Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 83 of 157
CVE-2015-5755P4MEDIUMCVSS 6.8≤ 10.10.42015-08-17
CVE-2015-5755 [MEDIUM] CWE-119 CVE-2015-5755: CoreText in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitr
CoreText in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-5761.
nvd
CVE-2015-5761P4MEDIUMCVSS 6.8≤ 10.10.42015-08-17
CVE-2015-5761 [MEDIUM] CVE-2015-5761: CoreText in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitr
CoreText in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-5755.
nvd
CVE-2018-4423P4HIGHCVSS 7.8fixed in 10.14.12019-04-03
CVE-2018-4423 [HIGH] CWE-20 CVE-2018-4423: A logic issue was addressed with improved validation. This issue affected versions prior to macOS Mo
A logic issue was addressed with improved validation. This issue affected versions prior to macOS Mojave 10.14.1.
nvd
CVE-2010-3798P4MEDIUMCVSS 6.8v10.6.0v10.6.1+3 more2010-11-16
CVE-2010-3798 [MEDIUM] CWE-119 CVE-2010-3798: Heap-based buffer overflow in xar in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to
Heap-based buffer overflow in xar in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted xar archive.
nvd
CVE-2014-1262P4HIGHCVSS 7.5≤ 10.9.1v10.92014-02-27
CVE-2014-1262 [HIGH] CWE-119 CVE-2014-1262: Apple Type Services (ATS) in Apple OS X before 10.9.2 allows attackers to bypass the App Sandbox pro
Apple Type Services (ATS) in Apple OS X before 10.9.2 allows attackers to bypass the App Sandbox protection mechanism via crafted Mach messages that trigger memory corruption.
nvd
CVE-2010-1836P4MEDIUMCVSS 6.8v10.5.8v10.6.0+4 more2010-11-15
CVE-2010-1836 [MEDIUM] CWE-119 CVE-2010-1836: Stack-based buffer overflow in CoreGraphics in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows
Stack-based buffer overflow in CoreGraphics in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.
nvd
CVE-2010-1808P4MEDIUMCVSS 6.8v10.5.8v10.6.42010-08-25
CVE-2010-1808 [MEDIUM] CWE-119 CVE-2010-1808: Stack-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 and 10.6.4 allows
Stack-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 and 10.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted embedded font in a document.
nvd
CVE-2015-5778P4MEDIUMCVSS 6.8≤ 10.10.42015-08-17
CVE-2015-5778 [MEDIUM] CVE-2015-5778: CoreMedia Playback in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to exec
CoreMedia Playback in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-5777.
nvd
CVE-2015-5777P4MEDIUMCVSS 6.8≤ 10.10.42015-08-17
CVE-2015-5777 [MEDIUM] CWE-119 CVE-2015-5777: CoreMedia Playback in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to exec
CoreMedia Playback in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-5778.
nvd
CVE-2016-4708P4MEDIUMCVSS 6.5fixed in 10.12.02016-09-25
CVE-2016-4708 [MEDIUM] CWE-200 CVE-2016-4708: CFNetwork in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 misparses
CFNetwork in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 misparses the Set-Cookie header, which allows remote attackers to obtain sensitive information via a crafted HTTP response.
nvd
CVE-2003-0881P4HIGHCVSS 7.5≤ 10.32003-11-03
CVE-2003-0881 [HIGH] CVE-2003-0881: Mail in Mac OS X before 10.3, when configured to use MD5 Challenge Response, uses plaintext authenti
Mail in Mac OS X before 10.3, when configured to use MD5 Challenge Response, uses plaintext authentication if the CRAM-MD5 hashed login fails, which could allow remote attackers to gain privileges by sniffing the password.
nvd
CVE-2014-1256P4HIGHCVSS 7.5≤ 10.9.1v10.7.0+12 more2014-02-27
CVE-2014-1256 [HIGH] CWE-119 CVE-2014-1256: Buffer overflow in Apple Type Services (ATS) in Apple OS X before 10.9.2 allows attackers to bypass
Buffer overflow in Apple Type Services (ATS) in Apple OS X before 10.9.2 allows attackers to bypass the App Sandbox protection mechanism via crafted Mach messages.
nvd
CVE-2013-5179P4HIGHCVSS 7.5≤ 10.8.5v10.8.0+5 more2013-10-24
CVE-2013-5179 [HIGH] CWE-264 CVE-2013-5179: App Sandbox in Apple Mac OS X before 10.9 allows attackers to bypass intended sandbox restrictions v
App Sandbox in Apple Mac OS X before 10.9 allows attackers to bypass intended sandbox restrictions via a crafted app that uses the LaunchServices interface to specify process arguments.
nvd
CVE-2011-3437P4MEDIUMCVSS 6.8v10.7.0v10.7.12011-10-14
CVE-2011-3437 [MEDIUM] CWE-189 CVE-2011-3437: Integer signedness error in Apple Type Services (ATS) in Apple Mac OS X 10.7 before 10.7.2 allows re
Integer signedness error in Apple Type Services (ATS) in Apple Mac OS X 10.7 before 10.7.2 allows remote attackers to execute arbitrary code via a crafted embedded Type 1 font in a document.
nvd
CVE-2016-7667P4HIGHCVSS 7.5≤ 10.12.12017-02-20
CVE-2016-7667 [HIGH] CWE-20 CVE-2016-7667: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service via a crafted string.
nvd
CVE-2015-5771P4MEDIUMCVSS 6.8≤ 10.10.42015-08-17
CVE-2015-5771 [MEDIUM] CWE-119 CVE-2015-5771: Quartz Composer Framework in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary
Quartz Composer Framework in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted QuickTime file.
nvd
CVE-2010-1837P4MEDIUMCVSS 6.8v10.5.8v10.6.0+4 more2010-11-15
CVE-2010-1837 [MEDIUM] CWE-119 CVE-2010-1837: CoreText in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitr
CoreText in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font in a PDF document.
nvd
CVE-2015-3679P4MEDIUMCVSS 6.8≤ 10.10.32015-07-03
CVE-2015-3679 [MEDIUM] CWE-119 CVE-2015-3679: Apple Type Services (ATS) in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary
Apple Type Services (ATS) in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-3680, CVE-2015-3681, and CVE-2015-3682.
nvd
CVE-2015-3680P4MEDIUMCVSS 6.8≤ 10.10.32015-07-03
CVE-2015-3680 [MEDIUM] CVE-2015-3680: Apple Type Services (ATS) in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary
Apple Type Services (ATS) in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-3679, CVE-2015-3681, and CVE-2015-3682.
nvd
CVE-2015-3682P4MEDIUMCVSS 6.8≤ 10.10.32015-07-03
CVE-2015-3682 [MEDIUM] CVE-2015-3682: Apple Type Services (ATS) in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary
Apple Type Services (ATS) in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-3679, CVE-2015-3680, and CVE-2015-3681.
nvd