Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 97 of 157
CVE-2016-4745P4MEDIUMCVSS 5.3≤ 10.11.62016-09-25
CVE-2016-4745 [MEDIUM] CWE-200 CVE-2016-4745: The Kerberos 5 (aka krb5) PAM module in Apple OS X before 10.12 does not use constant-time operation
The Kerberos 5 (aka krb5) PAM module in Apple OS X before 10.12 does not use constant-time operations for determining username validity, which makes it easier for remote attackers to enumerate user accounts via a timing side-channel attack.
nvd
CVE-2009-0019P4HIGHCVSS 7.5v10.4.11v10.5.62009-02-13
CVE-2009-0019 [HIGH] CWE-119 CVE-2009-0019: Remote Apple Events in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial o
Remote Apple Events in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial of service (application termination) or obtain sensitive information via unspecified vectors that trigger an out-of-bounds memory access.
nvd
CVE-2014-4374P4MEDIUMCVSS 5.0≤ 10.9.42014-09-18
CVE-2014-4374 [MEDIUM] CVE-2014-4374: NSXMLParser in Foundation in Apple iOS before 8 allows attackers to read arbitrary files via XML dat
NSXMLParser in Foundation in Apple iOS before 8 allows attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
nvd
CVE-2008-0997P4MEDIUMCVSS 6.8v10.4.112008-03-18
CVE-2008-0997 [MEDIUM] CWE-119 CVE-2008-0997: Stack-based buffer overflow in AppKit in Apple Mac OS X 10.4.11 allows user-assisted remote attacker
Stack-based buffer overflow in AppKit in Apple Mac OS X 10.4.11 allows user-assisted remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted PostScript Printer Description (PPD) file that is not properly handled when querying a network printer.
nvd
CVE-2015-3762P4MEDIUMCVSS 5.0≤ 10.10.42015-08-16
CVE-2015-3762 [MEDIUM] CWE-200 CVE-2015-3762: The Text Formats component in Apple OS X before 10.10.5, as used in TextEdit, allows remote attacker
The Text Formats component in Apple OS X before 10.10.5, as used in TextEdit, allows remote attackers to read arbitrary files via a text file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
nvd
CVE-2005-1933P4HIGHCVSS 7.5v10.42005-06-13
CVE-2005-1933 [HIGH] CVE-2005-1933: Dashboard in Apple Mac OS X Tiger 10.4 allows attackers to execute arbitrary commands by overriding
Dashboard in Apple Mac OS X Tiger 10.4 allows attackers to execute arbitrary commands by overriding the behavior of system widgets via a user widget with the same bundle identifier (CFBundleIdentifier), a different vulnerability than CVE-2005-1474.
nvd
CVE-2016-4713P4MEDIUMCVSS 5.3≤ 10.11.62016-09-25
CVE-2016-4713 [MEDIUM] CWE-200 CVE-2016-4713: CoreDisplay in Apple OS X before 10.12 allows attackers to view arbitrary users' screens by leveragi
CoreDisplay in Apple OS X before 10.12 allows attackers to view arbitrary users' screens by leveraging screen-sharing access.
nvd
CVE-2017-2535P4HIGHCVSS 7.8≤ 10.12.42017-05-22
CVE-2017-2535 [HIGH] CWE-20 CVE-2017-2535: An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue invol
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Security" component. It allows attackers to conduct sandbox-escape attacks or cause a denial of service (resource consumption) via a crafted app.
nvd
CVE-2009-2827P4MEDIUMCVSS 6.8v10.5.82009-11-10
CVE-2009-2827 [MEDIUM] CWE-119 CVE-2009-2827: Heap-based buffer overflow in Disk Images in Apple Mac OS X 10.5.8 allows user-assisted remote attac
Heap-based buffer overflow in Disk Images in Apple Mac OS X 10.5.8 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FAT filesystem on a disk image.
nvd
CVE-2009-2811P4MEDIUMCVSS 6.8v10.5.82009-09-14
CVE-2009-2811 [MEDIUM] CWE-94 CVE-2009-2811: Incomplete blacklist vulnerability in Launch Services in Apple Mac OS X 10.5.8 allows user-assisted
Incomplete blacklist vulnerability in Launch Services in Apple Mac OS X 10.5.8 allows user-assisted remote attackers to execute arbitrary code via a .fileloc file, which does not trigger a "potentially unsafe" warning message in the Quarantine feature.
