Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 79 of 157
CVE-2015-3661P4MEDIUMCVSS 6.8≤ 10.10.32015-07-03
CVE-2015-3661 [MEDIUM] CWE-119 CVE-2015-3661: QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other produc
QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3662, CVE-2015-3663, CVE-2015-3666, CVE-2015-3667, and CVE-2015-3668.
nvd
CVE-2015-3662P4MEDIUMCVSS 6.8≤ 10.10.32015-07-03
CVE-2015-3662 [MEDIUM] CVE-2015-3662: QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other produc
QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3661, CVE-2015-3663, CVE-2015-3666, CVE-2015-3667, and CVE-2015-3668.
nvd
CVE-2015-3685P4MEDIUMCVSS 6.8≤ 10.10.32015-07-03
CVE-2015-3685 [MEDIUM] CWE-119 CVE-2015-3685: CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrar
CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted text file, a different vulnerability than CVE-2015-3686, CVE-2015-3687, CVE-2015-3688, and CVE-2015-3689.
nvd
CVE-2015-3663P4MEDIUMCVSS 6.8≤ 10.10.32015-07-03
CVE-2015-3663 [MEDIUM] CVE-2015-3663: QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other produc
QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3661, CVE-2015-3662, CVE-2015-3666, CVE-2015-3667, and CVE-2015-3668.
nvd
CVE-2014-4427P4HIGHCVSS 7.5≤ 10.9.52014-10-18
CVE-2014-4427 [HIGH] CWE-264 CVE-2014-4427: App Sandbox in Apple OS X before 10.10 allows attackers to bypass a sandbox protection mechanism via
App Sandbox in Apple OS X before 10.10 allows attackers to bypass a sandbox protection mechanism via the accessibility API.
nvd
CVE-2020-9826P4HIGHCVSS 7.5fixed in 10.15.52020-06-09
CVE-2020-9826 [HIGH] CWE-20 CVE-2020-9826: A denial of service issue was addressed with improved input validation. This issue is fixed in iOS 1
A denial of service issue was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5. A remote attacker may be able to cause a denial of service.
nvd
CVE-2010-4010P4MEDIUMCVSS 6.8v10.5.82010-11-16
CVE-2010-4010 [MEDIUM] CWE-189 CVE-2010-4010: Integer signedness error in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 allows remote attacke
Integer signedness error in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary code via a crafted embedded Compact Font Format (CFF) font in a document.
nvd
CVE-2015-3669P4MEDIUMCVSS 6.8≤ 10.10.32015-07-03
CVE-2015-3669 [MEDIUM] CVE-2015-3669: QT Media Foundation in Apple QuickTime before 7.7.7 allows remote attackers to execute arbitrary cod
QT Media Foundation in Apple QuickTime before 7.7.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3664 and CVE-2015-3665.
nvd
CVE-2016-4626P4HIGHCVSS 7.8fixed in 10.11.62016-07-22
CVE-2016-4626 [HIGH] CWE-476 CVE-2016-4626: IOHIDFamily in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.
IOHIDFamily in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors.
nvd
CVE-2015-3794P4MEDIUMCVSS 6.8≤ 10.10.42015-08-17
CVE-2015-3794 [MEDIUM] CWE-119 CVE-2015-3794: The Speech UI in Apple OS X before 10.10.5, when speech alerts are enabled, allows remote attackers
The Speech UI in Apple OS X before 10.10.5, when speech alerts are enabled, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Unicode string.
nvd
CVE-2011-0176P4MEDIUMCVSS 6.8≤ 10.6.6v10.6.0+5 more2011-03-23
CVE-2011-0176 [MEDIUM] CWE-119 CVE-2011-0176: Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote
Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code via a document that contains a crafted embedded Type 1 font.
nvd
CVE-2011-0177P4MEDIUMCVSS 6.8≤ 10.6.6v10.6.0+5 more2011-03-23
CVE-2011-0177 [MEDIUM] CWE-119 CVE-2011-0177: Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote
Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code via a document that contains a crafted SFNT table in an embedded font.
nvd
CVE-2011-0175P4MEDIUMCVSS 6.8≤ 10.6.6v10.6.0+5 more2011-03-23
CVE-2011-0175 [MEDIUM] CWE-119 CVE-2011-0175: Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote
Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code via a document that contains a crafted embedded TrueType font.
nvd
CVE-2016-1716P4HIGHCVSS 7.8≤ 10.11.22016-02-01
CVE-2016-1716 [HIGH] CWE-119 CVE-2016-1716: AppleGraphicsPowerManagement in Apple OS X before 10.11.3 allows local users to gain privileges or c
AppleGraphicsPowerManagement in Apple OS X before 10.11.3 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2016-1809P4HIGHCVSS 7.5≤ 10.11.42016-05-20
CVE-2016-1809 [HIGH] CVE-2016-1809: Disk Utility in Apple OS X before 10.11.5 uses incorrect encryption keys for disk images, which has
Disk Utility in Apple OS X before 10.11.5 uses incorrect encryption keys for disk images, which has unspecified impact and attack vectors.
nvd
CVE-2017-2477P4CRITICALCVSS 9.8≤ 10.12.32017-04-02
CVE-2017-2477 [CRITICAL] CWE-119 CVE-2017-2477: An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "libxslt" component. It allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2019-8851P4HIGHCVSS 7.5fixed in 10.15.22020-10-27
CVE-2019-8851 [HIGH] CVE-2019-8851: A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10
A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. A Mac may not lock immediately upon wake.
nvd
CVE-2015-7064P4MEDIUMCVSS 6.8≤ 10.11.12015-12-11
CVE-2015-7064 [MEDIUM] CWE-119 CVE-2015-7064: OpenGL in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows
OpenGL in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2015-7066.
nvd
CVE-2015-7066P4MEDIUMCVSS 6.8≤ 10.11.12015-12-11
CVE-2015-7066 [MEDIUM] CVE-2015-7066: OpenGL in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows
OpenGL in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2015-7064.
nvd
CVE-2015-5944P4MEDIUMCVSS 6.8≤ 10.11.02015-10-23
CVE-2015-5944 [MEDIUM] CWE-119 CVE-2015-5944: CoreText in Apple OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a d
CoreText in Apple OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file.
nvd