cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 51 of 157
CVE-2018-4100P3HIGHCVSS 7.5fixed in 10.13.32018-04-03
CVE-2018-4100 [HIGH] CWE-400 CVE-2018-4100: An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13 An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. watchOS before 4.2.2 is affected. The issue involves the "LinkPresentation" component. It allows remote attackers to cause a denial of service (resource consumption) via a crafted text message.
nvd
CVE-2010-1816P3HIGHCVSS 7.8v10.6.0v10.6.1+2 more2017-04-13
CVE-2010-1816 [HIGH] CWE-119 CVE-2010-1816: Buffer overflow in ImageIO in Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10 Buffer overflow in ImageIO in Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a crafted image.
nvd
CVE-2016-4650P3HIGHCVSS 7.8fixed in 10.11.52017-04-20
CVE-2016-4650 [HIGH] CWE-119 CVE-2016-4650: Heap-based buffer overflow in IOHIDFamily in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS b Heap-based buffer overflow in IOHIDFamily in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS before 9.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2018-4343P3HIGHCVSS 7.8fixed in 10.142019-04-03
CVE-2018-4343 [HIGH] CWE-119 CVE-2018-4343: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
nvd
CVE-2018-4126P3HIGHCVSS 7.8fixed in 10.142019-04-03
CVE-2018-4126 [HIGH] CWE-119 CVE-2018-4126: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5, iTunes 12.9 for Windows, iCloud for Windows 7.7.
nvd
CVE-2016-1843P3HIGHCVSS 7.5≤ 10.11.42016-05-20
CVE-2016-1843 [HIGH] CWE-20 CVE-2016-1843: The Messages component in Apple OS X before 10.11.5 mishandles filename encoding, which allows remot The Messages component in Apple OS X before 10.11.5 mishandles filename encoding, which allows remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2016-1853P3HIGHCVSS 7.5≤ 10.11.42016-05-20
CVE-2016-1853 [HIGH] CWE-200 CVE-2016-1853: Tcl in Apple OS X before 10.11.5 allows remote attackers to obtain sensitive information by leveragi Tcl in Apple OS X before 10.11.5 allows remote attackers to obtain sensitive information by leveraging SSLv2 support.
nvd
CVE-2017-2407P3HIGHCVSS 7.8≤ 10.12.32017-04-02
CVE-2017-2407 [HIGH] CWE-119 CVE-2017-2407: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "FontParser" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a cr
nvd
CVE-2017-2435P3HIGHCVSS 7.8≤ 10.12.32017-04-02
CVE-2017-2435 [HIGH] CWE-119 CVE-2017-2435: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "CoreText" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a craf
nvd
CVE-2017-2406P3HIGHCVSS 7.8≤ 10.12.32017-04-02
CVE-2017-2406 [HIGH] CWE-119 CVE-2017-2406: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "FontParser" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a cr
nvd
CVE-2015-5903P3CRITICALCVSS 10.0≤ 10.10.52015-09-18
CVE-2015-5903 [CRITICAL] CVE-2015-5903: The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5868 and CVE-2015-5896.
nvd
CVE-2017-2487P3HIGHCVSS 7.8≤ 10.12.32017-04-02
CVE-2017-2487 [HIGH] CWE-119 CVE-2017-2487: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "FontParser" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a cr
nvd
CVE-2014-4388P3HIGHCVSS 7.8≤ 10.9.52014-09-18
CVE-2014-4388 [HIGH] CWE-20 CVE-2014-4388: IOKit in Apple iOS before 8 and Apple TV before 7 does not properly validate IODataQueue object meta IOKit in Apple iOS before 8 and Apple TV before 7 does not properly validate IODataQueue object metadata, which allows attackers to execute arbitrary code in a privileged context via an application that provides crafted values in unspecified metadata fields, a different vulnerability than CVE-2014-4418.
nvd
CVE-2016-1806P3HIGHCVSS 7.8≤ 10.11.42016-05-20
CVE-2016-1806 [HIGH] CWE-284 CVE-2016-1806: Crash Reporter in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileg Crash Reporter in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2016-1824P3HIGHCVSS 7.8fixed in 10.11.52016-05-20
CVE-2016-1824 [HIGH] CVE-2016-1824: IOHIDFamily in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2. IOHIDFamily in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1823.
nvd
CVE-2016-1750P3HIGHCVSS 7.8fixed in 10.11.42016-03-24
CVE-2016-1750 [HIGH] CWE-416 CVE-2016-1750: Use-after-free vulnerability in the kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before Use-after-free vulnerability in the kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2015-5750P3HIGHCVSS 7.5≤ 10.10.42015-08-17
CVE-2015-5750 [HIGH] CWE-119 CVE-2015-5750: Data Detectors Engine in Apple OS X before 10.10.5 allows attackers to execute arbitrary code or cau Data Detectors Engine in Apple OS X before 10.10.5 allows attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted series of Unicode characters.
nvd
CVE-2018-4196P3HIGHCVSS 7.8fixed in 10.13.52018-06-08
CVE-2018-4196 [HIGH] CWE-200 CVE-2018-4196: An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Accessibility Framework" component. It allows attackers to execute arbitrary code in a privileged context or obtain sensitive information via a crafted app.
nvd
CVE-2017-13809P3HIGHCVSS 7.8≤ 10.13.02017-11-13
CVE-2017-13809 [HIGH] CWE-20 CVE-2017-13809: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "AppleScript" component. It allows remote attackers to execute arbitrary code via a crafted AppleScript file that is mishandled by osadecompile.
nvd
CVE-2017-13858P3HIGHCVSS 7.8fixed in 10.13.22017-12-25
CVE-2017-13858 [HIGH] CWE-20 CVE-2017-13858: An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "IOKit" component. It allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
Apple macOS vulnerabilities | cvebase