Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 94 of 157
CVE-2010-3793P4MEDIUMCVSS 6.8v10.6.0v10.6.1+3 more2010-11-16
CVE-2010-3793 [MEDIUM] CWE-119 CVE-2010-3793: QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code o
QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Sorenson movie file.
nvd
CVE-2010-3789P4MEDIUMCVSS 6.8v10.6.0v10.6.1+3 more2010-11-16
CVE-2010-3789 [MEDIUM] CWE-119 CVE-2010-3789: QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code o
QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted AVI file.
nvd
CVE-2009-2810P4MEDIUMCVSS 6.8v10.6v10.6.12009-11-10
CVE-2009-2810 [MEDIUM] CVE-2009-2810: Launch Services in Apple Mac OS X 10.6.x before 10.6.2 recursively clears quarantine information upo
Launch Services in Apple Mac OS X 10.6.x before 10.6.2 recursively clears quarantine information upon opening a quarantined folder, which allows user-assisted remote attackers to execute arbitrary code via a quarantined application that does not trigger a "potentially unsafe" warning message.
nvd
CVE-2014-4412P4MEDIUMCVSS 6.8≤ 10.9.42014-09-18
CVE-2014-4412 [MEDIUM] CWE-119 CVE-2014-4412: WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote attackers to execute arbi
WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-09-17-1 and APPLE-SA-2014-09-17-2.
nvd
CVE-2010-0518P4MEDIUMCVSS 6.8v10.6.0v10.6.1+1 more2010-03-30
CVE-2010-0518 [MEDIUM] CWE-119 CVE-2010-0518: QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause
QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with Sorenson encoding.
nvd
CVE-2017-7121P4CRITICALCVSS 9.8≤ 10.12.62017-10-23
CVE-2017-7121 [CRITICAL] CWE-20 CVE-2017-7121: An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involve
An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the third-party "file" product. Versions before 5.30 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
nvd
CVE-2017-7125P4CRITICALCVSS 9.8≤ 10.12.62017-10-23
CVE-2017-7125 [CRITICAL] CWE-20 CVE-2017-7125: An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involve
An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the third-party "file" product. Versions before 5.30 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
nvd
CVE-2017-7124P4CRITICALCVSS 9.8≤ 10.12.62017-10-23
CVE-2017-7124 [CRITICAL] CWE-20 CVE-2017-7124: An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involve
An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the third-party "file" product. Versions before 5.30 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
nvd
CVE-2017-7123P4CRITICALCVSS 9.8≤ 10.12.62017-10-23
CVE-2017-7123 [CRITICAL] CWE-20 CVE-2017-7123: An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involve
An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the third-party "file" product. Versions before 5.30 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
nvd
CVE-2017-7122P4CRITICALCVSS 9.8≤ 10.12.62017-10-23
CVE-2017-7122 [CRITICAL] CWE-20 CVE-2017-7122: An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involve
An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the third-party "file" product. Versions before 5.30 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
nvd
CVE-2011-0181P4MEDIUMCVSS 6.8≤ 10.6.6v10.5.8+6 more2011-03-23
CVE-2011-0181 [MEDIUM] CWE-189 CVE-2011-0181: Integer overflow in ImageIO in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbit
Integer overflow in ImageIO in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted XBM image.
nvd
CVE-2011-0193P4MEDIUMCVSS 6.8v10.6.0v10.6.1+5 more2011-03-23
CVE-2011-0193 [MEDIUM] CWE-119 CVE-2011-0193: Multiple buffer overflows in Image RAW in Apple Mac OS X before 10.6.7 allow remote attackers to exe
Multiple buffer overflows in Image RAW in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Canon RAW image.
nvd
CVE-2010-0060P4MEDIUMCVSS 6.8v10.6.0v10.6.1+1 more2010-03-30
CVE-2010-0060 [MEDIUM] CWE-119 CVE-2010-0060: CoreAudio in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause
CoreAudio in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted audio content with QDMC encoding.
nvd
CVE-2016-4674P4HIGHCVSS 7.8≤ 10.12.02017-02-20
CVE-2016-4674 [HIGH] CWE-119 CVE-2016-4674: An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "ATS" component. It allows local users to gain privileges or cause a denial of service (memory corruption and application crash) via unspecified vectors.
nvd
CVE-2011-3448P4MEDIUMCVSS 6.8≤ 10.7.2v10.6.0+10 more2012-02-02
CVE-2011-3448 [MEDIUM] CWE-119 CVE-2011-3448: Heap-based buffer overflow in CoreMedia in Apple Mac OS X before 10.7.3 allows remote attackers to e
Heap-based buffer overflow in CoreMedia in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with H.264 encoding.
nvd
CVE-2014-4411P4MEDIUMCVSS 6.8≤ 10.9.42014-09-18
CVE-2014-4411 [MEDIUM] CWE-119 CVE-2014-4411: WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote attackers to execute arbi
WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-09-17-1 and APPLE-SA-2014-09-17-2.
nvd
CVE-2015-1069P4MEDIUMCVSS 6.8≤ 10.10.22015-03-18
CVE-2015-1069 [MEDIUM] CWE-399 CVE-2015-1069: WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote
WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.
nvd
CVE-2014-4414P4MEDIUMCVSS 6.8≤ 10.9.42014-09-18
CVE-2014-4414 [MEDIUM] CWE-119 CVE-2014-4414: WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote attackers to execute arbi
WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-09-17-1 and APPLE-SA-2014-09-17-2.
nvd
CVE-2014-4413P4MEDIUMCVSS 6.8≤ 10.9.42014-09-18
CVE-2014-4413 [MEDIUM] CWE-119 CVE-2014-4413: WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote attackers to execute arbi
WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-09-17-1 and APPLE-SA-2014-09-17-2.
nvd
CVE-2014-4410P4MEDIUMCVSS 6.8≤ 10.9.42014-09-18
CVE-2014-4410 [MEDIUM] CWE-119 CVE-2014-4410: WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote attackers to execute arbi
WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-09-17-1 and APPLE-SA-2014-09-17-2.
nvd