cbcvebase.

Apple macOS vulnerabilities

3,438 known vulnerabilities affecting apple/macos.

Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL204HIGH1438MEDIUM1494LOW151UNKNOWN151

Vulnerabilities

Page 8 of 172
CVE-2020-36228P3HIGHCVSS 7.5≥ 11.1, < 11.42021-01-26
CVE-2020-36228 [HIGH] CWE-191 CVE-2020-36228: An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certif An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, resulting in denial of service.
nvd
CVE-2019-8565P3HIGHCVSS 7.0PoC≥ unspecified, < macOS Mojave 10.14.42019-12-18
CVE-2019-8565 [HIGH] CWE-362 CVE-2019-8565: A race condition was addressed with additional validation. This issue is fixed in iOS 12.2, macOS Mo A race condition was addressed with additional validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4. A malicious application may be able to gain root privileges.
nvd
CVE-2019-6218P3HIGHCVSS 7.8PoC≥ unspecified, < macOS Mojave 10.14.32019-03-05
CVE-2019-6218 [HIGH] CWE-787 CVE-2019-6218: A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 1 A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2024-2398P2HIGHCVSS 8.6fixed in 12.7.6≥ 13.0, < 13.6.8+1 more2024-03-27
CVE-2024-2398 [HIGH] CWE-772 CVE-2024-2398: When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received h When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory. Further, this error condition fails silen
nvd
CVE-2020-36227P3HIGHCVSS 7.5≥ 11.1, < 11.42021-01-26
CVE-2020-36227 [HIGH] CWE-835 CVE-2020-36227: A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in denial of service.
nvd
CVE-2020-36222P3HIGHCVSS 7.5≥ 11.1, < 11.42021-01-26
CVE-2020-36222 [HIGH] CWE-617 CVE-2020-36222: A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the sasl A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of service.
nvd
CVE-2019-6205P3HIGHCVSS 7.8PoC≥ unspecified, < macOS Mojave 10.14.32019-03-05
CVE-2019-6205 [HIGH] CWE-787 CVE-2019-6205: A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iO A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A malicious application may cause unexpected changes in memory shared between processes.
nvd
CVE-2019-8514P3HIGHCVSS 7.8PoC≥ unspecified, < macOS Mojave 10.14.42019-12-18
CVE-2019-8514 [HIGH] CVE-2019-8514: A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS M A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. An application may be able to gain elevated privileges.
nvd
CVE-2019-8717P3HIGHCVSS 7.8PoC≥ unspecified, < macOS Catalina 10.152019-12-18
CVE-2019-8717 [HIGH] CWE-787 CVE-2019-8717: A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15, tvOS 13. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2019-8600P2CRITICALCVSS 9.8≥ unspecified, < macOS Mojave 10.14.52019-12-18
CVE-2019-8600 [CRITICAL] CWE-89 CVE-2019-8600: A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 1 A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. A maliciously crafted SQL query may lead to arbitrary code execution.
nvd
CVE-2018-25032P3HIGHCVSS 7.5≥ 11.0, < 11.6.6≥ 12.0.0, < 12.42022-03-25
CVE-2018-25032 [HIGH] CWE-787 CVE-2018-25032: zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
nvd
CVE-2024-27822P3HIGHCVSS 7.8PoC≥ 14.0, < 14.5fixed in 14.52024-05-14
CVE-2024-27822 [HIGH] CWE-277 CVE-2024-27822: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sonoma 14.5. An A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sonoma 14.5. An app may be able to gain root privileges.
nvd
CVE-2019-8649P3MEDIUMCVSS 6.1PoC≥ unspecified, < macOS Mojave 10.14.62019-12-18
CVE-2019-8649 [MEDIUM] CWE-79 CVE-2019-8649: A logic issue existed in the handling of synchronous page loads. This issue was addressed with impro A logic issue existed in the handling of synchronous page loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to universal cross sit
nvd
CVE-2022-37434P2CRITICALCVSS 9.8≥ 11.0, < 11.7.1≥ 12.0.0, < 12.6.12022-08-05
CVE-2022-37434 [CRITICAL] CWE-787 CVE-2022-37434: zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).
nvd
CVE-2019-8663P3MEDIUMCVSS 5.3PoC≥ unspecified, < macOS Mojave 10.14.62019-12-18
CVE-2019-8663 [MEDIUM] CVE-2019-8663: This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6 This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6. A remote attacker may be able to leak memory.
nvd
CVE-2019-8690P3MEDIUMCVSS 6.1PoC≥ unspecified, < macOS Mojave 10.14.62019-12-18
CVE-2019-8690 [MEDIUM] CWE-79 CVE-2019-8690: A logic issue existed in the handling of document loads. This issue was addressed with improved stat A logic issue existed in the handling of document loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to universal cross site script
nvd
CVE-2022-22616P3MEDIUMCVSS 5.5PoC≥ 11.0, < 11.6.5≥ 12.0.0, < 12.3+3 more2022-05-26
CVE-2022-22616 [MEDIUM] CVE-2022-22616: This issue was addressed with improved checks. This issue is fixed in Security Update 2022-003 Catal This issue was addressed with improved checks. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. A maliciously crafted ZIP archive may bypass Gatekeeper checks.
nvd
CVE-2019-8591P3HIGHCVSS 7.1PoC≥ unspecified, < macOS Mojave 10.14.52019-12-18
CVE-2019-8591 [HIGH] CWE-843 CVE-2019-8591: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.3, A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. An application may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2020-9839P3HIGHCVSS 7.0PoC≥ unspecified, < macOS Catalina 10.15.52020-06-09
CVE-2020-9839 [HIGH] CWE-362 CVE-2020-9839: A race condition was addressed with improved state handling. This issue is fixed in iOS 13.5 and iPa A race condition was addressed with improved state handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. An application may be able to gain elevated privileges.
nvd
CVE-2023-38604P3CRITICALCVSS 9.8fixed in 11.7.9≥ 12.0, < 12.6.8+4 more2023-07-28
CVE-2023-38604 [CRITICAL] CWE-787 CVE-2023-38604: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in wa An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in watchOS 9.6, macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Monterey 12.6.8, tvOS 16.6, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to execute arbitrary code with kernel privileges.
nvd
Apple macOS vulnerabilities | cvebase