Apple tvOS vulnerabilities
2,371 known vulnerabilities affecting apple/tvos.
Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL174HIGH1277MEDIUM858LOW59UNKNOWN3
Vulnerabilities
Page 85 of 119
CVE-2015-1078P4MEDIUMCVSS 6.8≤ 7.12015-03-18
CVE-2015-1078 [MEDIUM] CWE-399 CVE-2015-1078: WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote
WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.
nvd
CVE-2015-1070P4MEDIUMCVSS 6.8≤ 7.12015-03-18
CVE-2015-1070 [MEDIUM] CWE-399 CVE-2015-1070: WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote
WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.
nvd
CVE-2016-4660P4HIGHCVSS 7.1≤ 10.02017-02-20
CVE-2016-4660 [HIGH] CWE-200 CVE-2016-4660: An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "FontParser" component. It allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash)
nvdapple
CVE-2014-1292P4MEDIUMCVSS 6.8≤ 6.0.2v6.0+1 more2014-03-14
CVE-2014-1292 [MEDIUM] CVE-2014-1292: WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1290, CVE-2014-1291, CVE-2014-1293, and CVE-2014-1294.
nvd
CVE-2014-1290P4MEDIUMCVSS 6.8≤ 6.0.2v6.0+1 more2014-03-14
CVE-2014-1290 [MEDIUM] CVE-2014-1290: WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1291, CVE-2014-1292, CVE-2014-1293, and CVE-2014-1294.
nvd
CVE-2014-1291P4MEDIUMCVSS 6.8≤ 6.0.2v6.0+1 more2014-03-14
CVE-2014-1291 [MEDIUM] CVE-2014-1291: WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1290, CVE-2014-1292, CVE-2014-1293, and CVE-2014-1294.
nvd
CVE-2014-1289P4MEDIUMCVSS 6.8≤ 6.0.2v6.0+1 more2014-03-14
CVE-2014-1289 [MEDIUM] CWE-119 CVE-2014-1289: WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1290, CVE-2014-1291, CVE-2014-1292, CVE-2014-1293, and CVE-2014-1294.
nvd
CVE-2014-1294P4MEDIUMCVSS 6.8≤ 6.0.2v6.0+1 more2014-03-14
CVE-2014-1294 [MEDIUM] CVE-2014-1294: WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1290, CVE-2014-1291, CVE-2014-1292, and CVE-2014-1293.
nvd
CVE-2014-1293P4MEDIUMCVSS 6.8≤ 6.0.2v6.0+1 more2014-03-14
CVE-2014-1293 [MEDIUM] CVE-2014-1293: WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1290, CVE-2014-1291, CVE-2014-1292, and CVE-2014-1294.
nvd
CVE-2020-9994P4HIGHCVSS 7.1fixed in 13.4.5≥ unspecified, < tvOS 13.4.52020-10-22
CVE-2020-9994 [HIGH] CVE-2020-9994: A path handling issue was addressed with improved validation. This issue is fixed in iOS 13.5 and iP
A path handling issue was addressed with improved validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A malicious application may be able to overwrite arbitrary files.
nvd
CVE-2019-13118P4MEDIUMCVSS 5.3fixed in 12.42019-07-01
CVE-2019-13118 [MEDIUM] CWE-843 CVE-2019-13118: In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was
In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.
nvdapple
CVE-2018-4273P4MEDIUMCVSS 6.5fixed in 11.4.12019-04-03
CVE-2018-4273 [MEDIUM] CWE-119 CVE-2018-4273: Multiple memory corruption issues were addressed with improved input validation. This issue affected
Multiple memory corruption issues were addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvdapple
CVE-2018-4270P4MEDIUMCVSS 6.5fixed in 11.4.12019-04-03
CVE-2018-4270 [MEDIUM] CWE-119 CVE-2018-4270: A memory corruption issue was addressed with improved memory handling. This issue affected versions
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvdapple
CVE-2024-40799P4HIGHCVSS 7.1fixed in 17.62024-07-29
CVE-2024-40799 [HIGH] CWE-125 CVE-2024-40799: An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing a maliciously crafted file may lead to unexpected app termination.
nvdapple
CVE-2023-32357P4HIGHCVSS 7.1fixed in 16.5≥ unspecified, < 16.52023-06-23
CVE-2023-32357 [HIGH] CWE-125 CVE-2023-32357: An authorization issue was addressed with improved state management. This issue is fixed in watchOS
An authorization issue was addressed with improved state management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. An app may be able to retain access to system configuration files even after its permission is revoked.
nvdapple
CVE-2026-64725P4HIGHCVSS 7.1fixed in 26.62026-07-27
CVE-2026-64725 [HIGH] CWE-787 CVE-2026-64725: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause a denial-of-service.
nvd
CVE-2018-4368P4MEDIUMCVSS 6.5fixed in 12.12019-04-03
CVE-2018-4368 [MEDIUM] CWE-20 CVE-2018-4368: A denial of service issue was addressed with improved validation. This issue affected versions prior
A denial of service issue was addressed with improved validation. This issue affected versions prior to iOS 12.1, macOS Mojave 10.14.1, tvOS 12.1, watchOS 5.1.
nvdapple
CVE-2015-1086P4MEDIUMCVSS 6.9≤ 7.12015-04-10
CVE-2015-1086 [MEDIUM] CWE-20 CVE-2015-1086: The Audio Drivers subsystem in Apple iOS before 8.3 and Apple TV before 7.2 does not properly valida
The Audio Drivers subsystem in Apple iOS before 8.3 and Apple TV before 7.2 does not properly validate IOKit object metadata, which allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2016-7591P4MEDIUMCVSS 6.5v10.12016-12-12
CVE-2016-7591 [MEDIUM] CVE-2016-7591: tvOS 10.1
Apple Security Update: About the security content of tvOS 10.1
Product: tvOS
Version: 10.1
CVE: CVE-2016-7591
Component: IOHIDFamily
Impact: A local application with system privileges may be able to execute arbitrary code with kernel privileges
Description: A use after free issue was addressed through improved memory management.
apple
CVE-2018-4444P4MEDIUMCVSS 6.5fixed in 12.1.1≥ unspecified, < 12.12020-10-27
CVE-2018-4444 [MEDIUM] CVE-2018-4444: A logic issue was addressed with improved state management. This issue is fixed in Safari 12.0.2, iO
A logic issue was addressed with improved state management. This issue is fixed in Safari 12.0.2, iOS 12.1.1, tvOS 12.1.1, iTunes 12.9.2 for Windows. Processing maliciously crafted web content may disclose sensitive user information.
nvdapple