Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 80 of 157
CVE-2015-5926P4MEDIUMCVSS 6.8≤ 10.11.02015-10-23
CVE-2015-5926 [MEDIUM] CVE-2015-5926: The CoreGraphics component in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 al
The CoreGraphics component in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2015-5925.
nvd
CVE-2015-5925P4MEDIUMCVSS 6.8≤ 10.11.02015-10-23
CVE-2015-5925 [MEDIUM] CWE-119 CVE-2015-5925: The CoreGraphics component in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 al
The CoreGraphics component in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2015-5926.
nvd
CVE-2015-5933P4MEDIUMCVSS 6.8≤ 10.11.02015-10-23
CVE-2015-5933 [MEDIUM] CWE-119 CVE-2015-5933: Audio in Apple OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a deni
Audio in Apple OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted audio file, a different vulnerability than CVE-2015-5934.
nvd
CVE-2015-5934P4MEDIUMCVSS 6.8≤ 10.11.02015-10-23
CVE-2015-5934 [MEDIUM] CVE-2015-5934: Audio in Apple OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a deni
Audio in Apple OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted audio file, a different vulnerability than CVE-2015-5933.
nvd
CVE-2015-7065P4MEDIUMCVSS 6.8≤ 10.11.12015-12-11
CVE-2015-7065 [MEDIUM] CWE-119 CVE-2015-7065: OpenGL in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to
OpenGL in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
nvd
CVE-2015-1104P4MEDIUMCVSS 5.0≤ 10.10.22015-04-10
CVE-2015-1104 [MEDIUM] CWE-20 CVE-2015-1104: The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 does not prop
The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 does not properly determine whether an IPv6 packet had a local origin, which allows remote attackers to bypass an intended network-filtering protection mechanism via a crafted packet.
nvd
CVE-2015-5940P4MEDIUMCVSS 6.8≤ 10.11.02015-10-23
CVE-2015-5940 [MEDIUM] CWE-119 CVE-2015-5940: The Accelerate Framework component in Apple iOS before 9.1 and OS X before 10.11.1, when multi-threa
The Accelerate Framework component in Apple iOS before 9.1 and OS X before 10.11.1, when multi-threading is enabled, omits certain validation and locking steps, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
nvd
CVE-2015-5924P4MEDIUMCVSS 6.8≤ 10.11.02015-10-23
CVE-2015-5924 [MEDIUM] CWE-119 CVE-2015-5924: The OpenGL implementation in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to
The OpenGL implementation in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
nvd
CVE-2013-0976P4MEDIUMCVSS 6.8≤ 10.8.2v10.8.0+1 more2013-03-15
CVE-2013-0976 [MEDIUM] CWE-119 CVE-2013-0976: IOAcceleratorFamily in Apple Mac OS X before 10.8.3 allows remote attackers to execute arbitrary cod
IOAcceleratorFamily in Apple Mac OS X before 10.8.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted graphics image.
nvd
CVE-2006-4095P4HIGHCVSS 7.5fixed in 10.3.9≥ 10.4.0, < 10.4.92006-09-06
CVE-2006-4095 [HIGH] CWE-617 CVE-2006-4095: BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which cause an assertion failure when multiple RRsets are returned.
nvd
CVE-2012-3719P4MEDIUMCVSS 6.8≤ 10.7.4v10.0+69 more2012-09-20
CVE-2012-3719 [MEDIUM] CWE-20 CVE-2012-3719: Mail in Apple Mac OS X before 10.7.5 does not properly handle embedded web plugins, which allows rem
Mail in Apple Mac OS X before 10.7.5 does not properly handle embedded web plugins, which allows remote attackers to execute arbitrary plugin code via an e-mail message that triggers the loading of a third-party plugin.
nvd
CVE-2021-30857P4HIGHCVSS 7.0fixed in 10.15.7v10.15.72021-08-24
CVE-2021-30857 [HIGH] CWE-362 CVE-2021-30857: A race condition was addressed with improved locking. This issue is fixed in Security Update 2021-00
A race condition was addressed with improved locking. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, tvOS 15, iOS 15 and iPadOS 15, watchOS 8, macOS Big Sur 11.6. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2006-1450P4HIGHCVSS 7.5v10.3.9v10.4.62006-05-12
CVE-2006-1450 [HIGH] CVE-2006-1450: Mail in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to execute arbitrary code via an en
Mail in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to execute arbitrary code via an enriched text e-mail message with "invalid color information" that causes Mail to allocate and initialize arbitrary classes.
nvd
CVE-2013-5165P4MEDIUMCVSS 6.4≤ 10.8.5v10.8.0+5 more2013-10-24
CVE-2013-5165 [MEDIUM] CWE-264 CVE-2013-5165: socketfilterfw in Application Firewall in Apple Mac OS X before 10.9 does not properly implement the
socketfilterfw in Application Firewall in Apple Mac OS X before 10.9 does not properly implement the --blockApp option, which allows remote attackers to bypass intended access restrictions via a network connection to an application for which blocking was configured.
nvd
CVE-2022-32832P3MEDIUMCVSS 6.7v10.15.72022-09-23
CVE-2022-32832 [MEDIUM] CVE-2022-32832: The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15
The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app with root privileges may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2015-3414P4HIGHCVSS 7.5v10.10.52015-04-24
CVE-2015-3414 [HIGH] CWE-908 CVE-2015-3414: SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which all
SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via a crafted COLLATE clause, as demonstrated by COLLATE"""""""" at the end of a SELECT statement.
nvd
CVE-2016-1737P4MEDIUMCVSS 6.3≤ 10.11.32016-03-24
CVE-2016-1737 [MEDIUM] CWE-119 CVE-2016-1737: Carbon in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a den
Carbon in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dfont file.
nvd
CVE-2019-8612P4MEDIUMCVSS 6.5≥ 10.12.6, < 10.14.52020-10-27
CVE-2019-8612 [MEDIUM] CVE-2019-8612: A logic issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.1
A logic issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, tvOS 12.3, watchOS 5.2.1, macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, iOS 12.3. An attacker in a privileged network position can modify
nvd
CVE-2017-7158P4MEDIUMCVSS 6.5fixed in 10.13.22017-12-27
CVE-2017-7158 [MEDIUM] CWE-119 CVE-2017-7158: An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Screen Sharing Server" component. It allows attackers to obtain root privileges for reading files by leveraging screen-sharing access.
nvd
CVE-2011-0180P4LOWCVSS 2.1PoC≤ 10.6.6v10.6.0+5 more2011-03-23
CVE-2011-0180 [LOW] CWE-189 CVE-2011-0180: Integer overflow in HFS in Apple Mac OS X before 10.6.7 allows local users to read arbitrary (1) HFS
Integer overflow in HFS in Apple Mac OS X before 10.6.7 allows local users to read arbitrary (1) HFS, (2) HFS+, or (3) HFS+J files via a crafted F_READBOOTSTRAP ioctl call.
nvd