Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 61 of 157
CVE-2021-1787P3HIGHCVSS 7.8≥ 10.14, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-04-02
CVE-2021-1787 [HIGH] CWE-269 CVE-2021-1787: Multiple issues were addressed with improved logic. This issue is fixed in macOS Big Sur 11.2, Secur
Multiple issues were addressed with improved logic. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A local attacker may be able to elevate their privileges.
nvd
CVE-2022-32826P3HIGHCVSS 7.8v10.15.72022-09-23
CVE-2022-32826 [HIGH] CWE-269 CVE-2022-32826: An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.6
An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be able to gain root privileges.
nvd
CVE-2021-1802P3HIGHCVSS 7.8≥ 10.14, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-04-02
CVE-2021-1802 [HIGH] CWE-269 CVE-2021-1802: A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. A local attacker may be able to elevate their privileges.
nvd
CVE-2017-13892P3HIGHCVSS 7.5≥ 10.11, < 10.11.6≥ 10.12, < 10.12.6+2 more2021-12-23
CVE-2017-13892 [HIGH] CVE-2017-13892: An issue existed in the handling of Contact sharing. This issue was addressed with improved handling
An issue existed in the handling of Contact sharing. This issue was addressed with improved handling of user information. This issue is fixed in macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan. Sharing contact information may lead to unexpected data sharing.
nvd
CVE-2018-4296P3CRITICALCVSS 9.8v10.142020-10-27
CVE-2018-4296 [CRITICAL] CVE-2018-4296: This issue is fixed in macOS Mojave 10.14. A permissions issue existed in DiskArbitration. This was
This issue is fixed in macOS Mojave 10.14. A permissions issue existed in DiskArbitration. This was addressed with additional ownership checks.
nvd
CVE-2016-1729P3HIGHCVSS 7.3≤ 10.11.22016-02-01
CVE-2016-1729 [HIGH] CVE-2016-1729: Untrusted search path vulnerability in OSA Scripts in Apple OS X before 10.11.3 allows attackers to
Untrusted search path vulnerability in OSA Scripts in Apple OS X before 10.11.3 allows attackers to load arbitrary script libraries via a quarantined application.
nvd
CVE-2020-9774P3HIGHCVSS 7.5fixed in 10.15.32020-10-27
CVE-2020-9774 [HIGH] CWE-311 CVE-2020-9774: An issue existed with Siri Suggestions access to encrypted data. The issue was fixed by limiting acc
An issue existed with Siri Suggestions access to encrypted data. The issue was fixed by limiting access to encrypted data. This issue is fixed in macOS Catalina 10.15.3, Security Update 2020-001 Mojave, Security Update 2020-001 High Sierra. Encrypted data may be inappropriately accessed.
nvd
CVE-2004-1307P3HIGHCVSS 7.5v10.3v10.3.1+8 more2004-12-21
CVE-2004-1307 [HIGH] CVE-2004-1307: Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remot
Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow.
nvd
CVE-2007-4687P3CRITICALCVSS 9.3v10.4.1v10.4.2+8 more2007-11-15
CVE-2007-4687 [CRITICAL] CWE-16 CVE-2007-4687: The remote_cmds component in Apple Mac OS X 10.4 through 10.4.10 contains a symbolic link from the t
The remote_cmds component in Apple Mac OS X 10.4 through 10.4.10 contains a symbolic link from the tftpboot private directory to the root directory, which allows tftpd users to escape the private directory and access arbitrary files.
nvd
CVE-2015-7003P3MEDIUMCVSS 6.8≤ 10.11.02015-10-23
CVE-2015-7003 [MEDIUM] CWE-264 CVE-2015-7003: coreaudiod in Audio in Apple OS X before 10.11.1 does not initialize an unspecified data structure,
coreaudiod in Audio in Apple OS X before 10.11.1 does not initialize an unspecified data structure, which allows attackers to execute arbitrary code via a crafted app.
