cbcvebase.

Apple watchOS vulnerabilities

2,036 known vulnerabilities affecting apple/watchos.

Total CVEs
2,036
CISA KEV
51
actively exploited
Public exploits
137
Exploited in wild
85
Severity breakdown
CRITICAL141HIGH1004MEDIUM758LOW68UNKNOWN65

Vulnerabilities

Page 10 of 102
CVE-2017-5754P3MEDIUMCVSS 5.6v4.22017-12-05
CVE-2017-5754 [MEDIUM] CVE-2017-5754: watchOS 4.2 Apple Security Update: About the security content of watchOS 4.2 Product: watchOS Version: 4.2 CVE: CVE-2017-5754 Component: Kernel Impact: An application may be able to read kernel memory (Meltdown) Description: Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.
apple
CVE-2017-6979P3HIGHCVSS 7.0PoC≤ 3.22017-05-22
CVE-2017-6979 [HIGH] CWE-362 CVE-2017-6979: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "IOSurface" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvdapple
CVE-2016-1863P3HIGHCVSS 7.8PoCfixed in 2.2.22016-07-22
CVE-2016-1863 [HIGH] CWE-416 CVE-2016-1863: The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2 The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4582 and CVE-2016-4653.
nvdapple
CVE-2016-7637P3HIGHCVSS 7.8PoC≤ 2.2.22017-02-20
CVE-2016-7637 [HIGH] CWE-119 CVE-2016-7637: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvdapple
CVE-2016-7660P3HIGHCVSS 7.8PoC≤ 2.2.22017-02-20
CVE-2016-7660 [HIGH] CWE-264 CVE-2016-7660: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "syslog" component. It allows local users to gain privileges via unspecified vectors related to Mach port name references.
nvdapple
CVE-2019-8591P3HIGHCVSS 7.1PoCfixed in 5.2.1≥ unspecified, < watchOS 5.2.12019-12-18
CVE-2019-8591 [HIGH] CWE-843 CVE-2019-8591: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.3, A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. An application may be able to cause unexpected system termination or write kernel memory.
nvdapple
CVE-2020-9839P3HIGHCVSS 7.0PoCfixed in 6.2.5≥ unspecified, < watchOS 6.2.52020-06-09
CVE-2020-9839 [HIGH] CWE-362 CVE-2020-9839: A race condition was addressed with improved state handling. This issue is fixed in iOS 13.5 and iPa A race condition was addressed with improved state handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. An application may be able to gain elevated privileges.
nvd
CVE-2023-38604P3CRITICALCVSS 9.8fixed in 9.6≥ unspecified, < 9.62023-07-28
CVE-2023-38604 [CRITICAL] CWE-787 CVE-2023-38604: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in wa An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in watchOS 9.6, macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Monterey 12.6.8, tvOS 16.6, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2022-26711P3CRITICALCVSS 9.8fixed in 8.6≥ unspecified, < 8.6+3 more2022-05-26
CVE-2022-26711 [CRITICAL] CWE-190 CVE-2022-26711: An integer overflow issue was addressed with improved input validation. This issue is fixed in tvOS An integer overflow issue was addressed with improved input validation. This issue is fixed in tvOS 15.5, iTunes 12.12.4 for Windows, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
nvdapple
CVE-2022-32839P3CRITICALCVSS 9.8fixed in 8.7≥ unspecified, < 8.7+1 more2022-08-24
CVE-2022-32839 [CRITICAL] CWE-119 CVE-2022-32839: The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.5, mac The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6, tvOS 15.6, watchOS 8.7. A remote user may cause an unexpected app termination or arbitrary code execution.
nvdapple
CVE-2018-20346P3HIGHCVSS 8.1v5.1.32019-01-22
CVE-2018-20346 [HIGH] CVE-2018-20346: watchOS 5.1.3 Apple Security Update: About the security content of watchOS 5.1.3 Product: watchOS Version: 5.1.3 CVE: CVE-2018-20346 Component: SQLite Impact: A maliciously crafted SQL query may lead to arbitrary code execution Description: Multiple memory corruption issues were addressed with improved input validation.
apple
CVE-2015-7084P3HIGHCVSS 7.2PoC≤ 2.02015-12-11
CVE-2015-7084 [HIGH] CVE-2015-7084: The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 all The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-7083.
nvdapple
CVE-2020-9895P3CRITICALCVSS 9.8fixed in 6.2.8≥ unspecified, < watchOS 6.2.82020-10-16
CVE-2020-9895 [CRITICAL] CWE-416 CVE-2020-9895: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13. A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
nvdapple
CVE-2018-20506P3HIGHCVSS 8.1fixed in 5.1.32019-04-03
CVE-2018-20506 [HIGH] CVE-2018-20506: SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and result SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use ca
nvdapple
CVE-2022-42842P3CRITICALCVSS 9.8fixed in 9.2≥ unspecified, < 9.22022-12-15
CVE-2022-42842 [CRITICAL] CWE-787 CVE-2022-42842: The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monte The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. A remote user may be able to cause kernel code execution.
nvdapple
CVE-2022-42808P3CRITICALCVSS 9.8fixed in 9.1≥ unspecified, < 9.12022-11-01
CVE-2022-42808 [CRITICAL] CWE-787 CVE-2022-42808: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvO An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. A remote user may be able to cause kernel code execution.
nvdapple
CVE-2023-32412P3CRITICALCVSS 9.8fixed in 9.5≥ unspecified, < 9.52023-06-23
CVE-2023-32412 [CRITICAL] CWE-416 CVE-2023-32412: A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. A remote attacker may be able to cause unexpected app termination or arbitrary code execution.
nvdapple
CVE-2022-22629P3HIGHCVSS 8.8fixed in 8.5≥ unspecified, < 8.5+1 more2022-09-23
CVE-2022-22629 [HIGH] CWE-787 CVE-2022-22629: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Mo A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iTunes 12.12.3 for Windows, iOS 15.4 and iPadOS 15.4, tvOS 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2023-38598P3CRITICALCVSS 9.8fixed in 9.6≥ unspecified, < 9.62023-07-28
CVE-2023-38598 [CRITICAL] CWE-416 CVE-2023-38598: A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.6, macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Monterey 12.6.8, tvOS 16.6, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2023-36495P3CRITICALCVSS 9.8fixed in 9.6≥ unspecified, < 9.62023-07-28
CVE-2023-36495 [CRITICAL] CWE-190 CVE-2023-36495: An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.6 An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.6, macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, tvOS 16.6, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to execute arbitrary code with kernel privileges.
nvdapple
Apple watchOS vulnerabilities | cvebase