cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 5 of 157
CVE-2007-2386P3CRITICALCVSS 9.4PoCv10.4v10.4.1+7 more2007-05-24
CVE-2007-2386 [CRITICAL] CVE-2007-2386: Buffer overflow in mDNSResponder in Apple Mac OS X 10.4 up to 10.4.9 allows remote attackers to caus Buffer overflow in mDNSResponder in Apple Mac OS X 10.4 up to 10.4.9 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted UPnP Internet Gateway Device (IGD) packet.
nvd
CVE-2015-3783P3HIGHCVSS 7.5PoC≤ 10.10.42015-08-16
CVE-2015-3783 [HIGH] CWE-119 CVE-2015-3783: SceneKit in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a d SceneKit in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.
nvd
CVE-2015-5784P2CRITICALCVSS 9.3PoC≤ 10.10.42015-08-17
CVE-2015-5784 [CRITICAL] CWE-264 CVE-2015-5784: runner in Install.framework in the Install Framework Legacy component in Apple OS X before 10.10.5 d runner in Install.framework in the Install Framework Legacy component in Apple OS X before 10.10.5 does not properly drop privileges, which allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2018-4243P3HIGHCVSS 7.8PoCfixed in 10.13.52018-06-08
CVE-2018-4243 [HIGH] CWE-119 CVE-2018-4243: An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "Kernel" component. A buffer overflow in getvolattrlist allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2007-6165P3CRITICALCVSS 9.3PoCv10.52007-11-29
CVE-2007-6165 [CRITICAL] CVE-2007-6165: Mail in Apple Mac OS X Leopard (10.5.1) allows user-assisted remote attackers to execute arbitrary c Mail in Apple Mac OS X Leopard (10.5.1) allows user-assisted remote attackers to execute arbitrary code via an AppleDouble attachment containing an apparently-safe file type and script in a resource fork, which does not warn the user that a separate program is going to be executed. NOTE: this is a regression error related to CVE-2006-0395.
nvd
CVE-2013-0984P2CRITICALCVSS 9.3PoC≤ 10.6.8v10.0.0+58 more2013-06-05
CVE-2013-0984 [CRITICAL] CWE-119 CVE-2013-0984: Directory Service in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code Directory Service in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted message.
nvd
CVE-2017-2527P3CRITICALCVSS 9.8PoC≤ 10.12.42017-05-22
CVE-2017-2527 [CRITICAL] CWE-119 CVE-2017-2527: An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "CoreAnimation" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory consumption and application crash) via crafted data.
nvd
CVE-2014-8147P3HIGHCVSS 7.5PoC≤ 10.10.42015-05-25
CVE-2014-8147 [HIGH] CWE-189 CVE-2014-8147: The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implemen The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 uses an integer data type that is inconsistent with a header file, which allows remote attackers to cause a denial of service (incorrect malloc followed by invalid free) or possibly
nvd
CVE-2007-5863P3CRITICALCVSS 9.3PoCv10.5.12007-12-19
CVE-2007-5863 [CRITICAL] CWE-310 CVE-2007-5863: Software Update in Apple Mac OS X 10.5.1 allows remote attackers to execute arbitrary commands via a Software Update in Apple Mac OS X 10.5.1 allows remote attackers to execute arbitrary commands via a man-in-the-middle (MITM) attack between the client and the server, using a modified distribution definition file with the "allow-external-scripts" option.
nvd
CVE-2019-6225P3HIGHCVSS 7.8PoCfixed in 10.14.32019-03-05
CVE-2019-6225 [HIGH] CWE-787 CVE-2019-6225: A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A malicious application may be able to elevate privileges.
nvd
CVE-2015-3704P2CRITICALCVSS 9.3PoC≤ 10.10.32015-07-03
CVE-2015-3704 [CRITICAL] CWE-264 CVE-2015-3704: runner in Install.framework in the Install Framework Legacy subsystem in Apple OS X before 10.10.4 d runner in Install.framework in the Install Framework Legacy subsystem in Apple OS X before 10.10.4 does not properly drop privileges, which allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2010-1119P3CRITICALCVSS 10.0PoCv10.5v10.5.0+9 more2010-03-25
CVE-2010-1119 [CRITICAL] CWE-399 CVE-2010-1119: Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Safari before 4.1 on Mac OS X 10.4, and Safari on Apple iPhone OS allows remote attackers to execute arbitrary code or cause a denial of service (application crash), or read the SMS database or other data, via vectors related to "attribute man
nvd
CVE-2015-5754P2CRITICALCVSS 9.3PoC≤ 10.10.42015-08-17
CVE-2015-5754 [CRITICAL] CWE-362 CVE-2015-5754: Race condition in runner in Install.framework in the Install Framework Legacy component in Apple OS Race condition in runner in Install.framework in the Install Framework Legacy component in Apple OS X before 10.10.5 allows attackers to execute arbitrary code in a privileged context via a crafted app that leverages incorrect privilege dropping associated with a locking error.
nvd
CVE-2014-3566P3LOWCVSS 3.4PoC≤ 10.10.12014-10-15
CVE-2014-3566 [LOW] CWE-310 CVE-2014-3566: The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CB The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.
nvd
CVE-2021-44224P2HIGHCVSS 8.2v10.15.72021-12-20
CVE-2021-44224 [HIGH] CWE-476 CVE-2021-44224: A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to
nvd
CVE-2016-1768P3HIGHCVSS 7.8PoC≤ 10.11.32016-03-24
CVE-2016-1768 [HIGH] CVE-2016-1768: QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted FlashPix image, a different vulnerability than CVE-2016-1767.
nvd
CVE-2007-0236P3CRITICALCVSS 10.0PoCv10.4.82007-01-16
CVE-2007-0236 [CRITICAL] CWE-119 CVE-2007-0236: Double free vulnerability in the _ATPsndrsp function in Apple Mac OS X 10.4.8, and possibly other ve Double free vulnerability in the _ATPsndrsp function in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to cause a denial of service (kernel panic) and possibly execute arbitrary code via a crafted AppleTalk request that triggers a heap-based buffer overflow.
nvd
CVE-2015-7112P3CRITICALCVSS 9.3PoC≤ 10.11.12015-12-11
CVE-2015-7112 [CRITICAL] CVE-2015-7112: The IOHIDFamily API in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS befor The IOHIDFamily API in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2015-7111.
nvd
CVE-2017-2370P3HIGHCVSS 7.8PoCfixed in 10.12.32017-02-20
CVE-2017-2370 [HIGH] CWE-119 CVE-2017-2370: An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS before 10.1.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (buffer overflow) via a crafted
nvd
CVE-2006-6652P3CRITICALCVSS 9.0PoCv10.0v10.0.1+39 more2006-12-20
CVE-2006-6652 [CRITICAL] CWE-119 CVE-2006-6652: Buffer overflow in the glob implementation (glob.c) in libc in NetBSD-current before 20050914, NetBS Buffer overflow in the glob implementation (glob.c) in libc in NetBSD-current before 20050914, NetBSD 2.* and 3.* before 20061203, and Apple Mac OS X before 2007-004, as used by the FTP daemon and tnftpd, allows remote authenticated users to execute arbitrary code via a long pathname that results from path expansion.
nvd
Apple macOS vulnerabilities | cvebase