cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 99 of 157
CVE-2013-0973P4MEDIUMCVSS 6.8v10.6.8v10.7.0+5 more2013-03-15
CVE-2013-0973 [MEDIUM] CVE-2013-0973: Software Update in Apple Mac OS X through 10.7.5 does not prevent plugin loading within the marketin Software Update in Apple Mac OS X through 10.7.5 does not prevent plugin loading within the marketing-text WebView, which allows man-in-the-middle attackers to execute plugin code by modifying the client-server data stream.
nvd
CVE-2016-1770P4MEDIUMCVSS 6.5≤ 10.11.32016-03-24
CVE-2016-1770 [MEDIUM] CWE-284 CVE-2016-1770: The Reminders component in Apple OS X before 10.11.4 allows attackers to bypass an intended user-con The Reminders component in Apple OS X before 10.11.4 allows attackers to bypass an intended user-confirmation requirement and trigger a dialing action via a tel: URL.
nvd
CVE-2006-1455P4HIGHCVSS 7.8v10.3.9v10.4.62006-05-12
CVE-2006-1455 [HIGH] CVE-2006-1455: QuickTime Streaming Server in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to cause a de QuickTime Streaming Server in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to cause a denial of service (crash and connection interruption) via a QuickTime movie with a missing track, which triggers a null dereference.
nvd
CVE-2022-26691P4MEDIUMCVSS 6.7≥ 10.15, < 10.15.7v10.15.72022-05-26
CVE-2022-26691 [MEDIUM] CWE-697 CVE-2022-26691: A logic issue was addressed with improved state management. This issue is fixed in Security Update 2 A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges.
nvd
CVE-2014-3583P4MEDIUMCVSS 5.0v10.9.5v10.10.0+4 more2014-12-15
CVE-2014-3583 [MEDIUM] CWE-119 CVE-2014-3583: The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Serv The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause a denial of service (buffer over-read and daemon crash) via long response headers.
nvd
CVE-2005-2501P4HIGHCVSS 7.6v10.3.9v10.4.22005-08-19
CVE-2005-2501 [HIGH] CVE-2005-2501: Buffer overflow in AppKit for Mac OS X 10.3.9 and 10.4.2 allows external user-assisted attackers to Buffer overflow in AppKit for Mac OS X 10.3.9 and 10.4.2 allows external user-assisted attackers to execute arbitrary code via a crafted Rich Text Format (RTF) file.
nvd
CVE-2017-13886P4MEDIUMCVSS 6.5fixed in 10.13.22019-01-11
CVE-2017-13886 [MEDIUM] CVE-2017-13886: In macOS High Sierra before 10.13.2, an access issue existed with privileged WiFi system configurati In macOS High Sierra before 10.13.2, an access issue existed with privileged WiFi system configuration. This issue was addressed with additional restrictions.
nvd
CVE-2006-3505P4HIGHCVSS 7.5v10.3.9v10.4.72006-08-03
CVE-2006-3505 [HIGH] CVE-2006-3505: WebKit in Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause a denial of service (cra WebKit in Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTML document that causes WebKit to access an object that has already been deallocated.
nvd
CVE-2013-7338P4HIGHCVSS 7.1≤ 10.10.42014-04-22
CVE-2013-7338 [HIGH] CWE-20 CVE-2013-7338: Python before 3.3.4 RC1 allows remote attackers to cause a denial of service (infinite loop and CPU Python before 3.3.4 RC1 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a file size value larger than the size of the zip file to the (1) ZipExtFile.read, (2) ZipExtFile.read(n), (3) ZipExtFile.readlines, (4) ZipFile.extract, or (5) ZipFile.extractall function.
nvd
CVE-2019-8658P4MEDIUMCVSS 6.1fixed in 10.14.62019-12-18
CVE-2019-8658 [MEDIUM] CWE-79 CVE-2019-8658: A logic issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS M A logic issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd
CVE-2004-1086P4HIGHCVSS 7.5v10.2v10.2.1+14 more2004-12-02
CVE-2004-1086 [HIGH] CVE-2004-1086: Buffer overflow in PSNormalizer for Apple Mac OS X 10.3.6 allows remote attackers to execute arbitra Buffer overflow in PSNormalizer for Apple Mac OS X 10.3.6 allows remote attackers to execute arbitrary code via a crafted PostScript input file.
