cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 38 of 157
CVE-2015-3416P3HIGHCVSS 7.5≤ 10.6.82015-04-24
CVE-2015-3416 [HIGH] CWE-190 CVE-2015-3416: The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision a The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point conversions, which allows context-dependent attackers to cause a denial of service (integer overflow and stack-based buffer overflow) or possibly have unspecified other impact via large integers in a crafted printf fu
nvd
CVE-2015-8472P3HIGHCVSS 7.3≤ 10.11.32016-01-21
CVE-2015-8472 [HIGH] CVE-2015-8472: Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and 1.2.x before 1.2.55, Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and 1.2.x before 1.2.55, 1.3.x, 1.4.x before 1.4.18, 1.5.x before 1.5.25, and 1.6.x before 1.6.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG i
nvd
CVE-2008-1030P3CRITICALCVSS 10.0v10.4.11v10.5+2 more2008-06-02
CVE-2008-1030 [CRITICAL] CWE-20 CVE-2008-1030: Integer overflow in the CFDataReplaceBytes function in the CFData API in CoreFoundation in Apple Mac Integer overflow in the CFDataReplaceBytes function in the CFData API in CoreFoundation in Apple Mac OS X before 10.5.3 allows context-dependent attackers to execute arbitrary code or cause a denial of service (crash) via an invalid length argument, which triggers a heap-based buffer overflow.
nvd
CVE-2016-1775P3HIGHCVSS 7.8fixed in 10.11.42016-03-24
CVE-2016-1775 [HIGH] CWE-119 CVE-2016-1775: TrueTypeScaler in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 TrueTypeScaler in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file.
nvd
CVE-2016-1740P3HIGHCVSS 7.8fixed in 10.11.42016-03-24
CVE-2016-1740 [HIGH] CWE-119 CVE-2016-1740: FontParser in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 all FontParser in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document.
nvd
CVE-2018-4422P3HIGHCVSS 8.8fixed in 10.14.12019-04-03
CVE-2018-4422 [HIGH] CWE-119 CVE-2018-4422: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to macOS Mojave 10.14.1.
nvd
CVE-2015-6984P3HIGHCVSS 8.8≤ 10.11.02015-10-23
CVE-2015-6984 [HIGH] CWE-284 CVE-2015-6984: libarchive in Apple OS X before 10.11.1 allows attackers to write to arbitrary files via a crafted a libarchive in Apple OS X before 10.11.1 allows attackers to write to arbitrary files via a crafted app that conducts an unspecified symlink attack.
nvd
CVE-2020-36224P3HIGHCVSS 7.5≥ 10.14.0, < 10.14.6v10.14.62021-01-26
CVE-2020-36224 [HIGH] CWE-763 CVE-2020-36224: A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash i A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting in denial of service.
nvd
CVE-2020-3883P3HIGHCVSS 8.8fixed in 10.15.42020-04-01
CVE-2020-3883 [HIGH] CVE-2020-3883: This issue was addressed with improved checks. This issue is fixed in iOS 13.4 and iPadOS 13.4, macO This issue was addressed with improved checks. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. An application may be able to use arbitrary entitlements.
nvd
CVE-2007-3828P3CRITICALCVSS 10.0v10.4v10.4.1+9 more2007-07-17
CVE-2007-3828 [CRITICAL] CVE-2007-3828: Unspecified vulnerability in mDNSResponder in Apple Mac OS X allows remote attackers to execute arbi Unspecified vulnerability in mDNSResponder in Apple Mac OS X allows remote attackers to execute arbitrary code via unspecified vectors, a related issue to CVE-2007-2386.
nvd
CVE-2008-3642P3CRITICALCVSS 9.3v10.4.11v10.5.52008-10-10
CVE-2008-3642 [CRITICAL] CWE-119 CVE-2008-3642: Buffer overflow in ColorSync in Mac OS X 10.4.11 and 10.5.5 allows remote attackers to cause a denia Buffer overflow in ColorSync in Mac OS X 10.4.11 and 10.5.5 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via an image with a crafted ICC profile.
nvd
CVE-2007-0736P3CRITICALCVSS 9.3v10.3.9v10.4+9 more2007-04-24
CVE-2007-0736 [CRITICAL] CVE-2007-0736: Integer overflow in the RPC library in Libinfo in Apple Mac OS X 10.3.9 through 10.4.9 allows remote Integer overflow in the RPC library in Libinfo in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attackers to execute arbitrary code via crafted requests to portmap.
nvd
CVE-2015-6975P3HIGHCVSS 7.5≤ 10.11.02015-10-23
CVE-2015-6975 [HIGH] CWE-119 CVE-2015-6975: CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attack CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6992 and CVE-2015-7017.
nvd
CVE-2015-6992P3HIGHCVSS 7.5≤ 10.11.02015-10-23
CVE-2015-6992 [HIGH] CVE-2015-6992: CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attack CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6975 and CVE-2015-7017.
nvd
CVE-2015-7017P3HIGHCVSS 7.5≤ 10.11.02015-10-23
CVE-2015-7017 [HIGH] CVE-2015-7017: CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attack CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6975 and CVE-2015-6992.
nvd
CVE-2019-8852P3HIGHCVSS 7.8fixed in 10.15.22020-10-27
CVE-2019-8852 [HIGH] CWE-787 CVE-2019-8852: A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2021-30688P3HIGHCVSS 8.8≥ 10.15, ≤ 10.15.6v10.15.72021-09-08
CVE-2021-30688 [HIGH] CVE-2021-30688: A malicious application may be able to break out of its sandbox. This issue is fixed in macOS Big Su A malicious application may be able to break out of its sandbox. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina. A path handling issue was addressed with improved validation.
nvd
CVE-2017-2441P3HIGHCVSS 7.8≤ 10.12.32017-04-02
CVE-2017-2441 [HIGH] CWE-416 CVE-2017-2441: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "libc++abi" component. A use-after-free vulnerability allows remote attackers to execute arbitrary code via a crafted C++ app that is mishandled during dema
nvd
CVE-2015-3674P3HIGHCVSS 7.5≤ 10.10.32015-07-03
CVE-2015-3674 [HIGH] CWE-119 CVE-2015-3674: afpserver in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a afpserver in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2017-7172P3HIGHCVSS 7.8fixed in 10.13.22018-04-03
CVE-2017-7172 [HIGH] CWE-119 CVE-2017-7172: An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "CFNetwork Session" component. It allows attackers to execute arbitra
nvd
Apple macOS vulnerabilities | cvebase