cbcvebase.

Apple tvOS vulnerabilities

2,371 known vulnerabilities affecting apple/tvos.

Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL174HIGH1277MEDIUM858LOW59UNKNOWN3

Vulnerabilities

Page 74 of 119
CVE-2018-4303P4HIGHCVSS 7.8fixed in 12.1.12019-04-03
CVE-2018-4303 [HIGH] CWE-20 CVE-2018-4303: An input validation issue was addressed with improved input validation. This issue affected versions An input validation issue was addressed with improved input validation. This issue affected versions prior to macOS Mojave 10.14, iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2.
nvdapple
CVE-2016-4626P4HIGHCVSS 7.8fixed in 9.2.22016-07-22
CVE-2016-4626 [HIGH] CWE-476 CVE-2016-4626: IOHIDFamily in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2. IOHIDFamily in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors.
nvdapple
CVE-2015-7064P4MEDIUMCVSS 6.8≤ 9.02015-12-11
CVE-2015-7064 [MEDIUM] CWE-119 CVE-2015-7064: OpenGL in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows OpenGL in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2015-7066.
nvdapple
CVE-2015-7066P4MEDIUMCVSS 6.8≤ 9.02015-12-11
CVE-2015-7066 [MEDIUM] CVE-2015-7066: OpenGL in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows OpenGL in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2015-7064.
nvdapple
CVE-2015-7065P4MEDIUMCVSS 6.8≤ 9.02015-12-11
CVE-2015-7065 [MEDIUM] CWE-119 CVE-2015-7065: OpenGL in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to OpenGL in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
nvdapple
CVE-2017-13077P4MEDIUMCVSS 6.8v11.12017-10-31
CVE-2017-13077 [MEDIUM] CVE-2017-13077: tvOS 11.1 Apple Security Update: About the security content of tvOS 11.1 Product: tvOS Version: 11.1 CVE: CVE-2017-13077 Component: Wi-Fi Impact: An attacker in Wi-Fi range may force nonce reuse in WPA unicast/PTK clients (Key Reinstallation Attacks - KRACK) Description: A logic issue existed in the handling of state transitions. This was addressed with improved state management.
apple
CVE-2015-1104P4MEDIUMCVSS 5.0≤ 7.12015-04-10
CVE-2015-1104 [MEDIUM] CWE-20 CVE-2015-1104: The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 does not prop The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 does not properly determine whether an IPv6 packet had a local origin, which allows remote attackers to bypass an intended network-filtering protection mechanism via a crafted packet.
nvd
CVE-2020-9952P4HIGHCVSS 7.1fixed in 14.0≥ unspecified, < tvOS 14.02020-10-16
CVE-2020-9952 [HIGH] CWE-79 CVE-2020-9952: An input validation issue was addressed with improved input validation. This issue is fixed in iOS 1 An input validation issue was addressed with improved input validation. This issue is fixed in iOS 14.0 and iPadOS 14.0, tvOS 14.0, watchOS 7.0, Safari 14.0, iCloud for Windows 11.4, iCloud for Windows 7.21. Processing maliciously crafted web content may lead to a cross site scripting attack.
nvdapple
CVE-2018-4188P3MEDIUMCVSS 6.5v11.42018-05-29
CVE-2018-4188 [MEDIUM] CVE-2018-4188: tvOS 11.4 Apple Security Update: About the security content of tvOS 11.4 Product: tvOS Version: 11.4 CVE: CVE-2018-4188 Component: WebKit Impact: Visiting a malicious website may lead to address bar spoofing Description: An inconsistent user interface issue was addressed with improved state management.
apple
CVE-2021-30857P4HIGHCVSS 7.0fixed in 15.02021-08-24
CVE-2021-30857 [HIGH] CWE-362 CVE-2021-30857: A race condition was addressed with improved locking. This issue is fixed in Security Update 2021-00 A race condition was addressed with improved locking. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, tvOS 15, iOS 15 and iPadOS 15, watchOS 8, macOS Big Sur 11.6. A malicious application may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2022-32832P3MEDIUMCVSS 6.7fixed in 15.6≥ unspecified, < 15.62022-09-23
CVE-2022-32832 [MEDIUM] CVE-2022-32832: The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15 The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app with root privileges may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2019-8612P4MEDIUMCVSS 6.5fixed in 12.32020-10-27
CVE-2019-8612 [MEDIUM] CVE-2019-8612: A logic issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.1 A logic issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, tvOS 12.3, watchOS 5.2.1, macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, iOS 12.3. An attacker in a privileged network position can modify
nvdapple
CVE-2026-43707P4MEDIUMCVSS 6.5fixed in 26.62026-06-29
CVE-2026-43707 [MEDIUM] CWE-119 CVE-2026-43707: A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-43745P4MEDIUMCVSS 6.5fixed in 26.62026-06-29
CVE-2026-43745 [MEDIUM] CWE-787 CVE-2026-43745: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Sa An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2026-43732P3MEDIUMCVSS 6.5fixed in 26.62026-06-29
CVE-2026-43732 [MEDIUM] CWE-22 CVE-2026-43732: A path handling issue was addressed with improved validation. This issue is fixed in Safari 26.5.2, A path handling issue was addressed with improved validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may disclose sensitive user information.
nvd
CVE-2026-43740P4MEDIUMCVSS 6.5fixed in 26.62026-06-29
CVE-2026-43740 [MEDIUM] CWE-119 CVE-2026-43740: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26. The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may result in the disclosure of process memory.
nvd
CVE-2026-64735P4MEDIUMCVSS 6.5fixed in 26.62026-07-27
CVE-2026-64735 [MEDIUM] CWE-451 CVE-2026-64735: An inconsistent user interface issue was addressed with improved state management. This issue is fix An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote attacker may be able to bypass network filters.
nvd
CVE-2026-64743P4MEDIUMCVSS 6.5fixed in 26.62026-07-27
CVE-2026-64743 [MEDIUM] CWE-285 CVE-2026-64743: An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.6 An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.
nvd
CVE-2011-0162P4HIGHCVSS 7.8≤ 3.0.2v1.0.0+5 more2011-03-11
CVE-2011-0162 [HIGH] CWE-20 CVE-2011-0162: Wi-Fi in Apple iOS before 4.3 and Apple TV before 4.2 does not properly perform bounds checking for Wi-Fi in Apple iOS before 4.3 and Apple TV before 4.2 does not properly perform bounds checking for Wi-Fi frames, which allows remote attackers to cause a denial of service (device reset) via unspecified traffic on the local wireless network.
nvd
CVE-2025-43210P4MEDIUMCVSS 6.3fixed in 18.62026-04-02
CVE-2025-43210 [MEDIUM] CWE-125 CVE-2025-43210: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
nvdapple
Apple tvOS vulnerabilities | cvebase