Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 81 of 157
CVE-2009-2191P4HIGHCVSS 7.5v10.5.6v10.4.11+2 more2009-08-06
CVE-2009-2191 [HIGH] CWE-134 CVE-2009-2191: Format string vulnerability in Login Window in Apple Mac OS X 10.4.11 and 10.5 before 10.5.8 allows
Format string vulnerability in Login Window in Apple Mac OS X 10.4.11 and 10.5 before 10.5.8 allows attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in an application name.
nvd
CVE-2009-0155P3MEDIUMCVSS 6.8v10.5.0v10.5.1+5 more2009-05-13
CVE-2009-0155 [MEDIUM] CWE-189 CVE-2009-0155: Integer underflow in CoreGraphics in Apple Mac OS X 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1,
Integer underflow in CoreGraphics in Apple Mac OS X 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF file that triggers a heap-based buffer overflow.
nvd
CVE-2006-1441P4HIGHCVSS 7.5v10.4.62006-05-12
CVE-2006-1441 [HIGH] CVE-2006-1441: Integer overflow in CFNetwork in Apple Mac OS X 10.4.6 allows remote attackers to execute arbitrary
Integer overflow in CFNetwork in Apple Mac OS X 10.4.6 allows remote attackers to execute arbitrary code via crafted chunked transfer encoding.
nvd
CVE-2010-2498P4MEDIUMCVSS 6.8fixed in 10.6.52010-08-19
CVE-2010-2498 [MEDIUM] CWE-787 CVE-2010-2498: The psh_glyph_find_strong_points function in pshinter/pshalgo.c in FreeType before 2.4.0 does not pr
The psh_glyph_find_strong_points function in pshinter/pshalgo.c in FreeType before 2.4.0 does not properly implement hinting masks, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a crafted font file that triggers an invalid free operation.
nvd
CVE-2011-1417P4MEDIUMCVSS 6.8≤ 10.6.6v10.6.0+5 more2011-03-11
CVE-2011-1417 [MEDIUM] CWE-189 CVE-2011-1417: Integer overflow in QuickLook, as used in Apple Mac OS X before 10.6.7 and MobileSafari in Apple iOS
Integer overflow in QuickLook, as used in Apple Mac OS X before 10.6.7 and MobileSafari in Apple iOS before 4.2.7 and 4.3.x before 4.3.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a Microsoft Office document with a crafted size field in the OfficeArtMetafileHeader, rela
nvd
CVE-2009-0020P4HIGHCVSS 7.8v10.4.11v10.5.62009-02-13
CVE-2009-0020 [HIGH] CWE-399 CVE-2009-0020: Unspecified vulnerability in CarbonCore in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers
Unspecified vulnerability in CarbonCore in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted resource fork that triggers memory corruption.
nvd
CVE-2005-3705P4HIGHCVSS 7.5v10.3.9v10.4.32005-12-01
CVE-2005-3705 [HIGH] CVE-2005-3705: Heap-based buffer overflow in WebKit in Mac OS X and OS X Server 10.3.9 and 10.4.3, as used in appli
Heap-based buffer overflow in WebKit in Mac OS X and OS X Server 10.3.9 and 10.4.3, as used in applications such as Safari, allows remote attackers to execute arbitrary code via unknown attack vectors.
nvd
CVE-2017-6977P4HIGHCVSS 8.6≤ 10.12.42017-05-22
CVE-2017-6977 [HIGH] CWE-119 CVE-2017-6977: An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Speech Framework" component. It allows attackers to conduct sandbox-escape attacks or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2005-2757P4HIGHCVSS 7.5v10.3v10.3.1+12 more2005-12-01
CVE-2005-2757 [HIGH] CVE-2005-2757: Heap-based buffer overflow in CoreFoundation in Mac OS X and OS X Server 10.4 through 10.4.3 allows
Heap-based buffer overflow in CoreFoundation in Mac OS X and OS X Server 10.4 through 10.4.3 allows remote attackers to execute arbitrary code via unknown attack vectors involving "validation of URLs."
