-9868 [CRITICAL] CWE-295 CVE-2020-9868: A certificate validation issue existed when processing administrator added certificates. This issue
A certificate validation issue existed when processing administrator added certificates. This issue was addressed with improved certificate validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. An attacker may have been able to impersonate a trusted website using shared key material for an ad
nvd
CVE-2006-6129P4MEDIUMCVSS 4.6PoCv10.4.82006-11-27
CVE-2006-6129 [MEDIUM] CVE-2006-6129: Integer overflow in the fatfile_getarch2 in Apple Mac OS X allows local users to cause a denial of s
Integer overflow in the fatfile_getarch2 in Apple Mac OS X allows local users to cause a denial of service and possibly execute arbitrary code via a crafted Mach-O Universal program that triggers memory corruption.
nvd
CVE-2017-7001P3HIGHCVSS 8.8fixed in 10.12.52018-04-03
CVE-2017-7001 [HIGH] CWE-119 CVE-2017-7001: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
nvd
CVE-2020-8286P3HIGHCVSS 7.5fixed in 10.14.6≥ 10.15, < 10.15.7+2 more2020-12-14
CVE-2020-8286 [HIGH] CWE-295 CVE-2020-8286: curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insu
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.
nvd
CVE-2021-30712P3HIGHCVSS 7.8≥ 10.14, ≤ 10.14.5≥ 10.15, ≤ 10.15.6+2 more2021-09-08
CVE-2021-30712 [HIGH] CVE-2021-30712: A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
nvd
CVE-2019-8634P3HIGHCVSS 8.8fixed in 10.12.6fixed in 10.14.5+3 more2019-12-18
CVE-2019-8634 [HIGH] CWE-287 CVE-2019-8634: An authentication issue was addressed with improved state management. This issue is fixed in macOS M
An authentication issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.5. A user may be unexpectedly logged in to another user’s account.
nvd
CVE-2019-8781P3HIGHCVSS 7.8fixed in 10.152019-12-18
CVE-2019-8781 [HIGH] CWE-787 CVE-2019-8781: A memory corruption issue was addressed with improved state management. This issue is fixed in macOS
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2016-1840P3HIGHCVSS 7.8fixed in 10.11.52016-05-20
CVE-2016-1840 [HIGH] CWE-119 CVE-2016-1840: Heap-based buffer overflow in the xmlFAParsePosCharGroup function in libxml2 before 2.9.4, as used i
Heap-based buffer overflow in the xmlFAParsePosCharGroup function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document.
nvd
CVE-2015-1132P3CRITICALCVSS 10.0fixed in 10.10.32015-04-10
CVE-2015-1132 [CRITICAL] CVE-2015-1132: fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privilege
fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1131, CVE-2015-1133, CVE-2015-1134, and CVE-2015-1135.
nvd
CVE-2016-1801P3HIGHCVSS 7.5fixed in 10.11.52016-05-20
CVE-2016-1801 [HIGH] CWE-200 CVE-2016-1801: The CFNetwork Proxies subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS before 9.2.
The CFNetwork Proxies subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS before 9.2.1 mishandles URLs in http and https requests, which allows remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2015-3795P3CRITICALCVSS 9.3≤ 10.10.42015-08-17
CVE-2015-3795 [CRITICAL] CWE-119 CVE-2015-3795: libxpc in Apple iOS before 8.4.1 and OS X before 10.10.5 allows attackers to execute arbitrary code
libxpc in Apple iOS before 8.4.1 and OS X before 10.10.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app that sends a malformed XPC message.
nvd
CVE-2021-30677P3HIGHCVSS 8.8≥ 10.14, ≤ 10.14.5≥ 10.15, ≤ 10.15.6+2 more2021-09-08
CVE-2021-30677 [HIGH] CVE-2021-30677: This issue was addressed with improved environment sanitization. This issue is fixed in tvOS 14.6, i
This issue was addressed with improved environment sanitization. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave, macOS Big Sur 11.4, watchOS 7.5. A malicious application may be able to break out of its sandbox.
nvd