cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 73 of 157
CVE-2015-7074P3MEDIUMCVSS 6.8≤ 10.11.12015-12-11
CVE-2015-7074 [MEDIUM] CWE-119 CVE-2015-7074: CoreMedia Playback in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote a CoreMedia Playback in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed media file.
nvd
CVE-2015-5939P3MEDIUMCVSS 6.8≤ 10.11.02015-10-23
CVE-2015-5939 [MEDIUM] CVE-2015-5939: ImageIO in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attacke ImageIO in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted metadata in an image, a different vulnerability than CVE-2015-5935, CVE-2015-5936, and CVE-2015-5937.
nvd
CVE-2015-5937P3MEDIUMCVSS 6.8≤ 10.11.02015-10-23
CVE-2015-5937 [MEDIUM] CVE-2015-5937: ImageIO in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attacke ImageIO in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted metadata in an image, a different vulnerability than CVE-2015-5935, CVE-2015-5936, and CVE-2015-5939.
nvd
CVE-2015-5936P3MEDIUMCVSS 6.8≤ 10.11.02015-10-23
CVE-2015-5936 [MEDIUM] CVE-2015-5936: ImageIO in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attacke ImageIO in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted metadata in an image, a different vulnerability than CVE-2015-5935, CVE-2015-5937, and CVE-2015-5939.
nvd
CVE-2015-5935P3MEDIUMCVSS 6.8≤ 10.11.02015-10-23
CVE-2015-5935 [MEDIUM] CWE-119 CVE-2015-5935: ImageIO in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attacke ImageIO in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted metadata in an image, a different vulnerability than CVE-2015-5936, CVE-2015-5937, and CVE-2015-5939.
nvd
CVE-2019-8509P3HIGHCVSS 7.8≥ 10.13.6, < 10.15.12020-10-27
CVE-2019-8509 [HIGH] CVE-2019-8509: This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Catalina 10.1 This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, macOS Catalina 10.15. A malicious application may be able to elevate privileges.
nvd
CVE-2020-29620P3HIGHCVSS 7.8≥ 10.14, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-04-02
CVE-2020-29620 [HIGH] CWE-269 CVE-2020-29620: This issue was addressed with improved entitlements. This issue is fixed in macOS Big Sur 11.1, Secu This issue was addressed with improved entitlements. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may be able to elevate privileges.
nvd
CVE-2015-1093P3MEDIUMCVSS 6.8fixed in 10.10.32015-04-10
CVE-2015-1093 [MEDIUM] CVE-2015-1093: FontParser in Apple iOS before 8.3 and Apple OS X before 10.10.3 allows remote attackers to execute FontParser in Apple iOS before 8.3 and Apple OS X before 10.10.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file.
nvd
CVE-2015-7008P3MEDIUMCVSS 6.8≤ 10.11.02015-10-23
CVE-2015-7008 [MEDIUM] CVE-2015-7008: FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitr FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7009, CVE-2015-7010, and CVE-2015-7018.
nvd
CVE-2015-7018P3MEDIUMCVSS 6.8≤ 10.11.02015-10-23
CVE-2015-7018 [MEDIUM] CVE-2015-7018: FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitr FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7008, CVE-2015-7009, and CVE-2015-7010.
nvd
CVE-2015-7009P3MEDIUMCVSS 6.8≤ 10.11.02015-10-23
CVE-2015-7009 [MEDIUM] CVE-2015-7009: FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitr FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7008, CVE-2015-7010, and CVE-2015-7018.
nvd
CVE-2015-6991P3MEDIUMCVSS 6.8≤ 10.11.02015-10-23
CVE-2015-6991 [MEDIUM] CVE-2015-6991: FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitr FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6993, CVE-2015-7008, CVE-2015-7009, CVE-2015-7010, and CVE-2015-7018.
nvd
CVE-2015-6990P3MEDIUMCVSS 6.8≤ 10.11.02015-10-23
CVE-2015-6990 [MEDIUM] CVE-2015-6990: FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitr FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6991, CVE-2015-6993, CVE-2015-7008, CVE-2015-7009, CVE-2015-7010, and CVE-2015-7018.
nvd
CVE-2015-7010P3MEDIUMCVSS 6.8≤ 10.11.02015-10-23
CVE-2015-7010 [MEDIUM] CVE-2015-7010: FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitr FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7008, CVE-2015-7009, and CVE-2015-7018.
nvd
CVE-2015-6977P3MEDIUMCVSS 6.8≤ 10.11.02015-10-23
CVE-2015-6977 [MEDIUM] CVE-2015-6977: FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitr FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7008, CVE-2015-7009, CVE-2015-7010, and CVE-2015-7018.
nvd
CVE-2015-6976P3MEDIUMCVSS 6.8≤ 10.11.02015-10-23
CVE-2015-6976 [MEDIUM] CWE-119 CVE-2015-6976: FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitr FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7008, CVE-2015-7009, CVE-2015-7010, and CVE-2015-7018.
nvd
CVE-2015-6993P3MEDIUMCVSS 6.8≤ 10.11.02015-10-23
CVE-2015-6993 [MEDIUM] CVE-2015-6993: FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitr FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-7008, CVE-2015-7009, CVE-2015-7010, and CVE-2015-7018.
nvd
CVE-2016-1758P4LOWCVSS 3.3PoC≤ 10.11.32016-03-24
CVE-2016-1758 [LOW] CWE-119 CVE-2016-1758: The kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to obtain sensitive memo The kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to obtain sensitive memory-layout information or cause a denial of service (out-of-bounds read) via a crafted app.
nvd
CVE-2010-0524P3HIGHCVSS 7.5v10.6.0v10.6.1+1 more2010-03-30
CVE-2010-0524 [HIGH] CWE-264 CVE-2010-0524: The default configuration of the FreeRADIUS server in Apple Mac OS X Server before 10.6.3 permits EA The default configuration of the FreeRADIUS server in Apple Mac OS X Server before 10.6.3 permits EAP-TLS authenticated connections on the basis of an arbitrary client certificate, which allows remote attackers to obtain network connectivity via a crafted RADIUS Access Request message.
nvd
CVE-2018-4276P3HIGHCVSS 7.5fixed in 10.13.62019-04-03
CVE-2018-4276 [HIGH] CWE-476 CVE-2018-4276: A null pointer dereference was addressed with improved validation. This issue affected versions prio A null pointer dereference was addressed with improved validation. This issue affected versions prior to macOS High Sierra 10.13.6.
nvd
Apple macOS vulnerabilities | cvebase