Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 33 of 157
CVE-2021-30775P3HIGHCVSS 7.8≥ 10.15, ≤ 10.15.6v10.15.72021-09-08
CVE-2021-30775 [HIGH] CWE-787 CVE-2021-30775: A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 1
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-004 Catalina. Processing a maliciously crafted audio file may lead to arbitrary code execution.
nvd
CVE-2020-9962P3HIGHCVSS 7.8≥ 10.14, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-04-02
CVE-2020-9962 [HIGH] CWE-120 CVE-2020-9962: A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Big Sur
A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.0, iOS 14.0 and iPadOS 14.0. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2022-26720P3HIGHCVSS 7.8fixed in 10.15.7v10.15.72022-05-26
CVE-2022-26720 [HIGH] CWE-787 CVE-2022-26720: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Sec
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2015-3707P3CRITICALCVSS 9.3≤ 10.10.32015-07-03
CVE-2015-3707 [CRITICAL] CVE-2015-3707: The FireWire driver in IOFireWireFamily in Apple OS X before 10.10.4 allows attackers to execute arb
The FireWire driver in IOFireWireFamily in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.
nvd
CVE-2018-4295P3CRITICALCVSS 9.8fixed in 10.142019-04-03
CVE-2018-4295 [CRITICAL] CWE-20 CVE-2018-4295: An input validation issue was addressed with improved input validation. This issue affected versions
An input validation issue was addressed with improved input validation. This issue affected versions prior to macOS Mojave 10.14.
nvd
CVE-2020-9898P3CRITICALCVSS 9.8≥ 10.13.6, < 10.15.62020-10-22
CVE-2020-9898 [CRITICAL] CVE-2020-9898: This issue was addressed with improved entitlements. This issue is fixed in iOS 13.6 and iPadOS 13.6
This issue was addressed with improved entitlements. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6. A sandboxed process may be able to circumvent sandbox restrictions.
nvd
CVE-2022-32815P3HIGHCVSS 7.8v10.15.72022-09-23
CVE-2022-32815 [HIGH] CWE-787 CVE-2022-32815: The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15
The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app with root privileges may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2022-32820P3HIGHCVSS 7.8v10.15.72022-09-23
CVE-2022-32820 [HIGH] CWE-787 CVE-2022-32820: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iO
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2018-20505P3HIGHCVSS 7.5fixed in 10.14.22019-04-03
CVE-2018-20505 [HIGH] CWE-89 CVE-2018-20505: SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers
SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers to cause a denial of service (application crash) by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases).
nvd
CVE-2017-13889P3CRITICALCVSS 9.8≥ 10.13.0, < 10.13.32019-01-11
CVE-2017-13889 [CRITICAL] CWE-287 CVE-2017-13889: In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 E
In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, a logic error existed in the validation of credentials. This was addressed with improved credential validation.
nvd
CVE-2015-1100P4MEDIUMCVSS 5.4PoC≤ 10.10.22015-04-10
CVE-2015-1100 [MEDIUM] CWE-119 CVE-2015-1100: The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attack
The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attackers to cause a denial of service (out-of-bounds memory access) or obtain sensitive memory-content information via a crafted app.
nvd
CVE-2015-3799P3CRITICALCVSS 9.3≤ 10.10.42015-08-17
CVE-2015-3799 [CRITICAL] CWE-255 CVE-2015-3799: The Apple ID OD plug-in in Apple OS X before 10.10.5 allows attackers to change arbitrary user passw
The Apple ID OD plug-in in Apple OS X before 10.10.5 allows attackers to change arbitrary user passwords via a crafted app.
nvd
CVE-2012-3716P3HIGHCVSS 7.5v10.7.0v10.7.1+3 more2012-09-20
CVE-2012-3716 [HIGH] CWE-119 CVE-2012-3716: CoreText in Apple Mac OS X 10.7.x before 10.7.5 allows remote attackers to execute arbitrary code or
CoreText in Apple Mac OS X 10.7.x before 10.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write or read) via a crafted text glyph.
nvd
CVE-2007-4709P3HIGHCVSS 8.8v10.5.12007-12-19
CVE-2007-4709 [HIGH] CWE-22 CVE-2007-4709: Directory traversal vulnerability in CFNetwork in Apple Mac OS X 10.5.1 allows remote attackers to o
Directory traversal vulnerability in CFNetwork in Apple Mac OS X 10.5.1 allows remote attackers to overwrite arbitrary files via a crafted HTTP response.
nvd
CVE-2006-2277P4MEDIUMCVSS 5.0PoCv10.4v10.4.1+5 more2006-05-10
CVE-2006-2277 [MEDIUM] CVE-2006-2277: Multiple Apple Mac OS X 10.4 applications might allow context-dependent attackers to cause a denial
Multiple Apple Mac OS X 10.4 applications might allow context-dependent attackers to cause a denial of service (application crash) via a crafted OpenEXR (.exr) image file, which triggers the crash when opening a folder using Finder, displaying the image in Safari, or using Preview to open the file.
nvd
CVE-2016-9843P3CRITICALCVSS 9.8≥ 10.0.0, < 10.13.02017-05-23
CVE-2016-9843 [CRITICAL] CVE-2016-9843: The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unsp
The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.
nvd
CVE-2004-0539P3CRITICALCVSS 10.0v10.2.8v10.3.42004-08-06
CVE-2004-0539 [CRITICAL] CVE-2004-0539: The "Show in Finder" button in the Safari web browser in Mac OS X 10.3.4 and 10.2.8 may execute down
The "Show in Finder" button in the Safari web browser in Mac OS X 10.3.4 and 10.2.8 may execute downloaded applications, which could allow remote attackers to execute arbitrary code.
nvd
CVE-2016-7582P3HIGHCVSS 8.8≤ 10.11.62017-02-20
CVE-2016-7582 [HIGH] CWE-264 CVE-2016-7582: An issue was discovered in certain Apple products. macOS before 10.12 is affected. The issue involve
An issue was discovered in certain Apple products. macOS before 10.12 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2015-3708P3HIGHCVSS 8.8≤ 10.10.32015-07-03
CVE-2015-3708 [HIGH] CVE-2015-3708: kextd in kext tools in Apple OS X before 10.10.4 allows attackers to write to arbitrary files via a
kextd in kext tools in Apple OS X before 10.10.4 allows attackers to write to arbitrary files via a crafted app that conducts a symlink attack.
nvd
CVE-2005-1689P3CRITICALCVSS 9.8fixed in 10.4.22005-07-18
CVE-2005-1689 [CRITICAL] CWE-415 CVE-2005-1689: Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier a
Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions.
nvd