Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
277
Exploited in wild
28
Severity breakdown
CRITICAL302HIGH1409MEDIUM1236LOW192
Vulnerabilities
Page 85 of 157
CVE-2015-7116MEDIUMCVSS 4.3≤ 10.11.02016-01-10
CVE-2015-7116 [MEDIUM] CVE-2015-7116: libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to
libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted XML document, a different vulnerability than CVE-2015-7115.
nvd
CVE-2015-7115MEDIUMCVSS 4.3≤ 10.11.02016-01-10
CVE-2015-7115 [MEDIUM] CWE-119 CVE-2015-7115: libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to
libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted XML document, a different vulnerability than CVE-2015-7116.
nvd
CVE-2015-5312HIGHCVSS 7.1≤ 10.11.32015-12-15
CVE-2015-5312 [HIGH] CVE-2015-5312: The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly preven
The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.
nvd
CVE-2015-7499MEDIUMCVSS 5.0≤ 10.11.32015-12-15
CVE-2015-7499 [MEDIUM] CWE-119 CVE-2015-7499: Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows contex
Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors.
nvd
CVE-2015-7500MEDIUMCVSS 5.0≤ 10.11.32015-12-15
CVE-2015-7500 [MEDIUM] CWE-119 CVE-2015-7500: The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to
The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect entities boundaries and start tags.
nvd
CVE-2015-8242MEDIUMCVSS 5.8≤ 10.11.32015-12-15
CVE-2015-8242 [MEDIUM] CWE-119 CVE-2015-8242: The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.
The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.
nvd
CVE-2015-7112CRITICALCVSS 9.3PoC≤ 10.11.12015-12-11
CVE-2015-7112 [CRITICAL] CVE-2015-7112: The IOHIDFamily API in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS befor
The IOHIDFamily API in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2015-7111.
nvd
CVE-2015-7071CRITICALCVSS 10.0≤ 10.11.12015-12-11
CVE-2015-7071 [CRITICAL] CWE-264 CVE-2015-7071: The File Bookmark component in Apple OS X before 10.11.2 allows attackers to bypass a sandbox protec
The File Bookmark component in Apple OS X before 10.11.2 allows attackers to bypass a sandbox protection mechanism for app scoped bookmarks via a crafted pathname.
nvd
CVE-2015-7111CRITICALCVSS 9.3≤ 10.11.12015-12-11
CVE-2015-7111 [CRITICAL] CWE-119 CVE-2015-7111: The IOHIDFamily API in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS befor
The IOHIDFamily API in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2015-7112.
nvd
CVE-2015-7109CRITICALCVSS 9.3≤ 10.11.12015-12-11
CVE-2015-7109 [CRITICAL] CWE-119 CVE-2015-7109: IOAcceleratorFamily in Apple OS X before 10.11.2 and tvOS before 9.1 allows attackers to execute arb
IOAcceleratorFamily in Apple OS X before 10.11.2 and tvOS before 9.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2015-7077HIGHCVSS 7.2PoC≤ 10.11.12015-12-11
CVE-2015-7077 [HIGH] CWE-119 CVE-2015-7077: The Intel Graphics Driver component in Apple OS X before 10.11.2 allows local users to gain privileg
The Intel Graphics Driver component in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial of service (out-of-bounds memory access) via unspecified vectors.
nvd
CVE-2015-7076HIGHCVSS 7.2≤ 10.11.12015-12-11
CVE-2015-7076 [HIGH] CVE-2015-7076: The Intel Graphics Driver component in Apple OS X before 10.11.2 allows local users to gain privileg
The Intel Graphics Driver component in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors.
nvd
CVE-2015-7047HIGHCVSS 7.2PoC≤ 10.11.12015-12-11
CVE-2015-7047 [HIGH] CWE-20 CVE-2015-7047: The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 all
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to gain privileges via a crafted mach message that is misparsed.
nvd
CVE-2015-7083HIGHCVSS 7.2PoC≤ 10.11.12015-12-11
CVE-2015-7083 [HIGH] CWE-119 CVE-2015-7083: The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 all
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-7084.
nvd
CVE-2015-7084HIGHCVSS 7.2PoC≤ 10.11.12015-12-11
CVE-2015-7084 [HIGH] CVE-2015-7084: The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 all
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-7083.
nvd
CVE-2015-7108HIGHCVSS 7.2PoC≤ 10.11.12015-12-11
CVE-2015-7108 [HIGH] CWE-119 CVE-2015-7108: The Bluetooth HCI interface in Apple OS X before 10.11.2 allows local users to gain privileges or ca
The Bluetooth HCI interface in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2015-7078HIGHCVSS 7.2PoC≤ 10.11.12015-12-11
CVE-2015-7078 [HIGH] CVE-2015-7078: Use-after-free vulnerability in Hypervisor in Apple OS X before 10.11.2 allows local users to gain p
Use-after-free vulnerability in Hypervisor in Apple OS X before 10.11.2 allows local users to gain privileges via vectors involving VM objects.
nvd
CVE-2015-7063HIGHCVSS 7.2≤ 10.11.12015-12-11
CVE-2015-7063 [HIGH] CWE-264 CVE-2015-7063: The kernel loader in EFI in Apple OS X before 10.11.2 allows local users to gain privileges via a cr
The kernel loader in EFI in Apple OS X before 10.11.2 allows local users to gain privileges via a crafted pathname.
nvd
CVE-2015-7068HIGHCVSS 7.8PoCfixed in 10.11.22015-12-11
CVE-2015-7068 [HIGH] CWE-476 CVE-2015-7068: IOKit SCSI in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 all
IOKit SCSI in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via an app that provides an unspecified userclient type.
nvd
CVE-2015-7106HIGHCVSS 7.2PoC≤ 10.11.12015-12-11
CVE-2015-7106 [HIGH] CWE-119 CVE-2015-7106: The Intel Graphics Driver component in Apple OS X before 10.11.2 allows local users to gain privileg
The Intel Graphics Driver component in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvd