Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 4 of 157
CVE-2010-0211P2CRITICALCVSS 9.8PoC≥ 10.6.0, < 10.6.52010-07-28
CVE-2010-0211 [CRITICAL] CWE-252 CVE-2010-0211: The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a ca
The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8 sequences, which triggers a free of an
nvd
CVE-2009-1955P3HIGHCVSS 7.5PoCfixed in 10.6.22009-06-08
CVE-2009-1955 [HIGH] CWE-776 CVE-2009-1955: The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as
The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFI
nvd
CVE-2019-8623P2HIGHCVSS 8.8PoCfixed in 10.14.52019-12-18
CVE-2019-8623 [HIGH] CWE-787 CVE-2019-8623: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8622P2HIGHCVSS 8.8PoCfixed in 10.14.52019-12-18
CVE-2019-8622 [HIGH] CWE-787 CVE-2019-8622: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2014-1912P2HIGHCVSS 7.5PoC≤ 10.10.42014-03-01
CVE-2014-1912 [HIGH] CWE-119 CVE-2014-1912: Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before
Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to execute arbitrary code via a crafted string.
nvd
CVE-2019-8671P2HIGHCVSS 8.8PoCfixed in 10.14.62019-12-18
CVE-2019-8671 [HIGH] CWE-787 CVE-2019-8671: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2015-4000P3LOWCVSS 3.7PoC≤ 10.10.32015-05-21
CVE-2015-4000 [LOW] CWE-310 CVE-2015-4000: The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, a
nvd
CVE-2019-8611P2HIGHCVSS 8.8PoCfixed in 10.14.52019-12-18
CVE-2019-8611 [HIGH] CWE-787 CVE-2019-8611: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2017-2524P2CRITICALCVSS 9.8PoCfixed in 10.12.52017-05-22
CVE-2017-2524 [CRITICAL] CWE-119 CVE-2017-2524: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "TextInput" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash)
nvd
CVE-2019-8662P2CRITICALCVSS 9.8PoCfixed in 10.14.62019-12-18
CVE-2019-8662 [CRITICAL] CWE-416 CVE-2019-8662: This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. An attacker may be able to trigger a use-after-free in an application deserializing an untrusted NSDictionary.
nvd
CVE-2017-2522P2CRITICALCVSS 9.8PoCfixed in 10.12.52017-05-22
CVE-2017-2522 [CRITICAL] CWE-119 CVE-2017-2522: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "CoreFoundation" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application c
nvd
CVE-2019-6224P2HIGHCVSS 8.8PoCfixed in 10.14.32019-03-05
CVE-2019-6224 [HIGH] CWE-119 CVE-2019-6224: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.1
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A remote attacker may be able to initiate a FaceTime call causing arbitrary code execution.
nvd
CVE-2016-1741P2CRITICALCVSS 9.8PoC≤ 10.11.32016-03-24
CVE-2016-1741 [CRITICAL] CWE-119 CVE-2016-1741: The NVIDIA driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to
The NVIDIA driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2018-4089P2HIGHCVSS 8.8PoCfixed in 10.13.32018-04-03
CVE-2018-4089 [HIGH] CWE-119 CVE-2018-4089: An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. Safari before 11.0.3 is affected. tvOS before 11.2.5 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a
nvd
CVE-2017-2521P2HIGHCVSS 8.8PoCfixed in 10.12.52017-05-22
CVE-2017-2521 [HIGH] CWE-119 CVE-2017-2521: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a
nvd
CVE-2014-4492P2HIGHCVSS 7.5PoC≤ 10.10.12015-01-30
CVE-2014-4492 [HIGH] CWE-19 CVE-2014-4492: libnetcore in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not
libnetcore in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not verify that certain values have the expected data type, which allows attackers to execute arbitrary code in an _networkd context via a crafted XPC message from a sandboxed app, as demonstrated by lack of verification of the XPC dictionary data type.
nvd
CVE-2018-8897P2HIGHCVSS 7.8PoCfixed in 10.13.42018-05-08
CVE-2018-8897 [HIGH] CWE-362 CVE-2018-8897: A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Develop
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-system kernels, resulting in unexpected behavior for #DB exceptions that are deferred by MOV SS or POP SS, as demonstrated by (for example) privilege escalation in Windows, macOS
nvd
CVE-2014-8835P2CRITICALCVSS 9.3PoCv10.10.0v10.10.12015-01-30
CVE-2014-8835 [CRITICAL] CWE-19 CVE-2014-8835: The xpc_data_get_bytes function in libxpc in Apple OS X before 10.10.2 does not verify that a dictio
The xpc_data_get_bytes function in libxpc in Apple OS X before 10.10.2 does not verify that a dictionary's Attributes key has the xpc_data data type, which allows attackers to execute arbitrary code by providing a crafted dictionary to sysmond, related to an "XPC type confusion" issue.
nvd
CVE-2002-0656P3HIGHCVSS 7.5PoCv10.0v10.0.1+9 more2002-08-12
CVE-2002-0656 [HIGH] CVE-2002-0656: Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers
Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a large session ID in SSL3.
nvd
CVE-2017-7047P2HIGHCVSS 8.8PoCfixed in 10.12.62017-07-20
CVE-2017-7047 [HIGH] CWE-119 CVE-2017-7047: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "libxpc" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a craft
nvd