cbcvebase.

Apple tvOS vulnerabilities

2,371 known vulnerabilities affecting apple/tvos.

Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL174HIGH1277MEDIUM858LOW59UNKNOWN3

Vulnerabilities

Page 64 of 119
CVE-2017-2435P3HIGHCVSS 7.8≤ 10.1.12017-04-02
CVE-2017-2435 [HIGH] CWE-119 CVE-2017-2435: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "CoreText" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a craf
nvdapple
CVE-2017-2487P3HIGHCVSS 7.8≤ 10.1.12017-04-02
CVE-2017-2487 [HIGH] CWE-119 CVE-2017-2487: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "FontParser" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a cr
nvdapple
CVE-2014-4388P3HIGHCVSS 7.8≤ 6.2v6.0+5 more2014-09-18
CVE-2014-4388 [HIGH] CWE-20 CVE-2014-4388: IOKit in Apple iOS before 8 and Apple TV before 7 does not properly validate IODataQueue object meta IOKit in Apple iOS before 8 and Apple TV before 7 does not properly validate IODataQueue object metadata, which allows attackers to execute arbitrary code in a privileged context via an application that provides crafted values in unspecified metadata fields, a different vulnerability than CVE-2014-4418.
nvd
CVE-2014-4418P3HIGHCVSS 7.8≤ 6.2v6.0+5 more2014-09-18
CVE-2014-4418 [HIGH] CVE-2014-4418: IOKit in Apple iOS before 8 and Apple TV before 7 does not properly validate IODataQueue object meta IOKit in Apple iOS before 8 and Apple TV before 7 does not properly validate IODataQueue object metadata, which allows attackers to execute arbitrary code in a privileged context via an application that provides crafted values in unspecified metadata fields, a different vulnerability than CVE-2014-4388.
nvd
CVE-2016-1824P3HIGHCVSS 7.8fixed in 9.2.12016-05-20
CVE-2016-1824 [HIGH] CVE-2016-1824: IOHIDFamily in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2. IOHIDFamily in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1823.
nvdapple
CVE-2016-1750P3HIGHCVSS 7.8fixed in 9.22016-03-24
CVE-2016-1750 [HIGH] CWE-416 CVE-2016-1750: Use-after-free vulnerability in the kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before Use-after-free vulnerability in the kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvdapple
CVE-2017-2401P3HIGHCVSS 7.8≤ 10.1.12017-04-02
CVE-2017-2401 [HIGH] CWE-119 CVE-2017-2401: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app
nvdapple
CVE-2017-7027P3HIGHCVSS 7.8≤ 10.2.12017-07-20
CVE-2017-7027 [HIGH] CWE-119 CVE-2017-7027: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a craft
nvdapple
CVE-2017-7009P3HIGHCVSS 7.8≤ 10.2.12017-07-20
CVE-2017-7009 [HIGH] CWE-119 CVE-2017-7009: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "IOUSBFamily" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a
nvdapple
CVE-2017-7026P3HIGHCVSS 7.8≤ 10.2.12017-07-20
CVE-2017-7026 [HIGH] CWE-119 CVE-2017-7026: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a craft
nvdapple
CVE-2019-8593P3HIGHCVSS 7.8fixed in 12.3≥ unspecified, < tvOS 12.32019-12-18
CVE-2019-8593 [HIGH] CWE-787 CVE-2019-8593: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12 A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.3, tvOS 12.3, watchOS 5.2.1. An application may be able to execute arbitrary code with system privileges.
nvdapple
CVE-2017-7162P3HIGHCVSS 7.8fixed in 11.22017-12-27
CVE-2017-7162 [HIGH] CWE-119 CVE-2017-7162: An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "IOKit" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvdapple
CVE-2017-7069P3HIGHCVSS 7.8≤ 10.2.12017-07-20
CVE-2017-7069 [HIGH] CWE-119 CVE-2017-7069: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a craft
nvdapple
CVE-2015-7053P3MEDIUMCVSS 6.8≤ 9.02015-12-11
CVE-2015-7053 [MEDIUM] CWE-119 CVE-2015-7053: ImageIO in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows ImageIO in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted image.
nvdapple
CVE-2017-13854P3HIGHCVSS 7.8fixed in 11.02018-04-03
CVE-2017-13854 [HIGH] CWE-119 CVE-2017-13854: An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvdapple
CVE-2019-8747P3HIGHCVSS 7.8v132019-09-24
CVE-2019-8747 [HIGH] CVE-2019-8747: tvOS 13 Apple Security Update: About the security content of tvOS 13 Product: tvOS Version: 13 CVE: CVE-2019-8747 Component: AppleFirmwareUpdateKext Impact: An application may be able to execute arbitrary code with kernel privileges Description: A memory corruption vulnerability was addressed with improved locking.
apple
CVE-2020-9971P3HIGHCVSS 7.8fixed in 14.0≥ unspecified, < 14.02021-04-02
CVE-2020-9971 [HIGH] CVE-2020-9971: A logic issue was addressed with improved validation. This issue is fixed in watchOS 7.0, tvOS 14.0, A logic issue was addressed with improved validation. This issue is fixed in watchOS 7.0, tvOS 14.0, iOS 14.0 and iPadOS 14.0, macOS Big Sur 11.0.1. A malicious application may be able to elevate privileges.
nvdapple
CVE-2021-1750P3HIGHCVSS 7.8fixed in 14.42021-04-02
CVE-2021-1750 [HIGH] CWE-269 CVE-2021-1750: Multiple issues were addressed with improved logic. This issue is fixed in macOS Big Sur 11.2, Secur Multiple issues were addressed with improved logic. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2025-43323P3HIGHCVSS 8.1fixed in 26.0fixed in 262025-11-04
CVE-2025-43323 [HIGH] CWE-200 CVE-2025-43323: This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26 and iPadO This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An app may be able to fingerprint the user.
nvdapple
CVE-2017-11122P3HIGHCVSS 7.5≤ 10.2.22017-10-04
CVE-2017-11122 [HIGH] CWE-200 CVE-2017-11122: On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56, an attacker can trigger an information leak due On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56, an attacker can trigger an information leak due to insufficient length validation, related to ICMPv6 router advertisement offloading.
nvdapple
Apple tvOS vulnerabilities | cvebase