nvd
CVE-2009-2809P4MEDIUMCVSS 6.8v10.4.11v10.5.82009-09-14
CVE-2009-2809 [MEDIUM] CWE-94 CVE-2009-2809: ImageIO in Apple Mac OS X 10.4.11 and 10.5.8 allows remote attackers to execute arbitrary code or ca
ImageIO in Apple Mac OS X 10.4.11 and 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PixarFilm encoded TIFF image, related to "multiple memory corruption issues."
nvd
CVE-2008-0045P4HIGHCVSS 7.1v10.4.112008-03-18
CVE-2008-0045 [HIGH] CWE-264 CVE-2008-0045: Unspecified vulnerability in AFP Server in Apple Mac OS X 10.4.11 allows remote attackers to bypass
Unspecified vulnerability in AFP Server in Apple Mac OS X 10.4.11 allows remote attackers to bypass cross-realm authentication via unknown manipulations of Kerberos principal realm names.
nvd
CVE-2007-3749P4HIGHCVSS 7.8≥ 10.4.0, ≤ 10.4.102007-11-15
CVE-2007-3749 [HIGH] CWE-665 CVE-2007-3749: The kernel in Apple Mac OS X 10.4 through 10.4.10 does not reset the current Mach Thread Port or Thr
The kernel in Apple Mac OS X 10.4 through 10.4.10 does not reset the current Mach Thread Port or Thread Exception Port when executing a setuid program, which allows local users to execute arbitrary code by creating the port before launching the setuid program, then writing to the address space of the setuid process.
nvd
CVE-2009-2805P4MEDIUMCVSS 6.8v10.4.11v10.5.82009-09-14
CVE-2009-2805 [MEDIUM] CWE-189 CVE-2009-2805: Integer overflow in CoreGraphics in Apple Mac OS X 10.4.11 and 10.5.8 allows remote attackers to exe
Integer overflow in CoreGraphics in Apple Mac OS X 10.4.11 and 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JBIG2 stream in a PDF file, leading to a heap-based buffer overflow.
nvd
CVE-2011-3458P4MEDIUMCVSS 6.8≤ 10.7.2v10.7.0+1 more2012-02-02
CVE-2011-3458 [MEDIUM] CWE-264 CVE-2011-3458: QuickTime in Apple Mac OS X before 10.7.3 does not prevent access to uninitialized memory locations,
QuickTime in Apple Mac OS X before 10.7.3 does not prevent access to uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MP4 file.
nvd
CVE-2010-0507P4MEDIUMCVSS 6.8≤ 10.6.2v10.5+11 more2010-03-30
CVE-2010-0507 [MEDIUM] CWE-119 CVE-2010-0507: Buffer overflow in Image RAW in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbi
Buffer overflow in Image RAW in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PEF image.
nvd
CVE-2010-0506P4MEDIUMCVSS 6.8v10.5.82010-03-30
CVE-2010-0506 [MEDIUM] CWE-119 CVE-2010-0506: Buffer overflow in Image RAW in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary c
Buffer overflow in Image RAW in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted NEF image.
nvd
CVE-2010-0515P4MEDIUMCVSS 6.8v10.6.0v10.6.1+1 more2010-03-30
CVE-2010-0515 [MEDIUM] CWE-119 CVE-2010-0515: QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause
QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with H.264 encoding.
nvd
CVE-2019-20807P4MEDIUMCVSS 5.3v10.13.6v10.14.62020-05-28
CVE-2019-20807 [MEDIUM] CWE-78 CVE-2019-20807: In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS comma
In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua).
nvd
CVE-2009-2800P4MEDIUMCVSS 6.8v10.4.11v10.5.82009-09-11
CVE-2009-2800 [MEDIUM] CWE-119 CVE-2009-2800: Buffer overflow in Alias Manager in Apple Mac OS X 10.4.11 and 10.5.8 allows attackers to execute ar
Buffer overflow in Alias Manager in Apple Mac OS X 10.4.11 and 10.5.8 allows attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted alias file.
nvd