Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 93 of 157
CVE-2015-3784P4MEDIUMCVSS 5.0≤ 10.10.42015-08-16
CVE-2015-3784 [MEDIUM] CWE-200 CVE-2015-3784: Office Viewer in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to read arbi
Office Viewer in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
nvd
CVE-2007-0735P4CRITICALCVSS 9.3v10.3.9v10.4+9 more2007-04-24
CVE-2007-0735 [CRITICAL] CVE-2007-0735: Use-after-free vulnerability in Libinfo in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attack
Use-after-free vulnerability in Libinfo in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors involving crafted web pages that trigger certain error conditions that are not properly reported in certain circumstances, resulting in accessing d
nvd
CVE-2008-0048P4MEDIUMCVSS 6.8v10.4.112008-03-18
CVE-2008-0048 [MEDIUM] CWE-119 CVE-2008-0048: Stack-based buffer overflow in AppKit in Apple Mac OS X 10.4.11 allows context-dependent attackers t
Stack-based buffer overflow in AppKit in Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via the a long file name to the NSDocument API.
nvd
CVE-2015-7081P4MEDIUMCVSS 5.0≤ 10.11.12015-12-11
CVE-2015-7081 [MEDIUM] CVE-2015-7081: iBooks in Apple iOS before 9.2 and OS X before 10.11.2 allows remote attackers to read arbitrary fil
iBooks in Apple iOS before 9.2 and OS X before 10.11.2 allows remote attackers to read arbitrary files via an iBooks file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
nvd
CVE-2006-6900P4CRITICALCVSS 10.0v10.42006-12-31
CVE-2006-6900 [CRITICAL] CVE-2006-6900: Unspecified vulnerability in the Bluetooth stack in Apple Mac OS 10.4 has unknown impact and attack
Unspecified vulnerability in the Bluetooth stack in Apple Mac OS 10.4 has unknown impact and attack vectors, related to an "implementation bug."
nvd
CVE-2010-0514P4MEDIUMCVSS 6.8v10.6.0v10.6.1+1 more2010-03-30
CVE-2010-0514 [MEDIUM] CWE-119 CVE-2010-0514: Heap-based buffer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to e
Heap-based buffer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with H.261 encoding.
nvd
CVE-2011-0213P4MEDIUMCVSS 6.8≥ 10.6.0, < 10.6.82011-06-24
CVE-2011-0213 [MEDIUM] CWE-120 CVE-2011-0213: Buffer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbi
Buffer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG file.
nvd
CVE-2011-3459P4MEDIUMCVSS 6.8≤ 10.7.2v10.6.0+10 more2012-02-02
CVE-2011-3459 [MEDIUM] CWE-189 CVE-2011-3459: Off-by-one error in QuickTime in Apple Mac OS X before 10.7.3 allows remote attackers to execute arb
Off-by-one error in QuickTime in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted rdrf atom in a movie file that triggers a buffer overflow.
nvd
CVE-2012-0661P4MEDIUMCVSS 6.8v10.7.0v10.7.1+1 more2012-05-11
CVE-2012-0661 [MEDIUM] CWE-399 CVE-2012-0661: Use-after-free vulnerability in QuickTime in Apple Mac OS X 10.7.x before 10.7.4 allows remote attac
Use-after-free vulnerability in QuickTime in Apple Mac OS X 10.7.x before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with JPEG2000 encoding.
nvd
CVE-2017-6986P4HIGHCVSS 7.8≤ 10.12.42017-05-22
CVE-2017-6986 [HIGH] CWE-119 CVE-2017-6986: An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "iBooks" component. It allows attackers to conduct sandbox-escape attacks or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-2512P4HIGHCVSS 7.8≤ 10.12.42017-05-22
CVE-2017-2512 [HIGH] CWE-119 CVE-2017-2512: An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Sandbox" component. It allows attackers to conduct sandbox-escape attacks or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2007-5853P4CRITICALCVSS 9.3v10.4.112007-12-19
CVE-2007-5853 [CRITICAL] CVE-2007-5853: Unspecified vulnerability in IO Storage Family in Apple Mac OS X 10.4.11 allows user-assisted attack
Unspecified vulnerability in IO Storage Family in Apple Mac OS X 10.4.11 allows user-assisted attackers to cause a denial of service (system shutdown) or execute arbitrary code via a disk image with crafted GUID partition maps, which triggers memory corruption.
nvd
CVE-2010-3788P4MEDIUMCVSS 6.8v10.6.0v10.6.1+3 more2010-11-16
CVE-2010-3788 [MEDIUM] CWE-20 CVE-2010-3788: QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during proc
QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during processing of JP2 image data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JP2 file.
nvd
CVE-2010-3792P4MEDIUMCVSS 6.8v10.6.0v10.6.1+3 more2010-11-16
CVE-2010-3792 [MEDIUM] CWE-189 CVE-2010-3792: Integer signedness error in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers
Integer signedness error in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG movie file.
nvd
CVE-2010-3795P4MEDIUMCVSS 6.8v10.6.0v10.6.1+3 more2010-11-16
CVE-2010-3795 [MEDIUM] CWE-119 CVE-2010-3795: QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during proc
QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during processing of GIF image data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted GIF file.
nvd
CVE-2010-3794P4MEDIUMCVSS 6.8v10.6.0v10.6.1+3 more2010-11-16
CVE-2010-3794 [MEDIUM] CWE-119 CVE-2010-3794: QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during proc
QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during processing of FlashPix image data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FlashPix file.
nvd
CVE-2014-4379P4HIGHCVSS 7.1≤ 10.9.42014-09-18
CVE-2014-4379 [HIGH] CWE-119 CVE-2014-4379: An unspecified IOHIDFamily function in Apple iOS before 8 and Apple TV before 7 lacks proper bounds
An unspecified IOHIDFamily function in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking to prevent reading of kernel pointers, which allows attackers to bypass the ASLR protection mechanism via a crafted application.
nvd
CVE-2011-0211P4MEDIUMCVSS 6.8≥ 10.6.0, < 10.6.82011-06-24
CVE-2011-0211 [MEDIUM] CWE-190 CVE-2011-0211: Integer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arb
Integer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file.
nvd
CVE-2011-0209P4MEDIUMCVSS 6.8fixed in 10.6.82011-06-24
CVE-2011-0209 [MEDIUM] CWE-190 CVE-2011-0209: Integer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arb
Integer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted RIFF WAV file.
nvd
CVE-2012-3722P4MEDIUMCVSS 6.8≤ 10.7.4v10.0+69 more2012-09-20
CVE-2012-3722 [MEDIUM] CWE-399 CVE-2012-3722: The Sorenson codec in QuickTime in Apple Mac OS X before 10.7.5, and in CoreMedia in iOS before 6, a
The Sorenson codec in QuickTime in Apple Mac OS X before 10.7.5, and in CoreMedia in iOS before 6, accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with Sorenson encoding.
nvd