Apple tvOS vulnerabilities
2,371 known vulnerabilities affecting apple/tvos.
Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL174HIGH1277MEDIUM858LOW59UNKNOWN3
Vulnerabilities
Page 23 of 119
CVE-2016-4609P3CRITICALCVSS 9.8fixed in 9.2.22016-07-22
CVE-2016-4609 [CRITICAL] CVE-2016-4609: libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud befo
libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4607, CVE-2016-460
nvdapple
CVE-2016-4607P3CRITICALCVSS 9.8fixed in 9.2.22016-07-22
CVE-2016-4607 [CRITICAL] CWE-119 CVE-2016-4607: libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud befo
libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4608, CVE-
nvdapple
CVE-2016-4610P3CRITICALCVSS 9.8v9.2.22016-07-18
CVE-2016-4610 [CRITICAL] CVE-2016-4610: tvOS 9.2.2
Apple Security Update: About the security content of tvOS 9.2.2
Product: tvOS
Version: 9.2.2
CVE: CVE-2016-4610
Component: Kernel
Impact: A local user may be able to cause a system denial of service
Description: A null pointer dereference was addressed through improved input validation.
apple
CVE-2016-4608P3CRITICALCVSS 9.8v9.2.22016-07-18
CVE-2016-4608 [CRITICAL] CVE-2016-4608: tvOS 9.2.2
Apple Security Update: About the security content of tvOS 9.2.2
Product: tvOS
Version: 9.2.2
CVE: CVE-2016-4608
Component: Kernel
Impact: A local user may be able to cause a system denial of service
Description: A null pointer dereference was addressed through improved input validation.
apple
CVE-2022-42795P3HIGHCVSS 8.8fixed in 16.02022-11-01
CVE-2022-42795 [HIGH] CWE-787 CVE-2022-42795: A memory consumption issue was addressed with improved memory handling. This issue is fixed in tvOS
A memory consumption issue was addressed with improved memory handling. This issue is fixed in tvOS 16, iOS 16, macOS Ventura 13, watchOS 9. Processing a maliciously crafted image may lead to arbitrary code execution.
nvdapple
CVE-2022-22624P3HIGHCVSS 8.8≥ unspecified, < 15.4≥ unspecified, < 12.32022-09-23
CVE-2022-22624 [HIGH] CWE-416 CVE-2022-22624: A use after free issue was addressed with improved memory management. This issue is fixed in macOS M
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.3, iOS 15.4 and iPadOS 15.4, tvOS 15.4, Safari 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2023-42950P3HIGHCVSS 8.8fixed in 17.2≥ unspecified, < 17.22024-03-28
CVE-2023-42950 [HIGH] CWE-416 CVE-2023-42950: A use after free issue was addressed with improved memory management. This issue is fixed in Safari
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2020-3878P3HIGHCVSS 7.8fixed in 13.4.5≥ unspecified, < tvOS 13.4.52020-02-27
CVE-2020-3878 [HIGH] CWE-125 CVE-2020-3878: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.5
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2019-6203P3CRITICALCVSS 9.8fixed in 12.2≥ unspecified, < tvOS 12.22020-04-17
CVE-2019-6203 [CRITICAL] CVE-2019-6203: A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS M
A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2. An attacker in a privileged network position may be able to intercept network traffic.
nvdapple
CVE-2024-27859P3HIGHCVSS 8.8fixed in 17.42025-02-10
CVE-2024-27859 [HIGH] CWE-94 CVE-2024-27859: The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing web content may lead to arbitrary code execution.
nvdapple
CVE-2023-42970P3HIGHCVSS 8.8fixed in 17.0≥ unspecified, < 172025-04-11
CVE-2023-42970 [HIGH] CWE-416 CVE-2023-42970: A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17, Safari 17. Processing web content may lead to arbitrary code execution.
nvdapple
CVE-2017-2519P3CRITICALCVSS 9.8fixed in 10.2.12017-05-22
CVE-2017-2519 [CRITICAL] CVE-2017-2519: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a craf
nvdapple
CVE-2017-7103P3CRITICALCVSS 9.8≤ 10.2.22017-10-23
CVE-2017-7103 [CRITICAL] CWE-119 CVE-2017-7103: An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affe
An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "Wi-Fi" component. It might allow remote attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via crafted Wi-Fi traffic.
nvdapple
CVE-2014-4461P3CRITICALCVSS 9.3≤ 7.0.1v6.0+8 more2014-11-18
CVE-2014-4461 [CRITICAL] CWE-20 CVE-2014-4461: The kernel in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly validate IOSharedDa
The kernel in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly validate IOSharedDataQueue object metadata, which allows attackers to execute arbitrary code in a privileged context via a crafted application.
nvd
CVE-2025-24230P3CRITICALCVSS 9.8fixed in 18.42025-03-31
CVE-2025-24230 [CRITICAL] CWE-125 CVE-2025-24230: An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. Playing a malicious audio file may lead to an unexpected app termination.
nvdapple
CVE-2025-24190P3CRITICALCVSS 9.8fixed in 18.42025-03-31
CVE-2025-24190 [CRITICAL] CWE-400 CVE-2025-24190: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory.
nvdapple
CVE-2016-1950P3HIGHCVSS 8.8≤ 9.12016-03-13
CVE-2016-1950 [HIGH] CWE-119 CVE-2016-1950: Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and
Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code via crafted ASN.1 data in an X.509 certificate.
nvdapple
CVE-2019-8527P3CRITICALCVSS 9.1fixed in 12.2≥ unspecified, < tvOS 12.22019-12-18
CVE-2019-8527 [CRITICAL] CWE-120 CVE-2019-8527: A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 12.2, macO
A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.
nvdapple
CVE-2016-4448P3CRITICALCVSS 9.8≤ 9.2.12016-06-09
CVE-2016-4448 [CRITICAL] CWE-134 CVE-2016-4448: Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
nvdapple
CVE-2025-43234P3CRITICALCVSS 9.8fixed in 18.62025-07-30
CVE-2025-43234 [CRITICAL] CWE-20 CVE-2025-43234: Multiple memory corruption issues were addressed with improved input validation. This issue is fixed
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing a maliciously crafted texture may lead to unexpected app termination.
nvdapple