Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 76 of 157
CVE-2009-0154P3MEDIUMCVSS 6.8v10.4.11v10.5.0+6 more2009-05-13
CVE-2009-0154 [MEDIUM] CWE-119 CVE-2009-0154: Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.4.11 and 10.5 before 10
Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code via a crafted Compact Font Format (CFF) font.
nvd
CVE-2015-5312P4HIGHCVSS 7.1≤ 10.11.32015-12-15
CVE-2015-5312 [HIGH] CVE-2015-5312: The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly preven
The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.
nvd
CVE-2017-2534P4HIGHCVSS 8.6≤ 10.12.42017-05-22
CVE-2017-2534 [HIGH] CVE-2017-2534: An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Speech Framework" component. It allows attackers to conduct sandbox-escape attacks via a crafted app.
nvd
CVE-2009-2828P3HIGHCVSS 7.5v10.5.82009-11-10
CVE-2009-2828 [HIGH] CWE-399 CVE-2009-2828: The server in DirectoryService in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary
The server in DirectoryService in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.
nvd
CVE-2008-1028P4CRITICALCVSS 9.3v10.4.112008-06-02
CVE-2008-1028 [CRITICAL] CWE-20 CVE-2008-1028: Unspecified vulnerability in AppKit in Apple Mac OS X before 10.5 allows user-assisted remote attack
Unspecified vulnerability in AppKit in Apple Mac OS X before 10.5 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted document file, as demonstrated by opening the document with TextEdit.
nvd
CVE-2015-5522P4MEDIUMCVSS 6.8≤ 10.6.82015-08-11
CVE-2015-5522 [MEDIUM] CWE-119 CVE-2015-5522: Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote
Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving a command character in an href.
nvd
CVE-2016-7643P4HIGHCVSS 8.1≤ 10.12.12017-02-20
CVE-2016-7643 [HIGH] CWE-125 CVE-2016-7643: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "ImageIO" component. It allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and application crash) via a crafte
nvd
CVE-2014-1261P4HIGHCVSS 7.5≤ 10.9.1v10.92014-02-27
CVE-2014-1261 [HIGH] CWE-189 CVE-2014-1261: Integer signedness error in CoreText in Apple OS X before 10.9.2 allows remote attackers to execute
Integer signedness error in CoreText in Apple OS X before 10.9.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Unicode font.
nvd
CVE-2010-0500P4HIGHCVSS 7.8≤ 10.6.2v10.5+11 more2010-03-30
CVE-2010-0500 [HIGH] CWE-20 CVE-2010-0500: Event Monitor in Apple Mac OS X before 10.6.3 does not properly validate hostnames of SSH clients, w
Event Monitor in Apple Mac OS X before 10.6.3 does not properly validate hostnames of SSH clients, which allows remote attackers to cause a denial of service (arbitrary client blacklisting) via a crafted DNS PTR record, related to a "plist injection issue."
nvd
CVE-2014-1391P4MEDIUMCVSS 6.8v10.7.5v10.8.5+5 more2014-09-19
CVE-2014-1391 [MEDIUM] CWE-119 CVE-2014-1391: QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or
QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with RLE encoding.
nvd
CVE-2006-4404P4CRITICALCVSS 10.0≤ 10.4.82006-11-30
CVE-2006-4404 [CRITICAL] CVE-2006-4404: The Installer application in Apple Mac OS X 10.4.8 and earlier, when used by a user with Admin crede
The Installer application in Apple Mac OS X 10.4.8 and earlier, when used by a user with Admin credentials, does not authenticate the user before installing certain software requiring system privileges.
nvd
CVE-2017-7126P4CRITICALCVSS 9.8≤ 10.12.62017-10-23
CVE-2017-7126 [CRITICAL] CWE-20 CVE-2017-7126: An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involve
An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the third-party "file" product. Versions before 5.30 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
nvd
CVE-2017-7076P4HIGHCVSS 7.8≤ 10.12.62017-10-23
CVE-2017-7076 [HIGH] CWE-119 CVE-2017-7076: An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves th
An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Mach-O file.
nvd
CVE-2016-4724P4HIGHCVSS 7.8≤ 10.11.62016-09-25
CVE-2016-4724 [HIGH] CWE-476 CVE-2016-4724: IOAcceleratorFamily in Apple iOS before 10 and OS X before 10.12 allows attackers to execute arbitra
IOAcceleratorFamily in Apple iOS before 10 and OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.
nvd
CVE-2016-1822P4HIGHCVSS 7.8≤ 10.11.42016-05-20
CVE-2016-1822 [HIGH] CWE-119 CVE-2016-1822: IOFireWireFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privil
IOFireWireFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2016-4780P4HIGHCVSS 7.8≤ 10.12.02017-02-20
CVE-2016-4780 [HIGH] CWE-476 CVE-2016-4780: An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "Thunderbolt" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.
nvd
CVE-2016-4683P4HIGHCVSS 7.8≤ 10.12.02017-02-20
CVE-2016-4683 [HIGH] CWE-119 CVE-2016-4683: An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "ImageIO" component. It allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds memory access and application crash) via a crafted SGI file.
nvd
CVE-2018-4183P4HIGHCVSS 8.2fixed in 10.13.52019-01-11
CVE-2018-4183 [HIGH] CVE-2018-4183: In macOS High Sierra before 10.13.5, an access issue was addressed with additional sandbox restricti
In macOS High Sierra before 10.13.5, an access issue was addressed with additional sandbox restrictions.
nvd
CVE-2018-4182P4HIGHCVSS 8.2fixed in 10.13.52019-01-11
CVE-2018-4182 [HIGH] CVE-2018-4182: In macOS High Sierra before 10.13.5, an access issue was addressed with additional sandbox restricti
In macOS High Sierra before 10.13.5, an access issue was addressed with additional sandbox restrictions on CUPS.
nvd
CVE-2016-1756P4HIGHCVSS 7.8≤ 10.11.32016-03-24
CVE-2016-1756 [HIGH] CVE-2016-1756: The kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to execute arbitrary cod
The kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.
nvd