cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 44 of 157
CVE-2019-15166P3HIGHCVSS 7.5fixed in 10.15.22019-10-03
CVE-2019-15166 [HIGH] CWE-120 CVE-2019-15166: lmp_print_data_link_subobjs() in print-lmp.c in tcpdump before 4.9.3 lacks certain bounds checks. lmp_print_data_link_subobjs() in print-lmp.c in tcpdump before 4.9.3 lacks certain bounds checks.
nvd
CVE-2008-0888P3CRITICALCVSS 9.3fixed in 10.6.32008-03-17
CVE-2008-0888 [CRITICAL] CWE-119 CVE-2008-0888: The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using inval The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.
nvd
CVE-2018-14463P3HIGHCVSS 7.5fixed in 10.15.22019-10-03
CVE-2018-14463 [HIGH] CWE-125 CVE-2018-14463: The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 2, a different vulnerability than CVE-2019-15167.
nvd
CVE-2015-8126P3HIGHCVSS 7.5fixed in 10.11.42015-11-13
CVE-2015-8126 [HIGH] CWE-120 CVE-2015-8126: Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1. Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value
nvd
CVE-2015-5874P3HIGHCVSS 7.5≤ 10.10.52015-09-18
CVE-2015-5874 [HIGH] CWE-119 CVE-2015-5874: CoreText in Apple iOS before 9 and iTunes before 12.3 allows remote attackers to execute arbitrary c CoreText in Apple iOS before 9 and iTunes before 12.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file.
nvd
CVE-2020-36223P3HIGHCVSS 7.5≥ 10.14.0, < 10.14.6v10.14.62021-01-26
CVE-2020-36223 [HIGH] CWE-125 CVE-2020-36223: A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling, resulting in denial of service (double free and out-of-bounds read).
nvd
CVE-2020-36229P3HIGHCVSS 7.5≥ 10.14.0, < 10.14.6v10.14.62021-01-26
CVE-2020-36229 [HIGH] CWE-843 CVE-2020-36229: A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X. A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resulting in denial of service.
nvd
CVE-2020-36226P3HIGHCVSS 7.5≥ 10.14.0, < 10.14.6v10.14.62021-01-26
CVE-2020-36226 [HIGH] CVE-2020-36226: A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in denial of service.
nvd
CVE-2018-4354P3HIGHCVSS 8.6fixed in 10.142019-04-03
CVE-2018-4354 [HIGH] CWE-119 CVE-2018-4354: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
nvd
CVE-2018-4341P3HIGHCVSS 8.6fixed in 10.142019-04-03
CVE-2018-4341 [HIGH] CWE-119 CVE-2018-4341: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
nvd
CVE-2015-5775P3HIGHCVSS 7.5≤ 10.10.42015-08-17
CVE-2015-5775 [HIGH] CVE-2015-5775: FontParser in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbi FontParser in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-3804 and CVE-2015-5756.
nvd
CVE-2015-3804P3HIGHCVSS 7.5≤ 10.10.42015-08-17
CVE-2015-3804 [HIGH] CWE-119 CVE-2015-3804: FontParser in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbi FontParser in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-5756 and CVE-2015-5775.
nvd
CVE-2018-4242P3HIGHCVSS 7.8fixed in 10.13.52018-06-08
CVE-2018-4242 [HIGH] CWE-119 CVE-2018-4242: An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Hypervisor" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2014-4495P3CRITICALCVSS 10.0≤ 10.10.12015-01-30
CVE-2014-4495 [CRITICAL] CWE-264 CVE-2014-4495: The kernel in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not The kernel in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not enforce the read-only attribute of a shared memory segment during use of a custom cache mode, which allows attackers to bypass intended access restrictions via a crafted app.
nvd
CVE-2016-1753P3HIGHCVSS 7.8fixed in 10.11.42016-03-24
CVE-2016-1753 [HIGH] CWE-190 CVE-2016-1753: Multiple integer overflows in the kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9 Multiple integer overflows in the kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allow attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2020-9794P3HIGHCVSS 8.1fixed in 10.15.52020-06-09
CVE-2020-9794 [HIGH] CWE-125 CVE-2020-9794: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.5 a An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. A malicious application may cause a denial of service or potentially disclose memory contents.
nvd
CVE-2017-2432P3HIGHCVSS 7.8≤ 10.12.32017-04-02
CVE-2017-2432 [HIGH] CWE-119 CVE-2017-2432: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "ImageIO" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a craft
nvd
CVE-2017-2379P3HIGHCVSS 7.8≤ 10.12.32017-04-02
CVE-2017-2379 [HIGH] CWE-119 CVE-2017-2379: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Carbon" component. It allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a crafted
nvd
CVE-2015-7044P3HIGHCVSS 7.6≤ 10.11.12015-12-11
CVE-2015-7044 [HIGH] CWE-254 CVE-2015-7044: The System Integrity Protection feature in Apple OS X before 10.11.2 mishandles union mounts, which The System Integrity Protection feature in Apple OS X before 10.11.2 mishandles union mounts, which allows attackers to execute arbitrary code in a privileged context via a crafted app with root privileges.
nvd
CVE-2014-4497P3CRITICALCVSS 10.0≤ 10.9.52015-01-30
CVE-2014-4497 [CRITICAL] CWE-189 CVE-2014-4497: Integer signedness error in IOBluetoothFamily in the Bluetooth implementation in Apple OS X before 1 Integer signedness error in IOBluetoothFamily in the Bluetooth implementation in Apple OS X before 10.10 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (write to kernel memory) via a crafted app.
nvd
Apple macOS vulnerabilities | cvebase