cbcvebase.

Apple tvOS vulnerabilities

2,371 known vulnerabilities affecting apple/tvos.

Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL149HIGH1258MEDIUM837LOW59UNKNOWN68

Vulnerabilities

Page 10 of 119
CVE-2017-13867P3HIGHCVSS 7.8PoCfixed in 11.22017-12-25
CVE-2017-13867 [HIGH] CWE-119 CVE-2017-13867: An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted a
nvdapple
CVE-2018-4206P3HIGHCVSS 7.8PoCv11.42018-05-29
CVE-2018-4206 [HIGH] CVE-2018-4206: tvOS 11.4 Apple Security Update: About the security content of tvOS 11.4 Product: tvOS Version: 11.4 CVE: CVE-2018-4206 Component: Crash Reporter Impact: An application may be able to gain elevated privileges Description: A memory corruption issue was addressed with improved error handling.
apple
CVE-2017-1000373P3MEDIUMCVSS 6.5PoCv112017-09-19
CVE-2017-1000373 [MEDIUM] CVE-2017-1000373: tvOS 11 Apple Security Update: About the security content of tvOS 11 Product: tvOS Version: 11 CVE: CVE-2017-1000373 Component: CVE-2017-1000373 Impact: Multiple issues in expat Description: Multiple issues were addressed by updating to version 2.2.1
apple
CVE-2018-4087P3HIGHCVSS 7.8PoCv11.2.52018-01-23
CVE-2018-4087 [HIGH] CVE-2018-4087: tvOS 11.2.5 Apple Security Update: About the security content of tvOS 11.2.5 Product: tvOS Version: 11.2.5 CVE: CVE-2018-4087 Component: Core Bluetooth Impact: An application may be able to execute arbitrary code with system privileges Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2015-7039P3MEDIUMCVSS 6.8PoC≤ 9.02015-12-11
CVE-2015-7039 [MEDIUM] CVE-2015-7039: Buffer overflow in libc in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS b Buffer overflow in libc in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code via a crafted package, a different vulnerability than CVE-2015-7038.
nvdapple
CVE-2022-42867P2HIGHCVSS 8.8fixed in 16.2≥ unspecified, < 16.2+1 more2022-12-15
CVE-2022-42867 [HIGH] CWE-416 CVE-2022-42867: A use after free issue was addressed with improved memory management. This issue is fixed in Safari A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2016-1823P3HIGHCVSS 7.8PoCfixed in 9.2.12016-05-20
CVE-2016-1823 [HIGH] CWE-125 CVE-2016-1823: The IOHIDDevice::handleReportWithTime function in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS The IOHIDDevice::handleReportWithTime function in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (out-of-bounds read and memory corruption) via a crafted IOHIDReportType enum, which triggers an incorrect cast, a differ
nvdapple
CVE-2017-7376P2CRITICALCVSS 9.8v112017-09-19
CVE-2017-7376 [CRITICAL] CVE-2017-7376: tvOS 11 Apple Security Update: About the security content of tvOS 11 Product: tvOS Version: 11 CVE: CVE-2017-7376 Component: CVE-2017-9233 Impact: Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution Description: A use after free issue was addressed with improved memory management.
apple
CVE-2019-6214P3HIGHCVSS 8.6PoC≥ unspecified, < tvOS 12.1.22019-03-05
CVE-2019-6214 [HIGH] CWE-843 CVE-2019-6214: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1. A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to break out of its sandbox.
nvdapple
CVE-2017-2483P3HIGHCVSS 7.8PoC≤ 10.1.12017-04-02
CVE-2017-2483 [HIGH] CWE-119 CVE-2017-2483: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. A buffer overflow allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvdapple
CVE-2019-6213P3HIGHCVSS 7.8PoC≥ unspecified, < tvOS 12.1.22019-03-05
CVE-2019-6213 [HIGH] CWE-119 CVE-2019-6213: A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, ma A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. An application may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2017-2482P3HIGHCVSS 7.8PoC≤ 10.1.12017-04-02
CVE-2017-2482 [HIGH] CWE-119 CVE-2017-2482: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. A buffer overflow allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvdapple
CVE-2016-1819P3HIGHCVSS 7.8PoCfixed in 9.2.12016-05-20
CVE-2016-1819 [HIGH] CVE-2016-1819: Use-after-free vulnerability in the IOAccelContext2::clientMemoryForType method in Apple iOS before Use-after-free vulnerability in the IOAccelContext2::clientMemoryForType method in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1817 and CVE-2016
nvdapple
CVE-2017-2473P3HIGHCVSS 7.8PoC≤ 10.1.12017-04-02
CVE-2017-2473 [HIGH] CWE-119 CVE-2017-2473: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app
nvdapple
CVE-2017-6997P3HIGHCVSS 7.8PoC≤ 10.22017-05-22
CVE-2017-6997 [HIGH] CWE-119 CVE-2017-6997: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvdapple
CVE-2017-6999P3HIGHCVSS 7.8PoC≤ 10.22017-05-22
CVE-2017-6999 [HIGH] CWE-119 CVE-2017-6999: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvdapple
CVE-2017-2472P3HIGHCVSS 7.8PoC≤ 10.1.12017-04-02
CVE-2017-2472 [HIGH] CWE-416 CVE-2017-2472: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.
nvdapple
CVE-2017-2490P3HIGHCVSS 7.8PoC≤ 10.1.12017-04-02
CVE-2017-2490 [HIGH] CWE-119 CVE-2017-2490: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app
nvdapple
CVE-2017-2360P3HIGHCVSS 7.8PoCfixed in 10.1.12017-02-20
CVE-2017-2360 [HIGH] CWE-416 CVE-2017-2360: An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS before 10.1.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted
nvdapple
CVE-2017-2365P3MEDIUMCVSS 6.5PoCfixed in 10.1.12017-02-20
CVE-2017-2365 [MEDIUM] CWE-200 CVE-2017-2365: An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0 An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
nvdapple
Apple tvOS vulnerabilities | cvebase