cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 56 of 157
CVE-2018-16229P3HIGHCVSS 7.5fixed in 10.15.22019-10-03
CVE-2018-16229 [HIGH] CWE-125 CVE-2018-16229: The DCCP parser in tcpdump before 4.9.3 has a buffer over-read in print-dccp.c:dccp_print_option(). The DCCP parser in tcpdump before 4.9.3 has a buffer over-read in print-dccp.c:dccp_print_option().
nvd
CVE-2007-4702P3CRITICALCVSS 9.3v10.52007-11-15
CVE-2007-4702 [CRITICAL] CVE-2007-4702: The Application Firewall in Apple Mac OS X 10.5, when "Block all incoming connections" is enabled, d The Application Firewall in Apple Mac OS X 10.5, when "Block all incoming connections" is enabled, does not prevent root processes or mDNSResponder from accepting connections, which might allow remote attackers or local root processes to bypass intended access restrictions.
nvd
CVE-2015-1157P3HIGHCVSS 7.8≤ 10.0.32015-05-28
CVE-2015-1157 [HIGH] CWE-17 CVE-2015-1157: CoreText in Apple iOS 8.x through 8.3 allows remote attackers to cause a denial of service (reboot a CoreText in Apple iOS 8.x through 8.3 allows remote attackers to cause a denial of service (reboot and messaging disruption) via crafted Unicode text that is not properly handled during display truncation in the Notifications feature, as demonstrated by Arabic characters in (1) an SMS message or (2) a WhatsApp message.
nvd
CVE-2007-5850P3HIGHCVSS 8.8v10.4.112007-12-19
CVE-2007-5850 [HIGH] CWE-119 CVE-2007-5850: Heap-based buffer overflow in Desktop Services in Apple Mac OS X 10.4.11 allows user-assisted attack Heap-based buffer overflow in Desktop Services in Apple Mac OS X 10.4.11 allows user-assisted attackers to execute arbitrary code via a directory with a crafted .DS_Store file.
nvd
CVE-2018-14469P3HIGHCVSS 7.5fixed in 10.15.22019-10-03
CVE-2018-14469 [HIGH] CWE-125 CVE-2018-14469: The IKEv1 parser in tcpdump before 4.9.3 has a buffer over-read in print-isakmp.c:ikev1_n_print(). The IKEv1 parser in tcpdump before 4.9.3 has a buffer over-read in print-isakmp.c:ikev1_n_print().
nvd
CVE-2018-14880P3HIGHCVSS 7.5fixed in 10.15.22019-10-03
CVE-2018-14880 [HIGH] CWE-125 CVE-2018-14880: The OSPFv3 parser in tcpdump before 4.9.3 has a buffer over-read in print-ospf6.c:ospf6_print_lshdr( The OSPFv3 parser in tcpdump before 4.9.3 has a buffer over-read in print-ospf6.c:ospf6_print_lshdr().
nvd
CVE-2014-4377P3MEDIUMCVSS 6.8≤ 10.9.42014-09-18
CVE-2014-4377 [MEDIUM] CWE-189 CVE-2014-4377: Integer overflow in CoreGraphics in Apple iOS before 8 and Apple TV before 7 allows remote attackers Integer overflow in CoreGraphics in Apple iOS before 8 and Apple TV before 7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.
nvd
CVE-2003-1009P3CRITICALCVSS 10.0v10.0.2v10.0.3+2 more2004-03-29
CVE-2003-1009 [CRITICAL] CVE-2003-1009: Directory Services in Apple Mac OS X 10.0.2, 10.0.3, 10.2.8, 10.3.2 and Apple Mac OS X Server 10.2 t Directory Services in Apple Mac OS X 10.0.2, 10.0.3, 10.2.8, 10.3.2 and Apple Mac OS X Server 10.2 through 10.3.2 accepts authentication server information from unknown LDAP or NetInfo sources as provided by a malicious DHCP server, which allows remote attackers to gain privileges.
nvd
CVE-2005-2516P3HIGHCVSS 7.5v10.3.9v10.4.22005-08-19
CVE-2005-2516 [HIGH] CVE-2005-2516: Safari in Mac OS X 10.3.9 and 10.4.2, when rendering Rich Text Format (RTF) files, can directly acce Safari in Mac OS X 10.3.9 and 10.4.2, when rendering Rich Text Format (RTF) files, can directly access URLs without performing the normal security checks, which allows remote attackers to execute arbitrary commands.
