cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 7 of 157
CVE-2022-22721P2CRITICALCVSS 9.1≥ 10.15, < 10.15.7v10.15.72022-03-14
CVE-2022-22721 [CRITICAL] CWE-190 CVE-2022-22721: If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit s If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.
nvd
CVE-2022-22719P2HIGHCVSS 7.5v10.15.72022-03-14
CVE-2022-22719 [HIGH] CWE-665 CVE-2022-22719: A carefully crafted request body can cause a read to a random memory area which could cause the proc A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier.
nvd
CVE-2020-36221P3HIGHCVSS 7.5≥ 10.14.0, < 10.14.6v10.14.62021-01-26
CVE-2020-36221 [HIGH] CWE-191 CVE-2020-36221: An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certif An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c serialNumberAndIssuerCheck).
nvd
CVE-2019-6214P3HIGHCVSS 8.6PoCfixed in 10.14.32019-03-05
CVE-2019-6214 [HIGH] CWE-843 CVE-2019-6214: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1. A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to break out of its sandbox.
nvd
CVE-2017-2483P3HIGHCVSS 7.8PoC≤ 10.12.32017-04-02
CVE-2017-2483 [HIGH] CWE-119 CVE-2017-2483: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. A buffer overflow allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2019-6213P3HIGHCVSS 7.8PoCfixed in 10.14.32019-03-05
CVE-2019-6213 [HIGH] CWE-119 CVE-2019-6213: A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, ma A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2006-5710P3HIGHCVSS 7.5PoCv10.4.82006-11-04
CVE-2006-5710 [HIGH] CWE-119 CVE-2006-5710: The Airport driver for certain Orinoco based Airport cards in Darwin kernel 8.8.0 in Apple Mac OS X The Airport driver for certain Orinoco based Airport cards in Darwin kernel 8.8.0 in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to execute arbitrary code via an 802.11 probe response frame without any valid information element (IE) fields after the header, which triggers a heap-based buffer overflow.
nvd
CVE-2017-2482P3HIGHCVSS 7.8PoC≤ 10.12.32017-04-02
CVE-2017-2482 [HIGH] CWE-119 CVE-2017-2482: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. A buffer overflow allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2017-13847P3HIGHCVSS 7.8PoCfixed in 10.13.22017-12-25
CVE-2017-13847 [HIGH] CWE-119 CVE-2017-13847: An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. The issue involves the "IOKit" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2016-1819P3HIGHCVSS 7.8PoCfixed in 10.11.52016-05-20
CVE-2016-1819 [HIGH] CVE-2016-1819: Use-after-free vulnerability in the IOAccelContext2::clientMemoryForType method in Apple iOS before Use-after-free vulnerability in the IOAccelContext2::clientMemoryForType method in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1817 and CVE-2016
nvd
CVE-2017-2473P3HIGHCVSS 7.8PoC≤ 10.12.32017-04-02
CVE-2017-2473 [HIGH] CWE-119 CVE-2017-2473: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app
nvd
CVE-2016-1757P3HIGHCVSS 7.0PoC≤ 10.11.32016-03-24
CVE-2016-1757 [HIGH] CWE-362 CVE-2016-1757: Race condition in the kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to exe Race condition in the kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2017-2472P3HIGHCVSS 7.8PoC≤ 10.12.32017-04-02
CVE-2017-2472 [HIGH] CWE-416 CVE-2017-2472: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.
nvd
CVE-2017-2490P3HIGHCVSS 7.8PoC≤ 10.12.32017-04-02
CVE-2017-2490 [HIGH] CWE-119 CVE-2017-2490: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app
nvd
CVE-2017-2360P3HIGHCVSS 7.8PoCfixed in 10.12.32017-02-20
CVE-2017-2360 [HIGH] CWE-416 CVE-2017-2360: An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS before 10.1.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted
nvd
CVE-2019-8513P3HIGHCVSS 7.8PoCfixed in 10.14.42019-12-18
CVE-2019-8513 [HIGH] CWE-78 CVE-2019-8513: This issue was addressed with improved checks. This issue is fixed in macOS Mojave 10.14.4. A local This issue was addressed with improved checks. This issue is fixed in macOS Mojave 10.14.4. A local user may be able to execute arbitrary shell commands.
nvd
CVE-2018-4193P3HIGHCVSS 7.8PoCfixed in 10.13.52018-06-08
CVE-2018-4193 [HIGH] CWE-119 CVE-2018-4193: An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Windows Server" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2019-8565P3HIGHCVSS 7.0PoCfixed in 10.14.42019-12-18
CVE-2019-8565 [HIGH] CWE-362 CVE-2019-8565: A race condition was addressed with additional validation. This issue is fixed in iOS 12.2, macOS Mo A race condition was addressed with additional validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4. A malicious application may be able to gain root privileges.
nvd
CVE-2019-6218P3HIGHCVSS 7.8PoCfixed in 10.14.32019-03-05
CVE-2019-6218 [HIGH] CWE-787 CVE-2019-6218: A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 1 A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2017-2474P3HIGHCVSS 7.8PoC≤ 10.12.32017-04-02
CVE-2017-2474 [HIGH] CVE-2017-2474: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. An off-by-one error allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
Apple macOS vulnerabilities | cvebase