Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 52 of 157
CVE-2017-13848P3HIGHCVSS 7.8fixed in 10.13.22017-12-25
CVE-2017-13848 [HIGH] CWE-20 CVE-2017-13848: An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "IOKit" component. It allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2017-2401P3HIGHCVSS 7.8≤ 10.12.32017-04-02
CVE-2017-2401 [HIGH] CWE-119 CVE-2017-2401: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app
nvd
CVE-2020-3854P3HIGHCVSS 7.8fixed in 10.15.32020-02-27
CVE-2020-3854 [HIGH] CWE-787 CVE-2020-3854: A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.3. An application may be able to execute arbitrary code with system privileges.
nvd
CVE-2019-8590P3HIGHCVSS 7.8fixed in 10.14.52019-12-18
CVE-2019-8590 [HIGH] CVE-2019-8590: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Mojave 10.14.5.
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Mojave 10.14.5. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2017-7009P3HIGHCVSS 7.8≤ 10.12.52017-07-20
CVE-2017-7009 [HIGH] CWE-119 CVE-2017-7009: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "IOUSBFamily" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a
nvd
CVE-2017-7026P3HIGHCVSS 7.8≤ 10.12.52017-07-20
CVE-2017-7026 [HIGH] CWE-119 CVE-2017-7026: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a craft
nvd
CVE-2017-7027P3HIGHCVSS 7.8≤ 10.12.52017-07-20
CVE-2017-7027 [HIGH] CWE-119 CVE-2017-7027: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a craft
nvd
CVE-2020-3892P3HIGHCVSS 7.8fixed in 10.15.42020-04-01
CVE-2020-3892 [HIGH] CWE-20 CVE-2020-3892: A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2020-3905P3HIGHCVSS 7.8fixed in 10.15.42020-04-01
CVE-2020-3905 [HIGH] CWE-20 CVE-2020-3905: A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2020-3893P3HIGHCVSS 7.8fixed in 10.15.42020-04-01
CVE-2020-3893 [HIGH] CWE-20 CVE-2020-3893: A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2020-3903P3HIGHCVSS 7.8fixed in 10.15.42020-04-01
CVE-2020-3903 [HIGH] CWE-787 CVE-2020-3903: A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.4. An application may be able to execute arbitrary code with system privileges.
nvd
CVE-2016-4698P3HIGHCVSS 7.8≤ 10.11.62016-09-25
CVE-2016-4698 [HIGH] CWE-20 CVE-2016-4698: AppleMobileFileIntegrity in Apple iOS before 10 and OS X before 10.12 mishandles process entitlement
AppleMobileFileIntegrity in Apple iOS before 10 and OS X before 10.12 mishandles process entitlement and Team ID values in the task port inheritance policy, which allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2019-8847P3HIGHCVSS 7.8fixed in 10.15.22020-10-27
CVE-2019-8847 [HIGH] CWE-787 CVE-2019-8847: A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2019-8824P3HIGHCVSS 7.8fixed in 10.15.12020-10-27
CVE-2019-8824 [HIGH] CWE-787 CVE-2019-8824: A memory corruption issue was addressed with improved state management. This issue is fixed in macOS
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2017-7162P3HIGHCVSS 7.8fixed in 10.13.22017-12-27
CVE-2017-7162 [HIGH] CWE-119 CVE-2017-7162: An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "IOKit" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2019-8776P3HIGHCVSS 7.8fixed in 10.152020-10-27
CVE-2019-8776 [HIGH] CWE-787 CVE-2019-8776: A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15. An application may be able to execute arbitrary code with system privileges.
nvd
CVE-2020-3871P3HIGHCVSS 7.8fixed in 10.15.32020-02-27
CVE-2020-3871 [HIGH] CWE-787 CVE-2020-3871: A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.3. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2020-3845P3HIGHCVSS 7.8fixed in 10.15.32020-02-27
CVE-2020-3845 [HIGH] CWE-787 CVE-2020-3845: A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.3. An application may be able to execute arbitrary code with system privileges.
nvd
CVE-2017-7069P3HIGHCVSS 7.8≤ 10.12.52017-07-20
CVE-2017-7069 [HIGH] CWE-119 CVE-2017-7069: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a craft
nvd
CVE-2015-7053P3MEDIUMCVSS 6.8≤ 10.11.12015-12-11
CVE-2015-7053 [MEDIUM] CWE-119 CVE-2015-7053: ImageIO in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows
ImageIO in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted image.
nvd