Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
277
Exploited in wild
28
Severity breakdown
CRITICAL302HIGH1409MEDIUM1236LOW192

Vulnerabilities

Page 46 of 157
CVE-2018-14462HIGHCVSS 7.5fixed in 10.15.22019-10-03
CVE-2018-14462 [HIGH] CWE-125 CVE-2018-14462: The ICMP parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp.c:icmp_print(). The ICMP parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp.c:icmp_print().
nvd
CVE-2019-15165MEDIUMCVSS 5.3≥ 10.13, < 10.13.6v10.13.6+2 more2019-10-03
CVE-2019-15165 [MEDIUM] CWE-770 CVE-2019-15165: sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocati sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.
nvd
CVE-2019-9506HIGHCVSS 8.1v10.12.6v10.13.6+1 more2019-08-14
CVE-2019-9506 [HIGH] CWE-310 CVE-2019-9506: The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encrypti The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.
nvd
CVE-2019-11041HIGHCVSS 7.1fixed in 10.15.12019-08-09
CVE-2019-11041 [HIGH] CWE-125 CVE-2019-11041: When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() functio When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
nvd
CVE-2019-11042HIGHCVSS 7.1fixed in 10.15.12019-08-09
CVE-2019-11042 [HIGH] CWE-125 CVE-2019-11042: When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() functio When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
nvd
CVE-2019-13565HIGHCVSS 7.5≥ 10.13, < 10.13.6≥ 10.14, < 10.14.6+3 more2019-07-26
CVE-2019-13565 [HIGH] CVE-2019-13565: An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session en An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session encryption, and relying on the SASL security layers in slapd access controls, it is possible to obtain access that would otherwise be denied via a simple bind for any identity covered in those ACLs. After the first SASL bind is completed, the sasl_ssf value is re
nvd
CVE-2019-13057MEDIUMCVSS 4.9≥ 10.13, < 10.13.6≥ 10.14, < 10.14.6+3 more2019-07-26
CVE-2019-13057 [MEDIUM] CVE-2019-13057: An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator deleg An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or
nvd
CVE-2019-13118MEDIUMCVSS 5.3v10.12.6v10.13.62019-07-01
CVE-2019-13118 [MEDIUM] CWE-843 CVE-2019-13118: In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.
nvd
CVE-2018-4288CRITICALCVSS 9.8fixed in 10.13.62019-04-03
CVE-2018-4288 [CRITICAL] CWE-119 CVE-2018-4288: Multiple memory corruption issues were addressed with improved memory handling. This issue affected Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to macOS High Sierra 10.13.6.
nvd
CVE-2018-4353CRITICALCVSS 9.8fixed in 10.142019-04-03
CVE-2018-4353 [CRITICAL] CWE-20 CVE-2018-4353: A configuration issue was addressed with additional restrictions. This issue affected versions prior A configuration issue was addressed with additional restrictions. This issue affected versions prior to macOS Mojave 10.14.
nvd
CVE-2018-4291CRITICALCVSS 9.8fixed in 10.13.62019-04-03
CVE-2018-4291 [CRITICAL] CWE-119 CVE-2018-4291: Multiple memory corruption issues were addressed with improved memory handling. This issue affected Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to macOS High Sierra 10.13.6.
nvd
CVE-2018-4332CRITICALCVSS 9.8fixed in 10.142019-04-03
CVE-2018-4332 [CRITICAL] CWE-119 CVE-2018-4332: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
nvd
CVE-2018-4310CRITICALCVSS 10.0fixed in 10.142019-04-03
CVE-2018-4310 [CRITICAL] CWE-269 CVE-2018-4310: An access issue was addressed with additional sandbox restrictions. This issue affected versions pri An access issue was addressed with additional sandbox restrictions. This issue affected versions prior to iOS 12, macOS Mojave 10.14.
nvd
CVE-2018-4286CRITICALCVSS 9.8fixed in 10.13.62019-04-03
CVE-2018-4286 [CRITICAL] CWE-119 CVE-2018-4286: Multiple memory corruption issues were addressed with improved memory handling. This issue affected Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to macOS High Sierra 10.13.6.
nvd
CVE-2018-4259CRITICALCVSS 9.8fixed in 10.13.62019-04-03
CVE-2018-4259 [CRITICAL] CWE-119 CVE-2018-4259: Multiple memory corruption issues were addressed with improved memory handling. This issue affected Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to macOS High Sierra 10.13.6.
nvd
CVE-2018-4295CRITICALCVSS 9.8fixed in 10.142019-04-03
CVE-2018-4295 [CRITICAL] CWE-20 CVE-2018-4295: An input validation issue was addressed with improved input validation. This issue affected versions An input validation issue was addressed with improved input validation. This issue affected versions prior to macOS Mojave 10.14.
nvd
CVE-2018-4287CRITICALCVSS 9.8fixed in 10.13.62019-04-03
CVE-2018-4287 [CRITICAL] CWE-119 CVE-2018-4287: Multiple memory corruption issues were addressed with improved memory handling. This issue affected Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to macOS High Sierra 10.13.6.
nvd
CVE-2018-4331CRITICALCVSS 9.8fixed in 10.142019-04-03
CVE-2018-4331 [CRITICAL] CWE-119 CVE-2018-4331: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
nvd
CVE-2018-4268CRITICALCVSS 9.8fixed in 10.13.62019-04-03
CVE-2018-4268 [CRITICAL] CWE-119 CVE-2018-4268: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to macOS High Sierra 10.13.6.
nvd
CVE-2018-4411HIGHCVSS 7.8fixed in 10.142019-04-03
CVE-2018-4411 [HIGH] CWE-119 CVE-2018-4411: A memory corruption issue was addressed with improved input validation. This issue affected versions A memory corruption issue was addressed with improved input validation. This issue affected versions prior to macOS Mojave 10.14.
nvd