cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 78 of 157
CVE-2018-4393P3HIGHCVSS 7.8fixed in 10.142019-04-03
CVE-2018-4393 [HIGH] CWE-119 CVE-2018-4393: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to macOS Mojave 10.14.
nvd
CVE-2014-8828P4HIGHCVSS 7.5≤ 10.9.52015-01-30
CVE-2014-8828 [HIGH] CWE-264 CVE-2014-8828: Sandbox in Apple OS X before 10.10 allows attackers to write to the sandbox-profile cache via a sand Sandbox in Apple OS X before 10.10 allows attackers to write to the sandbox-profile cache via a sandboxed app that includes a com.apple.sandbox segment in a path.
nvd
CVE-2018-4303P4HIGHCVSS 7.8fixed in 10.14v10.14.12019-04-03
CVE-2018-4303 [HIGH] CWE-20 CVE-2018-4303: An input validation issue was addressed with improved input validation. This issue affected versions An input validation issue was addressed with improved input validation. This issue affected versions prior to macOS Mojave 10.14, iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2.
nvd
CVE-2018-4334P3HIGHCVSS 7.8fixed in 10.142019-04-03
CVE-2018-4334 [HIGH] CWE-119 CVE-2018-4334: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to macOS Mojave 10.14.
nvd
CVE-2018-4451P3HIGHCVSS 7.8fixed in 10.142020-10-27
CVE-2018-4451 [HIGH] CVE-2018-4451: This issue is fixed in macOS Mojave 10.14. A memory corruption issue was addressed with improved inp This issue is fixed in macOS Mojave 10.14. A memory corruption issue was addressed with improved input validation.
nvd
CVE-2020-9788P4HIGHCVSS 7.8fixed in 10.15.52020-06-09
CVE-2020-9788 [HIGH] CWE-20 CVE-2020-9788: A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Cata A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.5. A file may be incorrectly rendered to execute JavaScript.
nvd
CVE-2014-1255P4HIGHCVSS 7.5≤ 10.9.1v10.92014-02-27
CVE-2014-1255 [HIGH] CWE-20 CVE-2014-1255: Apple Type Services (ATS) in Apple OS X before 10.9.2 does not properly validate calls to the free f Apple Type Services (ATS) in Apple OS X before 10.9.2 does not properly validate calls to the free function, which allows attackers to bypass the App Sandbox protection mechanism via crafted Mach messages.
nvd
CVE-2009-2824P4MEDIUMCVSS 6.8v10.5.82009-11-10
CVE-2009-2824 [MEDIUM] CWE-119 CVE-2009-2824: Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 allow remote attacke Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 allow remote attackers to execute arbitrary code via a crafted embedded font in a document.
nvd
CVE-2010-1846P4MEDIUMCVSS 6.8v10.5.8v10.6.0+4 more2010-11-16
CVE-2010-1846 [MEDIUM] CWE-119 CVE-2010-1846: Heap-based buffer overflow in Image RAW in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows rem Heap-based buffer overflow in Image RAW in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted RAW image.
nvd
CVE-2010-1831P4MEDIUMCVSS 6.8v10.5.8v10.6.0+4 more2010-11-15
CVE-2010-1831 [MEDIUM] CWE-119 CVE-2010-1831: Buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allow Buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code via a long name of an embedded font in a document.
nvd
CVE-2010-1832P4MEDIUMCVSS 6.8v10.5.8v10.6.0+4 more2010-11-15
CVE-2010-1832 [MEDIUM] CWE-119 CVE-2010-1832: Stack-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 and 10.6.x before Stack-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code via a crafted embedded font in a document.
nvd
CVE-2018-4450P3HIGHCVSS 7.8fixed in 10.14.22019-04-03
CVE-2018-4450 [HIGH] CWE-119 CVE-2018-4450: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to macOS Mojave 10.14.2.
nvd
CVE-2018-4285P4HIGHCVSS 7.8fixed in 10.13.62019-04-03
CVE-2018-4285 [HIGH] CWE-704 CVE-2018-4285: A type confusion issue was addressed with improved memory handling. This issue affected versions pri A type confusion issue was addressed with improved memory handling. This issue affected versions prior to macOS High Sierra 10.13.6.
nvd
CVE-2018-4463P3HIGHCVSS 7.8fixed in 10.14.22019-04-03
CVE-2018-4463 [HIGH] CWE-119 CVE-2018-4463: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to macOS Mojave 10.14.2.
nvd
CVE-2015-5773P4MEDIUMCVSS 6.8≤ 10.10.42015-08-17
CVE-2015-5773 [MEDIUM] CWE-119 CVE-2015-5773: QL Office in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbit QL Office in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted office document.
nvd
CVE-2015-5758P4MEDIUMCVSS 6.8≤ 10.10.42015-08-17
CVE-2015-5758 [MEDIUM] CWE-119 CVE-2015-5758: ImageIO in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitra ImageIO in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted TIFF image.
nvd
CVE-2015-5756P4MEDIUMCVSS 6.8≤ 10.10.42015-08-17
CVE-2015-5756 [MEDIUM] CVE-2015-5756: FontParser in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbi FontParser in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-3804 and CVE-2015-5775.
nvd
CVE-2015-3666P4MEDIUMCVSS 6.8≤ 10.10.32015-07-03
CVE-2015-3666 [MEDIUM] CVE-2015-3666: QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other produc QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3661, CVE-2015-3662, CVE-2015-3663, CVE-2015-3667, and CVE-2015-3668.
nvd
CVE-2015-3668P4MEDIUMCVSS 6.8≤ 10.10.32015-07-03
CVE-2015-3668 [MEDIUM] CVE-2015-3668: QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other produc QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3661, CVE-2015-3662, CVE-2015-3663, CVE-2015-3666, and CVE-2015-3667.
nvd
CVE-2015-3689P4MEDIUMCVSS 6.8≤ 10.10.32015-07-03
CVE-2015-3689 [MEDIUM] CVE-2015-3689: CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrar CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted text file, a different vulnerability than CVE-2015-3685, CVE-2015-3686, CVE-2015-3687, and CVE-2015-3688.
nvd
Apple macOS vulnerabilities | cvebase