cbcvebase.

Apple macOS vulnerabilities

3,438 known vulnerabilities affecting apple/macos.

Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL204HIGH1438MEDIUM1494LOW151UNKNOWN151

Vulnerabilities

Page 7 of 172
CVE-2019-8672P2HIGHCVSS 8.8PoC≥ unspecified, < macOS Mojave 10.14.62019-12-18
CVE-2019-8672 [HIGH] CWE-787 CVE-2019-8672: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8641P2CRITICALCVSS 9.8PoC≥ unspecified, < macOS Mojave 10.14.6 Supplemental Update 22019-12-18
CVE-2019-8641 [CRITICAL] CWE-125 CVE-2019-8641: An out-of-bounds read was addressed with improved input validation. An out-of-bounds read was addressed with improved input validation.
nvd
CVE-2019-8661P2CRITICALCVSS 9.8PoC≥ unspecified, < macOS Mojave 10.14.62019-12-18
CVE-2019-8661 [CRITICAL] CWE-416 CVE-2019-8661: A use after free issue was addressed with improved memory management. This issue is fixed in macOS M A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.6. A remote attacker may be able to cause arbitrary code execution.
nvd
CVE-2019-8623P2HIGHCVSS 8.8PoC≥ unspecified, < macOS Mojave 10.14.52019-12-18
CVE-2019-8623 [HIGH] CWE-787 CVE-2019-8623: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8622P2HIGHCVSS 8.8PoC≥ unspecified, < macOS Mojave 10.14.52019-12-18
CVE-2019-8622 [HIGH] CWE-787 CVE-2019-8622: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8671P2HIGHCVSS 8.8PoC≥ unspecified, < macOS Mojave 10.14.62019-12-18
CVE-2019-8671 [HIGH] CWE-787 CVE-2019-8671: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8611P2HIGHCVSS 8.8PoC≥ unspecified, < macOS Mojave 10.14.52019-12-18
CVE-2019-8611 [HIGH] CWE-787 CVE-2019-8611: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8662P2CRITICALCVSS 9.8PoC≥ unspecified, < macOS Mojave 10.14.62019-12-18
CVE-2019-8662 [CRITICAL] CWE-416 CVE-2019-8662: This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6 This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. An attacker may be able to trigger a use-after-free in an application deserializing an untrusted NSDictionary.
nvd
CVE-2019-6224P2HIGHCVSS 8.8PoC≥ unspecified, < macOS Mojave 10.14.32019-03-05
CVE-2019-6224 [HIGH] CWE-119 CVE-2019-6224: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.1 A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A remote attacker may be able to initiate a FaceTime call causing arbitrary code execution.
nvd
CVE-2019-6225P3HIGHCVSS 7.8PoC≥ unspecified, < macOS Mojave 10.14.32019-03-05
CVE-2019-6225 [HIGH] CWE-787 CVE-2019-6225: A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A malicious application may be able to elevate privileges.
nvd
CVE-2021-44224P2HIGHCVSS 8.2fixed in 10.15.7≥ 11.0, < 11.6.6+1 more2021-12-20
CVE-2021-44224 [HIGH] CWE-476 CVE-2021-44224: A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to
nvd
CVE-2011-3336P3HIGHCVSS 7.5PoCvthrough 20112020-02-12
CVE-2011-3336 [HIGH] CWE-400 CVE-2011-3336: regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion.
nvd
CVE-2022-42867P2HIGHCVSS 8.8fixed in 13.12022-12-15
CVE-2022-42867 [HIGH] CWE-416 CVE-2022-42867: A use after free issue was addressed with improved memory management. This issue is fixed in Safari A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2022-22720P2CRITICALCVSS 9.8fixed in 10.15.7≥ 11.0, < 11.6.6+1 more2022-03-14
CVE-2022-22720 [CRITICAL] CWE-444 CVE-2022-22720: Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling
nvd
CVE-2022-22721P2CRITICALCVSS 9.1≥ 11.0, < 11.6.6≥ 12.0, < 12.42022-03-14
CVE-2022-22721 [CRITICAL] CWE-190 CVE-2022-22721: If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit s If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.
nvd
CVE-2022-22719P2HIGHCVSS 7.5fixed in 10.15.7≥ 11.0, < 11.6.6+1 more2022-03-14
CVE-2022-22719 [HIGH] CWE-665 CVE-2022-22719: A carefully crafted request body can cause a read to a random memory area which could cause the proc A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier.
nvd
CVE-2020-36221P3HIGHCVSS 7.5≥ 11.1, < 11.42021-01-26
CVE-2020-36221 [HIGH] CWE-191 CVE-2020-36221: An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certif An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c serialNumberAndIssuerCheck).
nvd
CVE-2019-6214P3HIGHCVSS 8.6PoC≥ unspecified, < macOS Mojave 10.14.32019-03-05
CVE-2019-6214 [HIGH] CWE-843 CVE-2019-6214: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1. A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to break out of its sandbox.
nvd
CVE-2019-6213P3HIGHCVSS 7.8PoC≥ unspecified, < macOS Mojave 10.14.32019-03-05
CVE-2019-6213 [HIGH] CWE-119 CVE-2019-6213: A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, ma A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2019-8513P3HIGHCVSS 7.8PoC≥ unspecified, < macOS Mojave 10.14.42019-12-18
CVE-2019-8513 [HIGH] CWE-78 CVE-2019-8513: This issue was addressed with improved checks. This issue is fixed in macOS Mojave 10.14.4. A local This issue was addressed with improved checks. This issue is fixed in macOS Mojave 10.14.4. A local user may be able to execute arbitrary shell commands.
nvd
Apple macOS vulnerabilities | cvebase