cbcvebase.

Apple tvOS vulnerabilities

2,371 known vulnerabilities affecting apple/tvos.

Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL174HIGH1277MEDIUM858LOW59UNKNOWN3

Vulnerabilities

Page 40 of 119
CVE-2016-1847P3HIGHCVSS 8.8fixed in 9.2.12016-05-20
CVE-2016-1847 [HIGH] CWE-119 CVE-2016-1847: OpenGL, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS befor OpenGL, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
nvdapple
CVE-2016-4584P3HIGHCVSS 8.8fixed in 9.2.22016-07-22
CVE-2016-4584 [HIGH] CWE-119 CVE-2016-4584: The WebKit Page Loading implementation in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS befo The WebKit Page Loading implementation in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
nvdapple
CVE-2018-4372P3HIGHCVSS 8.8fixed in 12.12019-04-03
CVE-2018-4372 [HIGH] CWE-119 CVE-2018-4372: Multiple memory corruption issues were addressed with improved memory handling. This issue affected Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, tvOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.
nvdapple
CVE-2016-7594P3HIGHCVSS 8.8v10.12016-12-12
CVE-2016-7594 [HIGH] CVE-2016-7594: tvOS 10.1 Apple Security Update: About the security content of tvOS 10.1 Product: tvOS Version: 10.1 CVE: CVE-2016-7594 Component: ICU Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: A memory corruption issue was addressed through improved memory handling.
apple
CVE-2016-4611P3HIGHCVSS 8.8fixed in 10.02016-09-25
CVE-2016-4611 [HIGH] CWE-119 CVE-2016-4611: WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execu WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4730, CVE-2016-4733, CVE-2016-4734, and CVE-2016-4735.
nvdapple
CVE-2018-4378P3HIGHCVSS 8.8fixed in 12.12019-04-03
CVE-2018-4378 [HIGH] CWE-119 CVE-2018-4378: A memory corruption issue was addressed with improved validation. This issue affected versions prior A memory corruption issue was addressed with improved validation. This issue affected versions prior to iOS 12.1, tvOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.
nvdapple
CVE-2020-27911P3HIGHCVSS 7.8fixed in 14.2≥ unspecified, < 14.22020-12-08
CVE-2020-27911 [HIGH] CWE-190 CVE-2020-27911: An integer overflow was addressed through improved input validation. This issue is fixed in macOS Bi An integer overflow was addressed through improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, tvOS 14.2, iTunes 12.11 for Windows. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
nvd
CVE-2014-4489P3CRITICALCVSS 10.0≤ 7.0.12015-01-30
CVE-2014-4489 [CRITICAL] CVE-2014-4489: IOHIDFamily in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not IOHIDFamily in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not properly initialize event queues, which allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.
nvd
CVE-2025-43400P3MEDIUMCVSS 6.3fixed in 26.12025-09-29
CVE-2025-43400 [MEDIUM] CWE-787 CVE-2025-43400: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.1 and iPadOS 18.7.1, iOS 26.0.1 and iPadOS 26.0.1, macOS Sequoia 15.7.1, macOS Sonoma 14.8.1, macOS Tahoe 26.0.1, tvOS 26.1, visionOS 26.0.1, watchOS 26.1. Processing a maliciously crafted font may lead to unexpected app termination or corrupt p
nvdapple
CVE-2014-4486P3CRITICALCVSS 10.0≤ 7.0.12015-01-30
CVE-2014-4486 [CRITICAL] CVE-2014-4486: IOAcceleratorFamily in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 IOAcceleratorFamily in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not properly handle resource lists and IOService userclient types, which allows attackers to execute arbitrary code or cause a denial of service (NULL pointer dereference) via a crafted app.
nvd
CVE-2026-28995P3HIGHCVSS 8.8fixed in 26.52026-05-11
CVE-2026-28995 [HIGH] CWE-269 CVE-2026-28995: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS A logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A malicious app may be able to break out of its sandbox.
nvd
CVE-2014-4480P3CRITICALCVSS 10.0≤ 7.0.12015-01-30
CVE-2014-4480 [CRITICAL] CWE-59 CVE-2014-4480: Directory traversal vulnerability in afc in AppleFileConduit in Apple iOS before 8.1.3 and Apple TV Directory traversal vulnerability in afc in AppleFileConduit in Apple iOS before 8.1.3 and Apple TV before 7.0.3 allows attackers to access unintended filesystem locations by creating a symlink.
nvd
CVE-2018-4249P3HIGHCVSS 7.8v11.42018-05-29
CVE-2018-4249 [HIGH] CVE-2018-4249: tvOS 11.4 Apple Security Update: About the security content of tvOS 11.4 Product: tvOS Version: 11.4 CVE: CVE-2018-4249 Component: Kernel Impact: An application may be able to execute arbitrary code with kernel privileges Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2020-9876P3HIGHCVSS 7.8fixed in 14.0≥ unspecified, < tvOS 13.4.82020-10-22
CVE-2020-9876 [HIGH] CWE-787 CVE-2020-9876: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Opening a maliciously crafted PDF file may lead to an unexpected application termination or arbitrary
nvdapple
CVE-2024-27857P3HIGHCVSS 7.8fixed in 17.52024-06-10
CVE-2024-27857 [HIGH] CWE-119 CVE-2024-27857: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2. A remote attacker may be able to cause unexpected app termination or arbitrary code execution.
nvdapple
CVE-2020-27912P3HIGHCVSS 7.8fixed in 14.2≥ unspecified, < 14.22020-12-08
CVE-2020-27912 [HIGH] CWE-787 CVE-2020-27912: An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Bi An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, tvOS 14.2, iTunes 12.11 for Windows. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2020-9889P3HIGHCVSS 7.8fixed in 13.4.8≥ unspecified, < tvOS 13.4.82020-10-16
CVE-2020-9889 [HIGH] CWE-787 CVE-2020-9889: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. Processing a maliciously crafted audio file may lead to arbitrary code execution.
nvdapple
CVE-2016-9842P3HIGHCVSS 8.8fixed in 11.02017-05-23
CVE-2016-9842 [HIGH] CWE-1335 CVE-2016-9842: The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.
nvdapple
CVE-2022-22579P3HIGHCVSS 7.8fixed in 15.3≥ unspecified, < 15.32022-03-18
CVE-2022-22579 [HIGH] CVE-2022-22579: An information disclosure issue was addressed with improved state management. This issue is fixed in An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 15.3 and iPadOS 15.3, tvOS 15.3, Security Update 2022-001 Catalina, macOS Monterey 12.2, macOS Big Sur 11.6.3. Processing a maliciously crafted STL file may lead to unexpected application termination or arbitrary code execution.
nvdapple
CVE-2020-9919P3HIGHCVSS 7.8fixed in 13.4.8≥ unspecified, < tvOS 13.4.82020-10-22
CVE-2020-9919 [HIGH] CWE-787 CVE-2020-9919: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing a maliciously crafted image may lead to arbitrary code execution.
nvdapple
Apple tvOS vulnerabilities | cvebase