cbcvebase.

Apple tvOS vulnerabilities

2,371 known vulnerabilities affecting apple/tvos.

Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL149HIGH1258MEDIUM837LOW59UNKNOWN68

Vulnerabilities

Page 11 of 119
CVE-2017-2363P3MEDIUMCVSS 6.5PoCfixed in 10.1.12017-02-20
CVE-2017-2363 [MEDIUM] CWE-200 CVE-2017-2363: An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0 An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
nvdapple
CVE-2019-6218P3HIGHCVSS 7.8PoCfixed in 12.1.2≥ unspecified, < tvOS 12.1.22019-03-05
CVE-2019-6218 [HIGH] CWE-787 CVE-2019-6218: A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 1 A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A malicious application may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2017-2474P3HIGHCVSS 7.8PoC≤ 10.1.12017-04-02
CVE-2017-2474 [HIGH] CVE-2017-2474: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. An off-by-one error allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvdapple
CVE-2016-7612P3HIGHCVSS 7.8PoCv10.12016-12-12
CVE-2016-7612 [HIGH] CVE-2016-7612: tvOS 10.1 Apple Security Update: About the security content of tvOS 10.1 Product: tvOS Version: 10.1 CVE: CVE-2016-7612 Component: Kernel Impact: An application may be able to execute arbitrary code with kernel privileges Description: Multiple memory corruption issues were addressed through improved input validation.
apple
CVE-2017-6996P3HIGHCVSS 7.8PoC≤ 10.22017-05-22
CVE-2017-6996 [HIGH] CWE-119 CVE-2017-6996: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvdapple
CVE-2017-6998P3HIGHCVSS 7.8PoC≤ 10.22017-05-22
CVE-2017-6998 [HIGH] CWE-119 CVE-2017-6998: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvdapple
CVE-2017-6995P3HIGHCVSS 7.8PoC≤ 10.22017-05-22
CVE-2017-6995 [HIGH] CWE-119 CVE-2017-6995: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvdapple
CVE-2017-6994P3HIGHCVSS 7.8PoC≤ 10.22017-05-22
CVE-2017-6994 [HIGH] CWE-119 CVE-2017-6994: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvdapple
CVE-2017-6989P3HIGHCVSS 7.8PoC≤ 10.22017-05-22
CVE-2017-6989 [HIGH] CWE-119 CVE-2017-6989: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvdapple
CVE-2016-4669P3HIGHCVSS 7.8PoCfixed in 10.0.12017-02-20
CVE-2016-4669 [HIGH] CWE-20 CVE-2016-4669: An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Kernel" component. It allows local users to execute arbitrary code in a privileged context or cause a denial of service (MIG code mishandling and system c
nvdapple
CVE-2016-1828P3HIGHCVSS 7.8PoCfixed in 9.2.12016-05-20
CVE-2016-1828 [HIGH] CVE-2016-1828: The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2 The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1827, CVE-2016-1829, and CVE-2016-1830.
nvdapple
CVE-2016-1827P3HIGHCVSS 7.8PoCfixed in 9.2.12016-05-20
CVE-2016-1827 [HIGH] CWE-119 CVE-2016-1827: The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2 The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1828, CVE-2016-1829, and CVE-2016-1830.
nvdapple
CVE-2017-2367P3MEDIUMCVSS 6.5PoC≤ 10.1.12017-04-02
CVE-2017-2367 [MEDIUM] CVE-2017-2367: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
nvdapple
CVE-2017-2479P3MEDIUMCVSS 6.5PoCfixed in 10.22017-04-02
CVE-2017-2479 [MEDIUM] CWE-20 CVE-2017-2479: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affected. iTunes before 12.6 on Windows is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive inf
nvdapple
CVE-2017-7089P3MEDIUMCVSS 6.1PoC≤ 10.2.22017-10-23
CVE-2017-7089 [MEDIUM] CWE-79 CVE-2017-7089: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that is mishandled during parent-tab processing.
nvd
CVE-2016-1803P3HIGHCVSS 7.8PoCfixed in 9.2.12016-05-20
CVE-2016-1803 [HIGH] CWE-476 CVE-2016-1803: CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2. CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.
nvdapple
CVE-2016-1755P3HIGHCVSS 7.8PoCfixed in 9.22016-03-24
CVE-2016-1755 [HIGH] CVE-2016-1755: The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 all The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1754.
nvdapple
CVE-2016-1813P3HIGHCVSS 7.8PoCfixed in 9.2.12016-05-20
CVE-2016-1813 [HIGH] CWE-476 CVE-2016-1813: The IOAccelSharedUserClient2::page_off_resource method in Apple iOS before 9.3.2, OS X before 10.11. The IOAccelSharedUserClient2::page_off_resource method in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.
nvdapple
CVE-2019-6205P3HIGHCVSS 7.8PoCfixed in 12.1.2≥ unspecified, < tvOS 12.1.22019-03-05
CVE-2019-6205 [HIGH] CWE-787 CVE-2019-6205: A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iO A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A malicious application may cause unexpected changes in memory shared between processes.
nvdapple
CVE-2019-8514P3HIGHCVSS 7.8PoCfixed in 12.2≥ unspecified, < tvOS 12.22019-12-18
CVE-2019-8514 [HIGH] CVE-2019-8514: A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS M A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. An application may be able to gain elevated privileges.
nvdapple
Apple tvOS vulnerabilities | cvebase