Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 50 of 157
CVE-2020-3915P3HIGHCVSS 7.8fixed in 10.15.42020-10-22
CVE-2020-3915 [HIGH] CVE-2020-3915: A path handling issue was addressed with improved validation. This issue is fixed in macOS Catalina
A path handling issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be able to overwrite arbitrary files.
nvd
CVE-2021-30829P3HIGHCVSS 7.8≥ 10.15, ≤ 10.15.6v10.15.72021-10-19
CVE-2021-30829 [HIGH] CVE-2021-30829: A URI parsing issue was addressed with improved parsing. This issue is fixed in Security Update 2021
A URI parsing issue was addressed with improved parsing. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6. A local user may be able to execute arbitrary files.
nvd
CVE-2022-32910P3HIGHCVSS 7.5≥ 10.15, < 10.15.7v10.15.72022-11-01
CVE-2022-32910 [HIGH] CWE-693 CVE-2022-32910: A logic issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.8, macOS
A logic issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.8, macOS Monterey 12.5, Security Update 2022-005 Catalina. An archive may be able to bypass Gatekeeper.
nvd
CVE-2016-3142P3HIGHCVSS 8.2≤ 10.11.42016-03-31
CVE-2016-3142 [HIGH] CWE-119 CVE-2016-3142: The phar_parse_zipfile function in zip.c in the PHAR extension in PHP before 5.5.33 and 5.6.x before
The phar_parse_zipfile function in zip.c in the PHAR extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and application crash) by placing a PK\x05\x06 signature at an invalid location.
nvd
CVE-2008-1034P3CRITICALCVSS 9.3≤ 10.4v10.0+3 more2008-06-02
CVE-2008-1034 [CRITICAL] CWE-189 CVE-2008-1034: Integer underflow in Help Viewer in Apple Mac OS X before 10.5 allows remote attackers to execute ar
Integer underflow in Help Viewer in Apple Mac OS X before 10.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted help:topic URL that triggers a buffer overflow.
nvd
CVE-2009-3095P3MEDIUMCVSS 5.0fixed in 10.6.32009-09-08
CVE-2009-3095 [MEDIUM] CVE-2009-3095: The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access
The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.
nvd
CVE-2014-4434P4MEDIUMCVSS 4.9PoC≤ 10.9.52014-10-18
CVE-2014-4434 [MEDIUM] CWE-20 CVE-2014-4434: The kernel in Apple OS X before 10.10 allows physically proximate attackers to cause a denial of ser
The kernel in Apple OS X before 10.10 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted filename on an HFS filesystem.
nvd
CVE-2006-4866P4MEDIUMCVSS 4.6PoCv10.0v10.0.1+36 more2006-09-19
CVE-2006-4866 [MEDIUM] CVE-2006-4866: Buffer overflow in kextload in Apple OS X, as used by TDIXSupport in Roxio Toast Titanium and possib
Buffer overflow in kextload in Apple OS X, as used by TDIXSupport in Roxio Toast Titanium and possibly other products, allows local users to execute arbitrary code via a long extension argument.
nvd
CVE-2015-3717P3HIGHCVSS 7.5fixed in 10.10.42015-07-03
CVE-2015-3717 [HIGH] CWE-120 CVE-2015-3717: Multiple buffer overflows in the printf functionality in SQLite, as used in Apple iOS before 8.4 and
Multiple buffer overflows in the printf functionality in SQLite, as used in Apple iOS before 8.4 and OS X before 10.10.4, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2015-8865P3HIGHCVSS 7.3≤ 10.11.42016-05-20
CVE-2015-8865 [HIGH] CWE-119 CVE-2015-8865: The file_check_mem function in funcs.c in file before 5.23, as used in the Fileinfo component in PHP
The file_check_mem function in funcs.c in file before 5.23, as used in the Fileinfo component in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5, mishandles continuation-level jumps, which allows context-dependent attackers to cause a denial of service (buffer overflow and application crash) or possibly execute arbitrary code via a crafted
nvd
CVE-2020-12243P3HIGHCVSS 7.5≥ 10.13.0, < 10.13.6≥ 10.14.0, < 10.14.6+3 more2020-04-28
CVE-2020-12243 [HIGH] CWE-674 CVE-2020-12243: In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions
In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash).
nvd
CVE-2008-3621P3CRITICALCVSS 9.3v10.4.11v10.5+4 more2008-09-16
CVE-2008-3621 [CRITICAL] CWE-399 CVE-2008-3621: VideoConference in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows remote attackers to cause a
VideoConference in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via vectors involving H.264 encoded media.
nvd
CVE-2018-16451P3HIGHCVSS 7.5fixed in 10.15.22019-10-03
CVE-2018-16451 [HIGH] CWE-125 CVE-2018-16451: The SMB parser in tcpdump before 4.9.3 has buffer over-reads in print-smb.c:print_trans() for \MAILS
The SMB parser in tcpdump before 4.9.3 has buffer over-reads in print-smb.c:print_trans() for \MAILSLOT\BROWSE and \PIPE\LANMAN.
nvd
CVE-2019-6230P3HIGHCVSS 8.6fixed in 10.14.32019-03-05
CVE-2019-6230 [HIGH] CWE-665 CVE-2019-6230: A memory initialization issue was addressed with improved memory handling. This issue is fixed in iO
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3,macOS Mojave 10.14.3,tvOS 12.1.2,watchOS 5.1.3. A malicious application may be able to break out of its sandbox.
nvd
CVE-2011-3453P3HIGHCVSS 7.5≤ 10.7.2v10.7.0+1 more2012-02-02
CVE-2011-3453 [HIGH] CWE-189 CVE-2011-3453: Integer overflow in libresolv in Apple Mac OS X before 10.7.3 allows remote attackers to execute arb
Integer overflow in libresolv in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) via crafted DNS data.
nvd
CVE-2015-3773P3HIGHCVSS 7.5≤ 10.10.42015-08-16
CVE-2015-3773 [HIGH] CWE-119 CVE-2015-3773: The SMB client in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cau
The SMB client in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.
nvd
CVE-2009-0018P3HIGHCVSS 7.8v10.4.11v10.5.62009-02-13
CVE-2009-0018 [HIGH] CWE-119 CVE-2009-0018: The Remote Apple Events server in Apple Mac OS X 10.4.11 and 10.5.6 does not properly initialize a b
The Remote Apple Events server in Apple Mac OS X 10.4.11 and 10.5.6 does not properly initialize a buffer, which allows remote attackers to read portions of memory.
nvd
CVE-2016-4632P3HIGHCVSS 7.5fixed in 10.11.62016-07-22
CVE-2016-4632 [HIGH] CWE-119 CVE-2016-4632: ImageIO in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2
ImageIO in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.
nvd
CVE-2015-6978P3MEDIUMCVSS 6.8≤ 10.11.02015-10-23
CVE-2015-6978 [MEDIUM] CVE-2015-6978: FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitr
FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7008, CVE-2015-7009, CVE-2015-7010, and CVE-2015-7018.
nvd
CVE-2016-1818P3HIGHCVSS 7.8≤ 10.11.42016-05-20
CVE-2016-1818 [HIGH] CVE-2016-1818: IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS b
IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1817 and CVE-2016-1819.
nvd