cbcvebase.

Apple macOS vulnerabilities

3,438 known vulnerabilities affecting apple/macos.

Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1478MEDIUM1549LOW152

Vulnerabilities

Page 74 of 172
CVE-2022-24836P3HIGHCVSS 7.5≥ 13.0, < 13.12022-04-11
CVE-2022-24836 [HIGH] CWE-400 CVE-2022-24836: Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficie Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `= 1.13.4`. There are no known workarounds for this issue.
nvd
CVE-2021-23841P3MEDIUMCVSS 5.9≥ 11.1, < 11.42021-02-16
CVE-2021-23841 [MEDIUM] CWE-476 CVE-2021-23841: The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while parsing the issuer field (which might occur if the issuer field is maliciously constructed). This ma
nvd
CVE-2020-9847P3HIGHCVSS 8.6≥ unspecified, < macOS Catalina 10.15.52020-06-09
CVE-2020-9847 [HIGH] CWE-125 CVE-2020-9847: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Cata An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.5. A malicious application may be able to break out of its sandbox.
nvd
CVE-2020-8037P3HIGHCVSS 7.5≥ 11.0, < 11.32020-11-04
CVE-2020-8037 [HIGH] CWE-770 CVE-2020-8037: The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory. The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.
nvd
CVE-2024-44256P3HIGHCVSS 8.6≥ 13.0, < 13.7.1≥ 14.0, < 14.7.1+3 more2024-10-28
CVE-2024-44256 [HIGH] CVE-2024-44256: The issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.1, The issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An app may be able to break out of its sandbox.
nvd
CVE-2023-32414P3HIGHCVSS 8.6≥ 13.0, < 13.4≥ unspecified, < 13.42023-06-23
CVE-2023-32414 [HIGH] CWE-326 CVE-2023-32414: The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.4. An app may The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.4. An app may be able to break out of its sandbox.
nvd
CVE-2022-32208P3MEDIUMCVSS 5.9fixed in 13.02022-07-07
CVE-2022-32208 [MEDIUM] CWE-840 CVE-2022-32208: When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wron When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.
nvd
CVE-2020-9991P3HIGHCVSS 7.5≥ unspecified, < 11.02020-12-08
CVE-2020-9991 [HIGH] CVE-2020-9991: This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.0.1, watchOS This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, iOS 14.0 and iPadOS 14.0, iCloud for Windows 7.21, tvOS 14.0. A remote attacker may be able to cause a denial of service.
nvd
CVE-2019-20838P3HIGHCVSS 7.5fixed in 11.0.12020-06-15
CVE-2019-20838 [HIGH] CVE-2019-20838: libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \X or libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \X or \R has more than one fixed quantifier, a related issue to CVE-2019-20454.
nvd
CVE-2022-0261P3HIGHCVSS 7.8fixed in 13.02022-01-18
CVE-2022-0261 [HIGH] CWE-122 CVE-2022-0261: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2022-2125P3HIGHCVSS 7.8fixed in 11.7≥ 12.0, < 12.62022-06-19
CVE-2022-2125 [HIGH] CWE-122 CVE-2022-2125: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2022-1942P3HIGHCVSS 7.8fixed in 13.02022-05-31
CVE-2022-1942 [HIGH] CWE-122 CVE-2022-1942: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2022-1897P3HIGHCVSS 7.8fixed in 13.02022-05-27
CVE-2022-1897 [HIGH] CWE-787 CVE-2022-1897: Out-of-bounds Write in GitHub repository vim/vim prior to 8.2. Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2022-26981P3HIGHCVSS 7.8≥ 12.0, < 12.52022-03-13
CVE-2022-26981 [HIGH] CWE-120 CVE-2022-26981: Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (cal Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (called, indirectly, by tools/lou_checktable.c).
nvd
CVE-2019-8629P3HIGHCVSS 7.8≥ unspecified, < macOS Mojave 10.14.52019-12-18
CVE-2019-8629 [HIGH] CWE-665 CVE-2019-8629: A memory initialization issue was addressed with improved memory handling. This issue is fixed in ma A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.5. An application may be able to execute arbitrary code with system privileges.
nvd
CVE-2019-8555P3HIGHCVSS 7.8≥ unspecified, < macOS Mojave 10.14.42019-12-18
CVE-2019-8555 [HIGH] CWE-119 CVE-2019-8555: A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Mojave 1 A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Mojave 10.14.4. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2020-3863P3HIGHCVSS 7.8≥ unspecified, < 10.152020-10-27
CVE-2020-3863 [HIGH] CWE-787 CVE-2020-3863: A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.3, Security Update 2020-001 Mojave, Security Update 2020-001 High Sierra. An application may be able to execute arbitrary code with system privileges.
nvd
CVE-2020-3904P3HIGHCVSS 7.8≥ unspecified, < macOS Catalina 10.15.42020-04-01
CVE-2020-3904 [HIGH] CWE-787 CVE-2020-3904: Multiple memory corruption issues were addressed with improved state management. This issue is fixed Multiple memory corruption issues were addressed with improved state management. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2021-1761P3HIGHCVSS 7.5≥ 11.0.1, < 11.2≥ unspecified, < 11.2+2 more2021-04-02
CVE-2021-1761 [HIGH] CVE-2021-1761: This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security U This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause a denial of service.
nvd
CVE-2025-43330P3HIGHCVSS 8.2fixed in 15.7fixed in 262025-09-15
CVE-2025-43330 [HIGH] CWE-693 CVE-2025-43330: This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7, This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An app may be able to break out of its sandbox.
nvd
Apple macOS vulnerabilities | cvebase