← Back

Apple

apple

8,695 CVEs • 196 products

Products (196)

Click to collapse
Toggle
Iphone Os
iphone_os
Mac Os X
mac_os_x
Macos
macos
Tvos
tvos
Ipados
ipados
Watchos
watchos
Safari
safari
Itunes
itunes
Icloud
icloud
Visionos
visionos
Webkit
webkit
Quicktime
quicktime
Xcode
xcode
Ipad Os
ipad_os
Cups
cups
Apple Tv
apple_tv
Ipod Touch
ipod_touch
Os X Server
os_x_server
Swiftnio
swiftnio
Iphone
iphone
Garageband
garageband
Ichat
ichat
Imageio
imageio
Music
music
Keynote
keynote
Pages
pages
Tv Os
tv_os
Mail
mail
Iphoto
iphoto
Cfnetwork
cfnetwork
Terminal
terminal
Afp Server
afp_server
Time Capsule
time_capsule
Numbers
numbers
Iwork
iwork
Swift
swift
Webobjects
webobjects
Ical
ical
Webcore
webcore
Mdnsresponder
mdnsresponder
Coregraphics
coregraphics
Bonjour
bonjour
Watch Os
watch_os
Logic Pro X
logic_pro_x
Mac Os
mac_os
Appleshare
appleshare
Applescript
applescript
Xsan
xsan
Installer
installer
Imovie
imovie
A Ux
a_ux
Carboncore
carboncore
Java 1.5
java_1.5
Java 1.6
java_1.6
Ipad2
ipad2
Ichat Server
ichat_server
Boot Camp
boot_camp
Apple Support
apple_support
Shortcuts
shortcuts
Shazam
shazam
Files
files
Container
container
Claris Emailer
claris_emailer
802.11n
Ichat Av
ichat_av
Airport Card
airport_card
Weblog Server
weblog_server
Textedit
textedit
Preview
preview
Server Manager
server_manager
Pdfkit
pdfkit

