Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 62 of 157
CVE-2008-1577P3CRITICALCVSS 9.3v10.4.11v10.5+2 more2008-06-02
CVE-2008-1577 [CRITICAL] CVE-2008-1577: Unspecified vulnerability in the Pixlet codec in Apple Pixlet Video in Apple Mac OS X before 10.5.3
Unspecified vulnerability in the Pixlet codec in Apple Pixlet Video in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file, related to "multiple memory corruption issues."
nvd
CVE-2014-1252P3HIGHCVSS 7.5≤ 10.9.12014-01-24
CVE-2014-1252 [HIGH] CWE-415 CVE-2014-1252: Double free vulnerability in Apple Pages 2.x before 2.1 and 5.x before 5.1 allows remote attackers t
Double free vulnerability in Apple Pages 2.x before 2.1 and 5.x before 5.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Word file.
nvd
CVE-2018-14465P3HIGHCVSS 7.5fixed in 10.15.22019-10-03
CVE-2018-14465 [HIGH] CWE-125 CVE-2018-14465: The RSVP parser in tcpdump before 4.9.3 has a buffer over-read in print-rsvp.c:rsvp_obj_print().
The RSVP parser in tcpdump before 4.9.3 has a buffer over-read in print-rsvp.c:rsvp_obj_print().
nvd
CVE-2018-14467P3HIGHCVSS 7.5fixed in 10.15.22019-10-03
CVE-2018-14467 [HIGH] CWE-125 CVE-2018-14467: The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print(
The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_MP).
nvd
CVE-2018-14464P3HIGHCVSS 7.5fixed in 10.15.22019-10-03
CVE-2018-14464 [HIGH] CWE-125 CVE-2018-14464: The LMP parser in tcpdump before 4.9.3 has a buffer over-read in print-lmp.c:lmp_print_data_link_sub
The LMP parser in tcpdump before 4.9.3 has a buffer over-read in print-lmp.c:lmp_print_data_link_subobjs().
nvd
CVE-2018-14470P3HIGHCVSS 7.5fixed in 10.15.22019-10-03
CVE-2018-14470 [HIGH] CWE-125 CVE-2018-14470: The Babel parser in tcpdump before 4.9.3 has a buffer over-read in print-babel.c:babel_print_v2().
The Babel parser in tcpdump before 4.9.3 has a buffer over-read in print-babel.c:babel_print_v2().
nvd
CVE-2018-14461P3HIGHCVSS 7.5fixed in 10.15.22019-10-03
CVE-2018-14461 [HIGH] CWE-125 CVE-2018-14461: The LDP parser in tcpdump before 4.9.3 has a buffer over-read in print-ldp.c:ldp_tlv_print().
The LDP parser in tcpdump before 4.9.3 has a buffer over-read in print-ldp.c:ldp_tlv_print().
nvd
CVE-2018-14466P3HIGHCVSS 7.5fixed in 10.15.22019-10-03
CVE-2018-14466 [HIGH] CWE-125 CVE-2018-14466: The Rx parser in tcpdump before 4.9.3 has a buffer over-read in print-rx.c:rx_cache_find() and rx_ca
The Rx parser in tcpdump before 4.9.3 has a buffer over-read in print-rx.c:rx_cache_find() and rx_cache_insert().
nvd
CVE-2018-14462P3HIGHCVSS 7.5fixed in 10.15.22019-10-03
CVE-2018-14462 [HIGH] CWE-125 CVE-2018-14462: The ICMP parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp.c:icmp_print().
The ICMP parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp.c:icmp_print().
nvd
CVE-2015-3143P3MEDIUMCVSS 5.0≤ 10.9.5v10.10.0+4 more2015-04-24
CVE-2015-3143 [MEDIUM] CVE-2015-3143: cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remot
cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0015.
nvd
CVE-2002-1367P3CRITICALCVSS 10.0v10.2v10.2.22002-12-26
CVE-2002-1367 [CRITICAL] CVE-2002-1367: Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to add printers wit
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to add printers without authentication via a certain UDP packet, which can then be used to perform unauthorized activities such as stealing the local root certificate for the administration server via a "need authorization" page, as demonstrated by new-coke.
nvd
CVE-2018-14882P3HIGHCVSS 7.5fixed in 10.15.22019-10-03
CVE-2018-14882 [HIGH] CWE-125 CVE-2018-14882: The ICMPv6 parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp6.c.
The ICMPv6 parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp6.c.
nvd
CVE-2018-16230P3HIGHCVSS 7.5fixed in 10.15.22019-10-03
CVE-2018-16230 [HIGH] CWE-125 CVE-2018-16230: The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_attr_print() (MP_RE
The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_attr_print() (MP_REACH_NLRI).
nvd
CVE-2011-0230P3HIGHCVSS 7.5≤ 10.7.1v10.0+66 more2011-10-14
CVE-2011-0230 [HIGH] CWE-119 CVE-2011-0230: Buffer overflow in the ATSFontDeactivate API in Apple Type Services (ATS) in Apple Mac OS X before 1
Buffer overflow in the ATSFontDeactivate API in Apple Type Services (ATS) in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2014-0117P4MEDIUMCVSS 4.3≤ 10.10.22014-07-20
CVE-2014-0117 [MEDIUM] CWE-20 CVE-2014-0117: The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a reverse proxy is enabled,
The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a reverse proxy is enabled, allows remote attackers to cause a denial of service (child-process crash) via a crafted HTTP Connection header.
nvd
CVE-2016-4671P3HIGHCVSS 7.8≤ 10.12.02017-02-20
CVE-2016-4671 [HIGH] CWE-787 CVE-2016-4671: An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "ImageIO" component. It allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write and application crash) via a crafted PDF file.
nvd
CVE-2013-7422P3HIGHCVSS 7.5≤ 10.10.42015-08-16
CVE-2013-7422 [HIGH] CWE-189 CVE-2013-7422: Integer underflow in regcomp.c in Perl before 5.20, as used in Apple OS X before 10.10.5 and other p
Integer underflow in regcomp.c in Perl before 5.20, as used in Apple OS X before 10.10.5 and other products, allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a long digit string associated with an invalid backreference within a regular expression.
nvd
CVE-2016-1850P3HIGHCVSS 7.8≤ 10.11.42016-05-20
CVE-2016-1850 [HIGH] CWE-119 CVE-2016-1850: SceneKit in Apple OS X before 10.11.5 allows remote attackers to execute arbitrary code or cause a d
SceneKit in Apple OS X before 10.11.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file.
nvd
CVE-2007-4710P3CRITICALCVSS 9.3v10.4.112007-12-19
CVE-2007-4710 [CRITICAL] CWE-399 CVE-2007-4710: Unspecified vulnerability in ColorSync in Apple Mac OS X 10.4.11 allows remote attackers to cause a
Unspecified vulnerability in ColorSync in Apple Mac OS X 10.4.11 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via an image with a crafted ColorSync profile, which triggers memory corruption.
nvd
CVE-2015-7551P3HIGHCVSS 8.4≤ 10.11.32016-03-24
CVE-2015-7551 [HIGH] CVE-2015-7551: The Fiddle::Handle implementation in ext/fiddle/handle.c in Ruby before 2.0.0-p648, 2.1 before 2.1.8
The Fiddle::Handle implementation in ext/fiddle/handle.c in Ruby before 2.0.0-p648, 2.1 before 2.1.8, and 2.2 before 2.2.4, as distributed in Apple OS X before 10.11.4 and other products, mishandles tainting, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string, related to the D
nvd