cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 82 of 157
CVE-2016-4696P4HIGHCVSS 7.8≤ 10.11.62016-09-25
CVE-2016-4696 [HIGH] CWE-476 CVE-2016-4696: AppleEFIRuntime in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privilege AppleEFIRuntime in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.
nvd
CVE-2016-4640P4HIGHCVSS 7.8≤ 10.11.52016-07-22
CVE-2016-4640 [HIGH] CWE-119 CVE-2016-4640: Login Window in Apple OS X before 10.11.6 allows attackers to execute arbitrary code in a privileged Login Window in Apple OS X before 10.11.6 allows attackers to execute arbitrary code in a privileged context, obtain sensitive user information, or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2007-4700P4HIGHCVSS 7.5v10.4.1v10.4.2+8 more2007-11-15
CVE-2007-4700 [HIGH] CWE-264 CVE-2007-4700: Unspecified vulnerability in WebKit on Apple Mac OS X 10.4 through 10.4.10 allows remote attackers t Unspecified vulnerability in WebKit on Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to use Safari as an indirect proxy and send attacker-controlled data to arbitrary TCP ports via unknown vectors.
nvd
CVE-2011-0205P3MEDIUMCVSS 6.8v10.5.8v10.6.0+7 more2011-06-24
CVE-2011-0205 [MEDIUM] CWE-119 CVE-2011-0205: Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.8 allows remote attackers to exe Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG2000 image.
nvd
CVE-2017-7054P4HIGHCVSS 8.0≤ 10.12.52017-07-20
CVE-2017-7054 [HIGH] CWE-119 CVE-2017-7054: An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Bluetooth" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-7050P4HIGHCVSS 8.0≤ 10.12.52017-07-20
CVE-2017-7050 [HIGH] CWE-119 CVE-2017-7050: An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Bluetooth" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-7051P4HIGHCVSS 8.0≤ 10.12.52017-07-20
CVE-2017-7051 [HIGH] CWE-119 CVE-2017-7051: An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Bluetooth" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-2503P4HIGHCVSS 7.8≤ 10.12.42017-05-22
CVE-2017-2503 [HIGH] CWE-119 CVE-2017-2503: An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-2542P4HIGHCVSS 7.8≤ 10.12.42017-05-22
CVE-2017-2542 [HIGH] CWE-119 CVE-2017-2542: An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Multi-Touch" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-2543P4HIGHCVSS 7.8≤ 10.12.42017-05-22
CVE-2017-2543 [HIGH] CWE-119 CVE-2017-2543: An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Multi-Touch" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-2545P4HIGHCVSS 7.8≤ 10.12.42017-05-22
CVE-2017-2545 [HIGH] CWE-119 CVE-2017-2545: An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "IOGraphics" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-2494P4HIGHCVSS 7.8≤ 10.12.42017-05-22
CVE-2017-2494 [HIGH] CWE-119 CVE-2017-2494: An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2014-4350P4MEDIUMCVSS 6.8v10.7.5v10.8.5+5 more2014-09-19
CVE-2014-4350 [MEDIUM] CWE-119 CVE-2014-4350: Buffer overflow in QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execut Buffer overflow in QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MIDI file.
nvd
CVE-2014-4351P4MEDIUMCVSS 6.8≤ 10.9.52014-10-18
CVE-2014-4351 [MEDIUM] CWE-119 CVE-2014-4351: Buffer overflow in QuickTime in Apple OS X before 10.10 allows remote attackers to execute arbitrary Buffer overflow in QuickTime in Apple OS X before 10.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted audio samples in an m4a file.
nvd
CVE-2008-0054P4MEDIUMCVSS 6.4v10.4.112008-03-18
CVE-2008-0054 [MEDIUM] CWE-20 CVE-2008-0054: Foundation in Apple Mac OS X 10.4.11 might allow context-dependent attackers to execute arbitrary co Foundation in Apple Mac OS X 10.4.11 might allow context-dependent attackers to execute arbitrary code via a malformed selector name to the NSSelectorFromString API, which causes an "unexpected selector" to be used.
nvd
CVE-2010-0508P4CRITICALCVSS 10.0≤ 10.6.2v10.5+11 more2010-03-30
CVE-2010-0508 [CRITICAL] CVE-2010-0508: Mail in Apple Mac OS X before 10.6.3 does not disable the filter rules associated with a deleted mai Mail in Apple Mac OS X before 10.6.3 does not disable the filter rules associated with a deleted mail account, which has unspecified impact and attack vectors.
nvd
CVE-2018-4371P4HIGHCVSS 7.8fixed in 10.14.12019-04-03
CVE-2018-4371 [HIGH] CWE-125 CVE-2018-4371: An out-of-bounds read was addressed with improved input validation. This issue affected versions pri An out-of-bounds read was addressed with improved input validation. This issue affected versions prior to iOS 12.1, macOS Mojave 10.14.1, tvOS 12.1, watchOS 5.1.
nvd
CVE-2018-4424P4HIGHCVSS 7.8fixed in 10.14.12019-04-03
CVE-2018-4424 [HIGH] CWE-119 CVE-2018-4424: A buffer overflow was addressed with improved size validation. This issue affected versions prior to A buffer overflow was addressed with improved size validation. This issue affected versions prior to macOS Mojave 10.14.1.
nvd
CVE-2018-4421P4HIGHCVSS 7.8fixed in 10.14.12019-04-03
CVE-2018-4421 [HIGH] CWE-119 CVE-2018-4421: A memory initialization issue was addressed with improved memory handling. This issue affected versi A memory initialization issue was addressed with improved memory handling. This issue affected versions prior to macOS Mojave 10.14.1.
nvd
CVE-2004-1088P4HIGHCVSS 7.5v10.2v10.2.1+14 more2004-12-02
CVE-2004-1088 [HIGH] CVE-2004-1088: Postfix server for Apple Mac OS X 10.3.6, when using CRAM-MD5, allows remote attackers to send mail Postfix server for Apple Mac OS X 10.3.6, when using CRAM-MD5, allows remote attackers to send mail without authentication by replaying authentication information.
nvd
Apple macOS vulnerabilities | cvebase