Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 92 of 157
CVE-2018-4460P4MEDIUMCVSS 6.5fixed in 10.14.22019-04-03
CVE-2018-4460 [MEDIUM] CWE-20 CVE-2018-4460: A denial of service issue was addressed by removing the vulnerable code. This issue affected version
A denial of service issue was addressed by removing the vulnerable code. This issue affected versions prior to iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2.
nvd
CVE-2021-1860P4MEDIUMCVSS 6.5≥ 10.14, ≤ 10.14.5≥ 10.15, ≤ 10.15.5+3 more2021-09-08
CVE-2021-1860 [MEDIUM] CWE-665 CVE-2021-1860: A memory initialization issue was addressed with improved memory handling. This issue is fixed in Se
A memory initialization issue was addressed with improved memory handling. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A malicious application may be able to disclose kernel memory.
nvd
CVE-2019-8517P4MEDIUMCVSS 6.5fixed in 10.14.42019-12-18
CVE-2019-8517 [MEDIUM] CWE-125 CVE-2019-8517: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.2,
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. Processing a maliciously crafted font may result in the disclosure of process memory.
nvd
CVE-2021-1857P4MEDIUMCVSS 6.5v10.14v10.14.0+14 more2021-09-08
CVE-2021-1857 [MEDIUM] CWE-665 CVE-2021-1857: A memory initialization issue was addressed with improved memory handling. This issue is fixed in iT
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iTunes 12.11.3 for Windows, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iCloud for Windows 12.3, macOS Big Sur 11.3, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing maliciously crafted web content may disclose sensitiv
nvd
CVE-2010-1829P4MEDIUMCVSS 6.0v10.5.8v10.6.0+4 more2010-11-15
CVE-2010-1829 [MEDIUM] CWE-22 CVE-2010-1829: Directory traversal vulnerability in AFP Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 al
Directory traversal vulnerability in AFP Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote authenticated users to execute arbitrary code by creating files that are outside the bounds of a share.
nvd
CVE-2001-1412P4LOWCVSS 2.1PoCv10.4.92003-11-17
CVE-2001-1412 [LOW] CVE-2001-1412: nidump on MacOS X before 10.3 allows local users to read the encrypted passwords from the password f
nidump on MacOS X before 10.3 allows local users to read the encrypted passwords from the password file by specifying passwd as a command line argument.
nvd
CVE-2022-22589P4MEDIUMCVSS 6.1≥ 10.15, < 10.15.7v10.15.72022-03-18
CVE-2022-22589 [MEDIUM] CVE-2022-22589: A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 15.3 a
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing a maliciously crafted mail message may lead to running arbitrary javascript.
nvd
CVE-2014-2234P4MEDIUMCVSS 6.4≤ 10.9.22014-03-05
CVE-2014-2234 [MEDIUM] CWE-20 CVE-2014-2234: A certain Apple patch for OpenSSL in Apple OS X 10.9.2 and earlier uses a Trust Evaluation Agent (TE
A certain Apple patch for OpenSSL in Apple OS X 10.9.2 and earlier uses a Trust Evaluation Agent (TEA) feature without terminating certain TLS/SSL handshakes as specified in the SSL_CTX_set_verify callback function's documentation, which allows remote attackers to bypass extra verification within a custom application via a crafted certificate chain tha
nvd
CVE-2019-8525P4MEDIUMCVSS 6.7≥ 10.14.3, < 10.14.4≥ 10.12.6, < 10.14.52020-10-27
CVE-2019-8525 [MEDIUM] CWE-787 CVE-2019-8525: A memory corruption issue was addressed with improved state management. This issue is fixed in macOS
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, watchOS 5.2, macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, iOS 12.2. An application may be able to execute arbitrary c
nvd
CVE-2016-7579P4MEDIUMCVSS 5.9fixed in 10.12.12017-02-20
CVE-2016-7579 [MEDIUM] CWE-200 CVE-2016-7579: An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. The issue involves the "CFNetwork Proxies" component, which allows man-in-the-middle attackers to spoof a proxy password authentication requirement and obtain sensitive information.
