← Back

Mac Os X

mac_os_x

Vendor: Apple • 3,210 CVEs

CVEs (3,210)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
1Mac Os X
May 6, 2026
Sep 25, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Terminal in Apple OS X before 10.12 uses weak permissions for the .bash_history and .bash_session files, which allows local users to obtain sensitive information via unspecified vectors.
1Apple
4Iphone Os
Mac Os XTvos+1 more
May 6, 2026
Sep 25, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 mishandle signed disk images, which allows attackers to execute arbitrary code in a privileged context via a crafted app.
1Apple
1Mac Os X
May 6, 2026
Sep 25, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The SecKeyDeriveFromPassword function in Apple OS X before 10.12 does not use the CF_RETURNS_RETAINED keyword, which allows attackers to obtain sensitive information from process memory by triggering key derivation.
1Apple
2Iphone Os
Mac Os X
May 6, 2026
Sep 25, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
S2 Camera in Apple iOS before 10 and OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
1Apple
1Mac Os X
May 6, 2026
Sep 25, 2016
N/A· v4
5.3 MEDIUM· v3
4.6 MEDIUM· v2
Perl in Apple OS X before 10.12 allows local users to bypass the taint-mode protection mechanism via a crafted environment variable.
1Apple
1Mac Os X
May 6, 2026
Sep 25, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Kerberos 5 (aka krb5) PAM module in Apple OS X before 10.12 does not use constant-time operations for determining username validity, which makes it easier for remote attackers to enumerate user accounts via a timing...Show more
The Kerberos 5 (aka krb5) PAM module in Apple OS X before 10.12 does not use constant-time operations for determining username validity, which makes it easier for remote attackers to enumerate user accounts via a timing side-channel attack.Show less
1Apple
1Mac Os X
May 6, 2026
Sep 25, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
NSSecureTextField in Apple OS X before 10.12 does not enable Secure Input, which allows attackers to discover credentials via a crafted app.
1Apple
1Mac Os X
May 6, 2026
Sep 25, 2016
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
mDNSResponder in Apple OS X before 10.12, when VMnet.framework is used, arranges for a DNS proxy to listen on all interfaces, which allows remote attackers to obtain sensitive information by sending a DNS query to an uni...Show more
mDNSResponder in Apple OS X before 10.12, when VMnet.framework is used, arranges for a DNS proxy to listen on all interfaces, which allows remote attackers to obtain sensitive information by sending a DNS query to an unintended interface.Show less
2Apple
Debian
5Debian Linux
Iphone OsMac Os X+2 more
May 6, 2026
Sep 25, 2016
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
libxslt in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
1Apple
1Mac Os X
May 6, 2026
Sep 25, 2016
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
libarchive in Apple OS X before 10.12 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted file.
1Apple
1Mac Os X
May 6, 2026
Sep 25, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
IOThunderboltFamily in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
1Apple
4Iphone Os
Mac Os XTvos+1 more
May 6, 2026
Sep 25, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
IOAcceleratorFamily in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via...Show more
IOAcceleratorFamily in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.Show less
1Apple
4Iphone Os
Mac Os XTvos+1 more
May 6, 2026
Sep 25, 2016
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
IOAcceleratorFamily in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (memory corrupt...Show more
IOAcceleratorFamily in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (memory corruption) via a crafted web site.Show less
1Apple
2Iphone Os
Mac Os X
May 6, 2026
Sep 25, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
IOAcceleratorFamily in Apple iOS before 10 and OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.
1Apple
1Mac Os X
May 6, 2026
Sep 25, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Intel Graphics Driver in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
1Apple
2Iphone Os
Mac Os X
May 6, 2026
Sep 25, 2016
N/A· v4
5.9 MEDIUM· v3
7.1 HIGH· v2
The IDS - Connectivity component in Apple iOS before 10 and OS X before 10.12 allows man-in-the-middle attackers to conduct Call Relay spoofing attacks and cause a denial of service via unspecified vectors.
1Apple
4Iphone Os
Mac Os XTvos+1 more
May 6, 2026
Sep 25, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Buffer overflow in FontParser in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to obtain sensitive information from process memory via a crafted font file.
1Apple
1Mac Os X
May 6, 2026
Sep 25, 2016
N/A· v4
3.3 LOW· v3
5.0 MEDIUM· v2
The File Bookmark component in Apple OS X before 10.12 mishandles scoped-bookmark file descriptors, which allows attackers to cause a denial of service via a crafted app.
1Apple
1Mac Os X
May 6, 2026
Sep 25, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
diskutil in DiskArbitration in Apple OS X before 10.12 allows local users to gain privileges via unspecified vectors.
1Apple
1Mac Os X
May 6, 2026
Sep 25, 2016
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
The Date & Time Pref Pane component in Apple OS X before 10.12 mishandles the .GlobalPreferences file, which allows attackers to discover a user's location via a crafted app.