Apple tvOS vulnerabilities
2,227 known vulnerabilities affecting apple/tvos.
Total CVEs
2,227
CISA KEV
41
actively exploited
Public exploits
199
Exploited in wild
31
Severity breakdown
CRITICAL148HIGH1222MEDIUM795LOW59UNKNOWN3
Vulnerabilities
Page 36 of 112
CVE-2022-22662MEDIUMCVSS 6.5v15.42022-03-14
CVE-2022-22662 [MEDIUM] CVE-2022-22662: tvOS 15.4
Apple Security Update: About the security content of tvOS 15.4
Product: tvOS
Version: 15.4
CVE: CVE-2022-22662
Component: WebKit
Impact: Processing maliciously crafted web content may disclose sensitive user information
Description: A cookie management issue was addressed with improved state management.
apple
CVE-2022-26981HIGHCVSS 7.8fixed in 15.62022-03-13
CVE-2022-26981 [HIGH] CWE-120 CVE-2022-26981: Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (cal
Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (called, indirectly, by tools/lou_checktable.c).
nvdapple
CVE-2022-23308HIGHCVSS 7.5fixed in 15.52022-02-26
CVE-2022-23308 [HIGH] CWE-416 CVE-2022-23308: valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
nvdapple
CVE-2022-21658MEDIUMCVSS 6.3fixed in 15.42022-01-20
CVE-2022-21658 [MEDIUM] CWE-363 CVE-2022-21658: Rust is a multi-paradigm, general-purpose programming language designed for performance and safety,
Rust is a multi-paradigm, general-purpose programming language designed for performance and safety, especially safe concurrency. The Rust Security Response WG was notified that the `std::fs::remove_dir_all` standard library function is vulnerable a race condition enabling symlink following (CWE-363). An attacker could use this security issue to trick
nvdapple
CVE-2019-8703CRITICALCVSS 9.8≤ 13.0≥ unspecified, < 132021-12-23
CVE-2019-8703 [CRITICAL] CVE-2019-8703: This issue was addressed with improved entitlements. This issue is fixed in watchOS 6, tvOS 13, macO
This issue was addressed with improved entitlements. This issue is fixed in watchOS 6, tvOS 13, macOS Catalina 10.15, iOS 13. An application may be able to gain elevated privileges.
nvdapple
CVE-2017-13905HIGHCVSS 8.1fixed in 11.2≥ unspecified, < 11.22021-12-23
CVE-2017-13905 [HIGH] CWE-362 CVE-2017-13905: A race condition was addressed with additional validation. This issue is fixed in tvOS 11.2, iOS 11.
A race condition was addressed with additional validation. This issue is fixed in tvOS 11.2, iOS 11.2, macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan, watchOS 4.2. An application may be able to gain elevated privileges.
nvdapple
CVE-2019-8702MEDIUMCVSS 5.5fixed in 12.42021-12-23
CVE-2019-8702 [MEDIUM] CWE-668 CVE-2019-8702: This issue was addressed with a new entitlement. This issue is fixed in macOS Mojave 10.14.6, Securi
This issue was addressed with a new entitlement. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra, iOS 12.4, tvOS 12.4. A local user may be able to read a persistent account identifier.
nvdapple
CVE-2021-30949HIGHCVSS 7.8v15.22021-12-13
CVE-2021-30949 [HIGH] CVE-2021-30949: tvOS 15.2
Apple Security Update: About the security content of tvOS 15.2
Product: tvOS
Version: 15.2
CVE: CVE-2021-30949
Component: Kernel
Impact: A malicious application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed with improved state management.
apple
CVE-2021-31013MEDIUMCVSS 5.5v15.22021-12-13
CVE-2021-31013 [MEDIUM] CVE-2021-31013: tvOS 15.2
Apple Security Update: About the security content of tvOS 15.2
Product: tvOS
Version: 15.2
CVE: CVE-2021-31013
Component: FontParser
Impact: Processing a maliciously crafted font may result in the disclosure of process memory
Description: An out-of-bounds read was addressed with improved bounds checking.
apple
CVE-2021-30840HIGHCVSS 7.8fixed in 15.0≥ unspecified, < 152021-10-28
CVE-2021-30840 [HIGH] CVE-2021-30840: This issue was addressed with improved checks. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and
This issue was addressed with improved checks. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted dfont file may lead to arbitrary code execution.
nvdapple
CVE-2021-30818HIGHCVSS 8.8fixed in 15.0≥ unspecified, < 152021-10-28
CVE-2021-30818 [HIGH] CWE-843 CVE-2021-30818: A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.8 a
A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, iOS 15 and iPadOS 15, Safari 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2021-30814HIGHCVSS 7.8fixed in 15.0≥ unspecified, < 152021-10-28
CVE-2021-30814 [HIGH] CWE-787 CVE-2021-30814: A memory corruption issue was addressed with improved input validation. This issue is fixed in tvOS
A memory corruption issue was addressed with improved input validation. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted image may lead to arbitrary code execution.
nvdapple
CVE-2021-30809HIGHCVSS 8.8fixed in 15.0≥ unspecified, < 152021-10-28
CVE-2021-30809 [HIGH] CWE-416 CVE-2021-30809: A use after free issue was addressed with improved memory management. This issue is fixed in Safari
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 15, tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2021-30834HIGHCVSS 7.8fixed in 15.0≥ unspecified, < 152021-10-28
CVE-2021-30834 [HIGH] CVE-2021-30834: A logic issue was addressed with improved state management. This issue is fixed in iOS 14.8 and iPad
A logic issue was addressed with improved state management. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, iOS 15 and iPadOS 15, watchOS 8, Security Update 2021-007 Catalina. Processing a malicious audio file may result in unexpected application termination or arbitrary code execution.
nvdapple
CVE-2021-30823MEDIUMCVSS 6.5fixed in 15.0≥ unspecified, < 152021-10-28
CVE-2021-30823 [MEDIUM] CVE-2021-30823: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.0.1
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.0.1, iOS 14.8 and iPadOS 14.8, tvOS 15, Safari 15, watchOS 8. An attacker in a privileged network position may be able to bypass HSTS.
nvdapple
CVE-2021-30808MEDIUMCVSS 5.5fixed in 15.0≥ unspecified, < 152021-10-28
CVE-2021-30808 [MEDIUM] CVE-2021-30808: This issue was addressed with improved checks. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and
This issue was addressed with improved checks. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. A malicious application may be able to modify protected parts of the file system.
nvdapple
CVE-2021-30831MEDIUMCVSS 5.5fixed in 15.0≥ unspecified, < 152021-10-28
CVE-2021-30831 [MEDIUM] CWE-125 CVE-2021-30831: An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 15,
An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted font may result in the disclosure of process memory.
nvdapple
CVE-2021-30836MEDIUMCVSS 5.5fixed in 15.0≥ unspecified, < 152021-10-28
CVE-2021-30836 [MEDIUM] CWE-125 CVE-2021-30836: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.8
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted audio file may disclose restricted memory.
nvdapple
CVE-2021-30841HIGHCVSS 7.8fixed in 15.02021-10-19
CVE-2021-30841 [HIGH] CVE-2021-30841: This issue was addressed with improved checks. This issue is fixed in iOS 14.8 and iPadOS 14.8, macO
This issue was addressed with improved checks. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted dfont file may lead to arbitrary code execution.
nvdapple
CVE-2021-30846HIGHCVSS 7.8fixed in 15.0≥ unspecified, < 152021-10-19
CVE-2021-30846 [HIGH] CWE-787 CVE-2021-30846: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple