← Back

Apple

apple

8,795 CVEs • 196 products

Products (196)

Click to collapse
Toggle
Iphone Os
iphone_os
Mac Os X
mac_os_x
Macos
macos
Tvos
tvos
Ipados
ipados
Watchos
watchos
Safari
safari
Itunes
itunes
Visionos
visionos
Icloud
icloud
Webkit
webkit
Quicktime
quicktime
Xcode
xcode
Ipad Os
ipad_os
Cups
cups
Apple Tv
apple_tv
Ipod Touch
ipod_touch
Os X Server
os_x_server
Swiftnio
swiftnio
Iphone
iphone
Garageband
garageband
Ichat
ichat
Imageio
imageio
Music
music
Keynote
keynote
Pages
pages
Tv Os
tv_os
Mail
mail
Iphoto
iphoto
Cfnetwork
cfnetwork
Terminal
terminal
Afp Server
afp_server
Time Capsule
time_capsule
Numbers
numbers
Iwork
iwork
Swift
swift
Webobjects
webobjects
Ical
ical
Webcore
webcore
Mdnsresponder
mdnsresponder
Coregraphics
coregraphics
Bonjour
bonjour
Watch Os
watch_os
Logic Pro X
logic_pro_x
Mac Os
mac_os
Appleshare
appleshare
Applescript
applescript
Xsan
xsan
Installer
installer
Imovie
imovie
A Ux
a_ux
Carboncore
carboncore
Java 1.5
java_1.5
Java 1.6
java_1.6
Ipad2
ipad2
Ichat Server
ichat_server
Boot Camp
boot_camp
Apple Support
apple_support
Shortcuts
shortcuts
Shazam
shazam
Files
files
Container
container
Claris Emailer
claris_emailer
802.11n
Ichat Av
ichat_av
Airport Card
airport_card
Weblog Server
weblog_server
Textedit
textedit
Preview
preview
Server Manager
server_manager
Pdfkit
pdfkit

CVEs (8,795)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
2Ipad2
Iphone Os
Apr 29, 2026
Nov 11, 2011
N/A· v4
N/A· v3
1.2 LOW· v2
The Passcode Lock feature in Apple iOS before 5.0.1 on the iPad 2 does not properly implement the locked state, which allows physically proximate attackers to access data by opening a Smart Cover during power-off confirm...Show more
The Passcode Lock feature in Apple iOS before 5.0.1 on the iPad 2 does not properly implement the locked state, which allows physically proximate attackers to access data by opening a Smart Cover during power-off confirmation.Show less
2Apple
Suse
4Iphone Os
Linux Enterprise DesktopLinux Enterprise Server+1 more
Apr 29, 2026
Nov 11, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
FreeType in CoreGraphics in Apple iOS before 5.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font in a document.
2Apple
Google
4Chrome
Iphone OsItunes+1 more
Apr 29, 2026
Nov 11, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in Google Chrome before 15.0.874.120 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to editing.
1Apple
1Webobjects
Apr 29, 2026
Nov 9, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Apple WebObjects 5.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Apple
1Quicktime
Apr 29, 2026
Oct 28, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
Apple QuickTime before 7.7.1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted TKHD atoms in a QuickTime movie file.
1Apple
1Quicktime
Apr 29, 2026
Oct 28, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
Integer overflow in Apple QuickTime before 7.7.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with JPEG2000 encoding.
1Apple
1Quicktime
Apr 29, 2026
Oct 28, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
Buffer overflow in Apple QuickTime before 7.7.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with FLC encoding.
1Apple
1Quicktime
Apr 29, 2026
Oct 28, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
Integer signedness error in Apple QuickTime before 7.7.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted font table in a QuickTime movie file.
1Apple
1Quicktime
Apr 29, 2026
Oct 28, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
Integer overflow in Apple QuickTime before 7.7.1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT file.
2Apple
Google
4Chrome
Iphone OsItunes+1 more
Apr 29, 2026
Oct 25, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to editing operations in...Show more
Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to editing operations in conjunction with an unknown plug-in.Show less
2Apple
Google
3Chrome
Iphone OsSafari
Apr 29, 2026
Oct 25, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Google Chrome before 15.0.874.102 does not properly handle javascript: URLs, which allows remote attackers to bypass intended access restrictions and read cookies via unspecified vectors.
2Apple
Google
4Chrome
Iphone OsItunes+1 more
Apr 29, 2026
Oct 25, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to stale Cascading Style Sheets (CSS) t...Show more
Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to stale Cascading Style Sheets (CSS) token-sequence data.Show less
2Apple
Google
4Android
ChromeIphone Os+1 more
Apr 29, 2026
Oct 25, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
WebKit, as used in Google Chrome before 15.0.874.102 and Android before 4.4, allows remote attackers to bypass the Same Origin Policy and conduct Universal XSS (UXSS) attacks via vectors related to (1) the DOMWindow::cle...Show more
WebKit, as used in Google Chrome before 15.0.874.102 and Android before 4.4, allows remote attackers to bypass the Same Origin Policy and conduct Universal XSS (UXSS) attacks via vectors related to (1) the DOMWindow::clear function and use of a selection object, (2) the Object::GetRealNamedPropertyInPrototypeChain function and use of an __proto__ property, (3) the HTMLPlugInImageElement::allowedToLoadFrameURL function and use of a javascript: URL, (4) incorrect origins for XSLT-generated documents in the XSLTProcessor::createDocumentFromSource function, and (5) improper handling of synchronous frame loads in the ScriptController::executeIfJavaScriptURL function.Show less
2Apple
Google
3Chrome
Iphone OsSafari
Apr 29, 2026
Oct 25, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Google Chrome before 15.0.874.102 does not properly handle history data, which allows user-assisted remote attackers to spoof the URL bar via unspecified vectors.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Oct 14, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Integer signedness error in Apple Type Services (ATS) in Apple Mac OS X 10.7 before 10.7.2 allows remote attackers to execute arbitrary code via a crafted embedded Type 1 font in a document.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Oct 14, 2011
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Open Directory in Apple Mac OS X 10.7 before 10.7.2 does not require a user to provide the current password before changing this password, which allows remote attackers to bypass intended password-change restrictions by...Show more
Open Directory in Apple Mac OS X 10.7 before 10.7.2 does not require a user to provide the current password before changing this password, which allows remote attackers to bypass intended password-change restrictions by leveraging an unattended workstation.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Oct 14, 2011
N/A· v4
N/A· v3
2.1 LOW· v2
Open Directory in Apple Mac OS X 10.7 before 10.7.2 allows local users to read the password data of arbitrary users via unspecified vectors.
1Apple
1Iphone Os
Apr 29, 2026
Oct 14, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The WiFi component in Apple iOS before 5 stores WiFi credentials in an unspecified file, which makes it easier for remote attackers to obtain sensitive information via a crafted application.
1Apple
1Iphone Os
Apr 29, 2026
Oct 14, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The UIKit Alerts component in Apple iOS before 5 allows remote attackers to cause a denial of service (device hang) via a long tel: URL that triggers a large size for the acceptance dialog.
1Apple
1Iphone Os
Apr 29, 2026
Oct 14, 2011
N/A· v4
N/A· v3
2.1 LOW· v2
The Home screen component in Apple iOS before 5 does not properly support a certain application-switching gesture, which might allow physically proximate attackers to obtain sensitive state information by watching the de...Show more
The Home screen component in Apple iOS before 5 does not properly support a certain application-switching gesture, which might allow physically proximate attackers to obtain sensitive state information by watching the device's screen.Show less