nvd
CVE-2006-1456P3HIGHCVSS 7.5v10.3.9v10.4.62006-05-12
CVE-2006-1456 [HIGH] CVE-2006-1456: Buffer overflow in QuickTime Streaming Server in Apple Mac OS X 10.3.9 and 10.4.6 allows remote atta
Buffer overflow in QuickTime Streaming Server in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to execute arbitrary code via a crafted RTSP request, which is not properly handled during message logging.
nvd
CVE-2010-1820P3MEDIUMCVSS 6.8v10.6.0v10.6.1+3 more2010-09-21
CVE-2010-1820 [MEDIUM] CWE-287 CVE-2010-1820: Apple Filing Protocol (AFP) Server in Apple Mac OS X 10.6.x through 10.6.4 does not properly handle
Apple Filing Protocol (AFP) Server in Apple Mac OS X 10.6.x through 10.6.4 does not properly handle errors, which allows remote attackers to bypass the password requirement for shared-folder access by leveraging knowledge of a valid account name.
nvd
CVE-2007-0741P3HIGHCVSS 7.5v10.3.9v10.4+9 more2007-04-24
CVE-2007-0741 [HIGH] CVE-2007-0741: Buffer overflow in natd in network_cmds in Apple Mac OS X 10.3.9 through 10.4.9, when Internet Shari
Buffer overflow in natd in network_cmds in Apple Mac OS X 10.3.9 through 10.4.9, when Internet Sharing is enabled, allows remote attackers to execute arbitrary code via malformed RTSP packets.
nvd
CVE-2016-5131P3HIGHCVSS 8.8fixed in 10.122016-07-23
CVE-2016-5131 [HIGH] CWE-416 CVE-2016-5131: Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82,
Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.
nvd
CVE-2010-0105P4MEDIUMCVSS 4.9PoCv10.5.8v10.6.0+4 more2010-04-27
CVE-2010-0105 [MEDIUM] CVE-2010-0105: The hfs implementation in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 supports hard links to dire
The hfs implementation in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 supports hard links to directories and does not prevent certain deeply nested directory structures, which allows local users to cause a denial of service (filesystem corruption) via a crafted application that calls the mkdir and link functions, related to the fsck_hfs program in the disk
nvd
CVE-2011-3436P3MEDIUMCVSS 6.5v10.7.0v10.7.12011-10-14
CVE-2011-3436 [MEDIUM] CWE-264 CVE-2011-3436: Open Directory in Apple Mac OS X 10.7 before 10.7.2 does not require a user to provide the current p
Open Directory in Apple Mac OS X 10.7 before 10.7.2 does not require a user to provide the current password before changing this password, which allows remote attackers to bypass intended password-change restrictions by leveraging an unattended workstation.
nvd
CVE-2005-2518P3HIGHCVSS 7.5v10.3.9v10.4.22005-08-19
CVE-2005-2518 [HIGH] CVE-2005-2518: Buffer overflow in servermgrd in Mac OS X 10.3.9 and 10.4.2 allows remote attackers to execute arbit
Buffer overflow in servermgrd in Mac OS X 10.3.9 and 10.4.2 allows remote attackers to execute arbitrary code during authentication.
nvd
CVE-2018-14881P3HIGHCVSS 7.5fixed in 10.15.22019-10-03
CVE-2018-14881 [HIGH] CWE-125 CVE-2018-14881: The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print(
The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_RESTART).
nvd
CVE-2019-8603P3HIGHCVSS 8.8fixed in 10.14.52019-12-18
CVE-2019-8603 [HIGH] CWE-125 CVE-2019-8603: A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Moja
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Mojave 10.14.5. An application may be able to read restricted memory.
nvd
CVE-2008-1031P3CRITICALCVSS 9.3v10.4.11v10.5+2 more2008-06-02
CVE-2008-1031 [CRITICAL] CWE-119 CVE-2008-1031: CoreGraphics in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or ca
CoreGraphics in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document, related to an uninitialized variable.
nvd