cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 72 of 157
CVE-2018-4456P3HIGHCVSS 7.8fixed in 10.13.62019-04-03
CVE-2018-4456 [HIGH] CWE-119 CVE-2018-4456: A memory corruption issue was addressed with improved input validation. This issue affected versions A memory corruption issue was addressed with improved input validation. This issue affected versions prior to macOS High Sierra 10.13.6, macOS Mojave 10.14.
nvd
CVE-2019-8837P3HIGHCVSS 7.8fixed in 10.15.22020-10-27
CVE-2019-8837 [HIGH] CVE-2019-8837: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15. A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. A malicious application may be able to access restricted files.
nvd
CVE-2015-1139P3MEDIUMCVSS 6.8fixed in 10.10.32015-04-10
CVE-2015-1139 [MEDIUM] CWE-20 CVE-2015-1139: ImageIO in Apple OS X before 10.10.3 allows remote attackers to execute arbitrary code or cause a de ImageIO in Apple OS X before 10.10.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .sgi file.
nvd
CVE-2018-4411P3HIGHCVSS 7.8fixed in 10.142019-04-03
CVE-2018-4411 [HIGH] CWE-119 CVE-2018-4411: A memory corruption issue was addressed with improved input validation. This issue affected versions A memory corruption issue was addressed with improved input validation. This issue affected versions prior to macOS Mojave 10.14.
nvd
CVE-2018-4427P3HIGHCVSS 7.8fixed in 10.14.22019-04-03
CVE-2018-4427 [HIGH] CWE-119 CVE-2018-4427: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to: iOS 12.1, watchOS 5.1.2, tvOS 12.1.1, macOS High Sierra 10.13.6 Security Update 2018-003 High Sierra, macOS Sierra 10.12.6 Security Update 2018-006.
nvd
CVE-2021-30787P3HIGHCVSS 7.8≥ 10.14, ≤ 10.14.5≥ 10.15, ≤ 10.15.6+2 more2021-09-08
CVE-2021-30787 [HIGH] CVE-2021-30787: This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.5, Security U This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. An application may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2019-8542P3HIGHCVSS 7.8fixed in 10.14.42019-12-18
CVE-2019-8542 [HIGH] CWE-120 CVE-2019-8542: A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.2, macO A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. A malicious application may be able to elevate privileges.
nvd
CVE-2016-4638P3HIGHCVSS 7.8≤ 10.11.52016-07-22
CVE-2016-4638 [HIGH] CWE-264 CVE-2016-4638: Login Window in Apple OS X before 10.11.6 allows attackers to gain privileges via a crafted app that Login Window in Apple OS X before 10.11.6 allows attackers to gain privileges via a crafted app that leverages a "type confusion."
nvd
CVE-2019-8511P3HIGHCVSS 7.8fixed in 10.14.42019-12-18
CVE-2019-8511 [HIGH] CWE-120 CVE-2019-8511: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.2 A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, watchOS 5.2. A malicious application may be able to elevate privileges.
nvd
CVE-2019-6221P3HIGHCVSS 7.8fixed in 10.14.32019-03-05
CVE-2019-6221 [HIGH] CWE-125 CVE-2019-6221: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3 An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, iTunes 12.9.3 for Windows. A malicious application may be able to elevate privileges.
nvd
CVE-2018-4410P3HIGHCVSS 7.8fixed in 10.14.12019-04-03
CVE-2018-4410 [HIGH] CWE-119 CVE-2018-4410: A memory corruption issue was addressed with improved input validation. This issue affected versions A memory corruption issue was addressed with improved input validation. This issue affected versions prior to macOS Mojave 10.14.1.
nvd
CVE-2018-4350P3HIGHCVSS 7.8fixed in 10.142019-04-03
CVE-2018-4350 [HIGH] CWE-119 CVE-2018-4350: A memory corruption issue was addressed with improved input validation. This issue affected versions A memory corruption issue was addressed with improved input validation. This issue affected versions prior to macOS Mojave 10.14.
nvd
CVE-2018-4326P3HIGHCVSS 7.8fixed in 10.142019-04-03
CVE-2018-4326 [HIGH] CWE-119 CVE-2018-4326: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14.
nvd
CVE-2017-13911P3HIGHCVSS 7.8fixed in 10.11.6≥ 10.12, < 10.12.6+1 more2019-04-03
CVE-2017-13911 [HIGH] CWE-20 CVE-2017-13911: A configuration issue was addressed with additional restrictions. This issue affected versions prior A configuration issue was addressed with additional restrictions. This issue affected versions prior to macOS X El Capitan 10.11.6 Security Update 2018-002, macOS Sierra 10.12.6 Security Update 2018-002, macOS High Sierra 10.13.2.
nvd
CVE-2015-7016P3HIGHCVSS 7.6≤ 10.11.02015-10-23
CVE-2015-7016 [HIGH] CWE-264 CVE-2015-7016: The MCX Application Restrictions component in Apple OS X before 10.11.1, when Managed Configuration The MCX Application Restrictions component in Apple OS X before 10.11.1, when Managed Configuration is enabled, mishandles provisioning profiles, which allows attackers to bypass intended entitlement restrictions and gain privileges via a crafted developer-signed app.
nvd
CVE-2020-9827P3HIGHCVSS 7.5fixed in 10.15.52020-06-09
CVE-2020-9827 [HIGH] CVE-2020-9827: A denial of service issue was addressed with improved input validation. This issue is fixed in iOS 1 A denial of service issue was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A remote attacker may be able to cause a denial of service.
nvd
CVE-2020-9924P3HIGHCVSS 7.5fixed in 10.15.62020-10-22
CVE-2020-9924 [HIGH] CVE-2020-9924: A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10 A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15.6. A remote attacker may be able to cause a denial of service.
nvd
CVE-2015-3686P3MEDIUMCVSS 6.8≤ 10.10.32015-07-03
CVE-2015-3686 [MEDIUM] CVE-2015-3686: CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrar CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted text file, a different vulnerability than CVE-2015-3685, CVE-2015-3687, CVE-2015-3688, and CVE-2015-3689.
nvd
CVE-2015-3687P3MEDIUMCVSS 6.8≤ 10.10.32015-07-03
CVE-2015-3687 [MEDIUM] CVE-2015-3687: CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrar CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted text file, a different vulnerability than CVE-2015-3685, CVE-2015-3686, CVE-2015-3688, and CVE-2015-3689.
nvd
CVE-2015-3688P3MEDIUMCVSS 6.8≤ 10.10.32015-07-03
CVE-2015-3688 [MEDIUM] CVE-2015-3688: CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrar CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted text file, a different vulnerability than CVE-2015-3685, CVE-2015-3686, CVE-2015-3687, and CVE-2015-3689.
nvd
Apple macOS vulnerabilities | cvebase