Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 87 of 157
CVE-2016-4647P4HIGHCVSS 7.8≤ 10.11.52016-07-22
CVE-2016-4647 [HIGH] CWE-119 CVE-2016-4647: Audio in Apple OS X before 10.11.6 allows local users to gain privileges or cause a denial of servic
Audio in Apple OS X before 10.11.6 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted file.
nvd
CVE-2017-2437P4HIGHCVSS 7.8≤ 10.12.32017-04-02
CVE-2017-2437 [HIGH] CWE-119 CVE-2017-2437: An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "IOFireWireAVC" component. It allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2013-1032P4MEDIUMCVSS 6.8fixed in 10.8.52013-09-16
CVE-2013-1032 [MEDIUM] CWE-787 CVE-2013-1032: QuickTime in Apple Mac OS X before 10.8.5 allows remote attackers to execute arbitrary code or cause
QuickTime in Apple Mac OS X before 10.8.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted idsc atom in a QuickTime movie file.
nvd
CVE-2013-0975P4MEDIUMCVSS 6.8v10.7.0v10.7.1+8 more2013-06-05
CVE-2013-0975 [MEDIUM] CWE-119 CVE-2013-0975: Buffer overflow in QuickDraw Manager in Apple Mac OS X before 10.8.4 allows remote attackers to exec
Buffer overflow in QuickDraw Manager in Apple Mac OS X before 10.8.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image.
nvd
CVE-2015-3659P4MEDIUMCVSS 6.8≤ 10.10.32015-07-03
CVE-2015-3659 [MEDIUM] CWE-264 CVE-2015-3659: The SQLite authorizer in the Storage functionality in WebKit in Apple Safari before 6.2.7, 7.x befor
The SQLite authorizer in the Storage functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly restrict access to SQL functions, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted
nvd
CVE-2011-0179P4MEDIUMCVSS 6.8≤ 10.6.6v10.6.0+5 more2011-03-23
CVE-2011-0179 [MEDIUM] CWE-119 CVE-2011-0179: CoreText in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code or cause
CoreText in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a document that contains a crafted embedded font.
nvd
CVE-2013-5170P4MEDIUMCVSS 6.8≤ 10.8.5v10.8.0+5 more2013-10-24
CVE-2013-5170 [MEDIUM] CWE-119 CVE-2013-5170: Buffer underflow in CoreGraphics in Apple Mac OS X before 10.9 allows remote attackers to execute ar
Buffer underflow in CoreGraphics in Apple Mac OS X before 10.9 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.
nvd
CVE-2015-2783P4MEDIUMCVSS 5.8≤ 10.10.52015-06-09
CVE-2015-2783 [MEDIUM] CWE-119 CVE-2015-2783: ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote atta
ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read and application crash) via a crafted length value in conjunction with crafted serialized data in a phar archive, related to the phar_parse_metadata
nvd
CVE-2014-1370P4MEDIUMCVSS 6.8≤ 10.9.3v10.7.0+14 more2014-07-01
CVE-2014-1370 [MEDIUM] CWE-119 CVE-2014-1370: The byte-swapping implementation in copyfile in Apple OS X before 10.9.4 allows remote attackers to
The byte-swapping implementation in copyfile in Apple OS X before 10.9.4 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds memory access and application crash) via a crafted AppleDouble file in a ZIP archive.
nvd
CVE-2011-0174P4MEDIUMCVSS 6.8≤ 10.6.6v10.6.0+5 more2011-03-23
CVE-2011-0174 [MEDIUM] CWE-119 CVE-2011-0174: Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allows remot
Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code via a document that contains a crafted embedded OpenType font.
nvd
CVE-2015-7001P4MEDIUMCVSS 6.8≤ 10.11.12015-12-11
CVE-2015-7001 [MEDIUM] CWE-264 CVE-2015-7001: AppSandbox in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 mis
AppSandbox in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 mishandles hard links, which allows attackers to bypass Contacts access revocation via a crafted app.
nvd
CVE-2014-1319P4MEDIUMCVSS 6.8v10.9v10.9.1+1 more2014-04-23
CVE-2014-1319 [MEDIUM] CWE-119 CVE-2014-1319: Buffer overflow in ImageIO in Apple OS X 10.9.x through 10.9.2 allows remote attackers to execute ar
Buffer overflow in ImageIO in Apple OS X 10.9.x through 10.9.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG image.
nvd
CVE-2014-4441P4MEDIUMCVSS 6.8≤ 10.9.52014-10-18
CVE-2014-4441 [MEDIUM] CWE-264 CVE-2014-4441: NetFS Client Framework in Apple OS X before 10.10 does not ensure that the disabling of File Sharing
NetFS Client Framework in Apple OS X before 10.10 does not ensure that the disabling of File Sharing is always possible, which allows remote attackers to read or write to files by leveraging a state in which File Sharing is permanently enabled.
nvd
CVE-2015-6985P4MEDIUMCVSS 6.8≤ 10.11.02015-10-23
CVE-2015-6985 [MEDIUM] CWE-119 CVE-2015-6985: Apple Type Services (ATS) in Apple OS X before 10.11.1 allows remote attackers to execute arbitrary
Apple Type Services (ATS) in Apple OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web page.
nvd
CVE-2014-1315P4MEDIUMCVSS 6.8v10.9v10.9.1+1 more2014-04-23
CVE-2014-1315 [MEDIUM] CWE-134 CVE-2014-1315: Format string vulnerability in CoreServicesUIAgent in Apple OS X 10.9.x through 10.9.2 allows remote
Format string vulnerability in CoreServicesUIAgent in Apple OS X 10.9.x through 10.9.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a URL.
nvd
CVE-2018-4187P4MEDIUMCVSS 6.5fixed in 10.13.42018-06-08
CVE-2018-4187 [MEDIUM] CWE-20 CVE-2018-4187: An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13.4 Security Update 2018-001 is affected. The issue involves the "LinkPresentation" component. It allows remote attackers to spoof the UI via a crafted URL in a text message.
nvd
CVE-2018-4156P4HIGHCVSS 7.0fixed in 10.13.42018-04-03
CVE-2018-4156 [HIGH] CWE-362 CVE-2018-4156: An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4
An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. The issue involves the "PluginKit" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2018-4167P4HIGHCVSS 7.0fixed in 10.13.42018-04-03
CVE-2018-4167 [HIGH] CWE-362 CVE-2018-4167: An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4
An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "File System Events" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2018-4154P4HIGHCVSS 7.0fixed in 10.13.42018-04-03
CVE-2018-4154 [HIGH] CWE-362 CVE-2018-4154: An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4
An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. The issue involves the "Storage" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2018-4158P4HIGHCVSS 7.0fixed in 10.13.42018-04-03
CVE-2018-4158 [HIGH] CWE-362 CVE-2018-4158: An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4
An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. watchOS before 4.3 is affected. The issue involves the "CoreFoundation" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd