cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 41 of 157
CVE-2020-9890P3HIGHCVSS 7.8fixed in 10.15.62020-10-16
CVE-2020-9890 [HIGH] CWE-125 CVE-2020-9890: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.6 a An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. Processing a maliciously crafted audio file may lead to arbitrary code execution.
nvd
CVE-2020-9799P3HIGHCVSS 7.8fixed in 10.15.62020-10-16
CVE-2020-9799 [HIGH] CWE-125 CVE-2020-9799: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Cata An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.6. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2020-9891P3HIGHCVSS 7.8fixed in 10.15.62020-10-16
CVE-2020-9891 [HIGH] CWE-125 CVE-2020-9891: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.6 a An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. Processing a maliciously crafted audio file may lead to arbitrary code execution.
nvd
CVE-2020-9822P3HIGHCVSS 7.8fixed in 10.15.52020-06-09
CVE-2020-9822 [HIGH] CWE-787 CVE-2020-9822: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in mac An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.5. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2016-1762P3HIGHCVSS 8.1fixed in 10.11.42016-03-24
CVE-2016-1762 [HIGH] CWE-119 CVE-2016-1762: The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of servic The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
nvd
CVE-2020-9888P3HIGHCVSS 7.8fixed in 10.15.62020-10-16
CVE-2020-9888 [HIGH] CWE-125 CVE-2020-9888: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.6 a An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. Processing a maliciously crafted audio file may lead to arbitrary code execution.
nvd
CVE-2006-6061P3CRITICALCVSS 9.3v10.4.82006-11-22
CVE-2006-6061 [CRITICAL] CVE-2006-6061: com.apple.AppleDiskImageController in Apple Mac OS X 10.4.8, and possibly other versions, allows rem com.apple.AppleDiskImageController in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to execute arbitrary code via a malformed DMG image that triggers memory corruption. NOTE: the severity of this issue has been disputed by a third party, who states that the impact is limited to a denial of service (kernel panic) due to a vm_fau
nvd
CVE-2020-3826P3HIGHCVSS 7.8fixed in 10.15.32020-02-27
CVE-2020-3826 [HIGH] CWE-125 CVE-2020-3826: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.3. An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2021-30693P3HIGHCVSS 7.8≥ 10.14, ≤ 10.14.5≥ 10.15, ≤ 10.15.6+2 more2021-09-08
CVE-2021-30693 [HIGH] CWE-20 CVE-2021-30693: A validation issue was addressed with improved logic. This issue is fixed in macOS Big Sur 11.4, Sec A validation issue was addressed with improved logic. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2021-30859P3HIGHCVSS 7.8fixed in 10.15.7v10.15.72021-08-24
CVE-2021-30859 [HIGH] CWE-843 CVE-2021-30859: A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.8 a A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2021-30701P3HIGHCVSS 7.8≥ 10.15, ≤ 10.15.6v10.15.72021-09-08
CVE-2021-30701 [HIGH] CVE-2021-30701: This issue was addressed with improved checks. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS This issue was addressed with improved checks. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2021-30901P3HIGHCVSS 7.8fixed in 10.15.7v10.15.72021-08-24
CVE-2021-30901 [HIGH] CWE-787 CVE-2021-30901: Multiple out-of-bounds write issues were addressed with improved bounds checking. This issue is fixe Multiple out-of-bounds write issues were addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.0.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2020-27908P3HIGHCVSS 7.8fixed in 11.0.1fixed in 11.1.02021-04-02
CVE-2020-27908 [HIGH] CWE-125 CVE-2020-27908: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, watchOS 7.1, tvOS 14.2. Processing a maliciously crafted audio file may lead to arbitrary code execution.
nvd
CVE-2020-9975P3HIGHCVSS 7.8≥ 10.14, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-04-02
CVE-2020-9975 [HIGH] CWE-416 CVE-2020-9975: A use after free issue was addressed with improved memory management. This issue is fixed in macOS B A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.0, iOS 14.0 and iPadOS 14.0. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2021-1743P3HIGHCVSS 7.8≥ 10.14, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-04-02
CVE-2021-1743 [HIGH] CWE-125 CVE-2021-1743: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2022-26714P3HIGHCVSS 7.8fixed in 10.15.7v10.15.72022-05-26
CVE-2022-26714 [HIGH] CWE-787 CVE-2022-26714: A memory corruption issue was addressed with improved validation. This issue is fixed in tvOS 15.5, A memory corruption issue was addressed with improved validation. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 Catalina, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2019-8706P3HIGHCVSS 7.8fixed in 10.152020-10-27
CVE-2019-8706 [HIGH] CWE-787 CVE-2019-8706: A memory corruption issue was addressed with improved state management. This issue is fixed in macOS A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15, iOS 13.1 and iPadOS 13.1, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, watchOS 6. Processing a maliciously crafted audio file may lead to arbitrary code execution.
nvd
CVE-2020-9956P3HIGHCVSS 7.8≥ 10.14, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-04-02
CVE-2020-9956 [HIGH] CWE-125 CVE-2020-9956: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.0, iOS 14.0 and iPadOS 14.0. Processing a maliciously crafted font file may lead to arbitrary code execution.
nvd
CVE-2020-27924P3HIGHCVSS 7.8fixed in 11.1.0fixed in 11.0.12021-04-02
CVE-2020-27924 [HIGH] CWE-125 CVE-2020-27924: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, watchOS 7.1, tvOS 14.2. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2021-1776P3HIGHCVSS 7.8≥ 10.14, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-04-02
CVE-2021-1776 [HIGH] CWE-787 CVE-2021-1776: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in mac An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted font file may lead to arbitrary code execution.
nvd
Apple macOS vulnerabilities | cvebase