Apple macOS vulnerabilities

3,135 known vulnerabilities affecting apple/macos.

Total CVEs
3,135
CISA KEV
75
actively exploited
Public exploits
44
Exploited in wild
61
Severity breakdown
CRITICAL203HIGH1362MEDIUM1421LOW149

Vulnerabilities

Page 83 of 157
CVE-2023-32402MEDIUMCVSS 6.5≥ 13.0, < 13.4≥ unspecified, < 13.42023-06-23
CVE-2023-32402 [MEDIUM] CWE-125 CVE-2023-32402: An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9 An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing web content may disclose sensitive information.
nvd
CVE-2023-28191MEDIUMCVSS 5.5≥ 11.0.0, < 11.7.7≥ 12.0.0, < 12.6.6+4 more2023-06-23
CVE-2023-28191 [MEDIUM] CWE-346 CVE-2023-28191: This issue was addressed with improved redaction of sensitive information. This issue is fixed in wa This issue was addressed with improved redaction of sensitive information. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. An app may be able to bypass Privacy preferences.
nvd
CVE-2023-32385MEDIUMCVSS 5.5fixed in 13.4≥ unspecified, < 13.42023-06-23
CVE-2023-32385 [MEDIUM] CWE-770 CVE-2023-32385: A denial-of-service issue was addressed with improved memory handling. This issue is fixed in iOS 16 A denial-of-service issue was addressed with improved memory handling. This issue is fixed in iOS 16.5 and iPadOS 16.5, macOS Ventura 13.4. Opening a PDF file may lead to unexpected app termination.
nvd
CVE-2023-32388MEDIUMCVSS 5.5≥ 11.0, < 11.7.7≥ 12.0.0, < 12.6.6+4 more2023-06-23
CVE-2023-32388 [MEDIUM] CWE-281 CVE-2023-32388: A privacy issue was addressed with improved private data redaction for log entries. This issue is fi A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in watchOS 9.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. An app may be able to bypass Privacy preferences.
nvd
CVE-2023-32423MEDIUMCVSS 6.5≥ 13.0, < 13.4≥ unspecified, < 13.42023-06-23
CVE-2023-32423 [MEDIUM] CWE-120 CVE-2023-32423: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in watchOS A buffer overflow issue was addressed with improved memory handling. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing web content may disclose sensitive information.
nvd
CVE-2023-32363MEDIUMCVSS 5.5fixed in 13.4≥ unspecified, < 13.42023-06-23
CVE-2023-32363 [MEDIUM] CWE-125 CVE-2023-32363: A permissions issue was addressed by removing vulnerable code and adding additional checks. This iss A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Ventura 13.4. An app may be able to bypass Privacy preferences.
nvd
CVE-2023-32371MEDIUMCVSS 6.3≥ 13.0, < 13.4≥ unspecified, < 13.42023-06-23
CVE-2023-32371 [MEDIUM] CVE-2023-32371: The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, macOS The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, macOS Ventura 13.4. An app may be able to break out of its sandbox.
nvd
CVE-2023-32376MEDIUMCVSS 5.5≥ 13.0, < 13.4≥ unspecified, < 13.42023-06-23
CVE-2023-32376 [MEDIUM] CVE-2023-32376: This issue was addressed with improved entitlements. This issue is fixed in iOS 16.5 and iPadOS 16.5 This issue was addressed with improved entitlements. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. An app may be able to modify protected parts of the file system.
nvd
CVE-2023-28204MEDIUMCVSS 6.5KEV≥ 13.0, < 13.4≥ unspecified, < 13.42023-06-23
CVE-2023-28204 [MEDIUM] CWE-125 CVE-2023-28204: An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9 An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been actively exploited.
nvd
CVE-2023-32375MEDIUMCVSS 5.5≥ 12.0.0, < 12.6.6≥ 13.0, < 13.4+2 more2023-06-23
CVE-2023-32375 [MEDIUM] CWE-125 CVE-2023-32375: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Mon An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.6, macOS Ventura 13.4. Processing a 3D model may result in disclosure of process memory.
