cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 96 of 157
CVE-2010-0535P4MEDIUMCVSS 6.5v10.6.0v10.6.1+1 more2010-03-30
CVE-2010-0535 [MEDIUM] CWE-264 CVE-2010-0535: Dovecot in Apple Mac OS X 10.6 before 10.6.3, when Kerberos is enabled, does not properly enforce th Dovecot in Apple Mac OS X 10.6 before 10.6.3, when Kerberos is enabled, does not properly enforce the service access control list (SACL) for sending and receiving e-mail, which allows remote authenticated users to bypass intended access restrictions via unspecified vectors.
nvd
CVE-2014-9365P4MEDIUMCVSS 5.8≤ 10.10.42014-12-12
CVE-2014-9365 [MEDIUM] CVE-2014-9365: The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib libraries in CPython The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib libraries in CPython (aka Python) 2.x before 2.7.9 and 3.x before 3.4.3, when accessing an HTTPS URL, do not (a) check the certificate against a trust store or verify that the server hostname matches a domain name in the subject's (b) Common Name or (c) subjectAltName field of the
nvd
CVE-2016-7591P4MEDIUMCVSS 6.5≤ 10.12.12017-02-20
CVE-2016-7591 [MEDIUM] CWE-416 CVE-2016-7591: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "IOHIDFamily" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.
nvd
CVE-2020-3882P4MEDIUMCVSS 6.5fixed in 10.15.52020-06-09
CVE-2020-3882 [MEDIUM] CVE-2020-3882: This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.5. Import This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.5. Importing a maliciously crafted calendar invitation may exfiltrate user information.
nvd
CVE-2021-1873P4MEDIUMCVSS 6.5≥ 10.14, ≤ 10.14.5≥ 10.15, ≤ 10.15.5+3 more2021-09-08
CVE-2021-1873 [MEDIUM] CVE-2021-1873: An API issue in Accessibility TCC permissions was addressed with improved state management. This iss An API issue in Accessibility TCC permissions was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. A malicious application may be able to unexpectedly leak a user's credentials from secure text fields.
nvd
CVE-2008-0058P4MEDIUMCVSS 5.8v10.4.112008-03-18
CVE-2008-0058 [MEDIUM] CWE-362 CVE-2008-0058: Race condition in the NSURLConnection cache management functionality in Foundation for Apple Mac OS Race condition in the NSURLConnection cache management functionality in Foundation for Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary code via unspecified manipulations that cause messages to be sent to a deallocated object.
nvd
CVE-2019-8534P4MEDIUMCVSS 6.7≥ 10.14.3, < 10.14.42020-10-27
CVE-2019-8534 [MEDIUM] CWE-787 CVE-2019-8534: A logic issue existed resulting in memory corruption. This was addressed with improved state managem A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2019-8737P4MEDIUMCVSS 6.5fixed in 10.15.12020-10-27
CVE-2019-8737 [MEDIUM] CWE-20 CVE-2019-8737: A denial of service issue was addressed with improved validation. This issue is fixed in macOS Catal A denial of service issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, macOS Catalina 10.15. An attacker in a privileged position may be able to perform a denial of service attack.
nvd
CVE-2019-8528P4MEDIUMCVSS 6.7≥ 10.13.6, < 10.14.42020-10-27
CVE-2019-8528 [MEDIUM] CWE-416 CVE-2019-8528: A use after free issue was addressed with improved memory management. This issue is fixed in watchOS A use after free issue was addressed with improved memory management. This issue is fixed in watchOS 5.2, macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, iOS 12.2. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2019-8569P4MEDIUMCVSS 6.7fixed in 10.14.52020-10-27
CVE-2019-8569 [MEDIUM] CWE-787 CVE-2019-8569: A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra. An application may be able to execute arbitrary code with system privilege
nvd
CVE-2006-0384P4HIGHCVSS 7.5v10.3v10.3.1+14 more2006-03-02
CVE-2006-0384 [HIGH] CVE-2006-0384: automount in Mac OS X 10.4.5 and earlier allows remote file servers to cause a denial of service (un automount in Mac OS X 10.4.5 and earlier allows remote file servers to cause a denial of service (unresponsiveness) or execute arbitrary code via unspecified vectors that cause automount to "mount file systems with reserved names".
