cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 88 of 157
CVE-2018-4151P4HIGHCVSS 7.0fixed in 10.13.42018-04-03
CVE-2018-4151 [HIGH] CWE-362 CVE-2018-4151: An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. The issue involves the "iCloud Drive" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2022-26726P4MEDIUMCVSS 6.5fixed in 10.15.7v10.15.72022-05-26
CVE-2022-26726 [MEDIUM] CVE-2022-26726: This issue was addressed with improved checks. This issue is fixed in Security Update 2022-004 Catal This issue was addressed with improved checks. This issue is fixed in Security Update 2022-004 Catalina, watchOS 8.6, macOS Monterey 12.4, macOS Big Sur 11.6.6. An app may be able to capture a user's screen.
nvd
CVE-2021-1806P4HIGHCVSS 7.0≥ 10.14, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-04-02
CVE-2021-1806 [HIGH] CWE-362 CVE-2021-1806: A race condition was addressed with additional validation. This issue is fixed in macOS Big Sur 11.2 A race condition was addressed with additional validation. This issue is fixed in macOS Big Sur 11.2.1, macOS Catalina 10.15.7 Supplemental Update, macOS Mojave 10.14.6 Security Update 2021-002. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2015-5882P4HIGHCVSS 7.2≤ 10.10.52015-09-18
CVE-2015-5882 [HIGH] CWE-284 CVE-2015-5882: The processor_set_tasks API implementation in Apple iOS before 9 allows local users to bypass an ent The processor_set_tasks API implementation in Apple iOS before 9 allows local users to bypass an entitlement protection mechanism and obtain access to the task ports of arbitrary processes by leveraging root privileges.
nvd
CVE-2020-27921P4HIGHCVSS 7.0fixed in 11.0.1fixed in 11.1.02021-04-02
CVE-2020-27921 [HIGH] CWE-362 CVE-2020-27921: A race condition was addressed with improved state handling. This issue is fixed in macOS Big Sur 11 A race condition was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2021-22925P4MEDIUMCVSS 5.3v10.15.72021-08-05
CVE-2021-22925 [MEDIUM] CWE-200 CVE-2021-22925: curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revea
nvd
CVE-2019-8598P4MEDIUMCVSS 5.5fixed in 10.14.52019-12-18
CVE-2019-8598 [MEDIUM] CWE-119 CVE-2019-8598: An input validation issue was addressed with improved input validation. This issue is fixed in iOS 1 An input validation issue was addressed with improved input validation. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. A malicious application may be able to read restricted memory.
nvd
CVE-2020-9796P4HIGHCVSS 7.0fixed in 10.15.52020-10-22
CVE-2020-9796 [HIGH] CWE-362 CVE-2020-9796: A race condition was addressed with improved state handling. This issue is fixed in macOS Catalina 1 A race condition was addressed with improved state handling. This issue is fixed in macOS Catalina 10.15.5. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2019-8607P4MEDIUMCVSS 6.5fixed in 10.14.52019-12-18
CVE-2019-8607 [MEDIUM] CWE-125 CVE-2019-8607: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.3, An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may result in the disclosure of process memory.
nvd
CVE-2005-2747P4HIGHCVSS 7.5v10.4.22005-10-25
CVE-2005-2747 [HIGH] CVE-2005-2747: Buffer overflow in ImageIO for Apple Mac OS X 10.4.2, as used by applications such as WebCore and Sa Buffer overflow in ImageIO for Apple Mac OS X 10.4.2, as used by applications such as WebCore and Safari, allows remote attackers to execute arbitrary code via a crafted GIF file.
nvd
CVE-2022-22662P4MEDIUMCVSS 6.5≥ 10.15, < 10.15.7v10.15.72022-05-26
CVE-2022-22662 [MEDIUM] CVE-2022-22662: A cookie management issue was addressed with improved state management. This issue is fixed in Secur A cookie management issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Big Sur 11.6.5. Processing maliciously crafted web content may disclose sensitive user information.
nvd
CVE-2006-1469P4HIGHCVSS 7.5v10.4v10.4.1+5 more2006-06-27
CVE-2006-1469 [HIGH] CWE-119 CVE-2006-1469: Stack-based buffer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.6 allows attackers to cause Stack-based buffer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.6 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image.
nvd
CVE-2014-3620P4MEDIUMCVSS 5.0≤ 10.10.42014-11-18
CVE-2014-3620 [MEDIUM] CWE-310 CVE-2014-3620: cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cooki cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a top-level domain.
nvd
CVE-2010-0036P4HIGHCVSS 7.8v10.5.8v10.6.22010-01-20
CVE-2010-0036 [HIGH] CWE-119 CVE-2010-0036: Buffer overflow in CoreAudio in Apple Mac OS X 10.5.8 and 10.6.2 allows remote attackers to execute Buffer overflow in CoreAudio in Apple Mac OS X 10.5.8 and 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MP4 audio file.
nvd
CVE-2019-8736P4MEDIUMCVSS 6.5fixed in 10.152020-10-27
CVE-2019-8736 [MEDIUM] CWE-20 CVE-2019-8736: An input validation issue was addressed with improved input validation. This issue is fixed in macOS An input validation issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, macOS Catalina 10.15. An attacker in a privileged network position may be able to leak sensitive user information.
nvd
CVE-2019-8645P4MEDIUMCVSS 6.5fixed in 10.14.42020-10-27
CVE-2019-8645 [MEDIUM] CVE-2019-8645: An issue existed in the handling of encrypted Mail. This issue was addressed with improved isolation An issue existed in the handling of encrypted Mail. This issue was addressed with improved isolation of MIME in Mail. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra. An attacker in a privileged network position may be able to intercept the contents of S/MIME-encrypted e-mail.
nvd
CVE-2007-0719P4MEDIUMCVSS 6.8v10.3.9v10.4+8 more2007-03-13
CVE-2007-0719 [MEDIUM] CVE-2007-0719: Stack-based buffer overflow in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assi Stack-based buffer overflow in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via an image with a crafted ColorSync profile.
nvd
CVE-2005-0373P4HIGHCVSS 7.5v10.0v10.0.1+27 more2004-10-07
CVE-2005-0373 [HIGH] CVE-2005-0373: Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL but not in any official releases, allows remote attackers to execute arbitrary code.
nvd
CVE-2017-2448P4MEDIUMCVSS 5.9≤ 10.12.32017-04-02
CVE-2017-2448 [MEDIUM] CWE-200 CVE-2017-2448: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. The issue involves the "Keychain" component. It allows man-in-the-middle attackers to bypass an iCloud Keychain secret protection mechanism by leveraging lack of authentication for OTR packets.
nvd
CVE-2004-0079P4HIGHCVSS 7.5v10.3.32004-11-23
CVE-2004-0079 [HIGH] CWE-476 CVE-2004-0079: The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.
nvd
Apple macOS vulnerabilities | cvebase