Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 74 of 157
CVE-2015-3713P3MEDIUMCVSS 6.8≤ 10.10.32015-07-03
CVE-2015-3713 [MEDIUM] CWE-119 CVE-2015-3713: QuickTime in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a
QuickTime in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted movie file.
nvd
CVE-2019-8755P3HIGHCVSS 7.8fixed in 10.152019-12-18
CVE-2019-8755 [HIGH] CWE-476 CVE-2019-8755: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15. A malicious application may be able to determine kernel memory layout.
nvd
CVE-2014-4391P3MEDIUMCVSS 6.8≤ 10.9.42014-10-18
CVE-2014-4391 [MEDIUM] CWE-310 CVE-2014-4391: The Code Signing feature in Apple OS X before 10.10 does not properly handle incomplete resource env
The Code Signing feature in Apple OS X before 10.10 does not properly handle incomplete resource envelopes in signed bundles, which allows remote attackers to bypass intended app-author restrictions by omitting an execution-related resource.
nvd
CVE-2015-7107P3MEDIUMCVSS 6.8≤ 10.11.12015-12-11
CVE-2015-7107 [MEDIUM] CWE-119 CVE-2015-7107: QuickLook in Apple iOS before 9.2 and OS X before 10.11.2 allows remote attackers to execute arbitra
QuickLook in Apple iOS before 9.2 and OS X before 10.11.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted iWork file.
nvd
CVE-2014-4375P3HIGHCVSS 7.8≤ 10.9.52014-09-18
CVE-2014-4375 [HIGH] CVE-2014-4375: Double free vulnerability in Apple iOS before 8 and Apple TV before 7 allows local users to gain pri
Double free vulnerability in Apple iOS before 8 and Apple TV before 7 allows local users to gain privileges or cause a denial of service (device crash) via vectors related to Mach ports.
nvd
CVE-2016-4634P3HIGHCVSS 7.8≤ 10.11.52016-07-22
CVE-2016-4634 [HIGH] CWE-119 CVE-2016-4634: The Graphics Drivers subsystem in Apple OS X before 10.11.6 allows local users to gain privileges or
The Graphics Drivers subsystem in Apple OS X before 10.11.6 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2018-4170P3HIGHCVSS 7.8fixed in 10.13.42018-04-03
CVE-2018-4170 [HIGH] CWE-522 CVE-2018-4170: An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Admin Framework" component. It allows local users to discover a password by listing a process and its arguments during sysadminctl execution.
nvd
CVE-2019-8618P3HIGHCVSS 7.5fixed in 10.14.42020-10-27
CVE-2019-8618 [HIGH] CVE-2019-8618: A logic issue was addressed with improved restrictions. This issue is fixed in watchOS 5.2, macOS Mo
A logic issue was addressed with improved restrictions. This issue is fixed in watchOS 5.2, macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, iOS 12.2. A sandboxed process may be able to circumvent sandbox restrictions.
nvd
CVE-2019-8533P3HIGHCVSS 7.8fixed in 10.14.42019-12-18
CVE-2019-8533 [HIGH] CWE-287 CVE-2019-8533: A lock handling issue was addressed with improved lock handling. This issue is fixed in macOS Mojave
A lock handling issue was addressed with improved lock handling. This issue is fixed in macOS Mojave 10.14.4. A Mac may not lock when disconnecting from an external monitor.
nvd
CVE-2023-27960P3HIGHCVSS 7.8≥ 10.0, < 10.4.82023-05-08
CVE-2023-27960 [HIGH] CVE-2023-27960: This issue was addressed by removing the vulnerable code. This issue is fixed in GarageBand for macO
This issue was addressed by removing the vulnerable code. This issue is fixed in GarageBand for macOS 10.4.8. An app may be able to gain elevated privileges during the installation of GarageBand.
nvd
CVE-2017-13890P3HIGHCVSS 7.4fixed in 10.13.42018-04-03
CVE-2017-13890 [HIGH] CWE-20 CVE-2017-13890: An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. macOS before 10
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. macOS before 10.13 is affected. The issue involves the "CoreTypes" component. It allows remote attackers to trigger disk-image mounting via a crafted web site.
nvd
CVE-2008-2939P4MEDIUMCVSS 4.3≤ 10.5.62008-08-06
CVE-2008-2939 [MEDIUM] CWE-79 CVE-2008-2939: Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63
Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.
nvd
CVE-2015-7015P3MEDIUMCVSS 6.8≤ 10.11.02015-10-23
CVE-2015-7015 [MEDIUM] CWE-119 CVE-2015-7015: Heap-based buffer overflow in the DNS client library in configd in Apple iOS before 9.1, OS X before
Heap-based buffer overflow in the DNS client library in configd in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows attackers to execute arbitrary code via a crafted app that sends a spoofed configd response to a client.
nvd
CVE-2021-30938P3HIGHCVSS 7.7≥ 10.15, < 10.15.7v10.15.72021-08-24
CVE-2021-30938 [HIGH] CVE-2021-30938: This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.1, Security
This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.1, Security Update 2021-008 Catalina, macOS Big Sur 11.6.2. A local user may be able to cause unexpected system termination or read kernel memory.
nvd
CVE-2017-13887P3HIGHCVSS 7.5fixed in 10.13.22019-01-11
CVE-2017-13887 [HIGH] CWE-320 CVE-2017-13887: In macOS High Sierra before 10.13.2, a logic issue existed in APFS when deleting keys during hiberna
In macOS High Sierra before 10.13.2, a logic issue existed in APFS when deleting keys during hibernation. This was addressed with improved state management.
nvd
CVE-2020-9824P3HIGHCVSS 7.5fixed in 10.15.52020-06-09
CVE-2020-9824 [HIGH] CVE-2020-9824: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.5. A non-privileged user may be able to modify restricted network settings.
nvd
CVE-2015-5938P3MEDIUMCVSS 6.8≤ 10.11.02015-10-23
CVE-2015-5938 [MEDIUM] CWE-119 CVE-2015-5938: ImageIO in Apple OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a de
ImageIO in Apple OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted metadata in an image.
nvd
CVE-2015-0228P4MEDIUMCVSS 5.0v10.10.42015-03-08
CVE-2015-0228 [MEDIUM] CWE-20 CVE-2015-0228: The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server thr
The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Ping frame after a Lua script has called the wsupgrade function.
nvd
CVE-2015-3718P3MEDIUMCVSS 6.8≤ 10.10.32015-07-03
CVE-2015-3718 [MEDIUM] CVE-2015-3718: systemstatsd in the System Stats subsystem in Apple OS X before 10.10.4 does not properly interpret
systemstatsd in the System Stats subsystem in Apple OS X before 10.10.4 does not properly interpret data types encountered in interprocess communication, which allows attackers to execute arbitrary code with systemstatsd privileges via a crafted app, related to a "type confusion" issue.
nvd
CVE-2015-7060P3MEDIUMCVSS 6.8≤ 10.11.12015-12-11
CVE-2015-7060 [MEDIUM] CVE-2015-7060: The ASN.1 decoder in Apple OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remot
The ASN.1 decoder in Apple OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate, a different vulnerability than CVE-2015-7059 and CVE-2015-7061.
nvd