nvd
CVE-2021-30696P4MEDIUMCVSS 5.9≥ 10.14, ≤ 10.14.5≥ 10.15, ≤ 10.15.6+2 more2021-09-08
CVE-2021-30696 [MEDIUM] CVE-2021-30696: An attacker in a privileged network position may be able to misrepresent application state. This iss An attacker in a privileged network position may be able to misrepresent application state. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A logic issue was addressed with improved state management.
nvd
CVE-2013-5189P4MEDIUMCVSS 5.8≤ 10.8.5v10.8.0+5 more2013-10-24
CVE-2013-5189 [MEDIUM] CWE-264 CVE-2013-5189: Apple Mac OS X before 10.9 does not preserve a certain administrative system-preferences setting acr Apple Mac OS X before 10.9 does not preserve a certain administrative system-preferences setting across software updates, which allows context-dependent attackers to bypass intended access restrictions in opportunistic circumstances by leveraging an unintended security configuration after the completion of an update.
nvd
CVE-2017-13860P4MEDIUMCVSS 5.9fixed in 10.13.22017-12-25
CVE-2017-13860 [MEDIUM] CVE-2017-13860: An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. The issue involves the "Mail Drafts" component. It allows man-in-the-middle attackers to read e-mail content by leveraging mishandling of S/MIME credential encryption.
nvd
CVE-2013-1033P4MEDIUMCVSS 5.5≤ 10.8.4v10.8.0+3 more2013-09-16
CVE-2013-1033 [MEDIUM] CWE-264 CVE-2013-1033: Screen Lock in Apple Mac OS X before 10.8.5 does not properly track sessions, which allows remote au Screen Lock in Apple Mac OS X before 10.8.5 does not properly track sessions, which allows remote authenticated users to bypass locking by leveraging screen-sharing access.
nvd
CVE-2005-2514P4HIGHCVSS 7.5v10.3.92005-08-19
CVE-2005-2514 [HIGH] CVE-2005-2514: Buffer overflow in ping in Mac OS X 10.3.9 allows local users to execute arbitrary code. Buffer overflow in ping in Mac OS X 10.3.9 allows local users to execute arbitrary code.
nvd
CVE-2004-0429P4CRITICALCVSS 10.0v10.2.8v10.3.32004-12-31
CVE-2004-0429 [CRITICAL] CVE-2004-0429: Unknown vulnerability related to "the handling of large requests" in RAdmin for Apple Mac OS X 10.3. Unknown vulnerability related to "the handling of large requests" in RAdmin for Apple Mac OS X 10.3.3 and Mac OS X 10.2.8 may allow attackers to have unknown impact via unknown attack vectors.
nvd
CVE-2011-2821P4HIGHCVSS 7.5fixed in 10.7.42011-08-29
CVE-2011-2821 [HIGH] CWE-415 CVE-2011-2821: Double free vulnerability in libxml2, as used in Google Chrome before 13.0.782.215, allows remote at Double free vulnerability in libxml2, as used in Google Chrome before 13.0.782.215, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted XPath expression.
nvd
CVE-2006-0400P4HIGHCVSS 7.5v10.4v10.4.1+4 more2006-03-14
CVE-2006-0400 [HIGH] CVE-2006-0400: CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to bypass the same-origin poli CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to bypass the same-origin policy and execute Javascript in other domains via unknown vectors involving "crafted archives."
nvd
CVE-2015-1065P4MEDIUMCVSS 5.4≤ 10.10.22015-03-12
CVE-2015-1065 [MEDIUM] CWE-119 CVE-2015-1065: Multiple buffer overflows in iCloud Keychain in Apple iOS before 8.2 and Apple OS X through 10.10.2 Multiple buffer overflows in iCloud Keychain in Apple iOS before 8.2 and Apple OS X through 10.10.2 allow man-in-the-middle attackers to execute arbitrary code by modifying the client-server data stream during keychain recovery.
nvd
Apple macOS vulnerabilities | cvebase