Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 77 of 157
CVE-2016-1816P4HIGHCVSS 7.8≤ 10.11.42016-05-20
CVE-2016-1816 [HIGH] CVE-2016-1816: IOAcceleratorFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a pri
IOAcceleratorFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.
nvd
CVE-2011-0204P4MEDIUMCVSS 6.8v10.5.8v10.6.0+7 more2011-06-24
CVE-2011-0204 [MEDIUM] CWE-119 CVE-2011-0204: Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.8 allows remote attackers to exe
Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF image.
nvd
CVE-2016-4621P4HIGHCVSS 7.8≤ 10.11.52016-07-22
CVE-2016-4621 [HIGH] CWE-119 CVE-2016-4621: libc++abi in Apple OS X before 10.11.6 allows attackers to execute arbitrary code in a privileged co
libc++abi in Apple OS X before 10.11.6 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2016-1810P4HIGHCVSS 7.8≤ 10.11.42016-05-20
CVE-2016-1810 [HIGH] CWE-119 CVE-2016-1810: The Graphics Drivers subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary co
The Graphics Drivers subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2016-1792P4HIGHCVSS 7.8≤ 10.11.42016-05-20
CVE-2016-1792 [HIGH] CWE-119 CVE-2016-1792: The AMD subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privi
The AMD subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2016-1795P4HIGHCVSS 7.8≤ 10.11.42016-05-20
CVE-2016-1795 [HIGH] CWE-119 CVE-2016-1795: AppleGraphicsPowerManagement in Apple OS X before 10.11.5 allows attackers to execute arbitrary code
AppleGraphicsPowerManagement in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2016-1799P4HIGHCVSS 7.8≤ 10.11.42016-05-20
CVE-2016-1799 [HIGH] CWE-119 CVE-2016-1799: Audio in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged contex
Audio in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2016-1733P4HIGHCVSS 7.8≤ 10.11.32016-03-24
CVE-2016-1733 [HIGH] CWE-20 CVE-2016-1733: AppleRAID in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged co
AppleRAID in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2016-1759P4HIGHCVSS 7.8≤ 10.11.32016-03-24
CVE-2016-1759 [HIGH] CWE-119 CVE-2016-1759: The kernel in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged c
The kernel in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2014-8830P4MEDIUMCVSS 6.8≤ 10.10.12015-01-30
CVE-2014-8830 [MEDIUM] CWE-119 CVE-2014-8830: Heap-based buffer overflow in SceneKit in Apple OS X before 10.10.2 allows remote attackers to execu
Heap-based buffer overflow in SceneKit in Apple OS X before 10.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted accessor element in a Collada file.
nvd
CVE-2016-4594P4HIGHCVSS 7.8fixed in 10.11.62016-07-22
CVE-2016-4594 [HIGH] CWE-20 CVE-2016-4594: The Sandbox Profiles component in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, an
The Sandbox Profiles component in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows attackers to access the process list via a crafted app that makes an API call.
nvd
CVE-2014-4483P4MEDIUMCVSS 6.8≤ 10.10.12015-01-30
CVE-2014-4483 [MEDIUM] CWE-119 CVE-2014-4483: Buffer overflow in FontParser in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV bef
Buffer overflow in FontParser in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted font file in a PDF document.
nvd
CVE-2017-2546P4HIGHCVSS 7.8≤ 10.12.42017-05-22
CVE-2017-2546 [HIGH] CWE-119 CVE-2017-2546: An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2015-3667P4MEDIUMCVSS 6.8≤ 10.10.32015-07-03
CVE-2015-3667 [MEDIUM] CVE-2015-3667: QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other produc
QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3661, CVE-2015-3662, CVE-2015-3663, CVE-2015-3666, and CVE-2015-3668.
nvd
CVE-2017-6985P4HIGHCVSS 7.8≤ 10.12.42017-05-22
CVE-2017-6985 [HIGH] CWE-119 CVE-2017-6985: An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "NVIDIA Graphics Drivers" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-2421P4HIGHCVSS 7.8≤ 10.12.32017-04-02
CVE-2017-2421 [HIGH] CWE-362 CVE-2017-2421: An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "AppleGraphicsPowerManagement" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2016-7584P4HIGHCVSS 7.8≤ 10.12.02017-02-20
CVE-2016-7584 [HIGH] CWE-254 CVE-2016-7584: An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "AppleMobileFileIntegrity" component, which allows remote attackers to spoof signed code by using a matching team ID.
nvd
CVE-2018-4420P4HIGHCVSS 7.8fixed in 10.14.12019-04-03
CVE-2018-4420 [HIGH] CWE-119 CVE-2018-4420: A memory corruption issue was addressed by removing the vulnerable code. This issue affected version
A memory corruption issue was addressed by removing the vulnerable code. This issue affected versions prior to iOS 12.1, macOS Mojave 10.14.1, tvOS 12.1, watchOS 5.1.
nvd
CVE-2018-4402P3HIGHCVSS 7.8fixed in 10.14.12019-04-03
CVE-2018-4402 [HIGH] CWE-119 CVE-2018-4402: A memory corruption issue was addressed with improved memory handling. This issue affected versions
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to macOS Mojave 10.14.1.
nvd
CVE-2018-4449P3HIGHCVSS 7.8fixed in 10.14.22019-04-03
CVE-2018-4449 [HIGH] CWE-119 CVE-2018-4449: A memory corruption issue was addressed with improved memory handling. This issue affected versions
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to macOS Mojave 10.14.2.
nvd