Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 6 of 157
CVE-2014-4389P3CRITICALCVSS 9.3PoC≤ 10.9.42014-09-18
CVE-2014-4389 [CRITICAL] CWE-189 CVE-2014-4389: Integer overflow in IOKit in Apple iOS before 8 and Apple TV before 7 allows attackers to execute ar
Integer overflow in IOKit in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context via an application that provides crafted API arguments.
nvd
CVE-2006-1982P3HIGHCVSS 7.5PoCv10.3v10.3.1+14 more2006-04-21
CVE-2006-1982 [HIGH] CWE-119 CVE-2006-1982: Heap-based buffer overflow in the LZWDecodeVector function in Mac OS X before 10.4.6, as used in app
Heap-based buffer overflow in the LZWDecodeVector function in Mac OS X before 10.4.6, as used in applications that use ImageIO or AppKit, allows remote attackers to execute arbitrary code via crafted TIFF images.
nvd
CVE-2018-4241P3HIGHCVSS 7.8PoCfixed in 10.13.52018-06-08
CVE-2018-4241 [HIGH] CWE-119 CVE-2018-4241: An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "Kernel" component. A buffer overflow in mptcp_usr_connectx allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2004-0430P3MEDIUMCVSS 5.1PoC≤ 10.3.32004-07-07
CVE-2004-0430 [MEDIUM] CVE-2004-0430: Stack-based buffer overflow in AppleFileServer for Mac OS X 10.3.3 and earlier allows remote attacke
Stack-based buffer overflow in AppleFileServer for Mac OS X 10.3.3 and earlier allows remote attackers to execute arbitrary code via a LoginExt packet for a Cleartext Password User Authentication Method (UAM) request with a PathName argument that includes an AFPName type string that is longer than the associated length field.
nvd
CVE-2009-1236P3CRITICALCVSS 10.0PoC≤ 10.5.6v10.0+53 more2009-04-02
CVE-2009-1236 [CRITICAL] CWE-119 CVE-2009-1236: Heap-based buffer overflow in the AppleTalk networking stack in XNU 1228.3.13 and earlier on Apple M
Heap-based buffer overflow in the AppleTalk networking stack in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allows remote attackers to cause a denial of service (system crash) via a ZIP NOTIFY (aka ZIPOP_NOTIFY) packet that overwrites a certain ifPort structure member.
nvd
CVE-2009-0949P3HIGHCVSS 7.5PoC≥ 10.0.0, < 10.4.11≥ 10.5.0, < 10.5.82009-06-09
CVE-2009-0949 [HIGH] CWE-908 CVE-2009-0949: The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize mem
The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler request with two consecutive IPP_TAG_UNSUPPORTED tags.
nvd
CVE-2015-3693P3CRITICALCVSS 9.3PoC≤ 10.10.32015-07-03
CVE-2015-3693 [CRITICAL] CWE-254 CVE-2015-3693: Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not properly
Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not properly set refresh rates for DDR3 RAM, which might make it easier for remote attackers to conduct row-hammer attacks, and consequently gain privileges or cause a denial of service (memory corruption), by triggering certain patterns of access to memory locatio
nvd
CVE-2017-13876P3HIGHCVSS 7.8PoCfixed in 10.13.22017-12-25
CVE-2017-13876 [HIGH] CWE-119 CVE-2017-13876: An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted a
nvd
CVE-2017-13867P3HIGHCVSS 7.8PoCfixed in 10.13.22017-12-25
CVE-2017-13867 [HIGH] CWE-119 CVE-2017-13867: An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted a
nvd
CVE-2018-4206P3HIGHCVSS 7.8PoCfixed in 10.13.42018-06-08
CVE-2018-4206 [HIGH] CWE-119 CVE-2018-4206: An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13.4 Security Update 2018-001 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "Crash Reporter" component. It allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via
nvd
CVE-2015-3798P3HIGHCVSS 7.5PoC≤ 10.10.42015-08-17
CVE-2015-3798 [HIGH] CVE-2015-3798: The TRE library in Libc in Apple iOS before 8.4.1 and OS X before 10.10.5 allows context-dependent a
The TRE library in Libc in Apple iOS before 8.4.1 and OS X before 10.10.5 allows context-dependent attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted regular expression, a different vulnerability than CVE-2015-3796 and CVE-2015-3797.
nvd
CVE-2011-3336P3HIGHCVSS 7.5PoC≥ 10.6.0, ≤ 10.7.22020-02-12
CVE-2011-3336 [HIGH] CWE-400 CVE-2011-3336: regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion
regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion.
nvd
CVE-2015-3796P3HIGHCVSS 7.5PoC≤ 10.10.42015-08-17
CVE-2015-3796 [HIGH] CWE-119 CVE-2015-3796: The TRE library in Libc in Apple iOS before 8.4.1 and OS X before 10.10.5 allows context-dependent a
The TRE library in Libc in Apple iOS before 8.4.1 and OS X before 10.10.5 allows context-dependent attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted regular expression, a different vulnerability than CVE-2015-3797 and CVE-2015-3798.
nvd
CVE-2015-7039P3MEDIUMCVSS 6.8PoC≤ 10.11.12015-12-11
CVE-2015-7039 [MEDIUM] CVE-2015-7039: Buffer overflow in libc in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS b
Buffer overflow in libc in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code via a crafted package, a different vulnerability than CVE-2015-7038.
nvd
CVE-2010-1840P3HIGHCVSS 7.5PoCv10.5.8v10.6.0+4 more2010-11-15
CVE-2010-1840 [HIGH] CWE-119 CVE-2010-1840: Stack-based buffer overflow in the password-validation functionality in Directory Services in Apple
Stack-based buffer overflow in the password-validation functionality in Directory Services in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2017-2361P3MEDIUMCVSS 6.1PoC≤ 10.12.22017-02-20
CVE-2017-2361 [MEDIUM] CWE-79 CVE-2017-2361: An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Help Viewer" component, which allows XSS attacks via a crafted web site.
nvd
CVE-2016-7644P3HIGHCVSS 7.8PoC≤ 10.12.12017-02-20
CVE-2016-7644 [HIGH] CWE-416 CVE-2016-7644: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.
nvd
CVE-2007-0465P3HIGHCVSS 7.6PoCv10.4.82007-01-31
CVE-2007-0465 [HIGH] CVE-2007-0465: Format string vulnerability in Apple Installer 2.1.5 on Mac OS X 10.4.8 allows user-assisted remote
Format string vulnerability in Apple Installer 2.1.5 on Mac OS X 10.4.8 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a (1) PKG, (2) DISTZ, or (3) MPKG package filename.
nvd
CVE-2016-1823P3HIGHCVSS 7.8PoCfixed in 10.11.52016-05-20
CVE-2016-1823 [HIGH] CWE-125 CVE-2016-1823: The IOHIDDevice::handleReportWithTime function in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS
The IOHIDDevice::handleReportWithTime function in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (out-of-bounds read and memory corruption) via a crafted IOHIDReportType enum, which triggers an incorrect cast, a differ
nvd
CVE-2022-22720P2CRITICALCVSS 9.8v10.15.72022-03-14
CVE-2022-22720 [CRITICAL] CWE-444 CVE-2022-22720: Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered
Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling
nvd