Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 37 of 157
CVE-2020-27931P3HIGHCVSS 7.8fixed in 11.1.0fixed in 11.0.12021-04-02
CVE-2020-27931 [HIGH] CWE-787 CVE-2020-27931: A memory corruption issue existed in the processing of font files. This issue was addressed with imp
A memory corruption issue existed in the processing of font files. This issue was addressed with improved input validation. This issue is fixed in iOS 14.0 and iPadOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1, watchOS 7.0, tvOS 14.0. Processing a maliciously crafted font file may
nvd
CVE-2022-26756P3HIGHCVSS 7.8fixed in 10.15.7v10.15.72022-05-26
CVE-2022-26756 [HIGH] CWE-787 CVE-2022-26756: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Se
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2019-8561P3HIGHCVSS 7.8fixed in 10.14.42019-12-18
CVE-2019-8561 [HIGH] CWE-20 CVE-2019-8561: A logic issue was addressed with improved validation. This issue is fixed in macOS Mojave 10.14.4. A
A logic issue was addressed with improved validation. This issue is fixed in macOS Mojave 10.14.4. A malicious application may be able to elevate privileges.
nvd
CVE-2015-5757P3CRITICALCVSS 9.3≤ 10.10.42015-08-17
CVE-2015-5757 [CRITICAL] CWE-119 CVE-2015-5757: libpthread in Apple iOS before 8.4.1 and OS X before 10.10.5 allows attackers to execute arbitrary c
libpthread in Apple iOS before 8.4.1 and OS X before 10.10.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via an app that uses a crafted syscall to interfere with locking.
nvd
CVE-2019-20044P3HIGHCVSS 7.8fixed in 10.15.5≥ 10.13.0, < 10.13.6+4 more2020-02-24
CVE-2019-20044 [HIGH] CWE-273 CVE-2019-20044: In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIV
In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option. Zsh fails to overwrite the saved uid, so the original privileges can be restored by executing MODULE_PATH=/dir/with/module zmodload with a module that calls setuid().
nvd
CVE-2010-1377P3CRITICALCVSS 9.3v10.6.0v10.6.1+2 more2010-06-17
CVE-2010-1377 [CRITICAL] CWE-310 CVE-2010-1377: Open Directory in Apple Mac OS X 10.6 before 10.6.4 creates an unencrypted connection upon certain S
Open Directory in Apple Mac OS X 10.6 before 10.6.4 creates an unencrypted connection upon certain SSL failures, which allows man-in-the-middle attackers to spoof arbitrary network account servers, and possibly execute arbitrary code, via unspecified vectors.
nvd
CVE-2015-5866P3CRITICALCVSS 9.3≤ 10.10.52015-10-09
CVE-2015-5866 [CRITICAL] CWE-119 CVE-2015-5866: IOHIDFamily in Apple OS X before 10.11 allows attackers to execute arbitrary code in a privileged co
IOHIDFamily in Apple OS X before 10.11 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2021-30704P3HIGHCVSS 7.8≥ 10.14, ≤ 10.14.5≥ 10.15, ≤ 10.15.6+2 more2021-09-08
CVE-2021-30704 [HIGH] CVE-2021-30704: A logic issue was addressed with improved state management. This issue is fixed in tvOS 14.6, Securi
A logic issue was addressed with improved state management. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2021-30703P3HIGHCVSS 7.8≥ 10.14, ≤ 10.14.5≥ 10.15, ≤ 10.15.6+2 more2021-09-08
CVE-2021-30703 [HIGH] CWE-415 CVE-2021-30703: A double free issue was addressed with improved memory management. This issue is fixed in tvOS 14.6,
A double free issue was addressed with improved memory management. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave, macOS Big Sur 11.4, watchOS 7.5. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2022-22631P3HIGHCVSS 7.8≥ 10.15, < 10.15.7v10.15.72022-03-18
CVE-2022-22631 [HIGH] CWE-787 CVE-2022-22631: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in mac
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. An application may be able to gain elevated privileges.
nvd
CVE-2020-29622P3HIGHCVSS 7.5≥ 10.15, ≤ 10.15.6v10.15.72021-10-19
CVE-2020-29622 [HIGH] CWE-362 CVE-2020-29622: A race condition was addressed with additional validation. This issue is fixed in Security Update 20
A race condition was addressed with additional validation. This issue is fixed in Security Update 2021-005 Catalina. Mounting a maliciously crafted NFS network share may lead to arbitrary code execution with system privileges.
nvd
CVE-2018-4254P3CRITICALCVSS 9.8fixed in 10.13.52019-01-11
CVE-2018-4254 [CRITICAL] CWE-20 CVE-2018-4254: In macOS High Sierra before 10.13.5, an input validation issue existed in the kernel. This issue was
In macOS High Sierra before 10.13.5, an input validation issue existed in the kernel. This issue was addressed with improved input validation.
nvd
CVE-2015-5783P3CRITICALCVSS 9.3≤ 10.10.42015-08-17
CVE-2015-5783 [CRITICAL] CVE-2015-5783: IOGraphics in Apple OS X before 10.10.5 allows attackers to execute arbitrary code or cause a denial
IOGraphics in Apple OS X before 10.10.5 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2015-3770.
nvd
CVE-2015-3770P3CRITICALCVSS 9.3≤ 10.10.42015-08-16
CVE-2015-3770 [CRITICAL] CWE-119 CVE-2015-3770: IOGraphics in Apple OS X before 10.10.5 allows attackers to execute arbitrary code or cause a denial
IOGraphics in Apple OS X before 10.10.5 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2015-5783.
nvd
CVE-2015-3706P3CRITICALCVSS 9.3≤ 10.10.32015-07-03
CVE-2015-3706 [CRITICAL] CVE-2015-3706: IOAcceleratorFamily in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a pri
IOAcceleratorFamily in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2015-3705.
nvd
CVE-2015-3705P3CRITICALCVSS 9.3≤ 10.10.32015-07-03
CVE-2015-3705 [CRITICAL] CWE-119 CVE-2015-3705: IOAcceleratorFamily in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a pri
IOAcceleratorFamily in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2015-3706.
nvd
CVE-2015-7109P3CRITICALCVSS 9.3≤ 10.11.12015-12-11
CVE-2015-7109 [CRITICAL] CWE-119 CVE-2015-7109: IOAcceleratorFamily in Apple OS X before 10.11.2 and tvOS before 9.1 allows attackers to execute arb
IOAcceleratorFamily in Apple OS X before 10.11.2 and tvOS before 9.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2019-8767P3CRITICALCVSS 9.8fixed in 10.152020-10-27
CVE-2019-8767 [CRITICAL] CWE-787 CVE-2019-8767: A memory consumption issue was addressed with improved memory handling. This issue is fixed in macOS
A memory consumption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, macOS Catalina 10.15. Processing a maliciously crafted string may lead to heap corruption.
nvd
CVE-2018-16227P3HIGHCVSS 7.5fixed in 10.15.22019-10-03
CVE-2018-16227 [HIGH] CWE-125 CVE-2018-16227: The IEEE 802.11 parser in tcpdump before 4.9.3 has a buffer over-read in print-802_11.c for the Mesh
The IEEE 802.11 parser in tcpdump before 4.9.3 has a buffer over-read in print-802_11.c for the Mesh Flags subfield.
nvd
CVE-2015-3148P3MEDIUMCVSS 5.0v10.10.0v10.10.1+3 more2015-04-24
CVE-2015-3148 [MEDIUM] CWE-284 CVE-2015-3148: cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, w
cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request.
nvd