cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 49 of 157
CVE-2006-4406P3HIGHCVSS 7.5v10.3v10.3.1+15 more2006-11-30
CVE-2006-4406 [HIGH] CVE-2006-4406: Buffer overflow in PPP on Apple Mac OS X 10.4.x up to 10.4.8 and 10.3.x up to 10.3.9, when PPPoE is Buffer overflow in PPP on Apple Mac OS X 10.4.x up to 10.4.8 and 10.3.x up to 10.3.9, when PPPoE is enabled, allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2020-9837P3HIGHCVSS 7.5fixed in 10.15.52020-06-09
CVE-2020-9837 [HIGH] CWE-125 CVE-2020-9837: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.5 a An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5. A remote attacker may be able to leak memory.
nvd
CVE-2022-32812P3HIGHCVSS 7.8v10.15.72022-08-24
CVE-2022-32812 [HIGH] CWE-787 CVE-2022-32812: The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.5, m The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2018-4221P3HIGHCVSS 7.5fixed in 10.13.52018-06-08
CVE-2018-4221 [HIGH] CWE-200 CVE-2018-4221: An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. The issue involves the "Security" component. It allows web sites to track users by leveraging the transmission of S/MIME client certificates.
nvd
CVE-2019-8788P3HIGHCVSS 7.5fixed in 10.15.12019-12-18
CVE-2019-8788 [HIGH] CWE-20 CVE-2019-8788: An issue existed in the parsing of URLs. This issue was addressed with improved input validation. Th An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1. Improper URL processing may lead to data exfiltration.
nvd
CVE-2020-10010P3HIGHCVSS 7.8fixed in 11.0.1≥ 10.14, < 10.14.6+3 more2020-12-08
CVE-2020-10010 [HIGH] CWE-22 CVE-2020-10010: A path handling issue was addressed with improved validation. This issue is fixed in macOS Big Sur 1 A path handling issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. A local attacker may be able to elevate their privileges.
nvd
CVE-2020-9828P3HIGHCVSS 7.5fixed in 10.15.42020-10-22
CVE-2020-9828 [HIGH] CWE-125 CVE-2020-9828: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Cat An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A remote attacker may be able to leak sensitive user information.
nvd
CVE-2019-8508P3HIGHCVSS 7.8fixed in 10.14.42019-12-18
CVE-2019-8508 [HIGH] CWE-120 CVE-2019-8508: A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Mojave 1 A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Mojave 10.14.4. Mounting a maliciously crafted NFS network share may lead to arbitrary code execution with system privileges.
nvd
CVE-2019-8635P3HIGHCVSS 7.8fixed in 10.14.52019-12-18
CVE-2019-8635 [HIGH] CWE-415 CVE-2019-8635: A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.5. An application may be able to execute arbitrary code with system privileges.
nvd
CVE-2019-8758P3HIGHCVSS 7.8fixed in 10.152019-12-18
CVE-2019-8758 [HIGH] CWE-787 CVE-2019-8758: A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15. An application may be able to execute arbitrary code with system privileges.
nvd
CVE-2019-8748P3HIGHCVSS 7.8fixed in 10.152019-12-18
CVE-2019-8748 [HIGH] CWE-787 CVE-2019-8748: A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2019-8529P3HIGHCVSS 7.8fixed in 10.14.42019-12-18
CVE-2019-8529 [HIGH] CWE-787 CVE-2019-8529: A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 1 A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2020-10003P3HIGHCVSS 7.8fixed in 11.0.12020-12-08
CVE-2020-10003 [HIGH] CWE-59 CVE-2020-10003: An issue existed within the path validation logic for symlinks. This issue was addressed with improv An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. A local attacker may be able to elevate their privileges.
nvd
CVE-2019-8616P3HIGHCVSS 7.8fixed in 10.14.52019-12-18
CVE-2019-8616 [HIGH] CWE-787 CVE-2019-8616: A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.5. An application may be able to execute arbitrary code with system privileges.
nvd
CVE-2019-8697P3HIGHCVSS 7.8fixed in 10.14.62019-12-18
CVE-2019-8697 [HIGH] CWE-787 CVE-2019-8697: A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.6. An application may be able to execute arbitrary code with system privileges.
nvd
CVE-2020-9900P3HIGHCVSS 7.8fixed in 10.15.62020-10-22
CVE-2020-9900 [HIGH] CWE-59 CVE-2020-9900: An issue existed within the path validation logic for symlinks. This issue was addressed with improv An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A local attacker may be able to elevate their privileges.
nvd
CVE-2020-9927P3HIGHCVSS 7.8fixed in 10.15.62020-10-22
CVE-2020-9927 [HIGH] CWE-787 CVE-2020-9927: A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.6. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2021-30927P3HIGHCVSS 7.8v10.15.72021-08-24
CVE-2021-30927 [HIGH] CWE-416 CVE-2021-30927: A use after free issue was addressed with improved memory management. This issue is fixed in macOS B A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2020-9901P3HIGHCVSS 7.8fixed in 10.15.62020-10-22
CVE-2020-9901 [HIGH] CWE-59 CVE-2020-9901: An issue existed within the path validation logic for symlinks. This issue was addressed with improv An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8. A local attacker may be able to elevate their privileges.
nvd
CVE-2018-4169P3CRITICALCVSS 9.8≥ 10.13.0, < 10.13.32019-01-11
CVE-2018-4169 [CRITICAL] CWE-125 CVE-2018-4169: In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 E In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, an out-of-bounds read was addressed with improved input validation.
nvd
Apple macOS vulnerabilities | cvebase