nvd
CVE-2014-4443P4HIGHCVSS 7.8≤ 10.9.52014-10-18
CVE-2014-4443 [HIGH] CWE-20 CVE-2014-4443: Apple OS X before 10.10 allows remote attackers to cause a denial of service (NULL pointer dereferen
Apple OS X before 10.10 allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted ASN.1 data.
nvd
CVE-2010-3790P4MEDIUMCVSS 6.8v10.6.0v10.6.1+3 more2010-11-16
CVE-2010-3790 [MEDIUM] CWE-119 CVE-2010-3790: QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code o
QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file that causes an image sample transformation to scale a sprite outside a buffer boundary.
nvd
CVE-2009-0040P4MEDIUMCVSS 6.8fixed in 10.5.82009-02-22
CVE-2009-0040 [MEDIUM] CWE-824 CVE-2009-0040: The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush a
The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file that triggers a free of an uninitialized pointer in (1) the png_read_png function, (2) p
nvd
CVE-2009-0158P4MEDIUMCVSS 6.8v10.4.11v10.5.0+6 more2009-05-13
CVE-2009-0158 [MEDIUM] CWE-119 CVE-2009-0158: Stack-based buffer overflow in telnet in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote
Stack-based buffer overflow in telnet in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long hostname for a telnet server.
nvd
CVE-2010-0516P4MEDIUMCVSS 6.8v10.6.0v10.6.1+1 more2010-03-30
CVE-2010-0516 [MEDIUM] CWE-119 CVE-2010-0516: Heap-based buffer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to e
Heap-based buffer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with RLE encoding, which triggers memory corruption when the length of decompressed data exceeds that of the allocated heap chunk.
nvd
CVE-2015-1103P4HIGHCVSS 7.5≤ 10.10.22015-04-10
CVE-2015-1103 [HIGH] CWE-20 CVE-2015-1103: The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 makes routing
The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 makes routing changes in response to ICMP_REDIRECT messages, which allows remote attackers to cause a denial of service (network outage) or obtain sensitive packet-content information via a crafted ICMP packet.
nvd
CVE-2009-0943P4MEDIUMCVSS 6.8v10.4.11v10.5.0+6 more2009-05-13
CVE-2009-0943 [MEDIUM] CWE-20 CVE-2009-0943: Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that HTML pathnames are
Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that HTML pathnames are located in a registered help book, which allows remote attackers to execute arbitrary code via a help: URL that triggers invocation of AppleScript files.
nvd
CVE-2015-2348P4MEDIUMCVSS 5.0≤ 10.10.52015-03-30
CVE-2015-2348 [MEDIUM] CVE-2015-2348: The move_uploaded_file implementation in ext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x
The move_uploaded_file implementation in ext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 truncates a pathname upon encountering a \x00 character, which allows remote attackers to bypass intended extension restrictions and create files with unexpected names via a crafted second argument. NOTE: this vulnerability
nvd
CVE-2010-0055P4CRITICALCVSS 10.0v10.5.82010-03-30
CVE-2010-0055 [CRITICAL] CVE-2010-0055: xar in Apple Mac OS X 10.5.8 does not properly validate package signatures, which allows attackers t
xar in Apple Mac OS X 10.5.8 does not properly validate package signatures, which allows attackers to have an unspecified impact via a modified package.
nvd
CVE-2009-0152P4HIGHCVSS 7.5≥ 10.5.0, < 10.5.72009-05-13
CVE-2009-0152 [HIGH] CWE-312 CVE-2009-0152: iChat in Apple Mac OS X 10.5 before 10.5.7 disables SSL for AOL Instant Messenger (AIM) communicatio
iChat in Apple Mac OS X 10.5 before 10.5.7 disables SSL for AOL Instant Messenger (AIM) communication in certain circumstances that are inconsistent with the Require SSL setting, which allows remote attackers to obtain sensitive information by sniffing the network.
nvd
CVE-2011-0200P4MEDIUMCVSS 6.8v10.6.0v10.6.1+6 more2011-06-24
CVE-2011-0200 [MEDIUM] CWE-189 CVE-2011-0200: Integer overflow in ColorSync in Apple Mac OS X before 10.6.8 allows remote attackers to execute arb
Integer overflow in ColorSync in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image containing a crafted embedded ColorSync profile that triggers a heap-based buffer overflow.
nvd