nvd
CVE-2021-30722P4MEDIUMCVSS 5.9≥ 10.14.0, ≤ 10.14.5≥ 10.15, ≤ 10.15.6+2 more2021-09-08
CVE-2021-30722 [MEDIUM] CVE-2021-30722: An information disclosure issue was addressed with improved state management. This issue is fixed in An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. An attacker in a privileged network position may be able to leak sensitive user information.
nvd
CVE-2004-0165P4MEDIUMCVSS 5.0v10.1v10.1.1+16 more2004-03-15
CVE-2004-0165 [MEDIUM] CVE-2004-0165: Format string vulnerability in Point-to-Point Protocol (PPP) daemon (pppd) 2.4.0 for Mac OS X 10.3.2 Format string vulnerability in Point-to-Point Protocol (PPP) daemon (pppd) 2.4.0 for Mac OS X 10.3.2 and earlier allows remote attackers to read arbitrary pppd process data, including PAP or CHAP authentication credentials, to gain privileges.
nvd
CVE-2008-0063P4HIGHCVSS 7.5fixed in 10.4.11≥ 10.5.0, < 10.5.22008-03-19
CVE-2008-0063 [HIGH] CWE-908 CVE-2008-0063: The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."
nvd
CVE-2018-4202P4MEDIUMCVSS 5.9fixed in 10.13.52018-06-08
CVE-2018-4202 [MEDIUM] CWE-20 CVE-2018-4202: An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. The issue involves the "iBooks" component. It allows man-in-the-middle attackers to spoof a password prompt.
nvd
CVE-2022-32799P4MEDIUMCVSS 5.9v10.15.72022-09-23
CVE-2022-32799 [MEDIUM] CWE-125 CVE-2022-32799: An out-of-bounds read issue was addressed with improved bounds checking. This issue is fixed in Secu An out-of-bounds read issue was addressed with improved bounds checking. This issue is fixed in Security Update 2022-005 Catalina, macOS Monterey 12.5. A user in a privileged network position may be able to leak sensitive information.
nvd
CVE-2018-4086P4MEDIUMCVSS 5.9fixed in 10.13.32018-04-03
CVE-2018-4086 [MEDIUM] CWE-295 CVE-2018-4086: An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13 An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "Security" component. It allows remote attackers to spoof certificate validation via crafted name constraints.
nvd
CVE-2009-1721P4MEDIUMCVSS 6.8fixed in 10.5.82009-07-31
CVE-2009-1721 [MEDIUM] CWE-824 CVE-2009-1721: The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allow The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of an uninitialized pointer.
nvd
CVE-2009-0944P4MEDIUMCVSS 6.8v10.4.11v10.5.0+6 more2009-05-13
CVE-2009-0944 [MEDIUM] CWE-94 CVE-2009-0944: The Microsoft Office Spotlight Importer in Spotlight in Apple Mac OS X 10.4.11 and 10.5 before 10.5. The Microsoft Office Spotlight Importer in Spotlight in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not properly validate Microsoft Office files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a file that triggers memory corruption.
nvd
CVE-2005-2505P4HIGHCVSS 7.5v10.3.92005-08-19
CVE-2005-2505 [HIGH] CVE-2005-2505: Buffer overflow in CoreFoundation in Mac OS X 10.3.9 allows attackers to execute arbitrary code via Buffer overflow in CoreFoundation in Mac OS X 10.3.9 allows attackers to execute arbitrary code via command line arguments to an application that uses CoreFoundation.
nvd
Apple macOS vulnerabilities | cvebase