Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 91 of 157
CVE-2021-30995P4HIGHCVSS 7.0≥ 10.15, < 10.15.7v10.15.72021-08-24
CVE-2021-30995 [HIGH] CWE-362 CVE-2021-30995: A race condition was addressed with improved state handling. This issue is fixed in macOS Big Sur 11
A race condition was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. A malicious application may be able to elevate privileges.
nvd
CVE-2015-7804P4MEDIUMCVSS 6.8≤ 10.11.12015-12-11
CVE-2015-7804 [MEDIUM] CWE-189 CVE-2015-7804: Off-by-one error in the phar_parse_zipfile function in ext/phar/zip.c in PHP before 5.5.30 and 5.6.x
Off-by-one error in the phar_parse_zipfile function in ext/phar/zip.c in PHP before 5.5.30 and 5.6.x before 5.6.14 allows remote attackers to cause a denial of service (uninitialized pointer dereference and application crash) by including the / filename in a .zip PHAR archive.
nvd
CVE-2010-0497P4MEDIUMCVSS 6.8≤ 10.6.2v10.5+11 more2010-03-30
CVE-2010-0497 [MEDIUM] CVE-2010-0497: Disk Images in Apple Mac OS X before 10.6.3 does not provide the expected warning for an unsafe file
Disk Images in Apple Mac OS X before 10.6.3 does not provide the expected warning for an unsafe file type in an internet enabled disk image, which makes it easier for user-assisted remote attackers to execute arbitrary code via a package file type.
nvd
CVE-2011-3450P4MEDIUMCVSS 6.8v10.7.0v10.7.1+1 more2012-02-02
CVE-2011-3450 [MEDIUM] CWE-399 CVE-2011-3450: CoreUI in Apple Mac OS X 10.7.x before 10.7.3 does not properly restrict the allocation of stack mem
CoreUI in Apple Mac OS X 10.7.x before 10.7.3 does not properly restrict the allocation of stack memory, which allows remote attackers to execute arbitrary code or cause a denial of service (memory consumption and application crash) via a long URL.
nvd
CVE-2014-1260P4MEDIUMCVSS 6.8≤ 10.8.5v10.8.0+5 more2014-02-27
CVE-2014-1260 [MEDIUM] CWE-119 CVE-2014-1260: QuickLook in Apple OS X through 10.8.5 allows remote attackers to execute arbitrary code or cause a
QuickLook in Apple OS X through 10.8.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Microsoft Office document.
nvd
CVE-2015-3727P4MEDIUMCVSS 6.8≤ 10.10.32015-07-03
CVE-2015-3727 [MEDIUM] CWE-264 CVE-2015-3727: WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS be
WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly restrict rename operations on WebSQL tables, which allows remote attackers to access an arbitrary web site's database via a crafted web site.
nvd
CVE-2015-3658P4MEDIUMCVSS 6.8≤ 10.10.32015-07-03
CVE-2015-3658 [MEDIUM] CWE-254 CVE-2015-3658: The Page Loading functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x bef
The Page Loading functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly consider redirects during decisions about sending an Origin header, which makes it easier for remote attackers to bypass CSRF protection mechanisms via a crafted web site.
nvd
CVE-2006-4402P4MEDIUMCVSS 5.1≤ 10.4.82006-11-30
CVE-2006-4402 [MEDIUM] CVE-2006-4402: Heap-based buffer overflow in the Finder in Apple Mac OS X 10.4.8 and earlier allows user-assisted r
Heap-based buffer overflow in the Finder in Apple Mac OS X 10.4.8 and earlier allows user-assisted remote attackers to execute arbitrary code by browsing directories containing crafted .DS_Store files.
nvd
CVE-2006-4391P4MEDIUMCVSS 5.1v10.4v10.4.1+6 more2006-10-03
CVE-2006-4391 [MEDIUM] CVE-2006-4391: Buffer overflow in Apple ImageIO on Apple Mac OS X 10.4 through 10.4.7 allows remote attackers to ex
Buffer overflow in Apple ImageIO on Apple Mac OS X 10.4 through 10.4.7 allows remote attackers to execute arbitrary code via a malformed JPEG2000 image.
nvd
CVE-2015-5849P4MEDIUMCVSS 6.8≤ 10.10.52015-10-09
CVE-2015-5849 [MEDIUM] CWE-264 CVE-2015-5849: The filtering implementation in AppleEvents in Apple OS X before 10.11 mishandles attempts to send e
The filtering implementation in AppleEvents in Apple OS X before 10.11 mishandles attempts to send events to a different user, which allows attackers to bypass intended access restrictions by leveraging a screen-sharing connection.
