Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 84 of 157
CVE-2015-3681P4MEDIUMCVSS 6.8≤ 10.10.32015-07-03
CVE-2015-3681 [MEDIUM] CVE-2015-3681: Apple Type Services (ATS) in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary
Apple Type Services (ATS) in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-3679, CVE-2015-3680, and CVE-2015-3682.
nvd
CVE-2010-1833P4MEDIUMCVSS 6.8v10.6.0v10.6.1+3 more2010-11-15
CVE-2010-1833 [MEDIUM] CWE-119 CVE-2010-1833: Apple Type Services (ATS) in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute
Apple Type Services (ATS) in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted embedded font in a document.
nvd
CVE-2016-4641P4HIGHCVSS 7.3≤ 10.11.52016-07-22
CVE-2016-4641 [HIGH] CWE-20 CVE-2016-4641: Login Window in Apple OS X before 10.11.6 allows attackers to execute arbitrary code in a privileged
Login Window in Apple OS X before 10.11.6 allows attackers to execute arbitrary code in a privileged context or obtain sensitive user information via a crafted app that leverages a "type confusion."
nvd
CVE-2014-1258P4MEDIUMCVSS 6.8≤ 10.9.1v10.8.0+6 more2014-02-27
CVE-2014-1258 [MEDIUM] CWE-119 CVE-2014-1258: Heap-based buffer overflow in CoreAnimation in Apple OS X before 10.9.2 allows remote attackers to e
Heap-based buffer overflow in CoreAnimation in Apple OS X before 10.9.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted image.
nvd
CVE-2015-6989P4MEDIUMCVSS 6.8≤ 10.11.02015-10-23
CVE-2015-6989 [MEDIUM] CWE-119 CVE-2015-6989: Grand Central Dispatch in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows
Grand Central Dispatch in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted package that is mishandled during dispatch calls.
nvd
CVE-2009-2812P4MEDIUMCVSS 6.8v10.5.82009-09-14
CVE-2009-2812 [MEDIUM] CVE-2009-2812: Launch Services in Apple Mac OS X 10.5.8 does not properly recognize an unsafe Uniform Type Identifi
Launch Services in Apple Mac OS X 10.5.8 does not properly recognize an unsafe Uniform Type Identifier (UTI) in an exported document type in a downloaded application, which allows remote attackers to trigger the automatic opening of a file, and execute arbitrary code, via a crafted web site.
nvd
CVE-2014-8816P4MEDIUMCVSS 6.8≤ 10.9.52015-01-30
CVE-2014-8816 [MEDIUM] CWE-399 CVE-2014-8816: CoreGraphics in Apple OS X before 10.10 allows remote attackers to execute arbitrary code or cause a
CoreGraphics in Apple OS X before 10.10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted PDF document.
nvd
CVE-2010-1637P4MEDIUMCVSS 6.5fixed in 10.6.82010-06-22
CVE-2010-1637 [MEDIUM] CWE-918 CVE-2010-1637: The Mail Fetch plugin in SquirrelMail 1.4.20 and earlier allows remote authenticated users to bypass
The Mail Fetch plugin in SquirrelMail 1.4.20 and earlier allows remote authenticated users to bypass firewall restrictions and use SquirrelMail as a proxy to scan internal networks via a modified POP3 port number.
nvd
CVE-2016-4718P4MEDIUMCVSS 6.5fixed in 10.12.02016-09-25
CVE-2016-4718 [MEDIUM] CWE-119 CVE-2016-4718: Buffer overflow in FontParser in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS
Buffer overflow in FontParser in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to obtain sensitive information from process memory via a crafted font file.
