cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 70 of 157
CVE-2016-1831P3HIGHCVSS 7.8≤ 10.11.42016-05-20
CVE-2016-1831 [HIGH] CWE-119 CVE-2016-1831: The kernel in Apple iOS before 9.3.2 and OS X before 10.11.5 allows attackers to execute arbitrary c The kernel in Apple iOS before 9.3.2 and OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2018-4347P3HIGHCVSS 7.8fixed in 10.142019-04-03
CVE-2018-4347 [HIGH] CWE-416 CVE-2018-4347: A use after free issue was addressed with improved memory management. This issue affected versions p A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5, iTunes 12.9 for Windows, iCloud for Windows 7.7.
nvd
CVE-2012-5366P3HIGHCVSS 7.5fixed in 10.92020-02-20
CVE-2012-5366 [HIGH] CWE-400 CVE-2012-5366: The IPv6 implementation in Apple Mac OS X (unknown versions, year 2012 and earlier) allows remote at The IPv6 implementation in Apple Mac OS X (unknown versions, year 2012 and earlier) allows remote attackers to cause a denial of service via a flood of ICMPv6 Router Advertisement packets containing multiple Routing entries.
nvd
CVE-2016-4681P3HIGHCVSS 7.8≤ 10.12.02017-02-20
CVE-2016-4681 [HIGH] CWE-119 CVE-2016-4681: An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "Core Image" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted JPEG file.
nvd
CVE-2016-7602P3HIGHCVSS 7.8≤ 10.12.12017-02-20
CVE-2016-7602 [HIGH] CWE-119 CVE-2016-7602: An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-2541P3HIGHCVSS 7.8≤ 10.12.42017-05-22
CVE-2017-2541 [HIGH] CWE-119 CVE-2017-2541: An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "WindowServer" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2016-4750P3HIGHCVSS 7.8≤ 10.11.62016-09-25
CVE-2016-4750 [HIGH] CWE-119 CVE-2016-4750: S2 Camera in Apple iOS before 10 and OS X before 10.12 allows attackers to execute arbitrary code in S2 Camera in Apple iOS before 10 and OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2016-4723P3HIGHCVSS 7.8≤ 10.11.62016-09-25
CVE-2016-4723 [HIGH] CWE-119 CVE-2016-4723: Intel Graphics Driver in Apple OS X before 10.12 allows attackers to execute arbitrary code in a pri Intel Graphics Driver in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2016-4703P3HIGHCVSS 7.8≤ 10.11.62016-09-25
CVE-2016-4703 [HIGH] CWE-119 CVE-2016-4703: Bluetooth in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged cont Bluetooth in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2016-4727P3HIGHCVSS 7.8≤ 10.11.62016-09-25
CVE-2016-4727 [HIGH] CWE-119 CVE-2016-4727: IOThunderboltFamily in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privi IOThunderboltFamily in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2016-7629P3HIGHCVSS 7.8≤ 10.12.12017-02-20
CVE-2016-7629 [HIGH] CWE-119 CVE-2016-7629: An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "kext tools" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-7014P3HIGHCVSS 7.8≤ 10.12.52017-07-20
CVE-2017-7014 [HIGH] CWE-119 CVE-2017-7014: An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-7035P3HIGHCVSS 7.8≤ 10.12.52017-07-20
CVE-2017-7035 [HIGH] CWE-119 CVE-2017-7035: An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-7017P3HIGHCVSS 7.8≤ 10.12.52017-07-20
CVE-2017-7017 [HIGH] CWE-119 CVE-2017-7017: An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-7044P3HIGHCVSS 7.8≤ 10.12.52017-07-20
CVE-2017-7044 [HIGH] CWE-119 CVE-2017-7044: An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-7021P3HIGHCVSS 7.8≤ 10.12.52017-07-20
CVE-2017-7021 [HIGH] CWE-119 CVE-2017-7021: An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "AppleGraphicsPowerManagement" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-7032P3HIGHCVSS 7.8≤ 10.12.52017-07-20
CVE-2017-7032 [HIGH] CWE-119 CVE-2017-7032: An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "kext tools" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-2420P3HIGHCVSS 7.8≤ 10.12.32017-04-02
CVE-2017-2420 [HIGH] CWE-119 CVE-2017-2420: An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Bluetooth" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2015-7073P3MEDIUMCVSS 6.8≤ 10.11.12015-12-11
CVE-2015-7073 [MEDIUM] CWE-119 CVE-2015-7073: Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allow remote atta Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted SSL handshake.
nvd
CVE-2017-2422P3HIGHCVSS 7.8≤ 10.12.32017-04-02
CVE-2017-2422 [HIGH] CWE-119 CVE-2017-2422: An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Multi-Touch" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
Apple macOS vulnerabilities | cvebase