cbcvebase.

Apple tvOS vulnerabilities

2,371 known vulnerabilities affecting apple/tvos.

Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL174HIGH1277MEDIUM858LOW59UNKNOWN3

Vulnerabilities

Page 32 of 119
CVE-2016-0802P3HIGHCVSS 8.8≤ 9.12016-02-07
CVE-2016-0802 [HIGH] CWE-20 CVE-2016-0802: The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6. The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted wireless control message packets, aka internal bug 25306181.
nvdapple
CVE-2019-8524P3HIGHCVSS 8.8fixed in 12.2≥ unspecified, < tvOS 12.22019-12-18
CVE-2019-8524 [HIGH] CWE-787 CVE-2019-8524: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2017-2530P3HIGHCVSS 8.8≤ 10.22017-05-22
CVE-2017-2530 [HIGH] CWE-119 CVE-2017-2530: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. iCloud before 6.2.1 on Windows is affected. tvOS before 10.2.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application cra
nvdapple
CVE-2017-2525P3HIGHCVSS 8.8≤ 10.22017-05-22
CVE-2017-2525 [HIGH] CWE-119 CVE-2017-2525: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
nvdapple
CVE-2017-2505P3HIGHCVSS 8.8fixed in 10.2.12017-05-22
CVE-2017-2505 [HIGH] CWE-119 CVE-2017-2505: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
nvdapple
CVE-2020-9783P3HIGHCVSS 8.8fixed in 13.4≥ unspecified, < tvOS 13.42020-04-01
CVE-2020-9783 [HIGH] CWE-416 CVE-2020-9783: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13. A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Processing maliciously crafted web content may lead to code execution.
nvd
CVE-2019-8638P3HIGHCVSS 8.8v12.22019-03-25
CVE-2019-8638 [HIGH] CVE-2019-8638: tvOS 12.2 Apple Security Update: About the security content of tvOS 12.2 Product: tvOS Version: 12.2 CVE: CVE-2019-8638 Component: WebKit Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2019-8639P3HIGHCVSS 8.8v12.22019-03-25
CVE-2019-8639 [HIGH] CVE-2019-8639: tvOS 12.2 Apple Security Update: About the security content of tvOS 12.2 Product: tvOS Version: 12.2 CVE: CVE-2019-8639 Component: WebKit Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2022-26763P3HIGHCVSS 7.8fixed in 15.52022-05-26
CVE-2022-26763 [HIGH] CWE-119 CVE-2022-26763: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in tv An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 Catalina, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. A malicious application may be able to execute arbitrary code with system privileges.
nvdapple
CVE-2014-1357P3CRITICALCVSS 10.0≤ 6.1.1v6.0+3 more2014-07-01
CVE-2014-1357 [CRITICAL] CWE-119 CVE-2014-1357: Heap-based buffer overflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple Heap-based buffer overflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 allows attackers to execute arbitrary code via a crafted application that generates log messages.
nvd
CVE-2017-13849P4MEDIUMCVSS 5.5PoCfixed in 11.12017-11-13
CVE-2017-13849 [MEDIUM] CWE-20 CVE-2017-13849: An issue was discovered in certain Apple products. iOS before 11.1 is affected. tvOS before 11.1 is An issue was discovered in certain Apple products. iOS before 11.1 is affected. tvOS before 11.1 is affected. watchOS before 4.1 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service (application crash) via a crafted text file.
nvdapple
CVE-2016-7663P3CRITICALCVSS 9.8v10.12016-12-12
CVE-2016-7663 [CRITICAL] CVE-2016-7663: tvOS 10.1 Apple Security Update: About the security content of tvOS 10.1 Product: tvOS Version: 10.1 CVE: CVE-2016-7663 Component: CoreFoundation Impact: Processing malicious strings may lead to an unexpected application termination or arbitrary code execution Description: A memory corruption issue existed in the processing of strings. This issue was addressed through improved bounds checking.
apple
CVE-2017-9233P3HIGHCVSS 7.5v112017-09-19
CVE-2017-9233 [HIGH] CVE-2017-9233: tvOS 11 Apple Security Update: About the security content of tvOS 11 Product: tvOS Version: 11 CVE: CVE-2017-9233 Component: CVE-2017-9233 Impact: Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution Description: A use after free issue was addressed with improved memory management.
apple
CVE-2021-30849P3HIGHCVSS 7.8fixed in 15.0≥ unspecified, < 152021-10-19
CVE-2021-30849 [HIGH] CWE-787 CVE-2021-30849: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, watchOS 8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, iTunes 12.12 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2018-16860P3HIGHCVSS 7.5v12.42019-07-22
CVE-2018-16860 [HIGH] CVE-2018-16860: tvOS 12.4 Apple Security Update: About the security content of tvOS 12.4 Product: tvOS Version: 12.4 CVE: CVE-2018-16860 Component: Heimdal Impact: An issue existed in Samba that may allow attackers to perform unauthorized actions by intercepting communications between services Description: This issue was addressed with improved checks to prevent unauthorized actions.
apple
CVE-2018-4332P3CRITICALCVSS 9.8fixed in 122019-04-03
CVE-2018-4332 [CRITICAL] CWE-119 CVE-2018-4332: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
nvdapple
CVE-2019-8756P3CRITICALCVSS 9.8fixed in 13≥ unspecified, < 132020-10-27
CVE-2019-8756 [CRITICAL] CWE-787 CVE-2019-8756: Multiple memory corruption issues were addressed with improved input validation. This issue is fixed Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Catalina 10.15, iOS 13, iCloud for Windows 7.14, iCloud for Windows 10.7, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, watchOS 6, iTunes 12.10.1 for Windows. Multiple issues in libxml2.
nvdapple
CVE-2019-8749P3CRITICALCVSS 9.8fixed in 13≥ unspecified, < 132020-10-27
CVE-2019-8749 [CRITICAL] CWE-787 CVE-2019-8749: Multiple memory corruption issues were addressed with improved input validation. This issue is fixed Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Catalina 10.15, iOS 13, iCloud for Windows 7.14, iCloud for Windows 10.7, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, watchOS 6, iTunes 12.10.1 for Windows. Multiple issues in libxml2.
nvdapple
CVE-2022-22641P3CRITICALCVSS 9.8fixed in 15.4≥ unspecified, < 15.42022-03-18
CVE-2022-22641 [CRITICAL] CWE-416 CVE-2022-22641: A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15 A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3. An application may be able to gain elevated privileges.
nvdapple
CVE-2025-30426P3CRITICALCVSS 9.8fixed in 18.42025-03-31
CVE-2025-30426 [CRITICAL] CWE-200 CVE-2025-30426: This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPa This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to enumerate a user's installed apps.
nvdapple
Apple tvOS vulnerabilities | cvebase