Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 71 of 157
CVE-2017-2422P3HIGHCVSS 7.8≤ 10.12.32017-04-02
CVE-2017-2422 [HIGH] CWE-119 CVE-2017-2422: An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Multi-Touch" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-2408P3HIGHCVSS 7.8≤ 10.12.32017-04-02
CVE-2017-2408 [HIGH] CWE-119 CVE-2017-2408: An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "IOATAFamily" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-2436P3HIGHCVSS 7.8≤ 10.12.32017-04-02
CVE-2017-2436 [HIGH] CWE-119 CVE-2017-2436: An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "IOFireWireAVC" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-2427P3HIGHCVSS 7.8≤ 10.12.32017-04-02
CVE-2017-2427 [HIGH] CWE-119 CVE-2017-2427: An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Bluetooth" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-2358P3HIGHCVSS 7.8≤ 10.12.22017-02-20
CVE-2017-2358 [HIGH] CWE-119 CVE-2017-2358: An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Graphics Drivers" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-2449P3HIGHCVSS 7.8≤ 10.12.32017-04-02
CVE-2017-2449 [HIGH] CWE-416 CVE-2017-2449: An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Bluetooth" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.
nvd
CVE-2017-2438P3HIGHCVSS 7.8≤ 10.12.32017-04-02
CVE-2017-2438 [HIGH] CWE-416 CVE-2017-2438: An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "AppleRAID" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.
nvd
CVE-2016-1735P3HIGHCVSS 7.8≤ 10.11.32016-03-24
CVE-2016-1735 [HIGH] CWE-119 CVE-2016-1735: Bluetooth in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged co
Bluetooth in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1736.
nvd
CVE-2016-1736P3HIGHCVSS 7.8≤ 10.11.32016-03-24
CVE-2016-1736 [HIGH] CVE-2016-1736: Bluetooth in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged co
Bluetooth in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1735.
nvd
CVE-2016-4697P3HIGHCVSS 7.8≤ 10.11.62016-09-25
CVE-2016-4697 [HIGH] CWE-119 CVE-2016-4697: Apple HSSPI Support in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privi
Apple HSSPI Support in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2016-4662P3HIGHCVSS 7.8≤ 10.12.02017-02-20
CVE-2016-4662 [HIGH] CWE-119 CVE-2016-4662: An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "AppleGraphicsControl" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2018-4415P3HIGHCVSS 7.8fixed in 10.14.12019-04-03
CVE-2018-4415 [HIGH] CWE-119 CVE-2018-4415: A memory corruption issue was addressed with improved memory handling. This issue affected versions
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to macOS Mojave 10.14.1.
nvd
CVE-2017-13829P3HIGHCVSS 7.8≤ 10.13.02017-11-13
CVE-2017-13829 [HIGH] CWE-119 CVE-2017-13829: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "CFNetwork" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-2548P3HIGHCVSS 7.8≤ 10.12.42017-05-22
CVE-2017-2548 [HIGH] CWE-119 CVE-2017-2548: An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "WindowServer" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-2537P3HIGHCVSS 7.8≤ 10.12.42017-05-22
CVE-2017-2537 [HIGH] CWE-119 CVE-2017-2537: An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "WindowServer" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-13853P3HIGHCVSS 7.8fixed in 10.12.62018-04-03
CVE-2017-13853 [HIGH] CWE-119 CVE-2017-13853: An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "AppleGraphicsControl" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-13838P3HIGHCVSS 7.8≤ 10.13.02017-11-13
CVE-2017-13838 [HIGH] CWE-119 CVE-2017-13838: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Sandbox" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-13843P3HIGHCVSS 7.8≤ 10.13.02017-11-13
CVE-2017-13843 [HIGH] CWE-119 CVE-2017-13843: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2008-3608P4CRITICALCVSS 9.3v10.4.11v10.5+4 more2008-09-16
CVE-2008-3608 [CRITICAL] CWE-399 CVE-2008-3608: ImageIO in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows context-dependent attackers to caus
ImageIO in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a crafted JPEG image with an embedded ICC profile.
nvd
CVE-2008-2332P3CRITICALCVSS 9.3v10.4.11v10.5+4 more2008-09-16
CVE-2008-2332 [CRITICAL] CWE-399 CVE-2008-2332: ImageIO in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows context-dependent attackers to caus
ImageIO in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a crafted TIFF image.
nvd