Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
277
Exploited in wild
28
Severity breakdown
CRITICAL302HIGH1409MEDIUM1236LOW192
Vulnerabilities
Page 96 of 157
CVE-2015-3773HIGHCVSS 7.5≤ 10.10.42015-08-16
CVE-2015-3773 [HIGH] CWE-119 CVE-2015-3773: The SMB client in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cau
The SMB client in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.
nvd
CVE-2015-3780MEDIUMCVSS 4.3≤ 10.10.42015-08-16
CVE-2015-3780 [MEDIUM] CWE-200 CVE-2015-3780: The Bluetooth subsystem in Apple OS X before 10.10.5 allows attackers to obtain sensitive kernel mem
The Bluetooth subsystem in Apple OS X before 10.10.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.
nvd
CVE-2015-3764MEDIUMCVSS 4.3≤ 10.10.42015-08-16
CVE-2015-3764 [MEDIUM] CWE-200 CVE-2015-3764: Notification Center in Apple OS X before 10.10.5 does not properly remove dismissed notifications, w
Notification Center in Apple OS X before 10.10.5 does not properly remove dismissed notifications, which allows attackers to read arbitrary notifications via a crafted app.
nvd
CVE-2015-3786MEDIUMCVSS 4.3≤ 10.10.42015-08-16
CVE-2015-3786 [MEDIUM] CWE-200 CVE-2015-3786: The Bluetooth subsystem in Apple OS X before 10.10.5 does not properly restrict Notification Center
The Bluetooth subsystem in Apple OS X before 10.10.5 does not properly restrict Notification Center Service access, which allows attackers to read Notification Center notifications of certain paired devices via a crafted app.
nvd
CVE-2015-3784MEDIUMCVSS 5.0≤ 10.10.42015-08-16
CVE-2015-3784 [MEDIUM] CWE-200 CVE-2015-3784: Office Viewer in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to read arbi
Office Viewer in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
nvd
CVE-2015-3782MEDIUMCVSS 4.3≤ 10.10.42015-08-16
CVE-2015-3782 [MEDIUM] CWE-200 CVE-2015-3782: CloudKit in Apple iOS before 8.4.1 and OS X before 10.10.5 allows attackers to access an iCloud user
CloudKit in Apple iOS before 8.4.1 and OS X before 10.10.5 allows attackers to access an iCloud user record associated with a previous user's login session via a crafted app.
nvd
CVE-2015-3766MEDIUMCVSS 4.3≤ 10.10.42015-08-16
CVE-2015-3766 [MEDIUM] CWE-200 CVE-2015-3766: The kernel in Apple iOS before 8.4.1 and OS X before 10.10.5 does not properly restrict the mach_por
The kernel in Apple iOS before 8.4.1 and OS X before 10.10.5 does not properly restrict the mach_port_space_info interface, which allows attackers to obtain sensitive memory-layout information via a crafted app.
nvd
CVE-2015-3762MEDIUMCVSS 5.0≤ 10.10.42015-08-16
CVE-2015-3762 [MEDIUM] CWE-200 CVE-2015-3762: The Text Formats component in Apple OS X before 10.10.5, as used in TextEdit, allows remote attacker
The Text Formats component in Apple OS X before 10.10.5, as used in TextEdit, allows remote attackers to read arbitrary files via a text file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
nvd
CVE-2015-3781MEDIUMCVSS 4.3≤ 10.10.42015-08-16
CVE-2015-3781 [MEDIUM] CWE-79 CVE-2015-3781: Cross-site scripting (XSS) vulnerability in Quick Look in Apple OS X before 10.10.5 allows remote at
Cross-site scripting (XSS) vulnerability in Quick Look in Apple OS X before 10.10.5 allows remote attackers to inject arbitrary web script or HTML via a previously visited web site that is rendered during a Quick Look search.
nvd
CVE-2015-3774MEDIUMCVSS 4.8≤ 10.10.42015-08-16
CVE-2015-3774 [MEDIUM] CWE-20 CVE-2015-3774: The Dictionary app in Apple OS X before 10.10.5 does not use HTTPS, which allows man-in-the-middle a
The Dictionary app in Apple OS X before 10.10.5 does not use HTTPS, which allows man-in-the-middle attackers to obtain sensitive information by sniffing the network or spoof word definitions by modifying the client-server data stream.
nvd
CVE-2015-3757LOWCVSS 2.1≤ 10.10.42015-08-16
CVE-2015-3757 [LOW] CWE-284 CVE-2015-3757: Apple OS X before 10.10.5 does not properly restrict access to the Date & Time preferences pane, whi
Apple OS X before 10.10.5 does not properly restrict access to the Date & Time preferences pane, which allows local users to spoof the time by visiting this pane.
nvd
CVE-2015-3778LOWCVSS 3.3≤ 10.10.42015-08-16
CVE-2015-3778 [LOW] CWE-200 CVE-2015-3778: bootp in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to obtain potentiall
bootp in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to obtain potentially sensitive information about MAC addresses seen in previous Wi-Fi sessions by sniffing an 802.11 network for DNAv4 broadcast traffic.
nvd
CVE-2015-3787LOWCVSS 3.3≤ 10.10.42015-08-16
CVE-2015-3787 [LOW] CWE-20 CVE-2015-3787: The Bluetooth subsystem in Apple OS X before 10.10.5 allows remote attackers to cause a denial of se
The Bluetooth subsystem in Apple OS X before 10.10.5 allows remote attackers to cause a denial of service via malformed Bluetooth ACL packets.
nvd
CVE-2015-1819MEDIUMCVSS 5.0≤ 10.11.32015-08-14
CVE-2015-1819 [MEDIUM] CWE-399 CVE-2015-1819: The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) vi
The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
nvd
CVE-2015-5523MEDIUMCVSS 4.3≤ 10.6.82015-08-11
CVE-2015-5523 [MEDIUM] CWE-119 CVE-2015-5523: The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial o
The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving multiple whitespace characters before an empty href, which triggers a large memory allocation.
nvd
CVE-2015-5522MEDIUMCVSS 6.8≤ 10.6.82015-08-11
CVE-2015-5522 [MEDIUM] CWE-119 CVE-2015-5522: Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote
Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving a command character in an href.
nvd
CVE-2015-0253MEDIUMCVSS 5.0v10.10.42015-07-20
CVE-2015-0253 [MEDIUM] CVE-2015-0253: The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initia
The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initialize the protocol structure member, which allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) by sending a request that lacks a method to an installation that enables the INCLUDES filter and has an ErrorDocument 400
nvd
CVE-2015-3185MEDIUMCVSS 4.3v10.10.42015-07-20
CVE-2015-3185 [MEDIUM] CWE-264 CVE-2015-3185: The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14
The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the pres
nvd
CVE-2015-3683CRITICALCVSS 9.3≤ 10.10.32015-07-03
CVE-2015-3683 [CRITICAL] CWE-119 CVE-2015-3683: The Bluetooth HCI interface implementation in Apple OS X before 10.10.4 allows attackers to execute
The Bluetooth HCI interface implementation in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2015-3693CRITICALCVSS 9.3PoC≤ 10.10.32015-07-03
CVE-2015-3693 [CRITICAL] CWE-254 CVE-2015-3693: Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not properly
Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not properly set refresh rates for DDR3 RAM, which might make it easier for remote attackers to conduct row-hammer attacks, and consequently gain privileges or cause a denial of service (memory corruption), by triggering certain patterns of access to memory locatio
nvd