Apple Macos Mojave vulnerabilities

65 known vulnerabilities affecting apple/macos_mojave.

Total CVEs
65
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL8HIGH30MEDIUM23UNKNOWN4

Vulnerabilities

Page 3 of 4
CVE-2018-4433MEDIUMCVSS 5.5v10.142018-09-24
CVE-2018-4433 [MEDIUM] CVE-2018-4433: macOS Mojave 10.14 Apple Security Update: About the security content of macOS Mojave 10.14 Product: macOS Mojave Version: 10.14 CVE: CVE-2018-4433 Component: DiskArbitration Impact: A malicious application may be able to modify contents of the EFI system partition and execute arbitrary code with kernel privileges if secure boot is not enabled Description: A permissions issue existed in DiskArbitration. This was addressed with additional ownership checks.
apple
CVE-2018-5383MEDIUMCVSS 6.8v10.142018-09-24
CVE-2018-5383 [MEDIUM] CVE-2018-5383: macOS Mojave 10.14 Apple Security Update: About the security content of macOS Mojave 10.14 Product: macOS Mojave Version: 10.14 CVE: CVE-2018-5383 Component: Bluetooth Impact: An attacker in a privileged network position may be able to intercept Bluetooth traffic Description: An input validation issue existed in Bluetooth. This issue was addressed with improved input validation.
apple
CVE-2018-4304MEDIUMCVSS 5.0v10.142018-09-24
CVE-2018-4304 [MEDIUM] CVE-2018-4304: macOS Mojave 10.14 Apple Security Update: About the security content of macOS Mojave 10.14 Product: macOS Mojave Version: 10.14 CVE: CVE-2018-4304 Component: Text Impact: Processing a maliciously crafted text file may lead to a denial of service Description: A denial of service issue was addressed with improved validation.
apple
CVE-2018-4418MEDIUMCVSS 5.5v10.142018-09-24
CVE-2018-4418 [MEDIUM] CVE-2018-4418: macOS Mojave 10.14 Apple Security Update: About the security content of macOS Mojave 10.14 Product: macOS Mojave Version: 10.14 CVE: CVE-2018-4418 Component: Intel Graphics Driver Impact: An application may be able to read restricted memory Description: A validation issue was addressed with improved input sanitization.
apple
CVE-2018-4321MEDIUMCVSS 5.3v10.142018-09-24
CVE-2018-4321 [MEDIUM] CVE-2018-4321: macOS Mojave 10.14 Apple Security Update: About the security content of macOS Mojave 10.14 Product: macOS Mojave Version: 10.14 CVE: CVE-2018-4321 Component: Auto Unlock Impact: A malicious application may be able to access local users AppleIDs Description: A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement.
apple
CVE-2018-4346MEDIUMCVSS 5.5v10.142018-09-24
CVE-2018-4346 [MEDIUM] CVE-2018-4346: macOS Mojave 10.14 Apple Security Update: About the security content of macOS Mojave 10.14 Product: macOS Mojave Version: 10.14 CVE: CVE-2018-4346 Component: Dictionary Impact: Parsing a maliciously crafted dictionary file may lead to disclosure of user information Description: A validation issue existed which allowed local file access. This was addressed with input sanitization.
apple
CVE-2016-0702MEDIUMCVSS 5.1v10.142018-09-24
CVE-2016-0702 [MEDIUM] CVE-2016-0702: macOS Mojave 10.14 Apple Security Update: About the security content of macOS Mojave 10.14 Product: macOS Mojave Version: 10.14 CVE: CVE-2016-0702 Component: CVE-2016-0702
apple
CVE-2018-4399MEDIUMCVSS 5.5v10.142018-09-24
CVE-2018-4399 [MEDIUM] CVE-2018-4399: macOS Mojave 10.14 Apple Security Update: About the security content of macOS Mojave 10.14 Product: macOS Mojave Version: 10.14 CVE: CVE-2018-4399 Component: Kernel Impact: A malicious application may be able to leak sensitive user information Description: An access issue existed with privileged API calls. This issue was addressed with additional restrictions.
apple
CVE-2018-4417MEDIUMCVSS 5.5v10.142018-09-24
CVE-2018-4417 [MEDIUM] CVE-2018-4417: macOS Mojave 10.14 Apple Security Update: About the security content of macOS Mojave 10.14 Product: macOS Mojave Version: 10.14 CVE: CVE-2018-4417 Component: AppleGraphicsControl Impact: An application may be able to read restricted memory Description: A validation issue was addressed with improved input sanitization.
apple
CVE-2018-4355MEDIUMCVSS 5.5v10.142018-09-24