nvd
CVE-2022-42807MEDIUMCVSS 4.3fixed in 13.0≥ unspecified, < 132023-06-23
CVE-2022-42807 [MEDIUM] CWE-640 CVE-2022-42807: A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. A user may accidentally add a participant to a Shared Album by pressing the Delete key
nvd
CVE-2023-32386LOWCVSS 3.3≥ 11.0, < 11.7.7≥ 12.0.0, < 12.6.6+4 more2023-06-23
CVE-2023-32386 [LOW] CWE-125 CVE-2023-32386: A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macO A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An app may be able to observe unprotected user data.
nvd
CVE-2022-42834LOWCVSS 3.3≥ 11.0, < 11.7.3≥ 12.0.0, < 12.6.3+3 more2023-06-23
CVE-2022-42834 [LOW] CWE-552 CVE-2022-42834: An access issue was addressed with improved access restrictions. This issue is fixed in macOS Monter An access issue was addressed with improved access restrictions. This issue is fixed in macOS Monterey 12.6.3, macOS Ventura 13, macOS Big Sur 11.7.3. An app may be able to access mail folder attachments through a temporary directory used during compression
nvd
CVE-2023-32394LOWCVSS 2.4≥ 13.0, < 13.4≥ unspecified, < 13.42023-06-23
CVE-2023-32394 [LOW] CWE-668 CVE-2023-32394: The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watch The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. A person with physical access to a device may be able to view contact information from the lock screen.
nvd
CVE-2023-32390LOWCVSS 2.4≥ 13.0, < 13.4≥ unspecified, < 13.42023-06-23
CVE-2023-32390 [LOW] CWE-125 CVE-2023-32390: The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watch The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, macOS Ventura 13.4. Photos belonging to the Hidden Photos Album could be viewed without authentication through Visual Lookup.
nvd
CVE-2023-34241HIGHCVSS 7.1fixed in 11.7.9≥ 12.0.0, < 12.6.8+1 more2023-06-22
CVE-2023-34241 [HIGH] CWE-416 CVE-2023-34241: OpenPrinting CUPS is a standards-based, open source printing system for Linux and other Unix-like op OpenPrinting CUPS is a standards-based, open source printing system for Linux and other Unix-like operating systems. Starting in version 2.0.0 and prior to version 2.4.6, CUPS logs data of free memory to the logging service AFTER the connection has been closed, when it should have logged the data right before. This is a use-after-free bug that impacts
nvd
CVE-2023-2953HIGHCVSS 7.5≥ 11.0, < 11.7.9≥ 12.0, < 12.6.8+1 more2023-05-30
CVE-2023-2953 [HIGH] CWE-476 CVE-2023-2953: A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_m A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
nvd
CVE-2023-28319HIGHCVSS 7.5≥ 11.0, < 11.7.9≥ 12.0, < 12.6.8+1 more2023-05-26
CVE-2023-28319 [HIGH] CWE-416 CVE-2023-28319: A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's public key using a SHA 256 hash. When this check fails, libcurl would free the memory for the fingerprint before it returns an error message containing the (now freed) hash. This flaw risks inserting sensitive heap-based data into the err
nvd
CVE-2023-28320MEDIUMCVSS 5.9≥ 11.0, < 11.7.9≥ 12.0, < 12.6.8+1 more2023-05-26
CVE-2023-28320 [MEDIUM] CWE-400 CVE-2023-28320: A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several differe A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows name resolves to time-out slow operations using `alarm()` and `siglongjmp()`. When doing this, libcurl used a global buffer that wa
nvd
CVE-2023-28321MEDIUMCVSS 5.9≥ 11.0, < 11.7.9≥ 12.0, < 12.6.8+1 more2023-05-26
CVE-2023-28321 [MEDIUM] CWE-295 CVE-2023-28321: An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports match An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private wildcard matching function would mat
nvd