cbcvebase.

Apple tvOS vulnerabilities

2,371 known vulnerabilities affecting apple/tvos.

Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL149HIGH1258MEDIUM837LOW59UNKNOWN68

Vulnerabilities

Page 13 of 119
CVE-2017-5754P3MEDIUMCVSS 5.6v11.22017-12-04
CVE-2017-5754 [MEDIUM] CVE-2017-5754: tvOS 11.2 Apple Security Update: About the security content of tvOS 11.2 Product: tvOS Version: 11.2 CVE: CVE-2017-5754 Component: Kernel Impact: An application may be able to read kernel memory (Meltdown) Description: Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.
apple
CVE-2017-6979P3HIGHCVSS 7.0PoC≤ 10.22017-05-22
CVE-2017-6979 [HIGH] CWE-362 CVE-2017-6979: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "IOSurface" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvdapple
CVE-2016-1863P3HIGHCVSS 7.8PoCfixed in 9.2.22016-07-22
CVE-2016-1863 [HIGH] CWE-416 CVE-2016-1863: The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2 The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4582 and CVE-2016-4653.
nvdapple
CVE-2016-7661P3HIGHCVSS 7.8PoCv10.12016-12-12
CVE-2016-7661 [HIGH] CVE-2016-7661: tvOS 10.1 Apple Security Update: About the security content of tvOS 10.1 Product: tvOS Version: 10.1 CVE: CVE-2016-7661 Component: Power Management Impact: A local user may be able to gain root privileges Description: An issue in mach port name references was addressed through improved validation.
apple
CVE-2016-7637P3HIGHCVSS 7.8PoCv10.12016-12-12
CVE-2016-7637 [HIGH] CVE-2016-7637: tvOS 10.1 Apple Security Update: About the security content of tvOS 10.1 Product: tvOS Version: 10.1 CVE: CVE-2016-7637 Component: Kernel Impact: A local user may be able to gain root privileges Description: A memory corruption issue was addressed through improved input validation.
apple
CVE-2016-7660P3HIGHCVSS 7.8PoCv10.12016-12-12
CVE-2016-7660 [HIGH] CVE-2016-7660: tvOS 10.1 Apple Security Update: About the security content of tvOS 10.1 Product: tvOS Version: 10.1 CVE: CVE-2016-7660 Component: Security Impact: Certificates may be unexpectedly evaluated as trusted Description: A certificate evaluation issue existed in certificate validation. This issue was addressed through additional validation of certificates.
apple
CVE-2019-8591P3HIGHCVSS 7.1PoCfixed in 12.3≥ unspecified, < tvOS 12.32019-12-18
CVE-2019-8591 [HIGH] CWE-843 CVE-2019-8591: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.3, A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. An application may be able to cause unexpected system termination or write kernel memory.
nvdapple
CVE-2020-9839P3HIGHCVSS 7.0PoCfixed in 13.4.5≥ unspecified, < tvOS 13.4.52020-06-09
CVE-2020-9839 [HIGH] CWE-362 CVE-2020-9839: A race condition was addressed with improved state handling. This issue is fixed in iOS 13.5 and iPa A race condition was addressed with improved state handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. An application may be able to gain elevated privileges.
nvd
CVE-2023-38604P3CRITICALCVSS 9.8fixed in 16.6≥ unspecified, < 16.62023-07-28
CVE-2023-38604 [CRITICAL] CWE-787 CVE-2023-38604: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in wa An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in watchOS 9.6, macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Monterey 12.6.8, tvOS 16.6, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2014-1287P3HIGHCVSS 7.2PoC≤ 6.0.2v6.0+1 more2014-03-14
CVE-2014-1287 [HIGH] CWE-119 CVE-2014-1287: USB Host in Apple iOS before 7.1 and Apple TV before 6.1 allows physically proximate attackers to ex USB Host in Apple iOS before 7.1 and Apple TV before 6.1 allows physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted USB messages.
nvd
CVE-2016-4622P3HIGHCVSS 8.8fixed in 9.2.22016-07-22
CVE-2016-4622 [HIGH] CVE-2016-4622: WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4589, CVE-2016-4623, and CVE-2016-4624.
nvdapple
CVE-2022-26711P3CRITICALCVSS 9.8fixed in 15.52022-05-26
CVE-2022-26711 [CRITICAL] CWE-190 CVE-2022-26711: An integer overflow issue was addressed with improved input validation. This issue is fixed in tvOS An integer overflow issue was addressed with improved input validation. This issue is fixed in tvOS 15.5, iTunes 12.12.4 for Windows, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
nvdapple
CVE-2022-32839P3CRITICALCVSS 9.8fixed in 15.6≥ unspecified, < 15.62022-08-24
CVE-2022-32839 [CRITICAL] CWE-119 CVE-2022-32839: The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.5, mac The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6, tvOS 15.6, watchOS 8.7. A remote user may cause an unexpected app termination or arbitrary code execution.
nvdapple
CVE-2018-20346P3HIGHCVSS 8.1v12.1.22019-01-22
CVE-2018-20346 [HIGH] CVE-2018-20346: tvOS 12.1.2 Apple Security Update: About the security content of tvOS 12.1.2 Product: tvOS Version: 12.1.2 CVE: CVE-2018-20346 Component: SQLite Impact: A maliciously crafted SQL query may lead to arbitrary code execution Description: Multiple memory corruption issues were addressed with improved input validation.
apple
CVE-2015-7084P3HIGHCVSS 7.2PoC≤ 9.02015-12-11
CVE-2015-7084 [HIGH] CVE-2015-7084: The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 all The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-7083.
nvdapple
CVE-2020-9895P3CRITICALCVSS 9.8fixed in 13.4.8≥ unspecified, < tvOS 13.4.82020-10-16
CVE-2020-9895 [CRITICAL] CWE-416 CVE-2020-9895: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13. A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
nvdapple
CVE-2018-20506P3HIGHCVSS 8.1fixed in 12.1.22019-04-03
CVE-2018-20506 [HIGH] CVE-2018-20506: SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and result SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use ca
nvdapple
CVE-2022-42842P3CRITICALCVSS 9.8fixed in 16.2≥ unspecified, < 16.2+2 more2022-12-15
CVE-2022-42842 [CRITICAL] CWE-787 CVE-2022-42842: The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monte The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. A remote user may be able to cause kernel code execution.
nvd
CVE-2022-42808P3CRITICALCVSS 9.8fixed in 16.1≥ unspecified, < 16.12022-11-01
CVE-2022-42808 [CRITICAL] CWE-787 CVE-2022-42808: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvO An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. A remote user may be able to cause kernel code execution.
nvdapple
CVE-2023-32412P3CRITICALCVSS 9.8fixed in 16.5≥ unspecified, < 16.52023-06-23
CVE-2023-32412 [CRITICAL] CWE-416 CVE-2023-32412: A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. A remote attacker may be able to cause unexpected app termination or arbitrary code execution.
nvdapple
Apple tvOS vulnerabilities | cvebase