cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 86 of 157
CVE-2011-0201P4HIGHCVSS 7.5v10.6.0v10.6.1+6 more2011-06-24
CVE-2011-0201 [HIGH] CWE-189 CVE-2011-0201: Off-by-one error in the CoreFoundation framework in Apple Mac OS X before 10.6.8 allows context-depe Off-by-one error in the CoreFoundation framework in Apple Mac OS X before 10.6.8 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a CFString object that triggers a buffer overflow.
nvd
CVE-2015-7803P4MEDIUMCVSS 6.8≤ 10.11.12015-12-11
CVE-2015-7803 [MEDIUM] CVE-2015-7803: The phar_get_entry_data function in ext/phar/util.c in PHP before 5.5.30 and 5.6.x before 5.6.14 all The phar_get_entry_data function in ext/phar/util.c in PHP before 5.5.30 and 5.6.x before 5.6.14 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a .phar file with a crafted TAR archive entry in which the Link indicator references a file that does not exist.
nvd
CVE-2010-2807P4MEDIUMCVSS 6.8fixed in 10.6.52010-08-19
CVE-2010-2807 [MEDIUM] CWE-681 CVE-2010-2807: FreeType before 2.4.2 uses incorrect integer data types during bounds checking, which allows remote FreeType before 2.4.2 uses incorrect integer data types during bounds checking, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
nvd
CVE-2010-0505P4MEDIUMCVSS 6.8≤ 10.6.2v10.5+11 more2010-03-30
CVE-2010-0505 [MEDIUM] CWE-119 CVE-2010-0505: Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.3 allows remote attackers to exe Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JP2 (JPEG2000) image, related to incorrect calculation and the CGImageReadGetBytesAtOffset function.
nvd
CVE-2017-13834P4HIGHCVSS 7.8≤ 10.13.02017-11-13
CVE-2017-13834 [HIGH] CWE-119 CVE-2017-13834: An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted mach binary.
nvd
CVE-2007-4691P4CRITICALCVSS 10.0v10.3.9v10.4.1+9 more2007-11-15
CVE-2007-4691 [CRITICAL] CWE-264 CVE-2007-4691: The NSURL component in Apple Mac OS X 10.4 through 10.4.10 performs case-sensitive comparisons that The NSURL component in Apple Mac OS X 10.4 through 10.4.10 performs case-sensitive comparisons that allow attackers to bypass intended restrictions for local file system URLs.
nvd
CVE-2013-1824P4MEDIUMCVSS 4.3≥ 10.0.0, < 10.8.52013-09-16
CVE-2013-1824 [MEDIUM] CWE-611 CVE-2013-1824: The SOAP parser in PHP before 5.3.22 and 5.4.x before 5.4.12 allows remote attackers to read arbitra The SOAP parser in PHP before 5.3.22 and 5.4.x before 5.4.12 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue in the soap_xmlParseFile and soap_xmlParseMemory functions.
nvd
CVE-2010-3786P4MEDIUMCVSS 6.8v10.6.0v10.6.1+3 more2010-11-16
CVE-2010-3786 [MEDIUM] CWE-119 CVE-2010-3786: QuickLook in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code o QuickLook in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Excel file.
nvd
CVE-2014-1371P4HIGHCVSS 7.5≤ 10.9.3v10.7.0+14 more2014-07-01
CVE-2014-1371 [HIGH] CWE-119 CVE-2014-1371: Array index error in Dock in Apple OS X before 10.9.4 allows attackers to execute arbitrary code or Array index error in Dock in Apple OS X before 10.9.4 allows attackers to execute arbitrary code or cause a denial of service (incorrect function-pointer dereference and application crash) by leveraging access to a sandboxed application for sending a message.
nvd
CVE-2009-2837P4MEDIUMCVSS 6.8v10.5.8v10.6+1 more2009-11-10
CVE-2009-2837 [MEDIUM] CWE-119 CVE-2009-2837: Heap-based buffer overflow in QuickDraw Manager in Apple Mac OS X before 10.6.2 allows remote attack Heap-based buffer overflow in QuickDraw Manager in Apple Mac OS X before 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image.
nvd
CVE-2018-4175P4HIGHCVSS 7.8fixed in 10.13.42018-04-03
CVE-2018-4175 [HIGH] CWE-20 CVE-2018-4175: An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "LaunchServices" component. It allows attackers to bypass the code-signing protection mechanism via a crafted app.
nvd
CVE-2013-1026P4MEDIUMCVSS 6.8≤ 10.8.4v10.8.0+3 more2013-09-16
CVE-2013-1026 [MEDIUM] CWE-119 CVE-2013-1026: Buffer overflow in ImageIO in Apple Mac OS X before 10.8.5 allows remote attackers to execute arbitr Buffer overflow in ImageIO in Apple Mac OS X before 10.8.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted JPEG2000 data in a PDF document.
nvd
CVE-2013-1025P4MEDIUMCVSS 6.8≤ 10.8.4v10.8.0+3 more2013-09-16
CVE-2013-1025 [MEDIUM] CWE-119 CVE-2013-1025: Buffer overflow in CoreGraphics in Apple Mac OS X before 10.8.5 allows remote attackers to execute a Buffer overflow in CoreGraphics in Apple Mac OS X before 10.8.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted JBIG2 data in a PDF document.
nvd
CVE-2010-1801P4MEDIUMCVSS 6.8v10.5.8v10.6.42010-08-25
CVE-2010-1801 [MEDIUM] CWE-119 CVE-2010-1801: Heap-based buffer overflow in CoreGraphics in Apple Mac OS X 10.5.8 and 10.6.4 allows remote attacke Heap-based buffer overflow in CoreGraphics in Apple Mac OS X 10.5.8 and 10.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF file.
nvd
CVE-2011-3228P4MEDIUMCVSS 6.8≤ 10.7.1v10.0+66 more2011-10-14
CVE-2011-3228 [MEDIUM] CWE-94 CVE-2011-3228: QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file.
nvd
CVE-2012-0660P4MEDIUMCVSS 6.8≤ 10.7.3v10.0+68 more2012-05-11
CVE-2012-0660 [MEDIUM] CWE-119 CVE-2012-0660: Buffer underflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arb Buffer underflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG file.
nvd
CVE-2016-4633P4HIGHCVSS 7.8≤ 10.11.52016-07-22
CVE-2016-4633 [HIGH] CWE-264 CVE-2016-4633: Intel Graphics Driver in Apple OS X before 10.11.6 allows attackers to execute arbitrary code in a p Intel Graphics Driver in Apple OS X before 10.11.6 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2014-3613P4MEDIUMCVSS 5.0≤ 10.10.42014-11-18
CVE-2014-3613 [MEDIUM] CWE-310 CVE-2014-3613: cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which a cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1.
nvd
CVE-2011-0224P4MEDIUMCVSS 6.8≤ 10.6.8v10.0+64 more2011-10-14
CVE-2011-0224 [MEDIUM] CWE-94 CVE-2011-0224: CoreMedia in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or caus CoreMedia in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted QuickTime movie file.
nvd
CVE-2011-3217P4MEDIUMCVSS 6.8≤ 10.6.8v10.0+64 more2011-10-14
CVE-2011-3217 [MEDIUM] CWE-119 CVE-2011-3217: MediaKit in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause MediaKit in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted disk image.
nvd