Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 86 of 157
CVE-2011-0201P4HIGHCVSS 7.5v10.6.0v10.6.1+6 more2011-06-24
CVE-2011-0201 [HIGH] CWE-189 CVE-2011-0201: Off-by-one error in the CoreFoundation framework in Apple Mac OS X before 10.6.8 allows context-depe
Off-by-one error in the CoreFoundation framework in Apple Mac OS X before 10.6.8 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a CFString object that triggers a buffer overflow.
nvd
CVE-2015-7803P4MEDIUMCVSS 6.8≤ 10.11.12015-12-11
CVE-2015-7803 [MEDIUM] CVE-2015-7803: The phar_get_entry_data function in ext/phar/util.c in PHP before 5.5.30 and 5.6.x before 5.6.14 all
The phar_get_entry_data function in ext/phar/util.c in PHP before 5.5.30 and 5.6.x before 5.6.14 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a .phar file with a crafted TAR archive entry in which the Link indicator references a file that does not exist.
nvd
CVE-2010-2807P4MEDIUMCVSS 6.8fixed in 10.6.52010-08-19
CVE-2010-2807 [MEDIUM] CWE-681 CVE-2010-2807: FreeType before 2.4.2 uses incorrect integer data types during bounds checking, which allows remote
FreeType before 2.4.2 uses incorrect integer data types during bounds checking, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
nvd
CVE-2010-0505P4MEDIUMCVSS 6.8≤ 10.6.2v10.5+11 more2010-03-30
CVE-2010-0505 [MEDIUM] CWE-119 CVE-2010-0505: Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.3 allows remote attackers to exe
Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JP2 (JPEG2000) image, related to incorrect calculation and the CGImageReadGetBytesAtOffset function.
nvd
CVE-2017-13834P4HIGHCVSS 7.8≤ 10.13.02017-11-13
CVE-2017-13834 [HIGH] CWE-119 CVE-2017-13834: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted mach binary.
nvd
CVE-2007-4691P4CRITICALCVSS 10.0v10.3.9v10.4.1+9 more2007-11-15
CVE-2007-4691 [CRITICAL] CWE-264 CVE-2007-4691: The NSURL component in Apple Mac OS X 10.4 through 10.4.10 performs case-sensitive comparisons that
The NSURL component in Apple Mac OS X 10.4 through 10.4.10 performs case-sensitive comparisons that allow attackers to bypass intended restrictions for local file system URLs.
nvd
CVE-2013-1824P4MEDIUMCVSS 4.3≥ 10.0.0, < 10.8.52013-09-16
CVE-2013-1824 [MEDIUM] CWE-611 CVE-2013-1824: The SOAP parser in PHP before 5.3.22 and 5.4.x before 5.4.12 allows remote attackers to read arbitra
The SOAP parser in PHP before 5.3.22 and 5.4.x before 5.4.12 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue in the soap_xmlParseFile and soap_xmlParseMemory functions.
nvd
CVE-2010-3786P4MEDIUMCVSS 6.8v10.6.0v10.6.1+3 more2010-11-16
CVE-2010-3786 [MEDIUM] CWE-119 CVE-2010-3786: QuickLook in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code o
QuickLook in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Excel file.
nvd
CVE-2014-1371P4HIGHCVSS 7.5≤ 10.9.3v10.7.0+14 more2014-07-01
CVE-2014-1371 [HIGH] CWE-119 CVE-2014-1371: Array index error in Dock in Apple OS X before 10.9.4 allows attackers to execute arbitrary code or
Array index error in Dock in Apple OS X before 10.9.4 allows attackers to execute arbitrary code or cause a denial of service (incorrect function-pointer dereference and application crash) by leveraging access to a sandboxed application for sending a message.
nvd
CVE-2009-2837P4MEDIUMCVSS 6.8v10.5.8v10.6+1 more2009-11-10
CVE-2009-2837 [MEDIUM] CWE-119 CVE-2009-2837: Heap-based buffer overflow in QuickDraw Manager in Apple Mac OS X before 10.6.2 allows remote attack
Heap-based buffer overflow in QuickDraw Manager in Apple Mac OS X before 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image.
nvd
CVE-2018-4175P4HIGHCVSS 7.8fixed in 10.13.42018-04-03
CVE-2018-4175 [HIGH] CWE-20 CVE-2018-4175: An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "LaunchServices" component. It allows attackers to bypass the code-signing protection mechanism via a crafted app.
nvd
CVE-2013-1026P4MEDIUMCVSS 6.8≤ 10.8.4v10.8.0+3 more2013-09-16
CVE-2013-1026 [MEDIUM] CWE-119 CVE-2013-1026: Buffer overflow in ImageIO in Apple Mac OS X before 10.8.5 allows remote attackers to execute arbitr
Buffer overflow in ImageIO in Apple Mac OS X before 10.8.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted JPEG2000 data in a PDF document.
nvd
CVE-2013-1025P4MEDIUMCVSS 6.8≤ 10.8.4v10.8.0+3 more2013-09-16
CVE-2013-1025 [MEDIUM] CWE-119 CVE-2013-1025: Buffer overflow in CoreGraphics in Apple Mac OS X before 10.8.5 allows remote attackers to execute a
Buffer overflow in CoreGraphics in Apple Mac OS X before 10.8.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted JBIG2 data in a PDF document.
nvd
CVE-2010-1801P4MEDIUMCVSS 6.8v10.5.8v10.6.42010-08-25
CVE-2010-1801 [MEDIUM] CWE-119 CVE-2010-1801: Heap-based buffer overflow in CoreGraphics in Apple Mac OS X 10.5.8 and 10.6.4 allows remote attacke
Heap-based buffer overflow in CoreGraphics in Apple Mac OS X 10.5.8 and 10.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF file.
nvd
CVE-2011-3228P4MEDIUMCVSS 6.8≤ 10.7.1v10.0+66 more2011-10-14
CVE-2011-3228 [MEDIUM] CWE-94 CVE-2011-3228: QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause
QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file.
nvd
CVE-2012-0660P4MEDIUMCVSS 6.8≤ 10.7.3v10.0+68 more2012-05-11
CVE-2012-0660 [MEDIUM] CWE-119 CVE-2012-0660: Buffer underflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arb
Buffer underflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG file.
nvd
CVE-2016-4633P4HIGHCVSS 7.8≤ 10.11.52016-07-22
CVE-2016-4633 [HIGH] CWE-264 CVE-2016-4633: Intel Graphics Driver in Apple OS X before 10.11.6 allows attackers to execute arbitrary code in a p
Intel Graphics Driver in Apple OS X before 10.11.6 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2014-3613P4MEDIUMCVSS 5.0≤ 10.10.42014-11-18
CVE-2014-3613 [MEDIUM] CWE-310 CVE-2014-3613: cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which a
cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1.
nvd
CVE-2011-0224P4MEDIUMCVSS 6.8≤ 10.6.8v10.0+64 more2011-10-14
CVE-2011-0224 [MEDIUM] CWE-94 CVE-2011-0224: CoreMedia in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or caus
CoreMedia in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted QuickTime movie file.
nvd
CVE-2011-3217P4MEDIUMCVSS 6.8≤ 10.6.8v10.0+64 more2011-10-14
CVE-2011-3217 [MEDIUM] CWE-119 CVE-2011-3217: MediaKit in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause
MediaKit in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted disk image.
nvd