Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 9 of 157
CVE-2019-6205P3HIGHCVSS 7.8PoCfixed in 10.14.32019-03-05
CVE-2019-6205 [HIGH] CWE-787 CVE-2019-6205: A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iO
A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A malicious application may cause unexpected changes in memory shared between processes.
nvd
CVE-2018-4083P3HIGHCVSS 7.8PoCfixed in 10.13.32018-04-03
CVE-2018-4083 [HIGH] CWE-119 CVE-2018-4083: An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue involves the "Touch Bar Support" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2019-8514P3HIGHCVSS 7.8PoCfixed in 10.14.42019-12-18
CVE-2019-8514 [HIGH] CVE-2019-8514: A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS M
A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. An application may be able to gain elevated privileges.
nvd
CVE-2019-8717P3HIGHCVSS 7.8PoCfixed in 10.152019-12-18
CVE-2019-8717 [HIGH] CWE-787 CVE-2019-8717: A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15, tvOS 13. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2016-1825P3HIGHCVSS 7.8PoC≤ 10.11.42016-05-20
CVE-2016-1825 [HIGH] CWE-119 CVE-2016-1825: IOHIDFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged
IOHIDFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2016-1743P3HIGHCVSS 7.8PoC≤ 10.11.32016-03-24
CVE-2016-1743 [HIGH] CWE-119 CVE-2016-1743: The Intel driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to
The Intel driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1744.
nvd
CVE-2016-1846P3HIGHCVSS 7.8PoC≤ 10.11.42016-05-20
CVE-2016-1846 [HIGH] CWE-119 CVE-2016-1846: The nvCommandQueue::GetHandleIndex method in the NVIDIA Graphics Drivers subsystem in Apple OS X bef
The nvCommandQueue::GetHandleIndex method in the NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference and memory corruption) via a crafted app.
nvd
CVE-2016-1794P3HIGHCVSS 7.8PoC≤ 10.11.42016-05-20
CVE-2016-1794 [HIGH] CVE-2016-1794: The AppleGraphicsControlClient::checkArguments method in AppleGraphicsControl in Apple OS X before 1
The AppleGraphicsControlClient::checkArguments method in AppleGraphicsControl in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.
nvd
CVE-2016-1861P3HIGHCVSS 7.8PoC≤ 10.11.42016-06-19
CVE-2016-1861 [HIGH] CVE-2016-1861: The NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows attackers to execute arbit
The NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1846.
nvd
CVE-2017-6978P3HIGHCVSS 7.8PoC≤ 10.12.42017-05-22
CVE-2017-6978 [HIGH] CWE-119 CVE-2017-6978: An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Accessibility Framework" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-2443P3HIGHCVSS 7.8PoC≤ 10.12.32017-04-02
CVE-2017-2443 [HIGH] CWE-119 CVE-2017-2443: An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2019-8600P2CRITICALCVSS 9.8fixed in 10.14.52019-12-18
CVE-2019-8600 [CRITICAL] CWE-89 CVE-2019-8600: A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 1
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. A maliciously crafted SQL query may lead to arbitrary code execution.
nvd
CVE-2016-1848P3HIGHCVSS 7.8PoC≤ 10.11.42016-05-20
CVE-2016-1848 [HIGH] CWE-119 CVE-2016-1848: QuickTime in Apple OS X before 10.11.5 allows remote attackers to execute arbitrary code or cause a
QuickTime in Apple OS X before 10.11.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file.
nvd
CVE-2016-1769P3HIGHCVSS 7.8PoC≤ 10.11.32016-03-24
CVE-2016-1769 [HIGH] CWE-119 CVE-2016-1769: QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a
QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Photoshop file.
nvd
CVE-2016-1821P3HIGHCVSS 7.8PoC≤ 10.11.42016-05-20
CVE-2016-1821 [HIGH] CVE-2016-1821: IOAudioFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privilege
IOAudioFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.
nvd
CVE-2016-1793P3HIGHCVSS 7.8PoC≤ 10.11.42016-05-20
CVE-2016-1793 [HIGH] CVE-2016-1793: AppleGraphicsDeviceControlClient in Apple OS X before 10.11.5 allows attackers to execute arbitrary
AppleGraphicsDeviceControlClient in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.
nvd
CVE-2016-1744P3HIGHCVSS 7.8PoC≤ 10.11.32016-03-24
CVE-2016-1744 [HIGH] CVE-2016-1744: The Intel driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to
The Intel driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1743.
nvd
CVE-2016-1749P3HIGHCVSS 7.8PoC≤ 10.11.32016-03-24
CVE-2016-1749 [HIGH] CWE-119 CVE-2016-1749: IOUSBFamily in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged
IOUSBFamily in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2018-25032P3HIGHCVSS 7.5≥ 10.15, < 10.15.7v10.15.7+13 more2022-03-25
CVE-2018-25032 [HIGH] CWE-787 CVE-2018-25032: zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
nvd
CVE-2018-4435P3HIGHCVSS 7.8PoCfixed in 10.14.22019-04-03
CVE-2018-4435 [HIGH] CWE-20 CVE-2018-4435: A logic issue was addressed with improved restrictions. This issue affected versions prior to iOS 12
A logic issue was addressed with improved restrictions. This issue affected versions prior to iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2.
nvd