← Back

Apple

apple

8,695 CVEs • 196 products

Products (196)

Click to collapse
Toggle
Iphone Os
iphone_os
Mac Os X
mac_os_x
Macos
macos
Tvos
tvos
Ipados
ipados
Watchos
watchos
Safari
safari
Itunes
itunes
Icloud
icloud
Visionos
visionos
Webkit
webkit
Quicktime
quicktime
Xcode
xcode
Ipad Os
ipad_os
Cups
cups
Apple Tv
apple_tv
Ipod Touch
ipod_touch
Os X Server
os_x_server
Swiftnio
swiftnio
Iphone
iphone
Garageband
garageband
Ichat
ichat
Imageio
imageio
Music
music
Keynote
keynote
Pages
pages
Tv Os
tv_os
Mail
mail
Iphoto
iphoto
Cfnetwork
cfnetwork
Terminal
terminal
Afp Server
afp_server
Time Capsule
time_capsule
Numbers
numbers
Iwork
iwork
Swift
swift
Webobjects
webobjects
Ical
ical
Webcore
webcore
Mdnsresponder
mdnsresponder
Coregraphics
coregraphics
Bonjour
bonjour
Watch Os
watch_os
Logic Pro X
logic_pro_x
Mac Os
mac_os
Appleshare
appleshare
Applescript
applescript
Xsan
xsan
Installer
installer
Imovie
imovie
A Ux
a_ux
Carboncore
carboncore
Java 1.5
java_1.5
Java 1.6
java_1.6
Ipad2
ipad2
Ichat Server
ichat_server
Boot Camp
boot_camp
Apple Support
apple_support
Shortcuts
shortcuts
Shazam
shazam
Files
files
Container
container
Claris Emailer
claris_emailer
802.11n
Ichat Av
ichat_av
Airport Card
airport_card
Weblog Server
weblog_server
Textedit
textedit
Preview
preview
Server Manager
server_manager
Pdfkit
pdfkit

CVEs (8,695)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
2Mac Os X
Quicktime
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
QuickTime in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted JPEG2000 image.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
QuickLook in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via an Excel spreadsheet with a crafted formula that...Show more
QuickLook in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via an Excel spreadsheet with a crafted formula that uses unspecified opcodes.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Libinfo in Apple Mac OS X before 10.6.7 does not properly handle an unspecified integer field in an NFS RPC packet, which allows remote attackers to cause a denial of service (lockd, statd, mountd, or portmap outage) via...Show more
Libinfo in Apple Mac OS X before 10.6.7 does not properly handle an unspecified integer field in an NFS RPC packet, which allows remote attackers to cause a denial of service (lockd, statd, mountd, or portmap outage) via a crafted packet, related to an "integer truncation issue."Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
7.2 HIGH· v2
The i386_set_ldt system call in the kernel in Apple Mac OS X before 10.6.7 does not properly handle call gates, which allows local users to gain privileges via vectors involving the creation of a call gate entry.
1Apple
3Imageio
Mac Os XMac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Integer overflow in ImageIO in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted XBM image.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
2.1 LOW· v2
Integer overflow in HFS in Apple Mac OS X before 10.6.7 allows local users to read arbitrary (1) HFS, (2) HFS+, or (3) HFS+J files via a crafted F_READBOOTSTRAP ioctl call.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
CoreText in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a document that contains a crafted embedded font.
1Apple
3Carboncore
Mac Os XMac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
2.1 LOW· v2
The FSFindFolder API in CarbonCore in Apple Mac OS X before 10.6.7 provides a world-readable directory in response to a call with the kTemporaryFolderType flag, which allows local users to obtain potentially sensitive in...Show more
The FSFindFolder API in CarbonCore in Apple Mac OS X before 10.6.7 provides a world-readable directory in response to a call with the kTemporaryFolderType flag, which allows local users to obtain potentially sensitive information by accessing this directory.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code via a document that contains a crafted SFNT table in an embedded font.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code via a document that contains a crafted embedded Type 1 font.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code via a document that contains a crafted embedded TrueType font.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code via a document that contains a crafted embedded OpenType font.
1Apple
3Applescript
Mac Os XMac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple format string vulnerabilities in AppleScript in Apple Mac OS X before 10.6.7 allow context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifi...Show more
Multiple format string vulnerabilities in AppleScript in Apple Mac OS X before 10.6.7 allow context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a (1) display dialog or (2) display alert command in a dialog in an AppleScript Studio application.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
4.9 MEDIUM· v2
AirPort in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to cause a denial of service (divide-by-zero error and reboot) via Wi-Fi frames on the local wireless network, a different vulnerability than CVE-2011-...Show more
AirPort in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to cause a denial of service (divide-by-zero error and reboot) via Wi-Fi frames on the local wireless network, a different vulnerability than CVE-2011-0162.Show less
1Apple
3Apple Tv
Iphone OsTvos
Apr 29, 2026
Mar 11, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The stateless address autoconfiguration (aka SLAAC) functionality in the IPv6 networking implementation in Apple iOS before 4.3 and Apple TV before 4.2 places the MAC address into the IPv6 address, which makes it easier...Show more
The stateless address autoconfiguration (aka SLAAC) functionality in the IPv6 networking implementation in Apple iOS before 4.3 and Apple TV before 4.2 places the MAC address into the IPv6 address, which makes it easier for remote IPv6 servers to track users by logging source IPv6 addresses.Show less
1Apple
2Safari
Webkit
Apr 29, 2026
Mar 11, 2011
N/A· v4
N/A· v3
2.6 LOW· v2
WebKit in Apple Safari before 5.0.4, when the Web Inspector is used, does not properly handle the window.console._inspectorCommandLineAPI property, which allows user-assisted remote attackers to bypass the Same Origin Po...Show more
WebKit in Apple Safari before 5.0.4, when the Web Inspector is used, does not properly handle the window.console._inspectorCommandLineAPI property, which allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted web site.Show less
1Apple
2Safari
Webkit
Apr 29, 2026
Mar 11, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The windows functionality in WebKit in Apple Safari before 5.0.4 allows remote attackers to bypass the Same Origin Policy, and force the upload of arbitrary local files from a client computer, via a crafted web site.
1Apple
2Safari
Webkit
Apr 29, 2026
Mar 11, 2011
N/A· v4
N/A· v3
5.8 MEDIUM· v2
The HTML5 drag and drop functionality in WebKit in Apple Safari before 5.0.4 allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via vectors related to the dragging of...Show more
The HTML5 drag and drop functionality in WebKit in Apple Safari before 5.0.4 allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via vectors related to the dragging of content. NOTE: this might overlap CVE-2011-0778.Show less
1Apple
3Iphone Os
SafariWebkit
Apr 29, 2026
Mar 11, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle unspecified "cached resources," which allows remote attackers to cause a denial of service (resource unavailability) via a crafted...Show more
WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle unspecified "cached resources," which allows remote attackers to cause a denial of service (resource unavailability) via a crafted web site that conducts a cache-poisoning attack.Show less
1Apple
3Apple Tv
Iphone OsTvos
Apr 29, 2026
Mar 11, 2011
N/A· v4
N/A· v3
7.8 HIGH· v2
Wi-Fi in Apple iOS before 4.3 and Apple TV before 4.2 does not properly perform bounds checking for Wi-Fi frames, which allows remote attackers to cause a denial of service (device reset) via unspecified traffic on the l...Show more
Wi-Fi in Apple iOS before 4.3 and Apple TV before 4.2 does not properly perform bounds checking for Wi-Fi frames, which allows remote attackers to cause a denial of service (device reset) via unspecified traffic on the local wireless network.Show less