cbcvebase.

Apple tvOS vulnerabilities

2,371 known vulnerabilities affecting apple/tvos.

Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL174HIGH1277MEDIUM858LOW59UNKNOWN3

Vulnerabilities

Page 21 of 119
CVE-2023-23517P3HIGHCVSS 8.8fixed in 16.3≥ unspecified, < 16.32023-02-27
CVE-2023-23517 [HIGH] CWE-119 CVE-2023-23517: The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.3, The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.3, macOS Ventura 13.2, watchOS 9.3, macOS Big Sur 11.7.3, Safari 16.3, tvOS 16.3, iOS 16.3 and iPadOS 16.3. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2018-4331P3CRITICALCVSS 9.8fixed in 122019-04-03
CVE-2018-4331 [CRITICAL] CWE-119 CVE-2018-4331: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
nvdapple
CVE-2022-26710P3HIGHCVSS 8.8fixed in 15.52022-11-01
CVE-2022-26710 [HIGH] CWE-416 CVE-2022-26710: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 15. A use after free issue was addressed with improved memory management. This issue is fixed in iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, tvOS 15.5, watchOS 8.6. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2022-26709P3HIGHCVSS 8.8fixed in 15.52022-11-01
CVE-2022-26709 [HIGH] CWE-416 CVE-2022-26709: A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15 A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4, Safari 15.5. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2024-27851P3HIGHCVSS 8.8fixed in 17.52024-06-10
CVE-2024-27851 [HIGH] CWE-119 CVE-2024-27851: The issue was addressed with improved bounds checks. This issue is fixed in Safari 17.5, iOS 17.5 an The issue was addressed with improved bounds checks. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2026-43715P3HIGHCVSS 8.8fixed in 26.62026-06-29
CVE-2026-43715 [HIGH] CWE-416 CVE-2026-43715: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.
nvd
CVE-2023-42866P3HIGHCVSS 8.8fixed in 16.6≥ unspecified, < 16.62024-01-10
CVE-2023-42866 [HIGH] CVE-2023-42866: The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.5, iO The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, tvOS 16.6, Safari 16.6, watchOS 9.6. Processing web content may lead to arbitrary code execution.
nvdapple
CVE-2024-54499P3HIGHCVSS 8.8fixed in 18.22025-01-27
CVE-2024-54499 [HIGH] CWE-416 CVE-2024-54499: A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18. A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2021-30993P3HIGHCVSS 8.1fixed in 15.22021-08-24
CVE-2021-30993 [HIGH] CWE-120 CVE-2021-30993: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Mo A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.1, watchOS 8.3, iOS 15.2 and iPadOS 15.2, tvOS 15.2. An attacker in a privileged network position may be able to execute arbitrary code.
nvdapple
CVE-2014-4488P3CRITICALCVSS 10.0≤ 7.0.12015-01-30
CVE-2014-4488 [CRITICAL] CWE-19 CVE-2014-4488: IOHIDFamily in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not IOHIDFamily in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not properly validate resource-queue metadata, which allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2017-7092P3HIGHCVSS 8.8≤ 10.2.22017-10-23
CVE-2017-7092 [HIGH] CWE-119 CVE-2017-7092: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory c
nvdapple
CVE-2019-6235P3CRITICALCVSS 10.0≥ unspecified, < tvOS 12.1.22019-03-04
CVE-2019-6235 [CRITICAL] CWE-787 CVE-2019-6235: A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3, iTunes 12.9.3 for Windows. A sandboxed process may be able to circumvent sandbox restrictions.
nvdapple
CVE-2024-56171P3HIGHCVSS 7.8v18.42025-03-31
CVE-2024-56171 [HIGH] CVE-2024-56171: tvOS 18.4 Apple Security Update: About the security content of tvOS 18.4 Product: tvOS Version: 18.4 CVE: CVE-2024-56171 Component: CVE-2024-56171 Impact: An app may be able to break out of its sandbox Description: This issue was addressed through improved state management.
apple
CVE-2019-5608P3CRITICALCVSS 9.8v12.22019-03-25
CVE-2019-5608 [CRITICAL] CVE-2019-5608: tvOS 12.2 Apple Security Update: About the security content of tvOS 12.2 Product: tvOS Version: 12.2 CVE: CVE-2019-5608 Component: Kernel Impact: A remote attacker may be able to alter network traffic data Description: A memory corruption issue existed in the handling of IPv6 packets. This issue was addressed with improved memory management.
apple
CVE-2020-3911P3CRITICALCVSS 9.8fixed in 13.4≥ unspecified, < tvOS 13.42020-04-01
CVE-2020-3911 [CRITICAL] CWE-120 CVE-2020-3911: A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 13.4 and i A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Multiple issues in libxml2.
nvd
CVE-2020-3910P3CRITICALCVSS 9.8fixed in 13.4≥ unspecified, < tvOS 13.42020-04-01
CVE-2020-3910 [CRITICAL] CWE-120 CVE-2020-3910: A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 13.4 and i A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Multiple issues in libxml2.
nvd
CVE-2024-54534P3CRITICALCVSS 9.8fixed in 18.22024-12-12
CVE-2024-54534 [CRITICAL] CWE-787 CVE-2024-54534: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.6, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to memory corruption.
nvd
CVE-2017-2415P3HIGHCVSS 8.8≤ 10.1.12017-04-02
CVE-2017-2415 [HIGH] CVE-2017-2415: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code by leveraging an unspecified "type confusion."
nvdapple
CVE-2020-9893P3HIGHCVSS 8.8fixed in 13.4.8≥ unspecified, < tvOS 13.4.82020-10-16
CVE-2020-9893 [HIGH] CWE-416 CVE-2020-9893: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13. A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
nvdapple
CVE-2020-9951P3HIGHCVSS 8.8fixed in 14.02020-10-16
CVE-2020-9951 [HIGH] CWE-416 CVE-2020-9951: A use after free issue was addressed with improved memory management. This issue is fixed in Safari A use after free issue was addressed with improved memory management. This issue is fixed in Safari 14.0. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
Apple tvOS vulnerabilities | cvebase