cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 90 of 157
CVE-2010-3785P4MEDIUMCVSS 6.8v10.5.8v10.6.0+4 more2010-11-16
CVE-2010-3785 [MEDIUM] CWE-119 CVE-2010-3785: Buffer overflow in QuickLook in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attacke Buffer overflow in QuickLook in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Office document.
nvd
CVE-2011-3223P4MEDIUMCVSS 6.8≤ 10.7.1v10.0+66 more2011-10-14
CVE-2011-3223 [MEDIUM] CWE-119 CVE-2011-3223: Buffer overflow in QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbi Buffer overflow in QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FLIC movie file.
nvd
CVE-2011-3222P4MEDIUMCVSS 6.8≤ 10.7.1v10.0+66 more2011-10-14
CVE-2011-3222 [MEDIUM] CWE-119 CVE-2011-3222: Buffer overflow in QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbi Buffer overflow in QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FlashPix file.
nvd
CVE-2010-3791P4MEDIUMCVSS 6.8v10.6.0v10.6.1+3 more2010-11-16
CVE-2010-3791 [MEDIUM] CWE-119 CVE-2010-3791: Buffer overflow in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execu Buffer overflow in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG movie file.
nvd
CVE-2006-4410P4HIGHCVSS 7.5v10.3.9v10.4+6 more2006-11-30
CVE-2006-4410 [HIGH] CVE-2006-4410: The Security Framework in Apple Mac OS X 10.3.9, and 10.4.x before 10.4.7, does not properly search The Security Framework in Apple Mac OS X 10.3.9, and 10.4.x before 10.4.7, does not properly search certificate revocation lists (CRL), which allows remote attackers to access systems by using revoked certificates.
nvd
CVE-2010-0513P4MEDIUMCVSS 6.8≤ 10.6.2v10.5+11 more2010-03-30
CVE-2010-0513 [MEDIUM] CWE-119 CVE-2010-0513: Stack-based buffer overflow in PS Normalizer in Apple Mac OS X before 10.6.3 allows remote attackers Stack-based buffer overflow in PS Normalizer in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PostScript document.
nvd
CVE-2009-2826P4MEDIUMCVSS 6.8v10.5.82009-11-10
CVE-2009-2826 [MEDIUM] CWE-189 CVE-2009-2826: Multiple integer overflows in CoreGraphics in Apple Mac OS X 10.5.8 allow remote attackers to execut Multiple integer overflows in CoreGraphics in Apple Mac OS X 10.5.8 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document that triggers a heap-based buffer overflow.
nvd
CVE-2010-1376P4MEDIUMCVSS 6.8v10.6.0v10.6.1+2 more2010-06-17
CVE-2010-1376 [MEDIUM] CWE-134 CVE-2010-1376: Multiple format string vulnerabilities in Network Authorization in Apple Mac OS X 10.6 before 10.6.4 Multiple format string vulnerabilities in Network Authorization in Apple Mac OS X 10.6 before 10.6.4 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a (1) afp, (2) cifs, or (3) smb URL.
nvd
CVE-2012-0659P4MEDIUMCVSS 6.8≤ 10.7.3v10.0+68 more2012-05-11
CVE-2012-0659 [MEDIUM] CWE-189 CVE-2012-0659: Integer overflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arb Integer overflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG file.
nvd
CVE-2011-3213P4HIGHCVSS 7.6≤ 10.7.1v10.0+66 more2011-10-14
CVE-2011-3213 [HIGH] CWE-264 CVE-2011-3213: The File Systems component in Apple Mac OS X before 10.7.2 does not properly track the specific X.50 The File Systems component in Apple Mac OS X before 10.7.2 does not properly track the specific X.509 certificate that a user manually accepted for an initial https WebDAV connection, which allows man-in-the-middle attackers to hijack WebDAV communication by presenting an arbitrary certificate for a subsequent connection.
nvd
CVE-2008-0057P4MEDIUMCVSS 6.8v10.4.112008-03-18
CVE-2008-0057 [MEDIUM] CWE-189 CVE-2008-0057: Multiple integer overflows in a "legacy serialization format" parser in AppKit in Apple Mac OS X 10. Multiple integer overflows in a "legacy serialization format" parser in AppKit in Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary code via a crafted serialized property list.
nvd
CVE-2009-1717P4MEDIUMCVSS 6.8v10.5v10.5.0+6 more2009-06-05
CVE-2009-1717 [MEDIUM] CWE-189 CVE-2009-1717: Integer overflow in Terminal in Apple Mac OS X 10.5 before 10.5.7 allows remote attackers to execute Integer overflow in Terminal in Apple Mac OS X 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted size value in a CSI[4 xterm resize escape sequence that triggers a heap-based buffer overflow.
nvd
CVE-2011-3221P4MEDIUMCVSS 6.8≤ 10.7.1v10.0+66 more2011-10-14
CVE-2011-3221 [MEDIUM] CWE-94 CVE-2011-3221: QuickTime in Apple Mac OS X before 10.7.2 does not properly handle the atom hierarchy in movie files QuickTime in Apple Mac OS X before 10.7.2 does not properly handle the atom hierarchy in movie files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted file.
nvd
CVE-2011-0184P4MEDIUMCVSS 6.8v10.6.0v10.6.1+5 more2011-03-23
CVE-2011-0184 [MEDIUM] CWE-119 CVE-2011-0184: QuickLook in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to execute arbitrary code or QuickLook in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via an Excel spreadsheet with a crafted formula that uses unspecified opcodes.
nvd
CVE-2011-0208P4MEDIUMCVSS 6.8v10.6.0v10.6.1+6 more2011-06-24
CVE-2011-0208 [MEDIUM] CWE-119 CVE-2011-0208: QuickLook in Apple Mac OS X 10.6 before 10.6.8 allows remote attackers to execute arbitrary code or QuickLook in Apple Mac OS X 10.6 before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Microsoft Office document.
nvd
CVE-2007-5856P4CRITICALCVSS 9.4v10.5.12007-12-19
CVE-2007-5856 [CRITICAL] CWE-16 CVE-2007-5856: Quick Look Apple Mac OS X 10.5.1, when previewing an HTML file, does not prevent plug-ins from makin Quick Look Apple Mac OS X 10.5.1, when previewing an HTML file, does not prevent plug-ins from making network requests, which might allow remote attackers to obtain sensitive information.
nvd
CVE-2013-1024P4MEDIUMCVSS 6.8≤ 10.8.3v10.7.0+8 more2013-06-05
CVE-2013-1024 [MEDIUM] CWE-20 CVE-2013-1024: CoreMedia Playback in Apple Mac OS X before 10.8.4 does not properly initialize memory during the pr CoreMedia Playback in Apple Mac OS X before 10.8.4 does not properly initialize memory during the processing of text tracks, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file.
nvd
CVE-2011-0210P4MEDIUMCVSS 6.8fixed in 10.6.82011-06-24
CVE-2011-0210 [MEDIUM] CWE-787 CVE-2011-0210: QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted sample tables in a movie file.
nvd
CVE-2010-1845P4MEDIUMCVSS 6.8v10.5.8v10.6.0+4 more2010-11-16
CVE-2010-1845 [MEDIUM] CWE-20 CVE-2010-1845: ImageIO in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitra ImageIO in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted PSD image.
nvd
CVE-2016-4678P4HIGHCVSS 7.8≤ 10.12.02017-02-20
CVE-2016-4678 [HIGH] CWE-476 CVE-2016-4678: An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "AppleSMC" component. It allows local users to gain privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors.
nvd