Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 39 of 157
CVE-2020-9967P3HIGHCVSS 7.8≥ 10.14, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-04-02
CVE-2020-9967 [HIGH] CWE-787 CVE-2020-9967: Multiple memory corruption issues were addressed with improved input validation. This issue is fixed
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.0, iOS 14.0 and iPadOS 14.0. A remote attacker may be able to cause unexpected system termination or corrupt kernel memo
nvd
CVE-2007-0731P3CRITICALCVSS 9.3v10.3.9v10.4.1+7 more2007-03-13
CVE-2007-0731 [CRITICAL] CVE-2007-0731: Stack-based buffer overflow in the Apple-specific Samba module (SMB File Server) in Apple Mac OS X 1
Stack-based buffer overflow in the Apple-specific Samba module (SMB File Server) in Apple Mac OS X 10.4 through 10.4.8 allows context-dependent attackers to execute arbitrary code via a long ACL.
nvd
CVE-2010-1841P3CRITICALCVSS 9.3v10.5.8v10.6.0+4 more2010-11-15
CVE-2010-1841 [CRITICAL] CWE-20 CVE-2010-1841: Disk Images in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arb
Disk Images in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted UDIF image.
nvd
CVE-2007-4703P3CRITICALCVSS 10.0v10.52007-11-15
CVE-2007-4703 [CRITICAL] CVE-2007-4703: The Application Firewall in Apple Mac OS X 10.5 does not prevent a root process from accepting incom
The Application Firewall in Apple Mac OS X 10.5 does not prevent a root process from accepting incoming connections, even when "Block incoming connections" has been set for its associated executable, which might allow remote attackers or local root processes to bypass intended access restrictions.
nvd
CVE-2020-9973P3HIGHCVSS 7.8≥ 10.13, < 10.13.6≥ 10.14, < 10.14.6+3 more2020-10-27
CVE-2020-9973 [HIGH] CWE-125 CVE-2020-9973: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Cata
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave, iOS 14.0 and iPadOS 14.0. Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution.
nvd
CVE-2015-7038P3MEDIUMCVSS 6.8≤ 10.11.12015-12-11
CVE-2015-7038 [MEDIUM] CWE-119 CVE-2015-7038: Buffer overflow in libc in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS b
Buffer overflow in libc in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code via a crafted package, a different vulnerability than CVE-2015-7039.
nvd
CVE-2019-8803P3HIGHCVSS 8.4fixed in 10.15.12019-12-18
CVE-2019-8803 [HIGH] CWE-613 CVE-2019-8803: An authentication issue was addressed with improved state management. This issue is fixed in iOS 13.
An authentication issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. A local attacker may be able to login to the account of a previously logged in user without valid credentials..
nvd
CVE-2016-4753P3HIGHCVSS 7.8fixed in 10.12.02016-09-25
CVE-2016-4753 [HIGH] CWE-20 CVE-2016-4753: Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 mishandle signed disk i
Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 mishandle signed disk images, which allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2017-2458P3HIGHCVSS 7.8≤ 10.12.32017-04-02
CVE-2017-2458 [HIGH] CWE-119 CVE-2017-2458: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Keyboards" component. A buffer overflow allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2002-1369P3CRITICALCVSS 10.0v10.2v10.2.22002-12-26
CVE-2002-1369 [CRITICAL] CVE-2002-1369: jobs.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly use the strncat
jobs.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly use the strncat function call when processing the options string, which allows remote attackers to execute arbitrary code via a buffer overflow attack.
nvd
CVE-2017-13905P3HIGHCVSS 8.1≥ 10.11, < 10.11.6≥ 10.12, < 10.12.6+2 more2021-12-23
CVE-2017-13905 [HIGH] CWE-362 CVE-2017-13905: A race condition was addressed with additional validation. This issue is fixed in tvOS 11.2, iOS 11.
A race condition was addressed with additional validation. This issue is fixed in tvOS 11.2, iOS 11.2, macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan, watchOS 4.2. An application may be able to gain elevated privileges.
nvd
CVE-2018-4248P3HIGHCVSS 7.5fixed in 10.13.62019-04-03
CVE-2018-4248 [HIGH] CWE-125 CVE-2018-4248: An out-of-bounds read was addressed with improved input validation. This issue affected versions pri
An out-of-bounds read was addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2.
nvd
CVE-2008-3610P3HIGHCVSS 7.6v10.5v10.5.1+3 more2008-09-16
CVE-2008-3610 [HIGH] CWE-287 CVE-2008-3610: Race condition in Login Window in Apple Mac OS X 10.5 through 10.5.4, when a blank-password account
Race condition in Login Window in Apple Mac OS X 10.5 through 10.5.4, when a blank-password account is enabled, allows attackers to bypass password authentication and login to any account via multiple attempts to login to the blank-password account, followed by selection of an arbitrary account from the user list.
nvd
CVE-2019-6210P3HIGHCVSS 7.8fixed in 10.14.32019-03-05
CVE-2019-6210 [HIGH] CWE-787 CVE-2019-6210: A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 1
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2004-0803P3HIGHCVSS 7.5v10.2v10.2.1+14 more2004-12-23
CVE-2004-0803 [HIGH] CVE-2004-0803: Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, re
Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer overflows, allow remote attackers to execute arbitrary code via TIFF files.
nvd
CVE-2022-22593P3HIGHCVSS 7.8fixed in 10.15.7v10.15.72022-03-18
CVE-2022-22593 [HIGH] CWE-120 CVE-2022-22593: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 15.3
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Security Update 2022-001 Catalina, macOS Monterey 12.2, macOS Big Sur 11.6.3. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2020-9892P3HIGHCVSS 7.8≥ 10.13.6, < 10.15.62020-10-22
CVE-2020-9892 [HIGH] CWE-787 CVE-2020-9892: Multiple memory corruption issues were addressed with improved state management. This issue is fixed
Multiple memory corruption issues were addressed with improved state management. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A malicious application may be able to execute arbitrary code with system privileges.
nvd
CVE-2020-3919P3HIGHCVSS 7.8fixed in 10.15.42020-04-01
CVE-2020-3919 [HIGH] CWE-665 CVE-2020-3919: A memory initialization issue was addressed with improved memory handling. This issue is fixed in iO
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2020-9954P3HIGHCVSS 7.8fixed in 10.15.72020-12-08
CVE-2020-9954 [HIGH] CWE-120 CVE-2020-9954: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in watchOS
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in watchOS 7.0, tvOS 14.0, macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave, iOS 14.0 and iPadOS 14.0. Playing a malicious audio file may lead to arbitrary code execution.
nvd
CVE-2020-3880P3HIGHCVSS 7.8fixed in 10.15.32020-10-27
CVE-2020-3880 [HIGH] CWE-125 CVE-2020-3880: An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 6
An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 6.1.2, iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, macOS Catalina 10.15.3, Security Update 2020-001 Mojave, Security Update 2020-001 High Sierra. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd