Apple watchOS vulnerabilities

1,895 known vulnerabilities affecting apple/watchos.

Total CVEs
1,895
CISA KEV
51
actively exploited
Public exploits
123
Exploited in wild
40
Severity breakdown
CRITICAL140HIGH970MEDIUM715LOW68UNKNOWN2

Vulnerabilities

Page 81 of 95
CVE-2017-2523CRITICALCVSS 9.8PoCfixed in 3.2.22017-05-22
CVE-2017-2523 [CRITICAL] CWE-119 CVE-2017-2523: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "Foundation" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash
nvdapple
CVE-2017-2524CRITICALCVSS 9.8PoCfixed in 3.2.22017-05-22
CVE-2017-2524 [CRITICAL] CWE-119 CVE-2017-2524: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "TextInput" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash)
nvdapple
CVE-2017-2518CRITICALCVSS 9.8fixed in 3.2.22017-05-22
CVE-2017-2518 [CRITICAL] CWE-416 CVE-2017-2518: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via
nvdapple
CVE-2017-2519CRITICALCVSS 9.8fixed in 3.2.22017-05-22
CVE-2017-2519 [CRITICAL] CVE-2017-2519: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a craf
nvdapple
CVE-2017-2522CRITICALCVSS 9.8PoCfixed in 3.2.22017-05-22
CVE-2017-2522 [CRITICAL] CWE-119 CVE-2017-2522: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "CoreFoundation" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application c
nvdapple
CVE-2017-6998HIGHCVSS 7.8PoC≤ 3.22017-05-22
CVE-2017-6998 [HIGH] CWE-119 CVE-2017-6998: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvdapple
CVE-2017-6989HIGHCVSS 7.8PoC≤ 3.22017-05-22
CVE-2017-6989 [HIGH] CWE-119 CVE-2017-6989: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvdapple
CVE-2017-6994HIGHCVSS 7.8PoC≤ 3.22017-05-22
CVE-2017-6994 [HIGH] CWE-119 CVE-2017-6994: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvdapple
CVE-2017-6997HIGHCVSS 7.8PoC≤ 3.22017-05-22
CVE-2017-6997 [HIGH] CWE-119 CVE-2017-6997: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvdapple
CVE-2017-2521HIGHCVSS 8.8PoCfixed in 3.2.22017-05-22
CVE-2017-2521 [HIGH] CWE-119 CVE-2017-2521: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a
nvdapple
CVE-2017-6979HIGHCVSS 7.0PoC≤ 3.22017-05-22
CVE-2017-6979 [HIGH] CWE-362 CVE-2017-6979: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "IOSurface" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvdapple
CVE-2017-6995HIGHCVSS 7.8PoC≤ 3.22017-05-22
CVE-2017-6995 [HIGH] CWE-119 CVE-2017-6995: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvdapple
CVE-2017-6996HIGHCVSS 7.8PoC≤ 3.22017-05-22
CVE-2017-6996 [HIGH] CWE-119 CVE-2017-6996: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvdapple
CVE-2017-2501HIGHCVSS 7.0PoCfixed in 3.2.22017-05-22
CVE-2017-2501 [HIGH] CWE-362 CVE-2017-2501: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "Kernel" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvdapple
CVE-2017-6999HIGHCVSS 7.8PoC≤ 3.22017-05-22
CVE-2017-6999 [HIGH] CWE-119 CVE-2017-6999: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvdapple
CVE-2017-6987MEDIUMCVSS 5.5≤ 3.22017-05-22
CVE-2017-6987 [MEDIUM] CWE-200 CVE-2017-6987: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvdapple
CVE-2017-2502MEDIUMCVSS 5.5fixed in 3.2.22017-05-22
CVE-2017-2502 [MEDIUM] CVE-2017-2502: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "CoreAudio" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvdapple
CVE-2017-2507MEDIUMCVSS 5.5fixed in 3.2.22017-05-22
CVE-2017-2507 [MEDIUM] CWE-200 CVE-2017-2507: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvdapple
CVE-2017-2428CRITICALCVSS 9.8≤ 3.1.32017-04-02
CVE-2017-2428 [CRITICAL] CVE-2017-2428: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves nghttp2 before 1.17.0 in the "HTTPProtocol" component. It allows remote HTTP/2 servers to have an unspecified impact via unknown vectors.
nvdapple
CVE-2017-2461HIGHCVSS 7.5≤ 3.1.32017-04-02
CVE-2017-2461 [HIGH] CWE-20 CVE-2017-2461: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service (resource consumption) via a crafted text message.
nvdapple