Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 58 of 157
CVE-2017-2451P3HIGHCVSS 7.8≤ 10.12.32017-04-02
CVE-2017-2451 [HIGH] CWE-119 CVE-2017-2451: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Security" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (buffer overflow) via a crafted app
nvd
CVE-2017-7008P3HIGHCVSS 7.8≤ 10.12.52017-07-20
CVE-2017-7008 [HIGH] CWE-119 CVE-2017-7008: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. The issue involves the "CoreAudio" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file.
nvd
CVE-2016-4778P3HIGHCVSS 7.8fixed in 10.122016-09-25
CVE-2016-4778 [HIGH] CWE-264 CVE-2016-4778: The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows at
The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2016-4726P3HIGHCVSS 7.8fixed in 10.12.02016-09-25
CVE-2016-4726 [HIGH] CWE-119 CVE-2016-4726: IOAcceleratorFamily in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3
IOAcceleratorFamily in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2018-4136P3HIGHCVSS 7.8fixed in 10.13.42018-04-03
CVE-2018-4136 [HIGH] CWE-125 CVE-2018-4136: An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (out-of-bounds read) via a crafted app.
nvd
CVE-2018-4160P3HIGHCVSS 7.8fixed in 10.13.42018-04-03
CVE-2018-4160 [HIGH] CWE-125 CVE-2018-4160: An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (out-of-bounds read) via a crafted app.
nvd
CVE-2017-7086P3HIGHCVSS 7.5≤ 10.12.62017-10-23
CVE-2017-7086 [HIGH] CWE-400 CVE-2017-7086: An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is
An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "libc" component. It allows remote attackers to cause a denial of service (resource consumption) via a crafted string that is mishandled by the glob function.
nvd
CVE-2017-2440P3HIGHCVSS 7.8≤ 10.12.32017-04-02
CVE-2017-2440 [HIGH] CWE-190 CVE-2017-2440: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (integer overflow) via a crafted app.
nvd
CVE-2017-6981P3HIGHCVSS 7.8≤ 10.12.42017-05-22
CVE-2017-6981 [HIGH] CWE-59 CVE-2017-6981: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "iBooks" component. It allows attackers to execute arbitrary code in a privileged context via a crafted app that uses symlinks.
nvd
CVE-2016-7616P3HIGHCVSS 7.8≤ 10.12.12017-02-20
CVE-2016-7616 [HIGH] CWE-119 CVE-2016-7616: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Disk Images" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2019-8629P3HIGHCVSS 7.8fixed in 10.14.52019-12-18
CVE-2019-8629 [HIGH] CWE-665 CVE-2019-8629: A memory initialization issue was addressed with improved memory handling. This issue is fixed in ma
A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.5. An application may be able to execute arbitrary code with system privileges.
nvd
CVE-2016-7606P3HIGHCVSS 7.8≤ 10.12.12017-02-20
CVE-2016-7606 [HIGH] CWE-119 CVE-2016-7606: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2019-8555P3HIGHCVSS 7.8fixed in 10.4.42019-12-18
CVE-2019-8555 [HIGH] CWE-119 CVE-2019-8555: A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Mojave 1
A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Mojave 10.14.4. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2016-7742P3HIGHCVSS 7.8≤ 10.12.12017-02-20
CVE-2016-7742 [HIGH] CWE-20 CVE-2016-7742: An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "xar" component, which allows remote attackers to execute arbitrary code via a crafted archive that triggers use of uninitialized memory locations.
nvd
CVE-2016-4700P3HIGHCVSS 7.8≤ 10.11.62016-09-25
CVE-2016-4700 [HIGH] CVE-2016-4700: AppleUUC in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged conte
AppleUUC in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-4699.
nvd
CVE-2020-3863P3HIGHCVSS 7.8fixed in 10.15.32020-10-27
CVE-2020-3863 [HIGH] CWE-787 CVE-2020-3863: A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.3, Security Update 2020-001 Mojave, Security Update 2020-001 High Sierra. An application may be able to execute arbitrary code with system privileges.
nvd
CVE-2020-3904P3HIGHCVSS 7.8fixed in 10.15.42020-04-01
CVE-2020-3904 [HIGH] CWE-787 CVE-2020-3904: Multiple memory corruption issues were addressed with improved state management. This issue is fixed
Multiple memory corruption issues were addressed with improved state management. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2021-1761P3HIGHCVSS 7.5≥ 10.14, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-04-02
CVE-2021-1761 [HIGH] CVE-2021-1761: This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security U
This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause a denial of service.
nvd
CVE-2015-7075P3MEDIUMCVSS 6.8≤ 10.11.12015-12-11
CVE-2015-7075 [MEDIUM] CWE-119 CVE-2015-7075: CoreMedia Playback in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before
CoreMedia Playback in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed media file.
nvd
CVE-2015-7105P3MEDIUMCVSS 6.8≤ 10.11.12015-12-11
CVE-2015-7105 [MEDIUM] CWE-119 CVE-2015-7105: CoreGraphics in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 a
CoreGraphics in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file.
nvd