Apple tvOS vulnerabilities

2,227 known vulnerabilities affecting apple/tvos.

Total CVEs
2,227
CISA KEV
41
actively exploited
Public exploits
199
Exploited in wild
31
Severity breakdown
CRITICAL148HIGH1222MEDIUM795LOW59UNKNOWN3

Vulnerabilities

Page 84 of 112
CVE-2017-13836MEDIUMCVSS 5.5v112017-09-19
CVE-2017-13836 [MEDIUM] CVE-2017-13836: tvOS 11 Apple Security Update: About the security content of tvOS 11 Product: tvOS Version: 11 CVE: CVE-2017-13836 Component: Kernel Impact: An application may be able to read restricted memory Description: A validation issue was addressed with improved input sanitization.
apple
CVE-2017-13817MEDIUMCVSS 5.5v112017-09-19
CVE-2017-13817 [MEDIUM] CVE-2017-13817: tvOS 11 Apple Security Update: About the security content of tvOS 11 Product: tvOS Version: 11 CVE: CVE-2017-13817 Component: Kernel Impact: A local user may be able to read kernel memory Description: An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed through improved input validation.
apple
CVE-2017-1000373MEDIUMCVSS 6.5PoCv112017-09-19
CVE-2017-1000373 [MEDIUM] CVE-2017-1000373: tvOS 11 Apple Security Update: About the security content of tvOS 11 Product: tvOS Version: 11 CVE: CVE-2017-1000373 Component: CVE-2017-1000373 Impact: Multiple issues in expat Description: Multiple issues were addressed by updating to version 2.2.1
apple
CVE-2017-13841MEDIUMCVSS 5.5v112017-09-19
CVE-2017-13841 [MEDIUM] CVE-2017-13841: tvOS 11 Apple Security Update: About the security content of tvOS 11 Product: tvOS Version: 11 CVE: CVE-2017-13841 Component: Kernel Impact: An application may be able to read restricted memory Description: A validation issue was addressed with improved input sanitization.
apple
CVE-2017-13822MEDIUMCVSS 5.5v112017-09-19
CVE-2017-13822 [MEDIUM] CVE-2017-13822: tvOS 11 Apple Security Update: About the security content of tvOS 11 Product: tvOS Version: 11 CVE: CVE-2017-13822 Component: Quick Look Impact: An application may be able to read restricted memory Description: A validation issue was addressed with improved input sanitization.
apple
CVE-2017-13840MEDIUMCVSS 5.5v112017-09-19
CVE-2017-13840 [MEDIUM] CVE-2017-13840: tvOS 11 Apple Security Update: About the security content of tvOS 11 Product: tvOS Version: 11 CVE: CVE-2017-13840 Component: Kernel Impact: An application may be able to read restricted memory Description: A validation issue was addressed with improved input sanitization.
apple
CVE-2017-13782MEDIUMCVSS 5.5v112017-09-19
CVE-2017-13782 [MEDIUM] CVE-2017-13782: tvOS 11 Apple Security Update: About the security content of tvOS 11 Product: tvOS Version: 11 CVE: CVE-2017-13782 Component: Kernel Impact: An application may be able to read restricted memory Description: A validation issue was addressed with improved input sanitization.
apple
CVE-2017-13828MEDIUMCVSS 5.5v112017-09-19
CVE-2017-13828 [MEDIUM] CVE-2017-13828: tvOS 11 Apple Security Update: About the security content of tvOS 11 Product: tvOS Version: 11 CVE: CVE-2017-13828 Component: Fonts Impact: Rendering untrusted text may lead to spoofing Description: An inconsistent user interface issue was addressed with improved state management.
apple
CVE-2017-13842MEDIUMCVSS 5.5v112017-09-19
CVE-2017-13842 [MEDIUM] CVE-2017-13842: tvOS 11 Apple Security Update: About the security content of tvOS 11 Product: tvOS Version: 11 CVE: CVE-2017-13842 Component: Kernel Impact: An application may be able to read restricted memory Description: A validation issue was addressed with improved input sanitization.
apple
CVE-2017-7062CRITICALCVSS 9.8≤ 10.2.12017-07-20
CVE-2017-7062 [CRITICAL] CWE-119 CVE-2017-7062: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Contacts" component. A buffer overflow allows remote attackers to execute arbitrary code or cause a denial of service (application crash).
nvdapple
CVE-2017-7019HIGHCVSS 8.8fixed in 10.2.22017-07-20
CVE-2017-7019 [HIGH] CWE-119 CVE-2017-7019: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit Page Loading" component. It allows remote attackers to execute arbitrary code or cause
nvdapple
CVE-2017-7041HIGHCVSS 8.8PoCfixed in 10.2.22017-07-20
CVE-2017-7041 [HIGH] CWE-119 CVE-2017-7041: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of s
nvdapple
CVE-2017-7027HIGHCVSS 7.8≤ 10.2.12017-07-20
CVE-2017-7027 [HIGH] CWE-119 CVE-2017-7027: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a craft
nvdapple
CVE-2017-7061HIGHCVSS 8.8PoCfixed in 10.2.22017-07-20
CVE-2017-7061 [HIGH] CWE-119 CVE-2017-7061: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of s
nvdapple
CVE-2017-7040HIGHCVSS 8.8PoCfixed in 10.2.22017-07-20
CVE-2017-7040 [HIGH] CWE-119 CVE-2017-7040: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of s
nvdapple
CVE-2017-7049HIGHCVSS 8.8PoCfixed in 10.2.22017-07-20
CVE-2017-7049 [HIGH] CWE-119 CVE-2017-7049: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of s
nvdapple
CVE-2017-7039HIGHCVSS 8.8PoCfixed in 10.2.22017-07-20
CVE-2017-7039 [HIGH] CWE-119 CVE-2017-7039: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of s
nvdapple
CVE-2017-7025HIGHCVSS 7.8≤ 10.2.12017-07-20
CVE-2017-7025 [HIGH] CWE-119 CVE-2017-7025: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a craft
nvdapple
CVE-2017-7024HIGHCVSS 7.8≤ 10.2.12017-07-20
CVE-2017-7024 [HIGH] CWE-119 CVE-2017-7024: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a craft
nvdapple
CVE-2017-7043HIGHCVSS 8.8PoCfixed in 10.2.22017-07-20
CVE-2017-7043 [HIGH] CWE-119 CVE-2017-7043: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of s
nvdapple