CVE-2018-4355 [MEDIUM] CVE-2018-4355: macOS Mojave 10.14 Apple Security Update: About the security content of macOS Mojave 10.14 Product: macOS Mojave Version: 10.14 CVE: CVE-2018-4355 Component: Hypervisor Impact: Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access with guest OS privilege via a terminal page fault and a side-channel analysis Desc
apple
CVE-2018-4348MEDIUMCVSS 5.5v10.142018-09-24
CVE-2018-4348 [MEDIUM] CVE-2018-4348: macOS Mojave 10.14 Apple Security Update: About the security content of macOS Mojave 10.14 Product: macOS Mojave Version: 10.14 CVE: CVE-2018-4348 Component: Login Window Impact: A local user may be able to cause a denial of service Description: A validation issue was addressed with improved logic.
apple
CVE-2018-3639MEDIUMCVSS 5.5ExploitedPoCv10.142018-09-24
CVE-2018-3639 [MEDIUM] CVE-2018-3639: macOS Mojave 10.14 Apple Security Update: About the security content of macOS Mojave 10.14 Product: macOS Mojave Version: 10.14 CVE: CVE-2018-3639 Component: Microcode Impact: Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis Descriptio
apple
CVE-2018-3646MEDIUMCVSS 5.6v10.142018-09-24
CVE-2018-3646 [MEDIUM] CVE-2018-3646: macOS Mojave 10.14 Apple Security Update: About the security content of macOS Mojave 10.14 Product: macOS Mojave Version: 10.14 CVE: CVE-2018-3646 Component: Hypervisor Impact: Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access with guest OS privilege via a terminal page fault and a side-channel analysis Desc
apple
CVE-2018-4324MEDIUMCVSS 5.5v10.142018-09-24
CVE-2018-4324 [MEDIUM] CVE-2018-4324: macOS Mojave 10.14 Apple Security Update: About the security content of macOS Mojave 10.14 Product: macOS Mojave Version: 10.14 CVE: CVE-2018-4324 Component: App Store Impact: A malicious application may be able to determine the Apple ID of the owner of the computer Description: A permissions issue existed in the handling of the Apple ID. This issue was addressed with improved access controls.
apple
CVE-2017-12618MEDIUMCVSS 4.7v10.142018-09-24
CVE-2017-12618 [MEDIUM] CVE-2017-12618: macOS Mojave 10.14 Apple Security Update: About the security content of macOS Mojave 10.14 Product: macOS Mojave Version: 10.14 CVE: CVE-2017-12618 Component: APR Impact: Multiple buffer overflow issues existed in Perl Description: Multiple issues in Perl were addressed with improved memory handling.
apple
CVE-2018-4406MEDIUMCVSS 6.5v10.142018-09-24
CVE-2018-4406 [MEDIUM] CVE-2018-4406: macOS Mojave 10.14 Apple Security Update: About the security content of macOS Mojave 10.14 Product: macOS Mojave Version: 10.14 CVE: CVE-2018-4406 Component: CUPS Impact: An attacker in a privileged position may be able to perform a denial of service attack Description: A denial of service issue was addressed with improved validation.
apple
CVE-2018-4338MEDIUMCVSS 5.5v10.142018-09-24
CVE-2018-4338 [MEDIUM] CVE-2018-4338: macOS Mojave 10.14 Apple Security Update: About the security content of macOS Mojave 10.14 Product: macOS Mojave Version: 10.14 CVE: CVE-2018-4338 Component: Wi-Fi Impact: An application may be able to read restricted memory Description: A validation issue was addressed with improved input sanitization.
apple
CVE-2018-4333MEDIUMCVSS 5.5v10.142018-09-24
CVE-2018-4333 [MEDIUM] CVE-2018-4333: macOS Mojave 10.14 Apple Security Update: About the security content of macOS Mojave 10.14 Product: macOS Mojave Version: 10.14 CVE: CVE-2018-4333 Component: Crash Reporter Impact: An application may be able to read restricted memory Description: A validation issue was addressed with improved input sanitization.
apple
CVE-2018-4308MEDIUMCVSS 5.5v10.142018-09-24
CVE-2018-4308 [MEDIUM] CVE-2018-4308: macOS Mojave 10.14 Apple Security Update: About the security content of macOS Mojave 10.14 Product: macOS Mojave Version: 10.14 CVE: CVE-2018-4308 Component: ATS Impact: An application may be able to read restricted memory Description: An out-of-bounds read was addressed with improved bounds checking.
apple
CVE-2018-4351MEDIUMCVSS 5.5v10.142018-09-24
CVE-2018-4351 [MEDIUM] CVE-2018-4351: macOS Mojave 10.14 Apple Security Update: About the security content of macOS Mojave 10.14 Product: macOS Mojave Version: 10.14 CVE: CVE-2018-4351 Component: Intel Graphics Driver Impact: An application may be able to read restricted memory Description: A memory initialization issue was addressed with improved memory handling.
apple