nvd
CVE-2016-1718P4HIGHCVSS 7.3≤ 10.11.22016-02-01
CVE-2016-1718 [HIGH] CWE-119 CVE-2016-1718: The IOAcceleratorFamily2 interface in IOAcceleratorFamily in Apple OS X before 10.11.3 allows local
The IOAcceleratorFamily2 interface in IOAcceleratorFamily in Apple OS X before 10.11.3 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2022-32807P4HIGHCVSS 7.1v10.15.72022-09-23
CVE-2022-32807 [HIGH] CVE-2022-32807: This issue was addressed with improved file handling. This issue is fixed in Security Update 2022-00
This issue was addressed with improved file handling. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. An app may be able to overwrite arbitrary files.
nvd
CVE-2018-4107P4MEDIUMCVSS 6.5fixed in 10.13.42018-04-03
CVE-2018-4107 [MEDIUM] CWE-20 CVE-2018-4107: An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "PDFKit" component. It allows remote attackers to bypass intended restrictions on visiting URLs within a PDF document.
nvd
CVE-2021-30652P4HIGHCVSS 7.0≥ 10.14, ≤ 10.14.5≥ 10.15, ≤ 10.15.5+3 more2021-09-08
CVE-2021-30652 [HIGH] CWE-362 CVE-2021-30652: A race condition was addressed with additional validation. This issue is fixed in Security Update 20
A race condition was addressed with additional validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A malicious application may be able to gain root privileges.
nvd
CVE-2021-30892P4MEDIUMCVSS 5.5fixed in 10.15.7v10.15.72021-08-24
CVE-2021-30892 [MEDIUM] CWE-732 CVE-2021-30892: An inherited permissions issue was addressed with additional restrictions. This issue is fixed in ma
An inherited permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.0.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. A malicious application may be able to modify protected parts of the file system.
nvd
CVE-2020-9771P4HIGHCVSS 7.1fixed in 10.15.42020-10-22
CVE-2020-9771 [HIGH] CVE-2020-9771: This issue was addressed with a new entitlement. This issue is fixed in macOS Catalina 10.15.4. A us
This issue was addressed with a new entitlement. This issue is fixed in macOS Catalina 10.15.4. A user may gain access to protected parts of the file system.
nvd
CVE-2006-1449P4HIGHCVSS 7.5v10.3.9v10.4.62006-05-12
CVE-2006-1449 [HIGH] CVE-2006-1449: Integer overflow in Mail in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to execute arbi
Integer overflow in Mail in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to execute arbitrary code via a crafted MacMIME encapsulated attachment.
nvd
CVE-2006-3946P4HIGHCVSS 7.5v10.3.9v10.4+7 more2006-07-31
CVE-2006-3946 [HIGH] CWE-119 CVE-2006-3946: WebCore in Apple Mac OS X 10.3.9 and 10.4 through 10.4.7 allows remote attackers to cause a denial o
WebCore in Apple Mac OS X 10.3.9 and 10.4 through 10.4.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted HTML that triggers a "memory management error" in WebKit, possibly due to a buffer overflow, as originally reported for the KHTMLParser::popOneBlock function in Apple Safari 2.0.4 using Jav
nvd
CVE-2006-1983P4MEDIUMCVSS 6.4v10.3v10.3.1+15 more2006-04-21
CVE-2006-1983 [MEDIUM] CWE-119 CVE-2006-1983: Multiple heap-based buffer overflows in Mac OS X 10.4.6 and earlier allow remote attackers to cause
Multiple heap-based buffer overflows in Mac OS X 10.4.6 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) PredictorVSetField function for TIFF or (2) CFAllocatorAllocate function for GIF, as used in applications that use ImageIO or AppKit. NOTE: the BMP vector has been re-assigned to CVE-200
nvd
CVE-2007-5855P4MEDIUMCVSS 6.4v10.4.11v10.5.12007-12-19
CVE-2007-5855 [MEDIUM] CWE-287 CVE-2007-5855: Mail in Apple Mac OS X 10.4.11 and 10.5.1, when an SMTP account has been set up using Account Assist
Mail in Apple Mac OS X 10.4.11 and 10.5.1, when an SMTP account has been set up using Account Assistant, can use plaintext authentication even when MD5 Challenge-Response authentication is available, which makes it easier for remote attackers to sniff account activity.
nvd