cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 68 of 157
CVE-2019-8640P3HIGHCVSS 7.5fixed in 10.14.52020-10-27
CVE-2019-8640 [HIGH] CWE-20 CVE-2019-8640: A logic issue was addressed with improved validation. This issue is fixed in macOS Mojave 10.14.5, S A logic issue was addressed with improved validation. This issue is fixed in macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra. A sandboxed process may be able to circumvent sandbox restrictions.
nvd
CVE-2015-1088P3MEDIUMCVSS 6.8≤ 10.10.22015-04-10
CVE-2015-1088 [MEDIUM] CWE-20 CVE-2015-1088: CFURL in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not properly validate URLs, which a CFURL in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not properly validate URLs, which allows remote attackers to execute arbitrary code via a crafted web site.
nvd
CVE-2019-14899P3HIGHCVSS 7.4fixed in 10.15.62019-12-11
CVE-2019-14899 [HIGH] CWE-300 CVE-2019-14899: A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a mal A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences about the websites they are visiting, and determine the correct sequence and acknowledgement numbers in use, allowing the bad actor to in
nvd
CVE-2014-1254P3MEDIUMCVSS 6.8≤ 10.9.1v10.8.0+6 more2014-02-27
CVE-2014-1254 [MEDIUM] CWE-119 CVE-2014-1254: Apple Type Services (ATS) in Apple OS X before 10.9.2 allows remote attackers to execute arbitrary c Apple Type Services (ATS) in Apple OS X before 10.9.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Type 1 font that is embedded in a document.
nvd
CVE-2008-3618P3CRITICALCVSS 9.0v10.5v10.5.1+3 more2008-09-16
CVE-2008-3618 [CRITICAL] CWE-264 CVE-2008-3618: The File Sharing pane in the Sharing preference pane in Apple Mac OS X 10.5 through 10.5.4 does not The File Sharing pane in the Sharing preference pane in Apple Mac OS X 10.5 through 10.5.4 does not inform users that the complete contents of their own home directories are shared for their own use, which might allow attackers to leverage other vulnerabilities and access files for which sharing was unintended.
nvd
CVE-2009-1237P4MEDIUMCVSS 4.9PoC≤ 10.5.6v10.0+53 more2009-04-02
CVE-2009-1237 [MEDIUM] CWE-399 CVE-2009-1237: Multiple memory leaks in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allow local Multiple memory leaks in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allow local users to cause a denial of service (kernel memory consumption) via a crafted (1) SYS_add_profil or (2) SYS___mac_getfsstat system call.
nvd
CVE-2021-1878P3MEDIUMCVSS 6.5≥ 10.14, ≤ 10.14.5≥ 10.15, ≤ 10.15.5+3 more2021-09-08
CVE-2021-1878 [MEDIUM] CWE-190 CVE-2021-1878: An integer overflow was addressed with improved input validation. This issue is fixed in macOS Big S An integer overflow was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. An attacker in a privileged network position may be able to leak sensitive user information.
nvd
CVE-2007-0430P4MEDIUMCVSS 4.9PoC≤ 10.4.82007-01-23
CVE-2007-0430 [MEDIUM] CVE-2007-0430: The shared_region_map_file_np function in Apple Mac OS X 10.4.8 and earlier kernel allows local user The shared_region_map_file_np function in Apple Mac OS X 10.4.8 and earlier kernel allows local users to cause a denial of service (memory corruption) via a large mappingCount value.
nvd
CVE-2015-3415P3HIGHCVSS 7.5v10.10.52015-04-24
CVE-2015-3415 [HIGH] CWE-404 CVE-2015-3415: The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via a crafted CHECK clause, as demonstrated by CHECK(0&O>O) in a CREATE TABLE statement.
nvd
CVE-2010-2519P3MEDIUMCVSS 6.8fixed in 10.6.52010-08-19
CVE-2010-2519 [MEDIUM] CWE-787 CVE-2010-2519: Heap-based buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType befor Heap-based buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted length value in a POST fragment header in a font file.
