cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 95 of 157
CVE-2002-1347P4CRITICALCVSS 9.8fixed in 10.3.82002-12-18
CVE-2002-1347 [CRITICAL] CWE-131 CVE-2002-1347: Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not
nvd
CVE-2016-4660P4HIGHCVSS 7.1≤ 10.12.02017-02-20
CVE-2016-4660 [HIGH] CWE-200 CVE-2016-4660: An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "FontParser" component. It allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash)
nvd
CVE-2013-0983P4MEDIUMCVSS 6.8≤ 10.8.3v10.8.0+2 more2013-06-05
CVE-2013-0983 [MEDIUM] CWE-119 CVE-2013-0983: Stack consumption vulnerability in CoreAnimation in Apple Mac OS X before 10.8.4 allows remote attac Stack consumption vulnerability in CoreAnimation in Apple Mac OS X before 10.8.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted text glyph in a URL encountered by Safari.
nvd
CVE-2015-7013P4MEDIUMCVSS 6.8≤ 10.11.02015-10-23
CVE-2015-7013 [MEDIUM] CWE-119 CVE-2015-7013: WebKit, as used in Apple Safari before 9.0.1 and iTunes before 12.3.1, allows remote attackers to ex WebKit, as used in Apple Safari before 9.0.1 and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-3 and APPLE-SA-2015-10-21-5.
nvd
CVE-2014-1269P4MEDIUMCVSS 6.8v10.7.0v10.7.1+12 more2014-02-27
CVE-2014-1269 [MEDIUM] CVE-2014-1269: WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execut WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1268 and CVE-2014-1270.
nvd
CVE-2014-1270P4MEDIUMCVSS 6.8v10.7.0v10.7.1+12 more2014-02-27
CVE-2014-1270 [MEDIUM] CVE-2014-1270: WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execut WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1268 and CVE-2014-1269.
nvd
CVE-2011-0202P4MEDIUMCVSS 6.8v10.5.8v10.6.0+7 more2011-06-24
CVE-2011-0202 [MEDIUM] CWE-189 CVE-2011-0202: Integer overflow in CoreGraphics in Apple Mac OS X before 10.6.8 allows remote attackers to execute Integer overflow in CoreGraphics in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted embedded Type 1 font in a PDF document.
nvd
CVE-2015-1140P4HIGHCVSS 7.2fixed in 10.10.32015-04-10
CVE-2015-1140 [HIGH] CWE-119 CVE-2015-1140: Buffer overflow in IOHIDFamily in Apple OS X before 10.10.3 allows local users to gain privileges vi Buffer overflow in IOHIDFamily in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors.
nvd
CVE-2014-1268P4MEDIUMCVSS 6.8v10.7.0v10.7.1+12 more2014-02-27
CVE-2014-1268 [MEDIUM] CWE-119 CVE-2014-1268: WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execut WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1269 and CVE-2014-1270.
nvd
CVE-2014-1259P4MEDIUMCVSS 6.8≤ 10.9.1v10.7.0+12 more2014-02-27
CVE-2014-1259 [MEDIUM] CWE-119 CVE-2014-1259: Buffer overflow in File Bookmark in Apple OS X before 10.9.2 allows attackers to execute arbitrary c Buffer overflow in File Bookmark in Apple OS X before 10.9.2 allows attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted filename.
nvd
CVE-2020-9994P4HIGHCVSS 7.1fixed in 10.15.52020-10-22
CVE-2020-9994 [HIGH] CVE-2020-9994: A path handling issue was addressed with improved validation. This issue is fixed in iOS 13.5 and iP A path handling issue was addressed with improved validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A malicious application may be able to overwrite arbitrary files.
nvd
CVE-2015-3715P4MEDIUMCVSS 6.8≤ 10.10.32015-07-03
CVE-2015-3715 [MEDIUM] CWE-254 CVE-2015-3715: The code-signing implementation in Apple OS X before 10.10.4 does not properly consider libraries th The code-signing implementation in Apple OS X before 10.10.4 does not properly consider libraries that are external to an application bundle, which allows attackers to bypass intended launch restrictions via a crafted library.
nvd
CVE-2019-13118P4MEDIUMCVSS 5.3v10.12.6v10.13.62019-07-01
CVE-2019-13118 [MEDIUM] CWE-843 CVE-2019-13118: In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.
nvd
CVE-2018-4228P4HIGHCVSS 7.0fixed in 10.13.52018-06-08
CVE-2018-4228 [HIGH] CWE-362 CVE-2018-4228: An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue invol An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "IOFireWireAVC" component. It allows attackers to execute arbitrary code in a privileged context via a crafted app that leverages a race condition.
nvd
CVE-2015-3671P4HIGHCVSS 7.2≤ 10.10.32015-07-03
CVE-2015-3671 [HIGH] CWE-284 CVE-2015-3671: Admin Framework in Apple OS X before 10.10.4 does not properly verify XPC entitlements, which allows Admin Framework in Apple OS X before 10.10.4 does not properly verify XPC entitlements, which allows local users to bypass authentication and obtain admin privileges via unspecified vectors.
nvd
CVE-2009-0161P4MEDIUMCVSS 6.4v10.5.0v10.5.1+5 more2009-05-13
CVE-2009-0161 [MEDIUM] CWE-20 CVE-2009-0161: The OpenSSL::OCSP module for Ruby in Apple Mac OS X 10.5 before 10.5.7 misinterprets an unspecified The OpenSSL::OCSP module for Ruby in Apple Mac OS X 10.5 before 10.5.7 misinterprets an unspecified invalid response as a successful OCSP certificate validation, which might allow remote attackers to spoof certificate authentication via a revoked certificate.
nvd
CVE-2021-30796P4MEDIUMCVSS 6.5v10.14v10.14.0+14 more2021-09-08
CVE-2021-30796 [MEDIUM] CVE-2021-30796: A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. Processing a maliciously crafted image may lead to a denial of service.
nvd
CVE-2009-2801P4MEDIUMCVSS 6.4v10.5.82010-03-30
CVE-2009-2801 [MEDIUM] CWE-264 CVE-2009-2801: The Application Firewall in Apple Mac OS X 10.5.8 drops unspecified firewall rules after a reboot, w The Application Firewall in Apple Mac OS X 10.5.8 drops unspecified firewall rules after a reboot, which might allow remote attackers to bypass intended access restrictions via packet data, related to a "timing issue."
nvd
CVE-2018-4368P4MEDIUMCVSS 6.5fixed in 10.14.12019-04-03
CVE-2018-4368 [MEDIUM] CWE-20 CVE-2018-4368: A denial of service issue was addressed with improved validation. This issue affected versions prior A denial of service issue was addressed with improved validation. This issue affected versions prior to iOS 12.1, macOS Mojave 10.14.1, tvOS 12.1, watchOS 5.1.
nvd
CVE-2009-2813P4MEDIUMCVSS 6.0v10.5.82009-09-14
CVE-2009-2813 [MEDIUM] CWE-264 CVE-2009-2813: Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in t Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems, does not properly handle errors in resolving pathnames, which allows remote authenticated users to bypass intended sharing restrictio
nvd
Apple macOS vulnerabilities | cvebase