cbcvebase.

Apple watchOS vulnerabilities

2,036 known vulnerabilities affecting apple/watchos.

Total CVEs
2,036
CISA KEV
51
actively exploited
Public exploits
137
Exploited in wild
85
Severity breakdown
CRITICAL160HIGH1024MEDIUM782LOW68UNKNOWN2

Vulnerabilities

Page 46 of 102
CVE-2020-6514P3MEDIUMCVSS 6.5fixed in 6.2.82020-07-22
CVE-2020-6514 [MEDIUM] CWE-200 CVE-2020-6514: Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.
nvdapple
CVE-2015-5874P3HIGHCVSS 7.5v1.02015-09-18
CVE-2015-5874 [HIGH] CWE-119 CVE-2015-5874: CoreText in Apple iOS before 9 and iTunes before 12.3 allows remote attackers to execute arbitrary c CoreText in Apple iOS before 9 and iTunes before 12.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file.
nvd
CVE-2018-4354P3HIGHCVSS 8.6fixed in 5.02019-04-03
CVE-2018-4354 [HIGH] CWE-119 CVE-2018-4354: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
nvd
CVE-2018-4341P3HIGHCVSS 8.6fixed in 5.02019-04-03
CVE-2018-4341 [HIGH] CWE-119 CVE-2018-4341: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
nvd
CVE-2016-1753P3HIGHCVSS 7.8fixed in 2.22016-03-24
CVE-2016-1753 [HIGH] CWE-190 CVE-2016-1753: Multiple integer overflows in the kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9 Multiple integer overflows in the kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allow attackers to execute arbitrary code in a privileged context via a crafted app.
nvdapple
CVE-2020-9794P3HIGHCVSS 8.1fixed in 6.2.5≥ unspecified, < watchOS 6.2.52020-06-09
CVE-2020-9794 [HIGH] CWE-125 CVE-2020-9794: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.5 a An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. A malicious application may cause a denial of service or potentially disclose memory contents.
nvd
CVE-2024-54514P3HIGHCVSS 8.6fixed in 11.22024-12-12
CVE-2024-54514 [HIGH] CVE-2024-54514: The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, watchOS 11.2. An app may be able to break out of its sandbox.
nvd
CVE-2017-2432P3HIGHCVSS 7.8≤ 3.1.32017-04-02
CVE-2017-2432 [HIGH] CWE-119 CVE-2017-2432: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "ImageIO" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a craft
nvdapple
CVE-2017-7025P3HIGHCVSS 7.8v3.2.32017-07-19
CVE-2017-7025 [HIGH] CVE-2017-7025: watchOS 3.2.3 Apple Security Update: About the security content of watchOS 3.2.3 Product: watchOS Version: 3.2.3 CVE: CVE-2017-7025 Component: Kernel Impact: An application may be able to execute arbitrary code with kernel privileges Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2017-7022P3HIGHCVSS 7.8v3.2.32017-07-19
CVE-2017-7022 [HIGH] CVE-2017-7022: watchOS 3.2.3 Apple Security Update: About the security content of watchOS 3.2.3 Product: watchOS Version: 3.2.3 CVE: CVE-2017-7022 Component: Kernel Impact: An application may be able to execute arbitrary code with system privileges Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2017-7023P3HIGHCVSS 7.8v3.2.32017-07-19
CVE-2017-7023 [HIGH] CVE-2017-7023: watchOS 3.2.3 Apple Security Update: About the security content of watchOS 3.2.3 Product: watchOS Version: 3.2.3 CVE: CVE-2017-7023 Component: Kernel Impact: An application may be able to execute arbitrary code with kernel privileges Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2017-7024P3HIGHCVSS 7.8v3.2.32017-07-19
CVE-2017-7024 [HIGH] CVE-2017-7024: watchOS 3.2.3 Apple Security Update: About the security content of watchOS 3.2.3 Product: watchOS Version: 3.2.3 CVE: CVE-2017-7024 Component: Kernel Impact: An application may be able to execute arbitrary code with system privileges Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2017-2379P3HIGHCVSS 7.8≤ 3.1.32017-04-02
CVE-2017-2379 [HIGH] CWE-119 CVE-2017-2379: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Carbon" component. It allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a crafted
nvdapple
CVE-2020-9941P3HIGHCVSS 7.5fixed in 7.02020-10-27
CVE-2020-9941 [HIGH] CVE-2020-9941: This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.7, Securi This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave. A remote attacker may be able to unexpectedly alter application state.
nvdapple
CVE-2016-4673P3HIGHCVSS 7.8fixed in 3.12017-02-20
CVE-2016-4673 [HIGH] CWE-119 CVE-2016-4673: An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "CoreGraphics" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via
nvdapple
CVE-2017-2416P3HIGHCVSS 7.8≤ 3.1.32017-04-02
CVE-2017-2416 [HIGH] CWE-119 CVE-2017-2416: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "ImageIO" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a craft
nvdapple
CVE-2018-4211P3HIGHCVSS 7.8fixed in 4.3.12018-06-08
CVE-2018-4211 [HIGH] CWE-119 CVE-2018-4211: An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "FontParser" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a
nvdapple
CVE-2017-2462P3HIGHCVSS 7.8≤ 3.1.32017-04-02
CVE-2017-2462 [HIGH] CWE-119 CVE-2017-2462: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Audio" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted
nvdapple
CVE-2017-2430P3HIGHCVSS 7.8≤ 3.1.32017-04-02
CVE-2017-2430 [HIGH] CWE-119 CVE-2017-2430: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Audio" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted
nvdapple
CVE-2017-2467P3HIGHCVSS 7.8≤ 3.1.32017-04-02
CVE-2017-2467 [HIGH] CWE-119 CVE-2017-2467: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "ImageIO" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a craft
nvdapple
Apple watchOS vulnerabilities | cvebase