cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 63 of 157
CVE-2007-3744P3MEDIUMCVSS 5.8v10.4v10.4.1+9 more2007-08-03
CVE-2007-3744 [MEDIUM] CWE-119 CVE-2007-3744: Heap-based buffer overflow in the UPnP IGD (Internet Gateway Device Standardized Device Control Prot Heap-based buffer overflow in the UPnP IGD (Internet Gateway Device Standardized Device Control Protocol) implementation in mDNSResponder on Apple Mac OS X 10.4.10 before 20070731 allows network-adjacent remote attackers to execute arbitrary code via a crafted packet.
nvd
CVE-2015-3797P3HIGHCVSS 7.5≤ 10.10.42015-08-17
CVE-2015-3797 [HIGH] CVE-2015-3797: The TRE library in Libc in Apple iOS before 8.4.1 and OS X before 10.10.5 allows context-dependent a The TRE library in Libc in Apple iOS before 8.4.1 and OS X before 10.10.5 allows context-dependent attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted regular expression, a different vulnerability than CVE-2015-3796 and CVE-2015-3798.
nvd
CVE-2017-13816P3HIGHCVSS 7.8≤ 10.13.02017-11-13
CVE-2017-13816 [HIGH] CWE-119 CVE-2017-13816: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "libarchive" component. It allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a crafted archive file.
nvd
CVE-2017-13813P3HIGHCVSS 7.8≤ 10.13.02017-11-13
CVE-2017-13813 [HIGH] CWE-119 CVE-2017-13813: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "libarchive" component. It allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a crafted archive file.
nvd
CVE-2017-7031P3HIGHCVSS 7.8≤ 10.12.52017-07-20
CVE-2017-7031 [HIGH] CWE-119 CVE-2017-7031: An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Foundation" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file.
nvd
CVE-2016-7618P3HIGHCVSS 7.8≤ 10.12.12017-02-20
CVE-2016-7618 [HIGH] CWE-119 CVE-2016-7618: An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Foundation" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted .gcx file.
nvd
CVE-2016-1804P3HIGHCVSS 7.8≤ 10.11.42016-05-20
CVE-2016-1804 [HIGH] CWE-119 CVE-2016-1804: The Multi-Touch subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in The Multi-Touch subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2016-1815P3HIGHCVSS 7.8≤ 10.11.42016-05-20
CVE-2016-1815 [HIGH] CWE-119 CVE-2016-1815: IOAcceleratorFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a pri IOAcceleratorFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2016-1808P3HIGHCVSS 7.8fixed in 10.11.52016-05-20
CVE-2016-1808 [HIGH] CWE-119 CVE-2016-1808: The Disk Images subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and wat The Disk Images subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2016-4777P3HIGHCVSS 7.8fixed in 10.12.02016-09-25
CVE-2016-4777 [HIGH] CWE-264 CVE-2016-4777: The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows at The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (invalid pointer dereference) via a crafted app.
nvd
CVE-2016-4772P3HIGHCVSS 7.5fixed in 10.122016-09-25
CVE-2016-4772 [HIGH] CWE-399 CVE-2016-4772: The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows re The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to cause a denial of service (unintended lock) via unspecified vectors.
nvd
CVE-2016-1812P3HIGHCVSS 7.8≤ 10.11.42016-05-20
CVE-2016-1812 [HIGH] CWE-119 CVE-2016-1812: Buffer overflow in Intel Graphics Driver in Apple OS X before 10.11.5 allows attackers to execute ar Buffer overflow in Intel Graphics Driver in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2017-7132P3HIGHCVSS 7.8≤ 10.13.02017-11-13
CVE-2017-7132 [HIGH] CWE-400 CVE-2017-7132: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Quick Look" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory consumption) via a crafted Office document.
nvd
CVE-2017-13825P3HIGHCVSS 7.8≤ 10.13.02017-11-13
CVE-2017-13825 [HIGH] CWE-400 CVE-2017-13825: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "CoreText" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory consumption) via a crafted font file.
nvd
CVE-2016-1754P3HIGHCVSS 7.8fixed in 10.11.42016-03-24
CVE-2016-1754 [HIGH] CWE-119 CVE-2016-1754: The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 all The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1755.
nvd
CVE-2017-13824P3HIGHCVSS 7.8≤ 10.13.02017-11-13
CVE-2017-13824 [HIGH] CWE-119 CVE-2017-13824: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Open Scripting Architecture" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted AppleScript file that is mishandled by osadecompile.
nvd
CVE-2017-2410P3HIGHCVSS 7.8≤ 10.12.32017-04-02
CVE-2017-2410 [HIGH] CWE-20 CVE-2017-2410: An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2017-13833P3HIGHCVSS 7.8≤ 10.13.02017-11-13
CVE-2017-13833 [HIGH] CWE-119 CVE-2017-13833: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "CFNetwork" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2005-2511P3CRITICALCVSS 10.0v10.4.22005-08-19
CVE-2005-2511 [CRITICAL] CVE-2005-2511: Unknown vulnerability in Mac OS X 10.4.2 and earlier, when using Kerberos authentication with LDAP, Unknown vulnerability in Mac OS X 10.4.2 and earlier, when using Kerberos authentication with LDAP, allows attackers to gain access to a root Terminal window.
nvd
CVE-2019-6219P3HIGHCVSS 7.5fixed in 10.14.32019-03-05
CVE-2019-6219 [HIGH] CWE-20 CVE-2019-6219: A denial of service issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, A denial of service issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, watchOS 5.1.3. Processing a maliciously crafted message may lead to a denial of service.
nvd
Apple macOS vulnerabilities | cvebase