nvd
CVE-2018-4157P4HIGHCVSS 7.0fixed in 10.13.42018-04-03
CVE-2018-4157 [HIGH] CWE-362 CVE-2018-4157: An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4
An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "Quick Look" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2018-4166P4HIGHCVSS 7.0fixed in 10.13.42018-04-03
CVE-2018-4166 [HIGH] CWE-362 CVE-2018-4166: An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4
An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "NSURLSession" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2018-4155P4HIGHCVSS 7.0fixed in 10.13.42018-04-03
CVE-2018-4155 [HIGH] CWE-362 CVE-2018-4155: An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4
An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "CoreFoundation" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2013-5168P4MEDIUMCVSS 6.8≤ 10.8.5v10.8.0+5 more2013-10-24
CVE-2013-5168 [MEDIUM] CWE-20 CVE-2013-5168: Console in Apple Mac OS X before 10.9 allows user-assisted remote attackers to execute arbitrary app
Console in Apple Mac OS X before 10.9 allows user-assisted remote attackers to execute arbitrary applications by triggering a log entry with a crafted attached URL.
nvd
CVE-2013-1027P4MEDIUMCVSS 6.8≤ 10.8.4v10.8.0+3 more2013-09-16
CVE-2013-1027 [MEDIUM] CWE-264 CVE-2013-1027: Installer in Apple Mac OS X before 10.8.5 provides an option to continue a package's installation af
Installer in Apple Mac OS X before 10.8.5 provides an option to continue a package's installation after encountering a revoked certificate, which might allow user-assisted remote attackers to execute arbitrary code via a crafted package.
nvd
CVE-2015-1095P4HIGHCVSS 7.2≤ 10.10.22015-04-10
CVE-2015-1095 [HIGH] CVE-2015-1095: IOHIDFamily in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows physi
IOHIDFamily in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HID device.
nvd
CVE-2021-30899P4HIGHCVSS 7.0fixed in 10.15.7v10.15.72021-08-24
CVE-2021-30899 [HIGH] CWE-362 CVE-2021-30899: A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 1
A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 12.0.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2022-22638P4MEDIUMCVSS 6.5≥ 10.15, < 10.15.7v10.15.72022-03-18
CVE-2022-22638 [MEDIUM] CWE-476 CVE-2022-22638: A null pointer dereference was addressed with improved validation. This issue is fixed in tvOS 15.4,
A null pointer dereference was addressed with improved validation. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, Security Update 2022-003 Catalina, watchOS 8.5, macOS Monterey 12.3. An attacker in a privileged position may be able to perform a denial of service attack.
nvd
CVE-2005-1342P4HIGHCVSS 7.5v10.3v10.3.1+8 more2005-05-04
CVE-2005-1342 [HIGH] CVE-2005-1342: The x-man-page: URI handler for Apple Terminal 1.4.4 in Mac OS X 10.3.9 does not cleanse terminal es
The x-man-page: URI handler for Apple Terminal 1.4.4 in Mac OS X 10.3.9 does not cleanse terminal escape sequences, which allows remote attackers to execute arbitrary commands.
nvd
CVE-2021-1811P4MEDIUMCVSS 6.5≥ 10.14, ≤ 10.14.5≥ 10.15, ≤ 10.15.5+3 more2021-09-08
CVE-2021-1811 [MEDIUM] CVE-2021-1811: A logic issue was addressed with improved state management. This issue is fixed in iTunes 12.11.3 fo
A logic issue was addressed with improved state management. This issue is fixed in iTunes 12.11.3 for Windows, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iCloud for Windows 12.3, macOS Big Sur 11.3, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing a maliciously crafted font may result in the disclosure of process memory.
nvd
CVE-2009-2190P4HIGHCVSS 7.8v10.5.6v10.5+7 more2009-08-06
CVE-2009-2190 [HIGH] CWE-399 CVE-2009-2190: launchd in Apple Mac OS X 10.5 before 10.5.8 allows remote attackers to cause a denial of service (i
launchd in Apple Mac OS X 10.5 before 10.5.8 allows remote attackers to cause a denial of service (individual service outage) by making many connections to an inetd-based launchd service.
nvd