cbcvebase.

Apple tvOS vulnerabilities

2,371 known vulnerabilities affecting apple/tvos.

Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL149HIGH1258MEDIUM837LOW59UNKNOWN68

Vulnerabilities

Page 18 of 119
CVE-2021-30852P3HIGHCVSS 8.8fixed in 15.0≥ unspecified, < 152021-08-24
CVE-2021-30852 [HIGH] CWE-843 CVE-2021-30852: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2024-23226P3HIGHCVSS 8.8fixed in 17.42024-03-08
CVE-2024-23226 [HIGH] CWE-787 CVE-2024-23226: The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17 The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing web content may lead to arbitrary code execution.
nvdapple
CVE-2022-32912P3HIGHCVSS 8.8v162022-09-12
CVE-2022-32912 [HIGH] CVE-2022-32912: tvOS 16 Apple Security Update: About the security content of tvOS 16 Product: tvOS Version: 16 CVE: CVE-2022-32912 Component: WebKit Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: An out-of-bounds read was addressed with improved bounds checking.
apple
CVE-2024-27808P3HIGHCVSS 8.8fixed in 17.52024-06-10
CVE-2024-27808 [HIGH] CWE-786 CVE-2024-27808: The issue was addressed with improved memory handling. This issue is fixed in Safari 17.5, iOS 17.5 The issue was addressed with improved memory handling. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing web content may lead to arbitrary code execution.
nvdapple
CVE-2017-2520P3CRITICALCVSS 9.8fixed in 10.2.12017-05-22
CVE-2017-2520 [CRITICAL] CWE-787 CVE-2017-2520: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via
nvdapple
CVE-2023-38592P3HIGHCVSS 8.8fixed in 16.6≥ unspecified, < 16.62023-07-28
CVE-2023-38592 [HIGH] CVE-2023-38592: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16.6 and iPadOS 1 A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16.6 and iPadOS 16.6, watchOS 9.6, tvOS 16.6, macOS Ventura 13.5. Processing web content may lead to arbitrary code execution.
nvdapple
CVE-2022-26719P3HIGHCVSS 8.8fixed in 15.52022-11-01
CVE-2022-26719 [HIGH] CWE-787 CVE-2022-26719: A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4, Safari 15.5. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2022-26716P3HIGHCVSS 8.8fixed in 15.52022-11-01
CVE-2022-26716 [HIGH] CWE-787 CVE-2022-26716: A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4, Safari 15.5. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2024-27833P3HIGHCVSS 8.8fixed in 17.52024-06-10
CVE-2024-27833 [HIGH] CWE-190 CVE-2024-27833: An integer overflow was addressed with improved input validation. This issue is fixed in Safari 17.5 An integer overflow was addressed with improved input validation. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, tvOS 17.5, visionOS 1.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2017-7112P3CRITICALCVSS 9.8≤ 10.2.22017-10-23
CVE-2017-7112 [CRITICAL] CWE-119 CVE-2017-7112: An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affe An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "Wi-Fi" component. It might allow remote attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via crafted Wi-Fi traffic.
nvdapple
CVE-2017-7108P3CRITICALCVSS 9.8≤ 10.2.22017-10-23
CVE-2017-7108 [CRITICAL] CWE-119 CVE-2017-7108: An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affe An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "Wi-Fi" component. It might allow remote attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via crafted Wi-Fi traffic.
nvdapple
CVE-2017-7110P3CRITICALCVSS 9.8≤ 10.2.22017-10-23
CVE-2017-7110 [CRITICAL] CWE-119 CVE-2017-7110: An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affe An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "Wi-Fi" component. It might allow remote attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via crafted Wi-Fi traffic.
nvdapple
CVE-2017-7105P3CRITICALCVSS 9.8≤ 10.2.22017-10-23
CVE-2017-7105 [CRITICAL] CWE-119 CVE-2017-7105: An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affe An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "Wi-Fi" component. It might allow remote attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via crafted Wi-Fi traffic.
nvdapple
CVE-2021-1864P3CRITICALCVSS 9.8fixed in 14.5≥ unspecified, < 14.52021-09-08
CVE-2021-1864 [CRITICAL] CWE-416 CVE-2021-1864: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14. A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. An attacker with JavaScript execution may be able to execute arbitrary code.
nvd
CVE-2011-2895P3CRITICALCVSS 9.3v9.1
CVE-2011-2895 [CRITICAL] CVE-2011-2895: tvOS 9.1 Apple Security Update: About the security content of tvOS 9.1 Product: tvOS Version: 9.1 CVE: CVE-2011-2895 Component: CVE-ID Impact: Processing a maliciously crafted package may lead to arbitrary code execution Description: Multiple buffer overflows existed in the C standard library. These issues were addressed through improved bounds checking.
apple
CVE-2023-40414P3CRITICALCVSS 9.8fixed in 17.0≥ unspecified, < 172024-01-10
CVE-2023-40414 [CRITICAL] CWE-416 CVE-2023-40414: A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 10, iOS 17 and iPadOS 17, tvOS 17, macOS Sonoma 14, Safari 17. Processing web content may lead to arbitrary code execution.
nvdapple
CVE-2020-3868P3HIGHCVSS 8.8fixed in 13.3.1≥ unspecified, < tvOS 13.3.12020-02-27
CVE-2020-3868 [HIGH] CWE-787 CVE-2020-3868: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8814P3HIGHCVSS 8.8fixed in 13.2≥ unspecified, < tvOS 13.22019-12-18
CVE-2019-8814 [HIGH] CWE-787 CVE-2019-8814: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2020-9789P3HIGHCVSS 8.8fixed in 13.4.5≥ unspecified, < tvOS 13.4.52020-06-09
CVE-2020-9789 [HIGH] CWE-787 CVE-2020-9789: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2020-9790P3HIGHCVSS 8.8fixed in 13.4.5≥ unspecified, < tvOS 13.4.52020-06-09
CVE-2020-9790 [HIGH] CWE-787 CVE-2020-9790: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
Apple tvOS vulnerabilities | cvebase