cbcvebase.

Apple tvOS vulnerabilities

2,371 known vulnerabilities affecting apple/tvos.

Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL149HIGH1258MEDIUM837LOW59UNKNOWN68

Vulnerabilities

Page 12 of 119
CVE-2019-8717P3HIGHCVSS 7.8PoCfixed in 13≥ unspecified, < tvOS 132019-12-18
CVE-2019-8717 [HIGH] CWE-787 CVE-2019-8717: A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15, tvOS 13. An application may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2017-2480P3MEDIUMCVSS 6.5PoCv10.22017-03-27
CVE-2017-2480 [MEDIUM] CVE-2017-2480: tvOS 10.2 Apple Security Update: About the security content of tvOS 10.2 Product: tvOS Version: 10.2 CVE: CVE-2017-2480 Component: WebKit Impact: Processing maliciously crafted web content may exfiltrate data cross-origin Description: A validation issue existed in element handling. This issue was addressed through improved validation.
apple
CVE-2019-8600P2CRITICALCVSS 9.8fixed in 12.3≥ unspecified, < tvOS 12.32019-12-18
CVE-2019-8600 [CRITICAL] CWE-89 CVE-2019-8600: A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 1 A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. A maliciously crafted SQL query may lead to arbitrary code execution.
nvdapple
CVE-2019-8718P3HIGHCVSS 7.8PoCfixed in 13≥ unspecified, < 132020-10-27
CVE-2019-8718 [HIGH] CWE-787 CVE-2019-8718: A memory corruption issue was addressed with improved memory handling. This issue is fixed in watchO A memory corruption issue was addressed with improved memory handling. This issue is fixed in watchOS 6, iOS 13, tvOS 13. An application may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2018-4435P3HIGHCVSS 7.8PoCfixed in 12.1.12019-04-03
CVE-2018-4435 [HIGH] CWE-20 CVE-2018-4435: A logic issue was addressed with improved restrictions. This issue affected versions prior to iOS 12 A logic issue was addressed with improved restrictions. This issue affected versions prior to iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2.
nvdapple
CVE-2017-2478P3HIGHCVSS 7.0PoC≤ 10.1.12017-04-02
CVE-2017-2478 [HIGH] CWE-362 CVE-2017-2478: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvdapple
CVE-2016-1719P3HIGHCVSS 7.8PoC≤ 9.12016-02-01
CVE-2016-1719 [HIGH] CWE-119 CVE-2016-1719: The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows loc The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvdapple
CVE-2019-8649P3MEDIUMCVSS 6.1PoCfixed in 12.4≥ unspecified, < tvOS 12.42019-12-18
CVE-2019-8649 [MEDIUM] CWE-79 CVE-2019-8649: A logic issue existed in the handling of synchronous page loads. This issue was addressed with impro A logic issue existed in the handling of synchronous page loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to universal cross sit
nvdapple
CVE-2015-7068P3HIGHCVSS 7.8PoCfixed in 9.12015-12-11
CVE-2015-7068 [HIGH] CWE-476 CVE-2015-7068: IOKit SCSI in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 all IOKit SCSI in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via an app that provides an unspecified userclient type.
nvdapple
CVE-2018-4240P3MEDIUMCVSS 6.5PoCfixed in 11.42018-06-08
CVE-2018-4240 [MEDIUM] CWE-20 CVE-2018-4240: An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "Messages" component. It allows remote attackers to cause a denial of service via a crafted message.
nvdapple
CVE-2017-2456P3HIGHCVSS 7.0PoC≤ 10.1.12017-04-02
CVE-2017-2456 [HIGH] CWE-362 CVE-2017-2456: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvdapple
CVE-2017-2501P3HIGHCVSS 7.0PoCfixed in 10.2.12017-05-22
CVE-2017-2501 [HIGH] CWE-362 CVE-2017-2501: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "Kernel" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvdapple
CVE-2018-4280P3HIGHCVSS 7.8PoCfixed in 11.4.12019-04-03
CVE-2018-4280 [HIGH] CWE-119 CVE-2018-4280: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2.
nvdapple
CVE-2016-7621P3HIGHCVSS 7.8PoCv10.12016-12-12
CVE-2016-7621 [HIGH] CVE-2016-7621: tvOS 10.1 Apple Security Update: About the security content of tvOS 10.1 Product: tvOS Version: 10.1 CVE: CVE-2016-7621 Component: Kernel Impact: A local user may be able to cause an unexpected system termination or arbitrary code execution in the kernel Description: A use after free issue was addressed through improved memory management.
apple
CVE-2018-4407P2HIGHCVSS 8.8fixed in 122019-04-03
CVE-2018-4407 [HIGH] CWE-119 CVE-2018-4407: A memory corruption issue was addressed with improved validation. This issue affected versions prior A memory corruption issue was addressed with improved validation. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
nvdapple
CVE-2016-1720P3HIGHCVSS 7.8PoCfixed in 9.1.12016-02-01
CVE-2016-1720 [HIGH] CWE-119 CVE-2016-1720: IOKit in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to ga IOKit in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvdapple
CVE-2016-1721P3HIGHCVSS 7.8PoCfixed in 9.1.12016-02-01
CVE-2016-1721 [HIGH] CWE-119 CVE-2016-1721: The kernel in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users The kernel in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvdapple
CVE-2019-8690P3MEDIUMCVSS 6.1PoCfixed in 12.4≥ unspecified, < tvOS 12.42019-12-18
CVE-2019-8690 [MEDIUM] CWE-79 CVE-2019-8690: A logic issue existed in the handling of document loads. This issue was addressed with improved stat A logic issue existed in the handling of document loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to universal cross site script
nvdapple
CVE-2017-2445P3MEDIUMCVSS 6.1PoC≤ 10.1.12017-04-02
CVE-2017-2445 [MEDIUM] CWE-79 CVE-2017-2445: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via crafted frame objects.
nvdapple
CVE-2017-2504P3MEDIUMCVSS 6.1PoCfixed in 10.2.12017-05-22
CVE-2017-2504 [MEDIUM] CWE-79 CVE-2017-2504: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with WebKit Editor commands.
nvdapple
Apple tvOS vulnerabilities | cvebase