nvd
CVE-2005-0713P4MEDIUMCVSS 4.6PoCv10.3v10.3.1+7 more2005-03-21
CVE-2005-0713 [MEDIUM] CVE-2005-0713: The Bluetooth Setup Assistant for Mac OS X before 10.3.8 can be launched without a keyboard or Bluet The Bluetooth Setup Assistant for Mac OS X before 10.3.8 can be launched without a keyboard or Bluetooth device, which allows local users to bypass access restrictions and gain privileges.
nvd
CVE-2014-4481P3MEDIUMCVSS 6.8≤ 10.10.12015-01-30
CVE-2014-4481 [MEDIUM] CWE-189 CVE-2014-4481: Integer overflow in CoreGraphics in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV Integer overflow in CoreGraphics in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.
nvd
CVE-2018-16228P3HIGHCVSS 7.5fixed in 10.15.22019-10-03
CVE-2018-16228 [HIGH] CWE-125 CVE-2018-16228: The HNCP parser in tcpdump before 4.9.3 has a buffer over-read in print-hncp.c:print_prefix(). The HNCP parser in tcpdump before 4.9.3 has a buffer over-read in print-hncp.c:print_prefix().
nvd
CVE-2011-3460P3HIGHCVSS 7.5≤ 10.7.2v10.6.0+10 more2012-02-02
CVE-2011-3460 [HIGH] CWE-119 CVE-2011-3460: Buffer overflow in QuickTime in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbi Buffer overflow in QuickTime in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PNG file.
nvd
CVE-2008-4221P3CRITICALCVSS 10.0≤ 10.5.5v10.4.11+5 more2008-12-17
CVE-2008-4221 [CRITICAL] CWE-399 CVE-2008-4221: The strptime API in Libsystem in Apple Mac OS X before 10.5.6 allows context-dependent attackers to The strptime API in Libsystem in Apple Mac OS X before 10.5.6 allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a crafted date string, related to improper memory allocation.
nvd
CVE-2014-9425P3HIGHCVSS 7.5≤ 10.10.52014-12-31
CVE-2014-9425 [HIGH] CVE-2014-9425: Double free vulnerability in the zend_ts_hash_graceful_destroy function in zend_ts_hash.c in the Zen Double free vulnerability in the zend_ts_hash_graceful_destroy function in zend_ts_hash.c in the Zend Engine in PHP through 5.5.20 and 5.6.x through 5.6.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-1755P3HIGHCVSS 7.5fixed in 10.6.8≥ 10.7.0, < 10.7.22011-06-21
CVE-2011-1755 [HIGH] CVE-2011-1755: jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remo jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
nvd
CVE-2010-1380P3HIGHCVSS 7.5v10.6.0v10.6.1+2 more2010-06-17
CVE-2010-1380 [HIGH] CWE-189 CVE-2010-1380: Integer overflow in the cgtexttops CUPS filter in Printing in Apple Mac OS X 10.6 before 10.6.4 allo Integer overflow in the cgtexttops CUPS filter in Printing in Apple Mac OS X 10.6 before 10.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to page sizes.
nvd
CVE-2010-3787P3MEDIUMCVSS 6.8v10.6.0v10.6.1+3 more2010-11-16
CVE-2010-3787 [MEDIUM] CWE-119 CVE-2010-3787: Heap-based buffer overflow in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attacke Heap-based buffer overflow in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JP2 image.
nvd
CVE-2015-4021P4MEDIUMCVSS 5.0≤ 10.10.42015-06-09
CVE-2015-4021 [MEDIUM] CWE-189 CVE-2015-4021: The phar_parse_tarfile function in ext/phar/tar.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6 The phar_parse_tarfile function in ext/phar/tar.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 does not verify that the first character of a filename is different from the \0 character, which allows remote attackers to cause a denial of service (integer underflow and memory corruption) via a crafted entry in a tar archive.
nvd
Apple macOS vulnerabilities | cvebase