cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 69 of 157
CVE-2011-0206P3HIGHCVSS 7.5v10.6.0v10.6.1+6 more2011-06-24
CVE-2011-0206 [HIGH] CWE-119 CVE-2011-0206: Buffer overflow in International Components for Unicode (ICU) in Apple Mac OS X before 10.6.8 allows Buffer overflow in International Components for Unicode (ICU) in Apple Mac OS X before 10.6.8 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving uppercase strings.
nvd
CVE-2016-4725P3HIGHCVSS 8.1fixed in 10.12.02016-09-25
CVE-2016-4725 [HIGH] CWE-119 CVE-2016-4725: IOAcceleratorFamily in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 IOAcceleratorFamily in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (memory corruption) via a crafted web site.
nvd
CVE-2018-4142P3HIGHCVSS 7.5fixed in 10.13.42018-04-03
CVE-2018-4142 [HIGH] CWE-20 CVE-2018-4142: An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service (application crash) via a crafted string.
nvd
CVE-2010-2808P3MEDIUMCVSS 6.8fixed in 10.6.52010-08-19
CVE-2010-2808 [MEDIUM] CWE-120 CVE-2010-2808: Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.2 all Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Adobe Type 1 Mac Font File (aka LWFN) font.
nvd
CVE-2008-0042P3MEDIUMCVSS 6.8v10.4.11v10.5+1 more2008-02-12
CVE-2008-0042 [MEDIUM] CWE-94 CVE-2008-0042: Argument injection vulnerability in Terminal.app in Terminal in Apple Mac OS X 10.4.11 and 10.5 thro Argument injection vulnerability in Terminal.app in Terminal in Apple Mac OS X 10.4.11 and 10.5 through 10.5.1 allows remote attackers to execute arbitrary code via unspecified URL schemes.
nvd
CVE-2011-3446P3HIGHCVSS 7.5≤ 10.7.2v10.7.0+1 more2012-02-02
CVE-2011-3446 [HIGH] CVE-2011-3446: Apple Type Services (ATS) in Apple Mac OS X before 10.7.3 does not properly manage memory for data-f Apple Type Services (ATS) in Apple Mac OS X before 10.7.3 does not properly manage memory for data-font files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted font that is accessed by Font Book.
nvd
CVE-2017-13846P4CRITICALCVSS 9.8≤ 10.13.02017-11-13
CVE-2017-13846 [CRITICAL] CVE-2017-13846: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the third-party "PCRE" product. Versions before 8.40 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
nvd
CVE-2017-13815P4CRITICALCVSS 9.8≤ 10.13.02017-11-13
CVE-2017-13815 [CRITICAL] CVE-2017-13815: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the third-party "file" product. Versions before 5.31 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
nvd
CVE-2016-7622P3HIGHCVSS 7.8≤ 10.12.12017-02-20
CVE-2016-7622 [HIGH] CWE-119 CVE-2016-7622: An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Grapher" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted .gcx file.
nvd
CVE-2007-0750P4CRITICALCVSS 9.3v10.4v10.4.1+8 more2007-05-24
CVE-2007-0750 [CRITICAL] CVE-2007-0750: Integer overflow in CoreGraphics in Apple Mac OS X 10.4 up to 10.4.9 allows remote user-assisted att Integer overflow in CoreGraphics in Apple Mac OS X 10.4 up to 10.4.9 allows remote user-assisted attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted PDF file.
nvd
CVE-2014-1379P4CRITICALCVSS 10.0≤ 10.9.3v10.8.0+8 more2014-07-01
CVE-2014-1379 [CRITICAL] CVE-2014-1379: Graphics Drivers in Apple OS X before 10.9.4 allows attackers to gain privileges or cause a denial o Graphics Drivers in Apple OS X before 10.9.4 allows attackers to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a 32-bit executable file for a crafted application.
nvd
CVE-2017-2431P3HIGHCVSS 7.8≤ 10.12.32017-04-02
CVE-2017-2431 [HIGH] CWE-119 CVE-2017-2431: An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "CoreMedia" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted .mov file.
nvd
CVE-2017-2413P3HIGHCVSS 7.8≤ 10.12.32017-04-02
CVE-2017-2413 [HIGH] CWE-119 CVE-2017-2413: An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "QuickTime" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted media file.
nvd
CVE-2019-8741P3HIGHCVSS 7.5fixed in 10.152020-02-28
CVE-2019-8741 [HIGH] CWE-835 CVE-2019-8741: A denial of service issue was addressed with improved input validation. A denial of service issue was addressed with improved input validation.
nvd
CVE-2009-0942P3MEDIUMCVSS 6.8v10.4.11v10.5.0+6 more2009-05-13
CVE-2009-0942 [MEDIUM] CWE-20 CVE-2009-0942: Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that certain Cascading Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that certain Cascading Style Sheets (CSS) are located in a registered help book, which allows remote attackers to execute arbitrary code via a help: URL that triggers invocation of AppleScript files.
nvd
CVE-2011-3919P3HIGHCVSS 7.5fixed in 10.7.42012-01-07
CVE-2011-3919 [HIGH] CWE-787 CVE-2011-3919: Heap-based buffer overflow in libxml2, as used in Google Chrome before 16.0.912.75, allows remote at Heap-based buffer overflow in libxml2, as used in Google Chrome before 16.0.912.75, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2017-7033P3HIGHCVSS 7.8≤ 10.12.52017-07-20
CVE-2017-7033 [HIGH] CWE-119 CVE-2017-7033: An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "afclip" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted audio file.
nvd
CVE-2017-7016P3HIGHCVSS 7.8≤ 10.12.52017-07-20
CVE-2017-7016 [HIGH] CWE-119 CVE-2017-7016: An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "afclip" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted audio file.
nvd
CVE-2017-13812P3HIGHCVSS 7.8≤ 10.13.02017-11-13
CVE-2017-13812 [HIGH] CWE-119 CVE-2017-13812: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "libarchive" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted archive file.
nvd
CVE-2017-13814P3HIGHCVSS 7.8≤ 10.13.02017-11-13
CVE-2017-13814 [HIGH] CWE-119 CVE-2017-13814: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "ImageIO" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted image file.
nvd
Apple macOS vulnerabilities | cvebase