cbcvebase.

Apple tvOS vulnerabilities

2,371 known vulnerabilities affecting apple/tvos.

Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL174HIGH1277MEDIUM858LOW59UNKNOWN3

Vulnerabilities

Page 105 of 119
CVE-2025-43445P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43445 [MEDIUM] CWE-125 CVE-2025-43445: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.7. An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process m
nvdapple
CVE-2025-43384P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43384 [MEDIUM] CWE-125 CVE-2025-43384: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
nvdapple
CVE-2025-43385P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43385 [MEDIUM] CWE-125 CVE-2025-43385: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
nvdapple
CVE-2025-43383P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43383 [MEDIUM] CWE-125 CVE-2025-43383: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
nvdapple
CVE-2025-43441P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43441 [MEDIUM] CWE-119 CVE-2025-43441: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7. The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2015-1117P4MEDIUMCVSS 6.9≤ 7.12015-04-10
CVE-2015-1117 [MEDIUM] CWE-264 CVE-2015-1117: The (1) setreuid and (2) setregid system-call implementations in the kernel in Apple iOS before 8.3, The (1) setreuid and (2) setregid system-call implementations in the kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 do not properly perform privilege drops, which makes it easier for attackers to execute code with unintended user or group privileges via a crafted app.
nvd
CVE-2026-28985P4MEDIUMCVSS 6.2fixed in 26.52026-05-11
CVE-2026-28985 [MEDIUM] CWE-476 CVE-2026-28985: A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5. An attacker on the local network may be able to cause a denial-of-service.
nvd
CVE-2020-11760P4MEDIUMCVSS 5.5fixed in 13.4.82020-04-14
CVE-2020-11760 [MEDIUM] CWE-125 CVE-2020-11760: An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompres An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompression in rleUncompress in ImfRle.cpp.
nvdapple
CVE-2020-11763P4MEDIUMCVSS 5.5fixed in 13.4.82020-04-14
CVE-2020-11763 [MEDIUM] CWE-125 CVE-2020-11763: An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and writ An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and write, as demonstrated by ImfTileOffsets.cpp.
nvdapple
CVE-2024-27804P4MEDIUMCVSS 5.5fixed in 17.52024-05-14
CVE-2024-27804 [MEDIUM] CWE-770 CVE-2024-27804: The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17 The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.3, watchOS 10.5. An app may be able to cause unexpected system termination.
nvdapple
CVE-2016-1802P4MEDIUMCVSS 5.5fixed in 9.2.12016-05-20
CVE-2016-1802 [MEDIUM] CWE-200 CVE-2016-1802: CCCrypt in CommonCrypto in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watch CCCrypt in CommonCrypto in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 mishandles return values during key-length calculations, which allows attackers to obtain sensitive information via a crafted app.
nvdapple
CVE-2016-4680P4MEDIUMCVSS 5.5fixed in 10.0.12017-02-20
CVE-2016-4680 [MEDIUM] CWE-200 CVE-2016-4680: An issue was discovered in certain Apple products. iOS before 10.1 is affected. tvOS before 10.0.1 i An issue was discovered in certain Apple products. iOS before 10.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Kernel" component. It allows attackers to obtain sensitive information from kernel memory via a crafted app.
nvdapple
CVE-2017-13828P4MEDIUMCVSS 5.5v112017-09-19
CVE-2017-13828 [MEDIUM] CVE-2017-13828: tvOS 11 Apple Security Update: About the security content of tvOS 11 Product: tvOS Version: 11 CVE: CVE-2017-13828 Component: Fonts Impact: Rendering untrusted text may lead to spoofing Description: An inconsistent user interface issue was addressed with improved state management.
apple
CVE-2018-4093P4MEDIUMCVSS 5.5v11.2.52018-01-23
CVE-2018-4093 [MEDIUM] CVE-2018-4093: tvOS 11.2.5 Apple Security Update: About the security content of tvOS 11.2.5 Product: tvOS Version: 11.2.5 CVE: CVE-2018-4093 Component: Kernel Impact: An application may be able to read restricted memory Description: A validation issue was addressed with improved input sanitization.
apple
CVE-2016-7607P4MEDIUMCVSS 5.5v10.12016-12-12
CVE-2016-7607 [MEDIUM] CVE-2016-7607: tvOS 10.1 Apple Security Update: About the security content of tvOS 10.1 Product: tvOS Version: 10.1 CVE: CVE-2016-7607 Component: Kernel Impact: An application may be able to read kernel memory Description: An insufficient initialization issue was addressed by properly initializing memory returned to user space.
apple
CVE-2017-6987P4MEDIUMCVSS 5.5≤ 10.22017-05-22
CVE-2017-6987 [MEDIUM] CWE-200 CVE-2017-6987: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvdapple
CVE-2019-8560P4MEDIUMCVSS 5.5fixed in 12.3≥ unspecified, < tvOS 12.32019-12-18
CVE-2019-8560 [MEDIUM] CWE-125 CVE-2019-8560: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.3, An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to read restricted memory.
nvdapple
CVE-2017-7028P4MEDIUMCVSS 5.5fixed in 10.2.22017-07-20
CVE-2017-7028 [MEDIUM] CWE-200 CVE-2017-7028: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvdapple
CVE-2017-7029P4MEDIUMCVSS 5.5fixed in 10.2.22017-07-20
CVE-2017-7029 [MEDIUM] CWE-200 CVE-2017-7029: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvdapple
CVE-2017-2502P4MEDIUMCVSS 5.5fixed in 10.2.12017-05-22
CVE-2017-2502 [MEDIUM] CVE-2017-2502: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "CoreAudio" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvdapple
Apple tvOS vulnerabilities | cvebase