Apple tvOS vulnerabilities
2,371 known vulnerabilities affecting apple/tvos.
Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL149HIGH1258MEDIUM837LOW59UNKNOWN68
Vulnerabilities
Page 10 of 119
CVE-2017-13867P3HIGHCVSS 7.8PoCfixed in 11.22017-12-25
CVE-2017-13867 [HIGH] CWE-119 CVE-2017-13867: An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted a
nvdapple
CVE-2018-4206P3HIGHCVSS 7.8PoCv11.42018-05-29
CVE-2018-4206 [HIGH] CVE-2018-4206: tvOS 11.4
Apple Security Update: About the security content of tvOS 11.4
Product: tvOS
Version: 11.4
CVE: CVE-2018-4206
Component: Crash Reporter
Impact: An application may be able to gain elevated privileges
Description: A memory corruption issue was addressed with improved error handling.
apple
CVE-2017-1000373P3MEDIUMCVSS 6.5PoCv112017-09-19
CVE-2017-1000373 [MEDIUM] CVE-2017-1000373: tvOS 11
Apple Security Update: About the security content of tvOS 11
Product: tvOS
Version: 11
CVE: CVE-2017-1000373
Component: CVE-2017-1000373
Impact: Multiple issues in expat
Description: Multiple issues were addressed by updating to version 2.2.1
apple
CVE-2018-4087P3HIGHCVSS 7.8PoCv11.2.52018-01-23
CVE-2018-4087 [HIGH] CVE-2018-4087: tvOS 11.2.5
Apple Security Update: About the security content of tvOS 11.2.5
Product: tvOS
Version: 11.2.5
CVE: CVE-2018-4087
Component: Core Bluetooth
Impact: An application may be able to execute arbitrary code with system privileges
Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2015-7039P3MEDIUMCVSS 6.8PoC≤ 9.02015-12-11
CVE-2015-7039 [MEDIUM] CVE-2015-7039: Buffer overflow in libc in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS b
Buffer overflow in libc in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code via a crafted package, a different vulnerability than CVE-2015-7038.
nvdapple
CVE-2022-42867P2HIGHCVSS 8.8fixed in 16.2≥ unspecified, < 16.2+1 more2022-12-15
CVE-2022-42867 [HIGH] CWE-416 CVE-2022-42867: A use after free issue was addressed with improved memory management. This issue is fixed in Safari
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2016-1823P3HIGHCVSS 7.8PoCfixed in 9.2.12016-05-20
CVE-2016-1823 [HIGH] CWE-125 CVE-2016-1823: The IOHIDDevice::handleReportWithTime function in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS
The IOHIDDevice::handleReportWithTime function in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (out-of-bounds read and memory corruption) via a crafted IOHIDReportType enum, which triggers an incorrect cast, a differ
nvdapple
CVE-2017-7376P2CRITICALCVSS 9.8v112017-09-19
CVE-2017-7376 [CRITICAL] CVE-2017-7376: tvOS 11
Apple Security Update: About the security content of tvOS 11
Product: tvOS
Version: 11
CVE: CVE-2017-7376
Component: CVE-2017-9233
Impact: Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution
Description: A use after free issue was addressed with improved memory management.
apple
CVE-2019-6214P3HIGHCVSS 8.6PoC≥ unspecified, < tvOS 12.1.22019-03-05
CVE-2019-6214 [HIGH] CWE-843 CVE-2019-6214: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to break out of its sandbox.
nvdapple
CVE-2017-2483P3HIGHCVSS 7.8PoC≤ 10.1.12017-04-02
CVE-2017-2483 [HIGH] CWE-119 CVE-2017-2483: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. A buffer overflow allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvdapple
CVE-2019-6213P3HIGHCVSS 7.8PoC≥ unspecified, < tvOS 12.1.22019-03-05
CVE-2019-6213 [HIGH] CWE-119 CVE-2019-6213: A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, ma
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. An application may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2017-2482P3HIGHCVSS 7.8PoC≤ 10.1.12017-04-02
CVE-2017-2482 [HIGH] CWE-119 CVE-2017-2482: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. A buffer overflow allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvdapple
CVE-2016-1819P3HIGHCVSS 7.8PoCfixed in 9.2.12016-05-20
CVE-2016-1819 [HIGH] CVE-2016-1819: Use-after-free vulnerability in the IOAccelContext2::clientMemoryForType method in Apple iOS before
Use-after-free vulnerability in the IOAccelContext2::clientMemoryForType method in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1817 and CVE-2016
nvdapple
CVE-2017-2473P3HIGHCVSS 7.8PoC≤ 10.1.12017-04-02
CVE-2017-2473 [HIGH] CWE-119 CVE-2017-2473: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app
nvdapple
CVE-2017-6997P3HIGHCVSS 7.8PoC≤ 10.22017-05-22
CVE-2017-6997 [HIGH] CWE-119 CVE-2017-6997: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvdapple
CVE-2017-6999P3HIGHCVSS 7.8PoC≤ 10.22017-05-22
CVE-2017-6999 [HIGH] CWE-119 CVE-2017-6999: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvdapple
CVE-2017-2472P3HIGHCVSS 7.8PoC≤ 10.1.12017-04-02
CVE-2017-2472 [HIGH] CWE-416 CVE-2017-2472: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.
nvdapple
CVE-2017-2490P3HIGHCVSS 7.8PoC≤ 10.1.12017-04-02
CVE-2017-2490 [HIGH] CWE-119 CVE-2017-2490: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app
nvdapple
CVE-2017-2360P3HIGHCVSS 7.8PoCfixed in 10.1.12017-02-20
CVE-2017-2360 [HIGH] CWE-416 CVE-2017-2360: An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS before 10.1.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted
nvdapple
CVE-2017-2365P3MEDIUMCVSS 6.5PoCfixed in 10.1.12017-02-20
CVE-2017-2365 [MEDIUM] CWE-200 CVE-2017-2365: An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
nvdapple