cbcvebase.

Apple tvOS vulnerabilities

2,371 known vulnerabilities affecting apple/tvos.

Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL174HIGH1277MEDIUM858LOW59UNKNOWN3

Vulnerabilities

Page 90 of 119
CVE-2019-8762P4MEDIUMCVSS 6.1fixed in 13≥ unspecified, < 132020-10-27
CVE-2019-8762 [MEDIUM] CWE-79 CVE-2019-8762: A validation issue was addressed with improved logic. This issue is fixed in Safari 13.0.1, iOS 13.1 A validation issue was addressed with improved logic. This issue is fixed in Safari 13.0.1, iOS 13.1 and iPadOS 13.1, iCloud for Windows 10.7, tvOS 13, iCloud for Windows 7.14, iTunes 12.10.1 for Windows. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
CVE-2023-32445P4MEDIUMCVSS 6.1fixed in 16.6≥ unspecified, < 16.62023-07-28
CVE-2023-32445 [MEDIUM] CWE-79 CVE-2023-32445: This issue was addressed with improved checks. This issue is fixed in Safari 16.6, watchOS 9.6, iOS This issue was addressed with improved checks. This issue is fixed in Safari 16.6, watchOS 9.6, iOS 15.7.8 and iPadOS 15.7.8, tvOS 16.6, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. Processing a document may lead to a cross site scripting attack.
nvdapple
CVE-2017-7164P4MEDIUMCVSS 5.9fixed in 11.22018-04-03
CVE-2017-7164 [MEDIUM] CWE-20 CVE-2017-7164: An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is affected. The issue involves the "App Store" component. It allows man-in-the-middle attackers to spoof password prompts.
nvdapple
CVE-2017-13080P4MEDIUMCVSS 5.3v11.22017-12-04
CVE-2017-13080 [MEDIUM] CVE-2017-13080: tvOS 11.2 Apple Security Update: About the security content of tvOS 11.2 Product: tvOS Version: 11.2 CVE: CVE-2017-13080 Component: Released for Apple TV 4K in tvOS 11.1. Impact: An attacker in Wi-Fi range may force nonce reuse in WPA multicast/GTK clients (Key Reinstallation Attacks - KRACK) Description: A logic issue existed in the handling of state transitions. This was addressed with improved state management.
apple
CVE-2014-4364P4MEDIUMCVSS 5.6≤ 6.2v6.0+5 more2014-09-18
CVE-2014-4364 [MEDIUM] CWE-310 CVE-2014-4364: The 802.1X subsystem in Apple iOS before 8 and Apple TV before 7 does not require strong authenticat The 802.1X subsystem in Apple iOS before 8 and Apple TV before 7 does not require strong authentication methods, which allows remote attackers to calculate credentials by offering LEAP authentication from a crafted Wi-Fi AP and then performing a cryptographic attack against the MS-CHAPv1 hash.
nvd
CVE-2021-30720P4MEDIUMCVSS 5.4fixed in 14.62021-09-08
CVE-2021-30720 [MEDIUM] CWE-287 CVE-2021-30720: A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 a A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. A malicious website may be able to access restricted ports on arbitrary servers.
nvdapple
CVE-2025-31241P4MEDIUMCVSS 5.3fixed in 18.52025-05-12
CVE-2025-31241 [MEDIUM] CWE-415 CVE-2025-31241: A double free issue was addressed with improved memory management. This issue is fixed in iOS 18.5 a A double free issue was addressed with improved memory management. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. A remote attacker may cause an unexpected app termination.
nvdapple
CVE-2015-1102P4HIGHCVSS 7.1≤ 7.12015-04-10
CVE-2015-1102 [HIGH] CWE-20 CVE-2015-1102: The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 does not prop The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 does not properly handle TCP headers, which allows man-in-the-middle attackers to cause a denial of service via unspecified vectors.
nvd
CVE-2021-30710P4HIGHCVSS 7.1fixed in 14.62021-09-08
CVE-2021-30710 [HIGH] CWE-787 CVE-2021-30710: A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. A malicious application may cause a denial of service or potentially disclose memory contents.
nvdapple
CVE-2017-7151P4HIGHCVSS 7.0fixed in 11.22019-04-03