CVEs (8,695)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Oct 26, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Mail.app in Mail for Apple Mac OS X 10.3.9, when using Kerberos 5 for SMTP authentication, can include uninitialized memory in a message, which might allow remote attackers to obtain sensitive information.
1Apple
3Mac Os X
Mac Os X ServerQuicktime
Apr 16, 2026
Oct 26, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
The Java extensions for QuickTime 6.52 and earlier in Apple Mac OS X 10.3.9 allow untrusted applets to call arbitrary functions in system libraries, which allows remote attackers to execute arbitrary code.
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Oct 26, 2005
N/A· v4
N/A· v3
4.6 MEDIUM· v2
SecurityAgent in Apple Mac OS X 10.4.2, under certain circumstances, can cause the "Switch User..." button to appear even though the "Enable fast user switching" setting is disabled, which can allow attackers with physic...Show more
SecurityAgent in Apple Mac OS X 10.4.2, under certain circumstances, can cause the "Switch User..." button to appear even though the "Enable fast user switching" setting is disabled, which can allow attackers with physical access to gain access to the desktop and bypass the "Require password to wake this computer from sleep or screen saver" setting.Show less
2Apple
Perry Kiehtreiber
3Mac Os X
Mac Os X ServerSecurityd
Apr 16, 2026
Oct 26, 2005
N/A· v4
N/A· v3
7.2 HIGH· v2
Authorization Services in securityd for Apple Mac OS X 10.3.9 allows local users to gain privileges by granting themselves certain rights that should be restricted to administrators.
1Apple
3Mac Os X
Mac Os X ServerSafari
Apr 16, 2026
Oct 26, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Safari after 2.0 in Apple Mac OS X 10.3.9 allows remote attackers to bypass domain restrictions via crafted web archives that cause Safari to render them as if they came from a different site.
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Oct 25, 2005
N/A· v4
N/A· v3
2.1 LOW· v2
The malloc function in the libSystem library in Apple Mac OS X 10.3.9 and 10.4.2 allows local users to overwrite arbitrary files by setting the MallocLogFile environment variable to the target file before running a setui...Show more
The malloc function in the libSystem library in Apple Mac OS X 10.3.9 and 10.4.2 allows local users to overwrite arbitrary files by setting the MallocLogFile environment variable to the target file before running a setuid application.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Oct 25, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in ImageIO for Apple Mac OS X 10.4.2, as used by applications such as WebCore and Safari, allows remote attackers to execute arbitrary code via a crafted GIF file.
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Oct 25, 2005
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Buffer overflow in QuickDraw Manager for Apple OS X 10.3.9 and 10.4.2, as used by applications such as Safari, Mail, and Finder, allows remote attackers to execute arbitrary code via a crafted PICT file.
1Apple
1Safari
Apr 16, 2026
Sep 21, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Apple Safari allows remote attackers to cause a denial of service (application crash) via a crafted data:// URL.
2Apple
Easy Software Products
2Cups
Mac Os X
Apr 16, 2026
Aug 19, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
CUPS in Mac OS X 10.3.9 and 10.4.2 allows remote attackers to cause a denial of service (CPU consumption) by sending a partial IPP request and closing the connection.
2Apple
Easy Software Products
2Cups
Mac Os X
Apr 16, 2026
Aug 19, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
CUPS in Mac OS X 10.3.9 and 10.4.2 does not properly close file descriptors when handling multiple simultaneous print jobs, which allows remote attackers to cause a denial of service (printing halt).
1Apple
2Mac Os X
Weblog Server
Apr 16, 2026
Aug 19, 2005
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Weblog Server in Mac OS X 10.4 to 10.4.2 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.
1Apple
2Mac Os X
Safari
Apr 16, 2026
Aug 19, 2005
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Safari in WebKit in Mac OS X 10.4 to 10.4.2 directly accesses URLs within PDF files without the normal security checks, which allows remote attackers to execute arbitrary code via links in a PDF file.
1Apple
1Mac Os X
Apr 16, 2026
Aug 19, 2005
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Buffer overflow in traceroute in Mac OS X 10.3.9 allows local users to execute arbitrary code via unknown vectors.
1Apple
1Mac Os X
Apr 16, 2026
Aug 19, 2005
N/A· v4
N/A· v3
2.1 LOW· v2
The password assistant in Mac OS X 10.4 to 10.4.2, when used to create multiple accounts from the same process, does not reset the suggested password list when the assistant is displayed, which allows attackers to view r...Show more
The password assistant in Mac OS X 10.4 to 10.4.2, when used to create multiple accounts from the same process, does not reset the suggested password list when the assistant is displayed, which allows attackers to view recently used passwords.Show less
1Apple
1Mac Os X
Apr 16, 2026
Aug 19, 2005
N/A· v4
N/A· v3
7.2 HIGH· v2
slpd in Directory Services in Mac OS X 10.3.9 creates insecure temporary files as root, which allows local users to gain privileges.
1Apple
1Mac Os X
Apr 16, 2026
Aug 19, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in servermgrd in Mac OS X 10.3.9 and 10.4.2 allows remote attackers to execute arbitrary code during authentication.
1Apple
2Mac Os X
Safari
Apr 16, 2026
Aug 19, 2005
N/A· v4
N/A· v3
2.6 LOW· v2
Safari in Mac OS X 10.3.9 and 10.4.2 submits forms from an XSL formatted page to the next page that is browsed by the user, which causes form data to be sent to the wrong site.
1Apple
2Mac Os X
Safari
Apr 16, 2026
Aug 19, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Safari in Mac OS X 10.3.9 and 10.4.2, when rendering Rich Text Format (RTF) files, can directly access URLs without performing the normal security checks, which allows remote attackers to execute arbitrary commands.
1Apple
1Mac Os X
Apr 16, 2026
Aug 19, 2005
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Quartz Composer Screen Saver in Mac OS X 10.4.2 allows local users to access links from the RSS Visualizer even when a password is required.