← Back

Apple

apple

8,851 CVEs • 196 products

Products (196)

Click to collapse
Toggle
Iphone Os
iphone_os
Mac Os X
mac_os_x
Macos
macos
Tvos
tvos
Ipados
ipados
Watchos
watchos
Safari
safari
Itunes
itunes
Visionos
visionos
Icloud
icloud
Webkit
webkit
Quicktime
quicktime
Xcode
xcode
Ipad Os
ipad_os
Cups
cups
Apple Tv
apple_tv
Ipod Touch
ipod_touch
Os X Server
os_x_server
Swiftnio
swiftnio
Iphone
iphone
Garageband
garageband
Ichat
ichat
Imageio
imageio
Music
music
Keynote
keynote
Pages
pages
Tv Os
tv_os
Mail
mail
Iphoto
iphoto
Cfnetwork
cfnetwork
Terminal
terminal
Afp Server
afp_server
Time Capsule
time_capsule
Numbers
numbers
Iwork
iwork
Swift
swift
Webobjects
webobjects
Ical
ical
Webcore
webcore
Mdnsresponder
mdnsresponder
Coregraphics
coregraphics
Bonjour
bonjour
Watch Os
watch_os
Logic Pro X
logic_pro_x
Mac Os
mac_os
Appleshare
appleshare
Applescript
applescript
Xsan
xsan
Installer
installer
Imovie
imovie
A Ux
a_ux
Carboncore
carboncore
Java 1.5
java_1.5
Java 1.6
java_1.6
Ipad2
ipad2
Ichat Server
ichat_server
Boot Camp
boot_camp
Apple Support
apple_support
Shortcuts
shortcuts
Shazam
shazam
Files
files
Container
container
Claris Emailer
claris_emailer
802.11n
Ichat Av
ichat_av
Airport Card
airport_card
Weblog Server
weblog_server
Textedit
textedit
Preview
preview
Server Manager
server_manager
Pdfkit
pdfkit

CVEs (8,851)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
libxpc in launchd in Apple OS X before 10.11 does not restrict the creation of processes for network connections, which allows remote attackers to cause a denial of service (resource consumption) by repeatedly connecting...Show more
libxpc in launchd in Apple OS X before 10.11 does not restrict the creation of processes for network connections, which allows remote attackers to cause a denial of service (resource consumption) by repeatedly connecting to the SSH port, a different vulnerability than CVE-2015-7761.Show less
1Apple
1Iphone Os
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
Apple iOS before 9.0.2 does not properly restrict the options available on the lock screen, which allows physically proximate attackers to read contact data or view photos via unspecified vectors.
2Apple
Icu Project
3International Components For Unicode
Mac Os XWatchos
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in International Components for Unicode (ICU) before 53.1.0, as used in Apple OS X before 10.11 and watchOS before 2, has unknown impact and attack vectors.
1Apple
1Watch Os
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
GasGauge in Apple watchOS before 2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5918.
1Apple
1Watch Os
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
GasGauge in Apple watchOS before 2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5919.
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Apple OS X before 10.11 does not ensure that the keychain's lock state is displayed correctly, which has unspecified impact and attack vectors.
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
4.7 MEDIUM· v2
The EFI component in Apple OS X before 10.11 allows physically proximate attackers to modify firmware during the EFI update process by inserting an Apple Ethernet Thunderbolt adapter with crafted code in an Option ROM, a...Show more
The EFI component in Apple OS X before 10.11 allows physically proximate attackers to modify firmware during the EFI update process by inserting an Apple Ethernet Thunderbolt adapter with crafted code in an Option ROM, aka a "Thunderstrike" issue. NOTE: this issue exists because of an incomplete fix for CVE-2014-4498.Show less
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heimdal, as used in Apple OS X before 10.11, allows remote attackers to conduct replay attacks against the SMB server via packet data that represents a Kerberos authenticated request.
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The debugging feature in the kernel in Apple OS X before 10.11 mismanages state, which allows local users to cause a denial of service via unspecified vectors.
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The Secure Empty Trash feature in Finder in Apple OS X before 10.11 improperly deletes Trash files, which might allow local users to obtain sensitive information by reading storage media, as demonstrated by reading a fla...Show more
The Secure Empty Trash feature in Finder in Apple OS X before 10.11 improperly deletes Trash files, which might allow local users to obtain sensitive information by reading storage media, as demonstrated by reading a flash drive.Show less
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
7.1 HIGH· v2
The protected range register in the EFI component in Apple OS X before 10.11 has an incorrect value, which allows attackers to cause a denial of service (boot failure) via a crafted app that writes to an unintended addre...Show more
The protected range register in the EFI component in Apple OS X before 10.11 has an incorrect value, which allows attackers to cause a denial of service (boot failure) via a crafted app that writes to an unintended address.Show less
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The Address Book framework in Apple OS X before 10.11 allows local users to gain privileges by using an environment variable to inject code into processes that rely on this framework.
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The X.509 certificate-trust implementation in Apple OS X before 10.11 does not recognize that the kSecRevocationRequirePositiveResponse flag implies a revocation-checking requirement, which makes it easier for man-in-the...Show more
The X.509 certificate-trust implementation in Apple OS X before 10.11 does not recognize that the kSecRevocationRequirePositiveResponse flag implies a revocation-checking requirement, which makes it easier for man-in-the-middle attackers to spoof endpoints by leveraging access to a revoked certificate.Show less
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
SMBClient in SMB in Apple OS X before 10.11 allows local users to obtain sensitive kernel memory-layout information via unspecified vectors.
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
The SMB implementation in the kernel in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
IOGraphics in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5871, CVE-2015-5872, and CVE-2...Show more
IOGraphics in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5871, CVE-2015-5872, and CVE-2015-5873.Show less
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
rsh in the remote_cmds component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors involving environment variables.
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
The Install Framework Legacy component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors involving a privileged executable file.
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
The TLS Handshake Protocol implementation in Secure Transport in Apple OS X before 10.11 accepts a Certificate Request message within a session in which no Server Key Exchange message has been sent, which allows remote a...Show more
The TLS Handshake Protocol implementation in Secure Transport in Apple OS X before 10.11 accepts a Certificate Request message within a session in which no Server Key Exchange message has been sent, which allows remote attackers to have an unspecified impact via crafted TLS data.Show less
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
3.3 LOW· v2
The Mail Drop feature in Mail in Apple OS X before 10.11 mishandles encryption parameters for attachments, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during transmi...Show more
The Mail Drop feature in Mail in Apple OS X before 10.11 mishandles encryption parameters for attachments, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during transmission of an S/MIME e-mail message with a large attachment.Show less