nvd
CVE-2010-2497P4MEDIUMCVSS 6.8fixed in 10.6.52010-08-19
CVE-2010-2497 [MEDIUM] CWE-191 CVE-2010-2497: Integer underflow in glyph handling in FreeType before 2.4.0 allows remote attackers to cause a deni
Integer underflow in glyph handling in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
nvd
CVE-2006-4412P4MEDIUMCVSS 6.8v10.3v10.3.1+17 more2006-11-30
CVE-2006-4412 [MEDIUM] CVE-2006-4412: WebKit in Apple Mac OS X 10.3.x through 10.3.9 and 10.4 through 10.4.8 allows remote attackers to ex
WebKit in Apple Mac OS X 10.3.x through 10.3.9 and 10.4 through 10.4.8 allows remote attackers to execute arbitrary code via a crafted HTML file, which accesses previously deallocated objects.
nvd
CVE-2018-4174P4MEDIUMCVSS 5.9fixed in 10.13.42018-04-03
CVE-2018-4174 [MEDIUM] CVE-2018-4174: An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4
An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. The issue involves the "Mail" component. It allows man-in-the-middle attackers to read S/MIME encrypted messages by leveraging an inconsistency in the user interface.
nvd
CVE-2016-4679P4MEDIUMCVSS 5.5fixed in 10.12.12017-02-20
CVE-2016-4679 [MEDIUM] CWE-59 CVE-2016-4679: An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "libarchive" component, which allows remote attackers to write to arbitrary files via a crafted archive containing a symlink.
nvd
CVE-2006-1442P4HIGHCVSS 7.5v10.3.9v10.4.62006-05-12
CVE-2006-1442 [HIGH] CVE-2006-1442: The bundle API in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 loads dynamic libraries even if
The bundle API in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 loads dynamic libraries even if the client application has not directly requested it, which allows attackers to execute arbitrary code from an untrusted bundle.
nvd
CVE-2004-0823P4HIGHCVSS 7.5v10.2.8v10.3.4+1 more2004-09-07
CVE-2004-0823 [HIGH] CVE-2004-0823: OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating
OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating systems, may allow certain authentication schemes to use hashed (crypt) passwords in the userPassword attribute as if they were plaintext passwords, which allows remote attackers to re-use hashed passwords without decrypting them.
nvd
CVE-2011-0196P4HIGHCVSS 7.8v10.5.82011-06-24
CVE-2011-0196 [HIGH] CWE-399 CVE-2011-0196: AirPort in Apple Mac OS X 10.5.8 allows remote attackers to cause a denial of service (out-of-bounds
AirPort in Apple Mac OS X 10.5.8 allows remote attackers to cause a denial of service (out-of-bounds read and reboot) via Wi-Fi frames on the local wireless network.
nvd
CVE-2008-1032P4MEDIUMCVSS 6.8v10.4.11v10.5+2 more2008-06-02
CVE-2008-1032 [MEDIUM] CVE-2008-1032: Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.3 allows user-assisted
Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.3 allows user-assisted remote attackers to execute arbitrary code via an (1) Automator, (2) Help, (3) Safari, or (4) Terminal content type for a downloadable object, which does not trigger a "potentially unsafe" warning message in (a) the Download Validation feature in Mac OS X 10.4
nvd
CVE-2016-1844P4MEDIUMCVSS 5.3≤ 10.11.42016-05-20
CVE-2016-1844 [MEDIUM] CWE-284 CVE-2016-1844: The Messages component in Apple OS X before 10.11.5 mishandles roster changes, which allows remote a
The Messages component in Apple OS X before 10.11.5 mishandles roster changes, which allows remote attackers to modify contact lists via unspecified vectors.
nvd
CVE-2008-3438P4HIGHCVSS 8.1≥ 10.0.0, ≤ 10.5.42008-08-01
CVE-2008-3438 [HIGH] CWE-494 CVE-2008-3438: Apple Mac OS X does not properly verify the authenticity of updates, which allows man-in-the-middle
Apple Mac OS X does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
nvd