cbcvebase.

Apple tvOS vulnerabilities

2,371 known vulnerabilities affecting apple/tvos.

Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL174HIGH1277MEDIUM858LOW59UNKNOWN3

Vulnerabilities

Page 72 of 119
CVE-2014-4466P3HIGHCVSS 7.5≤ 7.0.12014-12-10
CVE-2014-4466 [HIGH] CWE-399 CVE-2014-4466: WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-12-2-1.
nvd
CVE-2016-4725P3HIGHCVSS 8.1fixed in 10.02016-09-25
CVE-2016-4725 [HIGH] CWE-119 CVE-2016-4725: IOAcceleratorFamily in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 IOAcceleratorFamily in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (memory corruption) via a crafted web site.
nvdapple
CVE-2018-4142P3HIGHCVSS 7.5fixed in 11.32018-04-03
CVE-2018-4142 [HIGH] CWE-20 CVE-2018-4142: An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service (application crash) via a crafted string.
nvdapple
CVE-2017-13815P4CRITICALCVSS 9.8v112017-09-19
CVE-2017-13815 [CRITICAL] CVE-2017-13815: tvOS 11 Apple Security Update: About the security content of tvOS 11 Product: tvOS Version: 11 CVE: CVE-2017-13815 Component: CoreText Impact: Processing a maliciously crafted font file may lead to arbitrary code execution Description: A memory consumption issue was addressed with improved memory handling.
apple
CVE-2019-8741P3HIGHCVSS 7.5fixed in 13≥ unspecified, < tvOS 132020-02-28
CVE-2019-8741 [HIGH] CWE-835 CVE-2019-8741: A denial of service issue was addressed with improved input validation. A denial of service issue was addressed with improved input validation.
nvdapple
CVE-2017-13812P3HIGHCVSS 7.8v112017-09-19
CVE-2017-13812 [HIGH] CVE-2017-13812: tvOS 11 Apple Security Update: About the security content of tvOS 11 Product: tvOS Version: 11 CVE: CVE-2017-13812 Component: Kernel Impact: A malicious application may be able to learn information about the presence and operation of other applications on the device. Description: An application was able to access network activity information maintained by the operating system unrestricted. This issue was addressed by reducing the information available to thi
apple
CVE-2017-13814P3HIGHCVSS 7.8v112017-09-19
CVE-2017-13814 [HIGH] CVE-2017-13814: tvOS 11 Apple Security Update: About the security content of tvOS 11 Product: tvOS Version: 11 CVE: CVE-2017-13814 Component: ImageIO Impact: Processing a maliciously crafted image may lead to arbitrary code execution Description: A memory corruption issue was addressed with improved input validation.
apple
CVE-2016-1831P3HIGHCVSS 7.8≤ 9.22016-05-20
CVE-2016-1831 [HIGH] CWE-119 CVE-2016-1831: The kernel in Apple iOS before 9.3.2 and OS X before 10.11.5 allows attackers to execute arbitrary c The kernel in Apple iOS before 9.3.2 and OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2018-4347P3HIGHCVSS 7.8fixed in 122019-04-03
CVE-2018-4347 [HIGH] CWE-416 CVE-2018-4347: A use after free issue was addressed with improved memory management. This issue affected versions p A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5, iTunes 12.9 for Windows, iCloud for Windows 7.7.
nvdapple
CVE-2016-1683P3HIGHCVSS 7.5v9.2.22016-07-18
CVE-2016-1683 [HIGH] CVE-2016-1683: tvOS 9.2.2 Apple Security Update: About the security content of tvOS 9.2.2 Product: tvOS Version: 9.2.2 CVE: CVE-2016-1683 Component: Kernel Impact: A local user may be able to cause a system denial of service Description: A null pointer dereference was addressed through improved input validation.
apple
CVE-2015-7073P3MEDIUMCVSS 6.8≤ 9.02015-12-11
CVE-2015-7073 [MEDIUM] CWE-119 CVE-2015-7073: Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allow remote atta Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted SSL handshake.
nvdapple
CVE-2017-13829P3HIGHCVSS 7.8v112017-09-19
CVE-2017-13829 [HIGH] CVE-2017-13829: tvOS 11 Apple Security Update: About the security content of tvOS 11 Product: tvOS Version: 11 CVE: CVE-2017-13829 Component: CFNetwork Impact: An application may be able to execute arbitrary code with system privileges Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2017-13843P3HIGHCVSS 7.8v112017-09-19
CVE-2017-13843 [HIGH] CVE-2017-13843: tvOS 11 Apple Security Update: About the security content of tvOS 11 Product: tvOS Version: 11 CVE: CVE-2017-13843 Component: Kernel Impact: An application may be able to execute arbitrary code with kernel privileges Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2018-4427P3HIGHCVSS 7.8fixed in 12.1.12019-04-03
CVE-2018-4427 [HIGH] CWE-119 CVE-2018-4427: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to: iOS 12.1, watchOS 5.1.2, tvOS 12.1.1, macOS High Sierra 10.13.6 Security Update 2018-003 High Sierra, macOS Sierra 10.12.6 Security Update 2018-006.
nvdapple
CVE-2019-8542P3HIGHCVSS 7.8fixed in 12.2≥ unspecified, < tvOS 12.22019-12-18
CVE-2019-8542 [HIGH] CWE-120 CVE-2019-8542: A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.2, macO A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. A malicious application may be able to elevate privileges.
nvdapple
CVE-2020-9827P3HIGHCVSS 7.5fixed in 13.4.5≥ unspecified, < tvOS 13.4.52020-06-09
CVE-2020-9827 [HIGH] CVE-2020-9827: A denial of service issue was addressed with improved input validation. This issue is fixed in iOS 1 A denial of service issue was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A remote attacker may be able to cause a denial of service.
nvd
CVE-2021-30888P3HIGHCVSS 7.4fixed in 15.12021-08-24
CVE-2021-30888 [HIGH] CWE-601 CVE-2021-30888: An information leakage issue was addressed. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS M An information leakage issue was addressed. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, iOS 14.8.1 and iPadOS 14.8.1, tvOS 15.1, watchOS 8.1. A malicious website using Content Security Policy reports may be able to leak information via redirect behavior .
nvdapple
CVE-2015-7074P3MEDIUMCVSS 6.8≤ 9.02015-12-11
CVE-2015-7074 [MEDIUM] CWE-119 CVE-2015-7074: CoreMedia Playback in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote a CoreMedia Playback in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed media file.
nvdapple
CVE-2014-4375P3HIGHCVSS 7.8≤ 6.2v6.0+5 more2014-09-18
CVE-2014-4375 [HIGH] CVE-2014-4375: Double free vulnerability in Apple iOS before 8 and Apple TV before 7 allows local users to gain pri Double free vulnerability in Apple iOS before 8 and Apple TV before 7 allows local users to gain privileges or cause a denial of service (device crash) via vectors related to Mach ports.
nvd
CVE-2019-8618P3HIGHCVSS 7.5v12.22019-03-25
CVE-2019-8618 [HIGH] CVE-2019-8618: tvOS 12.2 Apple Security Update: About the security content of tvOS 12.2 Product: tvOS Version: 12.2 CVE: CVE-2019-8618 Component: Sandbox Impact: A sandboxed process may be able to circumvent sandbox restrictions Description: A logic issue was addressed with improved restrictions.
apple
Apple tvOS vulnerabilities | cvebase