nvd
CVE-2013-6799P4MEDIUMCVSS 4.7PoCv10.92013-11-18
CVE-2013-6799 [MEDIUM] CVE-2013-6799: Apple Mac OS X 10.9 allows local users to cause a denial of service (memory corruption or panic) by Apple Mac OS X 10.9 allows local users to cause a denial of service (memory corruption or panic) by creating a hard link to a directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-0105.
nvd
CVE-2005-2523P4MEDIUMCVSS 4.3PoCv10.4v10.4.1+1 more2005-08-19
CVE-2005-2523 [MEDIUM] CVE-2005-2523: Multiple cross-site scripting (XSS) vulnerabilities in Weblog Server in Mac OS X 10.4 to 10.4.2 allo Multiple cross-site scripting (XSS) vulnerabilities in Weblog Server in Mac OS X 10.4 to 10.4.2 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.
nvd
CVE-2018-14468P3HIGHCVSS 7.5fixed in 10.15.22019-10-03
CVE-2018-14468 [HIGH] CWE-125 CVE-2018-14468: The FRF.16 parser in tcpdump before 4.9.3 has a buffer over-read in print-fr.c:mfr_print(). The FRF.16 parser in tcpdump before 4.9.3 has a buffer over-read in print-fr.c:mfr_print().
nvd
CVE-2008-4220P3CRITICALCVSS 10.0≤ 10.5.5v10.4.11+5 more2008-12-17
CVE-2008-4220 [CRITICAL] CWE-189 CVE-2008-4220: Integer overflow in the inet_net_pton API in Libsystem in Apple Mac OS X before 10.5.6 allows contex Integer overflow in the inet_net_pton API in Libsystem in Apple Mac OS X before 10.5.6 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors. NOTE: this may be related to the WLB-2008080064 advisory published by SecurityReason on 20080822; however, as of 20081216, there
nvd
CVE-2008-3616P3CRITICALCVSS 10.0v10.4.11v10.5+4 more2008-09-16
CVE-2008-3616 [CRITICAL] CWE-189 CVE-2008-3616: Multiple integer overflows in the SearchKit API in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 al Multiple integer overflows in the SearchKit API in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allow context-dependent attackers to cause a denial of service (application crash) or execute arbitrary code via vectors associated with "passing untrusted input" to unspecified API functions.
nvd
CVE-2007-0267P4MEDIUMCVSS 6.6PoCv10.4.82007-01-17
CVE-2007-0267 [MEDIUM] CWE-399 CVE-2007-0267: The ufs_lookup function in the Mac OS X 10.4.8 and FreeBSD 6.1 kernels allows local users to cause a The ufs_lookup function in the Mac OS X 10.4.8 and FreeBSD 6.1 kernels allows local users to cause a denial of service (kernel panic) and possibly corrupt other filesystems by mounting a crafted UNIX File System (UFS) DMG image that contains a corrupted directory entry (struct direct), related to the ufs_dirbad function. NOTE: a third party states tha
nvd
CVE-2015-5776P3HIGHCVSS 7.5≤ 10.10.42015-08-17
CVE-2015-5776 [HIGH] CWE-119 CVE-2015-5776: Libinfo in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitra Libinfo in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by leveraging use of an AF_INET6 socket.
nvd
CVE-2014-4484P3HIGHCVSS 7.5≤ 10.10.12015-01-30
CVE-2014-4484 [HIGH] CWE-19 CVE-2014-4484: FontParser in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows re FontParser in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted .dfont file.
nvd
CVE-2016-4617P3HIGHCVSS 8.8≤ 10.11.62017-02-20
CVE-2016-4617 [HIGH] CWE-264 CVE-2016-4617: An issue was discovered in certain Apple products. macOS before 10.12 is affected. The issue involve An issue was discovered in certain Apple products. macOS before 10.12 is affected. The issue involves a sandbox escape related to launchctl process spawning in the "libxpc" component.
nvd
CVE-2020-9847P3HIGHCVSS 8.6fixed in 10.15.52020-06-09
CVE-2020-9847 [HIGH] CWE-125 CVE-2020-9847: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Cata An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.5. A malicious application may be able to break out of its sandbox.
nvd
CVE-2002-1383P3CRITICALCVSS 10.0v10.2v10.2.22002-12-26
CVE-2002-1383 [CRITICAL] CVE-2002-1383: Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote attackers to execute arbitrary code via (1) the CUPSd HTTP interface, as demonstrated by vanilla-coke, and (2) the image handling code in CUPS filters, as demonstrated by mksun.
nvd
Apple macOS vulnerabilities | cvebase