cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 89 of 157
CVE-2005-0126P4HIGHCVSS 7.5v10.2.8v10.3.7+1 more2005-05-02
CVE-2005-0126 [HIGH] CVE-2005-0126: ColorSync on Mac OS X 10.3.7 and 10.3.8 allows attackers to execute arbitrary code via malformed ICC ColorSync on Mac OS X 10.3.7 and 10.3.8 allows attackers to execute arbitrary code via malformed ICC color profiles that modify the heap.
nvd
CVE-2006-4394P4HIGHCVSS 7.5v10.4v10.4.1+6 more2006-10-03
CVE-2006-4394 [HIGH] CVE-2006-4394: A logic error in LoginWindow in Apple Mac OS X 10.4 through 10.4.7, allows network accounts without A logic error in LoginWindow in Apple Mac OS X 10.4 through 10.4.7, allows network accounts without GUIds to bypass service access controls and log into the system using loginwindow via unknown vectors.
nvd
CVE-2015-7942P4MEDIUMCVSS 6.8≤ 10.11.32015-11-18
CVE-2015-7942 [MEDIUM] CVE-2015-7942: The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different vulnerability than CVE-2015-7941.
nvd
CVE-2017-6988P4MEDIUMCVSS 5.9≤ 10.12.42017-05-22
CVE-2017-6988 [MEDIUM] CWE-295 CVE-2017-6988: An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "802.1X" component. It allows remote attackers to discover the network credentials of arbitrary users by operating a crafted network that requires 802.1X authentication, because EAP-TLS certificate validation mishandles certificate changes.
nvd
CVE-2015-1105P4MEDIUMCVSS 5.0≤ 10.10.22015-04-10
CVE-2015-1105 [MEDIUM] CWE-20 CVE-2015-1105: The TCP implementation in the kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple T The TCP implementation in the kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 does not properly implement the Urgent (aka out-of-band data) mechanism, which allows remote attackers to cause a denial of service via crafted packets.
nvd
CVE-2019-13057P4MEDIUMCVSS 4.9≥ 10.13, < 10.13.6≥ 10.14, < 10.14.6+3 more2019-07-26
CVE-2019-13057 [MEDIUM] CVE-2019-13057: An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator deleg An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or
nvd
CVE-2014-7185P4MEDIUMCVSS 6.4≤ 10.10.42014-10-08
CVE-2014-7185 [MEDIUM] CWE-189 CVE-2014-7185: Integer overflow in bufferobject.c in Python before 2.7.8 allows context-dependent attackers to obta Integer overflow in bufferobject.c in Python before 2.7.8 allows context-dependent attackers to obtain sensitive information from process memory via a large size and offset in a "buffer" function.
nvd
CVE-2009-2192P4HIGHCVSS 7.5v10.5.6v10.5+7 more2009-08-06
CVE-2009-2192 [HIGH] CWE-255 CVE-2009-2192: MobileMe in Apple Mac OS X 10.5 before 10.5.8 does not properly delete credentials upon signout from MobileMe in Apple Mac OS X 10.5 before 10.5.8 does not properly delete credentials upon signout from the preference pane, which makes it easier for attackers to hijack a MobileMe session via unspecified vectors, related to a "logic issue."
nvd
CVE-2015-0253P4MEDIUMCVSS 5.0v10.10.42015-07-20
CVE-2015-0253 [MEDIUM] CVE-2015-0253: The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initia The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initialize the protocol structure member, which allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) by sending a request that lacks a method to an installation that enables the INCLUDES filter and has an ErrorDocument 400
nvd
CVE-2009-0160P4MEDIUMCVSS 6.8v10.4.11v10.5.0+6 more2009-05-13
CVE-2009-0160 [MEDIUM] CWE-94 CVE-2009-0160: QuickDraw Manager in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execut QuickDraw Manager in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image that triggers memory corruption.
nvd
CVE-2002-0655P4HIGHCVSS 7.5v10.0v10.0.1+9 more2002-08-12
CVE-2002-0655 [HIGH] CVE-2002-0655: OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handle ASCII representati OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handle ASCII representations of integers on 64 bit platforms, which could allow attackers to cause a denial of service and possibly execute arbitrary code.
nvd
CVE-2010-0062P4MEDIUMCVSS 6.8v10.6.0v10.6.1+1 more2010-03-30
CVE-2010-0062 [MEDIUM] CWE-119 CVE-2010-0062: Heap-based buffer overflow in quicktime.qts in CoreMedia and QuickTime in Apple Mac OS X before 10.6 Heap-based buffer overflow in quicktime.qts in CoreMedia and QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed .3g2 movie file with H.263 encoding that triggers an incorrect buffer length calculation.
nvd
CVE-2015-3675P4MEDIUMCVSS 5.0≤ 10.10.32015-07-03
CVE-2015-3675 [MEDIUM] CWE-284 CVE-2015-3675: The default configuration of the Apache HTTP Server on Apple OS X before 10.10.4 does not enable the The default configuration of the Apache HTTP Server on Apple OS X before 10.10.4 does not enable the mod_hfs_apple module, which allows remote attackers to bypass HTTP authentication via a crafted URL.
nvd
CVE-2008-0056P4MEDIUMCVSS 6.8v10.4.112008-03-18
CVE-2008-0056 [MEDIUM] CWE-119 CVE-2008-0056: Stack-based buffer overflow in Foundation in Apple Mac OS X 10.4.11 allows context-dependent attacke Stack-based buffer overflow in Foundation in Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via a "long pathname with an unexpected structure" that triggers the overflow in NSFileManager.
nvd
CVE-2012-0658P4MEDIUMCVSS 6.8≤ 10.7.3v10.0+68 more2012-05-11
CVE-2012-0658 [MEDIUM] CWE-119 CVE-2012-0658: Buffer overflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbi Buffer overflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted audio sample tables in a movie file that is progressively downloaded.
nvd
CVE-2017-7010P4HIGHCVSS 7.8≤ 10.12.52017-07-20
CVE-2017-7010 [HIGH] CWE-125 CVE-2017-7010: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "libxml2" component. It allows remote attackers to obtain sensitive information or cause a deni
nvd
CVE-2017-7013P4HIGHCVSS 7.8≤ 10.12.52017-07-20
CVE-2017-7013 [HIGH] CWE-125 CVE-2017-7013: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "libxml2" component. It allows remote attackers to obtain sen
nvd
CVE-2017-7015P4HIGHCVSS 7.8≤ 10.12.52017-07-20
CVE-2017-7015 [HIGH] CWE-119 CVE-2017-7015: An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Audio" component. It allows remote attackers to obtain sensitive information from process memory or cause a denial of service (memory corruption) via a crafted audio file.
nvd
CVE-2016-7655P4HIGHCVSS 7.8≤ 10.12.12017-02-20
CVE-2016-7655 [HIGH] CWE-704 CVE-2016-7655: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. The issue involves the "CoreMedia External Displays" component. It allows local users to gain privileges or cause a denial of service (type confusion) via unspecified vectors.
nvd
CVE-2018-4219P4HIGHCVSS 7.8fixed in 10.13.52018-06-08
CVE-2018-4219 [HIGH] CWE-704 CVE-2018-4219: An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "ATS" component. It allows attackers to gain privileges via a crafted app that leverages type confusion.
nvd
Apple macOS vulnerabilities | cvebase