Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 57 of 157
CVE-2012-0662P3HIGHCVSS 7.5≤ 10.7.3v10.0+68 more2012-05-11
CVE-2012-0662 [HIGH] CWE-189 CVE-2012-0662: Integer overflow in the Security Framework in Apple Mac OS X before 10.7.4 allows remote attackers t
Integer overflow in the Security Framework in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted input.
nvd
CVE-2008-2311P3HIGHCVSS 7.6v10.4.1v10.4.2+13 more2008-07-01
CVE-2008-2311 [HIGH] CWE-59 CVE-2008-2311: Launch Services in Apple Mac OS X before 10.5, when Open Safe Files is enabled, allows remote attack
Launch Services in Apple Mac OS X before 10.5, when Open Safe Files is enabled, allows remote attackers to execute arbitrary code via a symlink attack, probably related to a race condition and automatic execution of a downloaded file.
nvd
CVE-2011-3457P3HIGHCVSS 7.5≤ 10.7.2v10.6.0+10 more2012-02-02
CVE-2011-3457 [HIGH] CWE-119 CVE-2011-3457: The OpenGL implementation in Apple Mac OS X before 10.7.3 does not properly perform OpenGL Shading L
The OpenGL implementation in Apple Mac OS X before 10.7.3 does not properly perform OpenGL Shading Language (aka GLSL) compilation, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted program.
nvd
CVE-2020-8037P3HIGHCVSS 7.5fixed in 10.14.6≥ 10.15, < 10.15.7+2 more2020-11-04
CVE-2020-8037 [HIGH] CWE-770 CVE-2020-8037: The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.
The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.
nvd
CVE-2012-0650P3HIGHCVSS 7.5≤ 10.6.8v10.0.0+58 more2012-09-20
CVE-2012-0650 [HIGH] CWE-119 CVE-2012-0650: Buffer overflow in the DirectoryService Proxy in DirectoryService in Apple Mac OS X through 10.6.8 a
Buffer overflow in the DirectoryService Proxy in DirectoryService in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2016-1820P3HIGHCVSS 7.8≤ 10.11.42016-05-20
CVE-2016-1820 [HIGH] CWE-119 CVE-2016-1820: Buffer overflow in IOAudioFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary
Buffer overflow in IOAudioFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2016-1826P3HIGHCVSS 7.8≤ 10.11.42016-05-20
CVE-2016-1826 [HIGH] CVE-2016-1826: Integer overflow in the dtrace implementation in the kernel in Apple OS X before 10.11.5 allows atta
Integer overflow in the dtrace implementation in the kernel in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2017-2461P3HIGHCVSS 7.5≤ 10.12.32017-04-02
CVE-2017-2461 [HIGH] CWE-20 CVE-2017-2461: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service (resource consumption) via a crafted text message.
nvd
CVE-2014-4459P3MEDIUMCVSS 6.8fixed in 10.10.12014-11-18
CVE-2014-4459 [MEDIUM] CVE-2014-4459: Use-after-free vulnerability in WebKit, as used in Apple OS X before 10.10.1, allows remote attacker
Use-after-free vulnerability in WebKit, as used in Apple OS X before 10.10.1, allows remote attackers to execute arbitrary code via crafted page objects in an HTML document.
nvd
CVE-2020-9991P3HIGHCVSS 7.5fixed in 11.0.12020-12-08
CVE-2020-9991 [HIGH] CVE-2020-9991: This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.0.1, watchOS
This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, iOS 14.0 and iPadOS 14.0, iCloud for Windows 7.21, tvOS 14.0. A remote attacker may be able to cause a denial of service.
nvd
CVE-2016-1817P3HIGHCVSS 7.8fixed in 10.11.52016-05-20
CVE-2016-1817 [HIGH] CWE-119 CVE-2016-1817: IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS b
IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1818 and CVE-2016-1819.
nvd
CVE-2016-4599P3HIGHCVSS 7.8≤ 10.11.52016-07-22
CVE-2016-4599 [HIGH] CWE-119 CVE-2016-4599: QuickTime in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a
QuickTime in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Photoshop document.
nvd
CVE-2016-4779P3HIGHCVSS 7.8≤ 10.11.62016-09-25
CVE-2016-4779 [HIGH] CWE-119 CVE-2016-4779: Apple Type Services (ATS) in Apple OS X before 10.12 allows remote attackers to execute arbitrary co
Apple Type Services (ATS) in Apple OS X before 10.12 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file.
nvd
CVE-2022-0261P3HIGHCVSS 7.8v10.12.62022-01-18
CVE-2022-0261 [HIGH] CWE-122 CVE-2022-0261: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2016-1746P3HIGHCVSS 7.8≤ 10.11.32016-03-24
CVE-2016-1746 [HIGH] CWE-20 CVE-2016-1746: IOGraphics in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged c
IOGraphics in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1747.
nvd
CVE-2016-1747P3HIGHCVSS 7.8≤ 10.11.32016-03-24
CVE-2016-1747 [HIGH] CVE-2016-1747: IOGraphics in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged c
IOGraphics in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1746.
nvd
CVE-2016-1797P3HIGHCVSS 7.8≤ 10.11.42016-05-20
CVE-2016-1797 [HIGH] CWE-284 CVE-2016-1797: Apple Type Services (ATS) in Apple OS X before 10.11.5 allows attackers to bypass intended FontValid
Apple Type Services (ATS) in Apple OS X before 10.11.5 allows attackers to bypass intended FontValidator sandbox-policy restrictions and execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2016-4712P3HIGHCVSS 7.8fixed in 10.12.02016-09-25
CVE-2016-4712 [HIGH] CWE-787 CVE-2016-4712: CoreCrypto in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows at
CoreCrypto in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via a crafted app.
nvd
CVE-2016-1829P3HIGHCVSS 7.8fixed in 10.11.52016-05-20
CVE-2016-1829 [HIGH] CVE-2016-1829: The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1827, CVE-2016-1828, and CVE-2016-1830.
nvd
CVE-2008-4237P3CRITICALCVSS 10.0≤ 10.5.5v10.5+4 more2008-12-17
CVE-2008-4237 [CRITICAL] CVE-2008-4237: Managed Client in Apple Mac OS X before 10.5.6 sometimes misidentifies a system when installing per-
Managed Client in Apple Mac OS X before 10.5.6 sometimes misidentifies a system when installing per-host configuration settings, which allows context-dependent attackers to have an unspecified impact by leveraging unintended settings, as demonstrated by the screen saver lock setting.
nvd