CVE-2017-7151 [HIGH] CWE-362 CVE-2017-7151: A race condition was addressed with additional validation. This issue affected versions prior to iOS A race condition was addressed with additional validation. This issue affected versions prior to iOS 11.2, macOS High Sierra 10.13.2, tvOS 11.2, watchOS 4.2, iTunes 12.7.2 for Windows, macOS High Sierra 10.13.4.
nvdapple
CVE-2016-4592P4MEDIUMCVSS 6.5v9.2.22016-07-18
CVE-2016-4592 [MEDIUM] CVE-2016-4592: tvOS 9.2.2 Apple Security Update: About the security content of tvOS 9.2.2 Product: tvOS Version: 9.2.2 CVE: CVE-2016-4592 Component: WebKit Impact: Processing maliciously crafted web content may lead to a system denial of service Description: A memory consumption issue was addressed through improved memory handling.
apple
CVE-2016-1811P4MEDIUMCVSS 6.5fixed in 9.2.12016-05-20
CVE-2016-1811 [MEDIUM] CWE-476 CVE-2016-1811: ImageIO in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 ImageIO in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted image.
nvdapple
CVE-2015-8317P4MEDIUMCVSS 5.0v9.2.22016-07-18
CVE-2015-8317 [MEDIUM] CVE-2015-8317: tvOS 9.2.2 Apple Security Update: About the security content of tvOS 9.2.2 Product: tvOS Version: 9.2.2 CVE: CVE-2015-8317 Component: Kernel Impact: A local user may be able to cause a system denial of service Description: A null pointer dereference was addressed through improved input validation.
apple
CVE-2013-0981P4HIGHCVSS 7.2≤ 5.2.0v1.0.0+27 more2013-03-20
CVE-2013-0981 [HIGH] CVE-2013-0981: The IOUSBDeviceFamily driver in the USB implementation in the kernel in Apple iOS before 6.1.3 and A The IOUSBDeviceFamily driver in the USB implementation in the kernel in Apple iOS before 6.1.3 and Apple TV before 5.2.1 accesses pipe object pointers that originated in userspace, which allows local users to gain privileges via crafted code.
nvd
CVE-2020-3862P4MEDIUMCVSS 6.5fixed in 13.3.1≥ unspecified, < tvOS 13.3.12020-02-27
CVE-2020-3862 [MEDIUM] CVE-2020-3862: A denial of service issue was addressed with improved memory handling. This issue is fixed in iOS 13 A denial of service issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. A malicious website may be able to cause a denial of service.
nvd
CVE-2019-8576P4HIGHCVSS 7.1fixed in 12.3≥ unspecified, < tvOS 12.32019-12-18
CVE-2019-8576 [HIGH] CWE-125 CVE-2019-8576: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.3, An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A local user may be able to cause unexpected system termination or read kernel memory.
nvdapple
CVE-2023-32420P4HIGHCVSS 7.1fixed in 16.5≥ unspecified, < 16.52023-06-23
CVE-2023-32420 [HIGH] CWE-125 CVE-2023-32420: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 16.5 An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. An app may be able to cause unexpected system termination or read kernel memory.
nvdapple
CVE-2024-27791P4HIGHCVSS 7.1fixed in 17.32024-04-24
CVE-2024-27791 [HIGH] CWE-119 CVE-2024-27791: The issue was addressed with improved checks. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, i The issue was addressed with improved checks. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3. An app may be able to corrupt coprocessor memory.
nvdapple
CVE-2020-9829P4MEDIUMCVSS 6.5fixed in 13.4.5≥ unspecified, < tvOS 13.4.52020-06-09
CVE-2020-9829 [MEDIUM] CWE-20 CVE-2020-9829: A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.5 a A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5. Processing a maliciously crafted text message may lead to application denial of service.
nvd
CVE-2023-23512P4MEDIUMCVSS 6.5fixed in 16.3≥ unspecified, < 16.32023-02-27
CVE-2023-23512 [MEDIUM] CVE-2023-23512: The issue was addressed with improved handling of caches. This issue is fixed in watchOS 9.3, tvOS 1 The issue was addressed with improved handling of caches. This issue is fixed in watchOS 9.3, tvOS 16.3, macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. Visiting a website may lead to an app denial-of-service.
nvdapple
Apple tvOS vulnerabilities | cvebase