Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 60 of 157
CVE-2017-7128P3CRITICALCVSS 9.8≤ 10.12.62017-10-23
CVE-2017-7128 [CRITICAL] CWE-119 CVE-2017-7128: An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is
An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the third-party "SQLite" product. Versions before 3.19.3 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other i
nvd
CVE-2017-7130P3CRITICALCVSS 9.8≤ 10.12.62017-10-23
CVE-2017-7130 [CRITICAL] CWE-119 CVE-2017-7130: An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is
An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the third-party "SQLite" product. Versions before 3.19.3 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other i
nvd
CVE-2017-7129P3CRITICALCVSS 9.8≤ 10.12.62017-10-23
CVE-2017-7129 [CRITICAL] CWE-119 CVE-2017-7129: An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is
An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the third-party "SQLite" product. Versions before 3.19.3 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other i
nvd
CVE-2010-4494P3HIGHCVSS 7.5fixed in 10.6.72010-12-07
CVE-2010-4494 [HIGH] CWE-415 CVE-2010-4494: Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.5
Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
nvd
CVE-2020-3851P3HIGHCVSS 7.8≥ 10.15.2, < 10.15.3≥ 10.13.6, < 10.15.42020-10-27
CVE-2020-3851 [HIGH] CWE-416 CVE-2020-3851: A use after free issue was addressed with improved memory management. This issue is fixed in macOS C
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Catalina 10.15.4, Security Update 2020-002 Mojave, Security Update 2020-002 High Sierra, macOS Catalina 10.15.3, Security Update 2020-001 Mojave, Security Update 2020-001 High Sierra. An application may be able to gain elevated privileges.
nvd
CVE-2020-3913P3HIGHCVSS 7.8fixed in 10.15.42020-04-01
CVE-2020-3913 [HIGH] CVE-2020-3913: A permissions issue existed. This issue was addressed with improved permission validation. This issu
A permissions issue existed. This issue was addressed with improved permission validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, watchOS 6.2. A malicious application may be able to elevate privileges.
nvd
CVE-2016-7662P3HIGHCVSS 7.5≤ 10.12.12017-02-20
CVE-2016-7662 [HIGH] CWE-295 CVE-2016-7662: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Security" component, which allows remote attackers to spoof certificates via unspecified vectors.
nvd
CVE-2018-4184P3HIGHCVSS 7.5fixed in 10.13.52018-06-08
CVE-2018-4184 [HIGH] CVE-2018-4184: An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Speech" component. It allows attackers to bypass a sandbox protection mechanism to obtain microphone access.
nvd
CVE-2009-0139P3CRITICALCVSS 9.3v10.5.62009-02-13
CVE-2009-0139 [CRITICAL] CWE-189 CVE-2009-0139: Integer overflow in the SMB component in Apple Mac OS X 10.5.6 allows remote SMB servers to cause a
Integer overflow in the SMB component in Apple Mac OS X 10.5.6 allows remote SMB servers to cause a denial of service (system shutdown) or execute arbitrary code via a crafted SMB file system that triggers a heap-based buffer overflow.
nvd
CVE-2010-0057P3HIGHCVSS 7.5≤ 10.6.2v10.5+11 more2010-03-30
CVE-2010-0057 [HIGH] CWE-264 CVE-2010-0057: AFP Server in Apple Mac OS X before 10.6.3 does not prevent guest use of AFP shares when guest acces
AFP Server in Apple Mac OS X before 10.6.3 does not prevent guest use of AFP shares when guest access is disabled, which allows remote attackers to bypass intended access restrictions via a mount request.
nvd
CVE-2019-8854P3HIGHCVSS 7.5fixed in 10.152020-10-27
CVE-2019-8854 [HIGH] CVE-2019-8854: A user privacy issue was addressed by removing the broadcast MAC address. This issue is fixed in mac
A user privacy issue was addressed by removing the broadcast MAC address. This issue is fixed in macOS Catalina 10.15, watchOS 6, iOS 13, tvOS 13. A device may be passively tracked by its Wi-Fi MAC address.
nvd
CVE-2016-4693P3HIGHCVSS 7.5≤ 10.12.12017-02-20
CVE-2016-4693 [HIGH] CWE-326 CVE-2016-4693: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Security" component, which makes it easier for attackers to bypass cryptographic protection mechanisms by leveraging use of the 3DES cipher.
nvd
CVE-2015-6980P3HIGHCVSS 7.8≤ 10.11.02016-01-11
CVE-2015-6980 [HIGH] CWE-264 CVE-2015-6980: Directory Utility in Apple OS X before 10.11.1 mishandles authentication for new sessions, which all
Directory Utility in Apple OS X before 10.11.1 mishandles authentication for new sessions, which allows local users to gain privileges via unspecified vectors.
nvd
CVE-2016-4716P3HIGHCVSS 7.8≤ 10.11.62016-09-25
CVE-2016-4716 [HIGH] CWE-264 CVE-2016-4716: diskutil in DiskArbitration in Apple OS X before 10.12 allows local users to gain privileges via uns
diskutil in DiskArbitration in Apple OS X before 10.12 allows local users to gain privileges via unspecified vectors.
nvd
CVE-2016-1717P3HIGHCVSS 7.8fixed in 10.11.32016-02-01
CVE-2016-1717 [HIGH] CWE-119 CVE-2016-1717: The Disk Images component in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allo
The Disk Images component in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2021-30784P3HIGHCVSS 7.8≥ 10.14.0, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-09-08
CVE-2021-30784 [HIGH] CVE-2021-30784: Multiple issues were addressed with improved logic. This issue is fixed in macOS Big Sur 11.5. A loc
Multiple issues were addressed with improved logic. This issue is fixed in macOS Big Sur 11.5. A local attacker may be able to execute code on the Apple T2 Security Chip.
nvd
CVE-2017-7080P3HIGHCVSS 7.5≤ 10.12.62017-10-23
CVE-2017-7080 [HIGH] CWE-295 CVE-2017-7080: An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is
An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "Security" component. It allows remote attackers to bypass intended certificate-trust restrictions via a revoked X.509 certificate.
nvd
CVE-2015-7054P3MEDIUMCVSS 6.8≤ 10.11.12015-12-11
CVE-2015-7054 [MEDIUM] CWE-19 CVE-2015-7054: zlib in the Compression component in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and
zlib in the Compression component in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 does not initialize memory for an unspecified data structure, which allows remote attackers to execute arbitrary code via a crafted web site.
nvd
CVE-2021-1839P3HIGHCVSS 7.8v10.14v10.14.0+14 more2021-09-08
CVE-2021-1839 [HIGH] CWE-269 CVE-2021-1839: The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.3,
The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. A local attacker may be able to elevate their privileges.
nvd
CVE-2020-9855P3HIGHCVSS 7.8fixed in 10.15.52020-06-09
CVE-2020-9855 [HIGH] CWE-20 CVE-2020-9855: A validation issue existed in the handling of symlinks. This issue was addressed with improved valid
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Catalina 10.15.5. A local attacker may be able to elevate their privileges.
nvd