Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
277
Exploited in wild
28
Severity breakdown
CRITICAL302HIGH1409MEDIUM1236LOW192

Vulnerabilities

Page 34 of 157
CVE-2020-9809MEDIUMCVSS 5.5fixed in 10.15.52020-06-09
CVE-2020-9809 [MEDIUM] CVE-2020-9809: An information disclosure issue was addressed with improved state management. This issue is fixed in An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A malicious application may be able to determine kernel memory layout.
nvd
CVE-2020-9792MEDIUMCVSS 4.6fixed in 10.15.52020-06-09
CVE-2020-9792 [MEDIUM] CWE-20 CVE-2020-9792: A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.5 a A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5. A USB device may be able to cause a denial of service.
nvd
CVE-2020-9856MEDIUMCVSS 5.3PoC≥ 10.13, < 10.13.6≥ 10.14, < 10.14.6+3 more2020-06-09
CVE-2020-9856 [MEDIUM] CVE-2020-9856: This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.5. An app This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.5. An application may be able to gain elevated privileges.
nvd
CVE-2020-9833MEDIUMCVSS 5.5fixed in 10.15.52020-06-09
CVE-2020-9833 [MEDIUM] CWE-665 CVE-2020-9833: A memory initialization issue was addressed with improved memory handling. This issue is fixed in ma A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.5. A local user may be able to read kernel memory.
nvd
CVE-2020-9831MEDIUMCVSS 5.5fixed in 10.15.52020-06-09
CVE-2020-9831 [MEDIUM] CWE-125 CVE-2020-9831: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Cata An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.5. A malicious application may be able to determine kernel memory layout.
nvd
CVE-2020-9811MEDIUMCVSS 5.5fixed in 10.15.52020-06-09
CVE-2020-9811 [MEDIUM] CVE-2020-9811: An information disclosure issue was addressed with improved state management. This issue is fixed in An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A local user may be able to read kernel memory.
nvd
CVE-2020-9859HIGHCVSS 7.8KEVfixed in 10.15.52020-06-05
CVE-2020-9859 [HIGH] CWE-415 CVE-2020-9859: A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 1 A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5 Supplemental Update, tvOS 13.4.6, watchOS 6.2.6. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2019-20807MEDIUMCVSS 5.3v10.13.6v10.14.62020-05-28
CVE-2019-20807 [MEDIUM] CWE-78 CVE-2019-20807: In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS comma In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua).
nvd
CVE-2020-6616MEDIUMCVSS 6.5≥ 10.13.0, < 10.13.6≥ 10.14.0, < 10.14.6+3 more2020-05-08
CVE-2020-6616 [MEDIUM] CVE-2020-6616: Some Broadcom chips mishandle Bluetooth random-number generation because a low-entropy Pseudo Random Some Broadcom chips mishandle Bluetooth random-number generation because a low-entropy Pseudo Random Number Generator (PRNG) is used in situations where a Hardware Random Number Generator (HRNG) should have been used to prevent spoofing. This affects, for example, Samsung Galaxy S8, S8+, and Note8 devices with the BCM4361 chipset. The Samsung ID is SVE-2020-1
nvd
CVE-2020-12243HIGHCVSS 7.5≥ 10.13.0, < 10.13.6≥ 10.14.0, < 10.14.6+3 more2020-04-28
CVE-2020-12243 [HIGH] CWE-674 CVE-2020-12243: In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash).
nvd
CVE-2019-6203CRITICALCVSS 9.8fixed in 10.14.42020-04-17
CVE-2019-6203 [CRITICAL] CVE-2019-6203: A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS M A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2. An attacker in a privileged network position may be able to intercept network traffic.
nvd
CVE-2020-11762MEDIUMCVSS 5.5fixed in 10.15.6≥ 10.13.0, < 10.13.6+3 more2020-04-14
CVE-2020-11762 [MEDIUM] CWE-125 CVE-2020-11762: An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read and write in DwaComp An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read and write in DwaCompressor::uncompress in ImfDwaCompressor.cpp when handling the UNKNOWN compression case.
nvd
CVE-2020-11758MEDIUMCVSS 5.5fixed in 10.15.6≥ 10.13.0, < 10.13.6+3 more2020-04-14
CVE-2020-11758 [MEDIUM] CWE-125 CVE-2020-11758: An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read in ImfOptimizedPixel An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read in ImfOptimizedPixelReading.h.
nvd
CVE-2020-11760MEDIUMCVSS 5.5fixed in 10.15.6≥ 10.13.0, < 10.13.6+3 more2020-04-14
CVE-2020-11760 [MEDIUM] CWE-125 CVE-2020-11760: An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompres An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompression in rleUncompress in ImfRle.cpp.
nvd
CVE-2020-11764MEDIUMCVSS 5.5≥ 10.13.0, < 10.13.6≥ 10.14.0, < 10.14.6+3 more2020-04-14
CVE-2020-11764 [MEDIUM] CWE-787 CVE-2020-11764: An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuf An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuffer in ImfMisc.cpp.
nvd
CVE-2020-11761MEDIUMCVSS 5.5fixed in 10.15.6≥ 10.13.0, < 10.13.6+3 more2020-04-14
CVE-2020-11761 [MEDIUM] CWE-125 CVE-2020-11761: An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncom An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncompression, as demonstrated by FastHufDecoder::refill in ImfFastHuf.cpp.
nvd
CVE-2020-11763MEDIUMCVSS 5.5≥ 10.13.0, < 10.13.6≥ 10.14.0, < 10.14.6+3 more2020-04-14
CVE-2020-11763 [MEDIUM] CWE-125 CVE-2020-11763: An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and writ An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and write, as demonstrated by ImfTileOffsets.cpp.
nvd
CVE-2020-11759MEDIUMCVSS 5.5≥ 10.13.0, < 10.13.6≥ 10.14.0, < 10.14.6+3 more2020-04-14
CVE-2020-11759 [MEDIUM] CWE-190 CVE-2020-11759: An issue was discovered in OpenEXR before 2.4.1. Because of integer overflows in CompositeDeepScanLi An issue was discovered in OpenEXR before 2.4.1. Because of integer overflows in CompositeDeepScanLine::Data::handleDeepFrameBuffer and readSampleCountForLineBlock, an attacker can write to an out-of-bounds pointer.
nvd
CVE-2020-11765MEDIUMCVSS 5.5≥ 10.13.0, < 10.13.6≥ 10.14.0, < 10.14.6+3 more2020-04-14
CVE-2020-11765 [MEDIUM] CWE-125 CVE-2020-11765: An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier, leading to an out-of-bounds read.
nvd
CVE-2019-14868HIGHCVSS 7.8fixed in 10.15.52020-04-02
CVE-2019-14868 [HIGH] CWE-77 CVE-2019-14868: In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and applications that allow remote unauthenticated attackers to provide one of those environment variables could allow them to exploit this iss
nvd