cbcvebase.

Apple tvOS vulnerabilities

2,371 known vulnerabilities affecting apple/tvos.

Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL174HIGH1277MEDIUM858LOW59UNKNOWN3

Vulnerabilities

Page 66 of 119
CVE-2021-30945P3HIGHCVSS 7.8fixed in 15.22021-08-24
CVE-2021-30945 [HIGH] CVE-2021-30945: This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15. This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. A local attacker may be able to elevate their privileges.
nvdapple
CVE-2021-1868P3HIGHCVSS 7.8fixed in 14.5≥ unspecified, < 14.52021-09-08
CVE-2021-1868 [HIGH] CWE-269 CVE-2021-1868: A logic issue was addressed with improved state management. This issue is fixed in Security Update 2 A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A local attacker may be able to elevate their privileges.
nvd
CVE-2022-32949P3HIGHCVSS 7.8fixed in 16.0≥ unspecified, < 162023-02-27
CVE-2022-32949 [HIGH] CWE-269 CVE-2022-32949: This issue was addressed with improved checks. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, This issue was addressed with improved checks. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, tvOS 16. An app may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2023-38565P3HIGHCVSS 7.8fixed in 16.62023-07-27
CVE-2023-38565 [HIGH] CVE-2023-38565: A path handling issue was addressed with improved validation. This issue is fixed in macOS Monterey A path handling issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.6.8, iOS 16.6 and iPadOS 16.6, macOS Big Sur 11.7.9, macOS Ventura 13.5, watchOS 9.6. An app may be able to gain root privileges.
nvdapple
CVE-2023-42848P3HIGHCVSS 7.8fixed in 17.1≥ unspecified, < 17.12024-02-21
CVE-2023-42848 [HIGH] CWE-787 CVE-2023-42848: The issue was addressed with improved bounds checks. This issue is fixed in watchOS 10.1, macOS Sono The issue was addressed with improved bounds checks. This issue is fixed in watchOS 10.1, macOS Sonoma 14.1, tvOS 17.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, macOS Ventura 13.6.1. Processing a maliciously crafted image may lead to heap corruption.
nvdapple
CVE-2024-54538P3HIGHCVSS 7.5fixed in 18.12024-12-20
CVE-2024-54538 [HIGH] CWE-770 CVE-2024-54538: A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 1 A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. A remote attacker may be able to cause a denial-of-service.
nvd
CVE-2023-23519P3HIGHCVSS 7.5fixed in 16.3≥ unspecified, < 16.32023-02-27
CVE-2023-23519 [HIGH] CWE-787 CVE-2023-23519: A memory corruption issue was addressed with improved state management. This issue is fixed in watch A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 9.3, tvOS 16.3, macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. Processing an image may lead to a denial-of-service.
nvdapple
CVE-2024-40856P3HIGHCVSS 7.5fixed in 182024-09-17
CVE-2024-40856 [HIGH] CVE-2024-40856: An integrity issue was addressed with Beacon Protection. This issue is fixed in iOS 18 and iPadOS 18 An integrity issue was addressed with Beacon Protection. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18. An attacker may be able to force a device to disconnect from a secure network.
nvdapple
CVE-2026-28986P3HIGHCVSS 7.5fixed in 26.52026-05-11
CVE-2026-28986 [HIGH] CWE-362 CVE-2026-28986: A race condition was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPa A race condition was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination.
nvd
CVE-2025-24209P3HIGHCVSS 7.0fixed in 18.42025-03-31
CVE-2025-24209 [HIGH] CWE-120 CVE-2025-24209: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 1 A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, watchOS 11.4. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2014-4377P3MEDIUMCVSS 6.8≤ 6.2v6.0+5 more2014-09-18
CVE-2014-4377 [MEDIUM] CWE-189 CVE-2014-4377: Integer overflow in CoreGraphics in Apple iOS before 8 and Apple TV before 7 allows remote attackers Integer overflow in CoreGraphics in Apple iOS before 8 and Apple TV before 7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.
nvd
CVE-2014-4484P3HIGHCVSS 7.5≤ 7.0.12015-01-30
CVE-2014-4484 [HIGH] CWE-19 CVE-2014-4484: FontParser in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows re FontParser in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted .dfont file.
nvd
CVE-2023-32437P3HIGHCVSS 8.6v16.52023-05-18
CVE-2023-32437 [HIGH] CVE-2023-32437: tvOS 16.5 Apple Security Update: About the security content of tvOS 16.5 Product: tvOS Version: 16.5 CVE: CVE-2023-32437 Component: NSURLSession Impact: An app may be able to break out of its sandbox Description: The issue was addressed with improvements to the file handling protocol.
apple
CVE-2017-2461P3HIGHCVSS 7.5≤ 10.1.12017-04-02
CVE-2017-2461 [HIGH] CWE-20 CVE-2017-2461: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service (resource consumption) via a crafted text message.
nvdapple
CVE-2014-4459P3MEDIUMCVSS 6.8fixed in 7.0.32014-11-18
CVE-2014-4459 [MEDIUM] CVE-2014-4459: Use-after-free vulnerability in WebKit, as used in Apple OS X before 10.10.1, allows remote attacker Use-after-free vulnerability in WebKit, as used in Apple OS X before 10.10.1, allows remote attackers to execute arbitrary code via crafted page objects in an HTML document.
nvd
CVE-2020-9991P3HIGHCVSS 7.5fixed in 14.0≥ unspecified, < 14.02020-12-08
CVE-2020-9991 [HIGH] CVE-2020-9991: This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.0.1, watchOS This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, iOS 14.0 and iPadOS 14.0, iCloud for Windows 7.21, tvOS 14.0. A remote attacker may be able to cause a denial of service.
nvdapple
CVE-2016-1817P3HIGHCVSS 7.8fixed in 9.2.12016-05-20
CVE-2016-1817 [HIGH] CWE-119 CVE-2016-1817: IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS b IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1818 and CVE-2016-1819.
nvdapple
CVE-2016-4712P3HIGHCVSS 7.8fixed in 10.02016-09-25
CVE-2016-4712 [HIGH] CWE-787 CVE-2016-4712: CoreCrypto in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows at CoreCrypto in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via a crafted app.
nvdapple
CVE-2016-1829P3HIGHCVSS 7.8fixed in 9.2.12016-05-20
CVE-2016-1829 [HIGH] CVE-2016-1829: The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2 The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1827, CVE-2016-1828, and CVE-2016-1830.
nvdapple
CVE-2017-2451P3HIGHCVSS 7.8≤ 10.1.12017-04-02
CVE-2017-2451 [HIGH] CWE-119 CVE-2017-2451: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Security" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (buffer overflow) via a crafted app
nvdapple
Apple tvOS vulnerabilities | cvebase