Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 67 of 157
CVE-2016-4710P3HIGHCVSS 7.8≤ 10.11.62016-09-25
CVE-2016-4710 [HIGH] CVE-2016-4710: WindowServer in Apple OS X before 10.12 allows local users to obtain root access via vectors that le
WindowServer in Apple OS X before 10.12 allows local users to obtain root access via vectors that leverage "type confusion," a different vulnerability than CVE-2016-4709.
nvd
CVE-2018-4180P3HIGHCVSS 7.8fixed in 10.13.52019-01-11
CVE-2018-4180 [HIGH] CVE-2018-4180: In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improve
In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions.
nvd
CVE-2019-8633P3HIGHCVSS 7.5≥ 10.13.6, < 10.14.52020-10-27
CVE-2019-8633 [HIGH] CWE-20 CVE-2019-8633: A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Moja
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, iOS 12.3, tvOS 12.3, watchOS 5.3. An application may be able to read restricted memory.
nvd
CVE-2016-4582P3HIGHCVSS 7.8fixed in 10.11.62016-07-22
CVE-2016-4582 [HIGH] CVE-2016-4582: The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2
The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1863 and CVE-2016-4653.
nvd
CVE-2019-8801P3HIGHCVSS 7.8fixed in 10.15.12019-12-18
CVE-2019-8801 [HIGH] CWE-426 CVE-2019-8801: A dynamic library loading issue existed in iTunes setup. This was addressed with improved path searc
A dynamic library loading issue existed in iTunes setup. This was addressed with improved path searching. This issue is fixed in macOS Catalina 10.15.1, iTunes for Windows 12.10.2. Running the iTunes installer in an untrusted directory may result in arbitrary code execution.
nvd
CVE-2016-1832P3HIGHCVSS 7.8fixed in 10.11.52016-05-20
CVE-2016-1832 [HIGH] CWE-119 CVE-2016-1832: libc in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 all
libc in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2016-1738P3HIGHCVSS 7.8≤ 10.11.32016-03-24
CVE-2016-1738 [HIGH] CWE-254 CVE-2016-1738: dyld in Apple OS X before 10.11.4 allows attackers to bypass a code-signing protection mechanism via
dyld in Apple OS X before 10.11.4 allows attackers to bypass a code-signing protection mechanism via a modified app.
nvd
CVE-2016-4775P3HIGHCVSS 7.8fixed in 10.12.02016-09-25
CVE-2016-4775 [HIGH] CWE-119 CVE-2016-4775: The kernel in Apple OS X before 10.12, tvOS before 10, and watchOS before 3 allows local users to ga
The kernel in Apple OS X before 10.12, tvOS before 10, and watchOS before 3 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2016-1722P3HIGHCVSS 7.8fixed in 10.11.32016-02-01
CVE-2016-1722 [HIGH] CWE-119 CVE-2016-1722: syslog in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to g
syslog in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2019-8579P3HIGHCVSS 7.8fixed in 10.14.42020-10-27
CVE-2019-8579 [HIGH] CWE-20 CVE-2019-8579: An input validation issue was addressed with improved memory handling. This issue is fixed in macOS
An input validation issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra. An application may be able to gain elevated privileges.
nvd
CVE-2019-8631P3HIGHCVSS 7.5fixed in 10.14.52020-10-27
CVE-2019-8631 [HIGH] CVE-2019-8631: A logic issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.1
A logic issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, iOS 12.3, tvOS 12.3. Users removed from an iMessage conversation may still be able to alter state.
nvd
CVE-2019-6239P3HIGHCVSS 7.8fixed in 10.14.42019-12-18
CVE-2019-6239 [HIGH] CVE-2019-6239: This issue was addressed with improved handling of file metadata. This issue is fixed in macOS Mojav
This issue was addressed with improved handling of file metadata. This issue is fixed in macOS Mojave 10.14.4. A malicious application may bypass Gatekeeper checks.
nvd
CVE-2010-1821P3HIGHCVSS 7.8v10.6.0v10.6.1+2 more2017-04-13
CVE-2010-1821 [HIGH] CWE-20 CVE-2010-1821: Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows local users to obt
Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows local users to obtain system privileges.
nvd
CVE-2019-8564P3HIGHCVSS 7.5fixed in 10.14.42020-10-27
CVE-2019-8564 [HIGH] CVE-2019-8564: A logic issue was addressed with improved validation. This issue is fixed in macOS Mojave 10.14.4, S
A logic issue was addressed with improved validation. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra. An attacker in a privileged network position can modify driver state.
nvd
CVE-2017-13832P3CRITICALCVSS 9.8≤ 10.13.02017-11-13
CVE-2017-13832 [CRITICAL] CVE-2017-13832: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "802.1X" component. It allows attackers to have an unspecified impact by leveraging TLS 1.0 support.
nvd
CVE-2022-32794P3HIGHCVSS 7.8≥ 10.15, < 10.15.7v10.15.72022-11-01
CVE-2022-32794 [HIGH] CWE-269 CVE-2022-32794: A logic issue was addressed with improved state management. This issue is fixed in Security Update 2
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. An app may be able to gain elevated privileges.
nvd
CVE-2009-2819P3CRITICALCVSS 9.3v10.5.82009-11-10
CVE-2009-2819 [CRITICAL] CWE-399 CVE-2009-2819: AFP Client in Apple Mac OS X 10.5.8 allows remote AFP servers to execute arbitrary code or cause a d
AFP Client in Apple Mac OS X 10.5.8 allows remote AFP servers to execute arbitrary code or cause a denial of service (memory corruption and system crash) via unspecified vectors.
nvd
CVE-2018-4217P3HIGHCVSS 7.5fixed in 10.13.52019-01-11
CVE-2018-4217 [HIGH] CWE-200 CVE-2018-4217: In macOS High Sierra before 10.13.5, a privacy issue in the handling of Open Directory records was a
In macOS High Sierra before 10.13.5, a privacy issue in the handling of Open Directory records was addressed with improved indexing.
nvd
CVE-2017-13837P3HIGHCVSS 7.5v10.13.02018-04-03
CVE-2017-13837 [HIGH] CVE-2017-13837: An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involve
An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "Installer" component. It does not properly restrict an app's entitlements for accessing the FileVault unlock key.
nvd
CVE-2004-0489P3HIGHCVSS 7.6≤ 10.3.32004-07-07
CVE-2004-0489 [HIGH] CWE-88 CVE-2004-0489: Argument injection vulnerability in the SSH URI handler for Safari on Mac OS 10.3.3 and earlier allo
Argument injection vulnerability in the SSH URI handler for Safari on Mac OS 10.3.3 and earlier allows remote attackers to (1) execute arbitrary code via the ProxyCommand option or (2) conduct port forwarding via the -R option.
nvd