← Back

Apple

apple

8,695 CVEs • 196 products

Products (196)

Click to collapse
Toggle
Iphone Os
iphone_os
Mac Os X
mac_os_x
Macos
macos
Tvos
tvos
Ipados
ipados
Watchos
watchos
Safari
safari
Itunes
itunes
Icloud
icloud
Visionos
visionos
Webkit
webkit
Quicktime
quicktime
Xcode
xcode
Ipad Os
ipad_os
Cups
cups
Apple Tv
apple_tv
Ipod Touch
ipod_touch
Os X Server
os_x_server
Swiftnio
swiftnio
Iphone
iphone
Garageband
garageband
Ichat
ichat
Imageio
imageio
Music
music
Keynote
keynote
Pages
pages
Tv Os
tv_os
Mail
mail
Iphoto
iphoto
Cfnetwork
cfnetwork
Terminal
terminal
Afp Server
afp_server
Time Capsule
time_capsule
Numbers
numbers
Iwork
iwork
Swift
swift
Webobjects
webobjects
Ical
ical
Webcore
webcore
Mdnsresponder
mdnsresponder
Coregraphics
coregraphics
Bonjour
bonjour
Watch Os
watch_os
Logic Pro X
logic_pro_x
Mac Os
mac_os
Appleshare
appleshare
Applescript
applescript
Xsan
xsan
Installer
installer
Imovie
imovie
A Ux
a_ux
Carboncore
carboncore
Java 1.5
java_1.5
Java 1.6
java_1.6
Ipad2
ipad2
Ichat Server
ichat_server
Boot Camp
boot_camp
Apple Support
apple_support
Shortcuts
shortcuts
Shazam
shazam
Files
files
Container
container
Claris Emailer
claris_emailer
802.11n
Ichat Av
ichat_av
Airport Card
airport_card
Weblog Server
weblog_server
Textedit
textedit
Preview
preview
Server Manager
server_manager
Pdfkit
pdfkit

CVEs (8,695)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
1Afp Server
Apr 16, 2026
Jun 16, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in the legacy client support for AFP Server for Mac OS X 10.4.1 allows attackers to execute arbitrary code.
1Apple
1Afp Server
Apr 16, 2026
Jun 16, 2005
N/A· v4
N/A· v3
2.1 LOW· v2
AFP Server for Mac OS X 10.4.1, when using an ACL enabled volume, does not properly remove an ACL when a file is copied to a directory that does not use ACLs, which will override the POSIX file permissions for that ACL.
1Apple
1Mac Os X
Apr 16, 2026
Jun 13, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Dashboard in Apple Mac OS X Tiger 10.4 allows attackers to execute arbitrary commands by overriding the behavior of system widgets via a user widget with the same bundle identifier (CFBundleIdentifier), a different vulne...Show more
Dashboard in Apple Mac OS X Tiger 10.4 allows attackers to execute arbitrary commands by overriding the behavior of system widgets via a user widget with the same bundle identifier (CFBundleIdentifier), a different vulnerability than CVE-2005-1474.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Jun 13, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Dashboard in Apple Mac OS X 10.4.1 allows remote attackers to install widgets via Safari without prompting the user, a different vulnerability than CVE-2005-1933.
1Apple
1Mac Os X
Apr 16, 2026
Jun 13, 2005
N/A· v4
N/A· v3
4.6 MEDIUM· v2
SecurityAgent in Apple Mac OS X 10.4.1 allows attackers with physical access to bypass the locked screensaver and launch background applications by opening a URL from a text input field.
1Apple
1Mac Os X
Apr 16, 2026
Jun 8, 2005
N/A· v4
N/A· v3
4.6 MEDIUM· v2
MCX Client for Apple Mac OS X 10.4.x up to 10.4.1 insecurely logs Portable Home Directory credentials, which allows local users to obtain the credentials.
1Apple
1Mac Os X Server
Apr 16, 2026
Jun 8, 2005
N/A· v4
N/A· v3
3.7 LOW· v2
Apple Mac OS X 10.4.x up to 10.4.1 sets insecure world- and group-writable permissions for the (1) system cache folder and (2) Dashboard system widgets, which allows local users to conduct unauthorized file operations vi...Show more
Apple Mac OS X 10.4.x up to 10.4.1 sets insecure world- and group-writable permissions for the (1) system cache folder and (2) Dashboard system widgets, which allows local users to conduct unauthorized file operations via "file race conditions."Show less
1Apple
1Mac Os X Server
Apr 16, 2026
Jun 8, 2005
N/A· v4
N/A· v3
2.1 LOW· v2
launchd 106 in Apple Mac OS X 10.4.x up to 10.4.1 allows local users to overwrite arbitrary files via a symlink attack on the socket file in an insecure temporary directory.
1Apple
1Mac Os X Server
Apr 16, 2026
Jun 8, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
NFS on Apple Mac OS X 10.4.x up to 10.4.1 does not properly obey the -network or -mask flags for a filesystem and exports it to everyone, which allows remote attackers to bypass intended access restrictions.
1Apple
1Mac Os X Server
Apr 16, 2026
Jun 8, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
LaunchServices in Apple Mac OS X 10.4.x up to 10.4.1 does not properly mark file extensions and MIME types as unsafe if an Apple Uniform Type Identifier (UTI) is not created when the type is added to the database of unsa...Show more
LaunchServices in Apple Mac OS X 10.4.x up to 10.4.1 does not properly mark file extensions and MIME types as unsafe if an Apple Uniform Type Identifier (UTI) is not created when the type is added to the database of unsafe types, which could allow attackers to bypass intended restrictions.Show less
1Apple
1Keynote
Apr 16, 2026
May 26, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Apple Keynote 2.0 and 2.0.1 allows remote attackers to read arbitrary files via the keynote: URI handler in a crafted Keynote presentation.
1Apple
1Mac Os X
Apr 16, 2026
May 19, 2005
N/A· v4
N/A· v3
2.1 LOW· v2
Certain system calls in Apple Mac OS X 10.4.1 do not properly enforce the permissions of certain directories without the POSIX read bit set, but with the execute bits set for group or other, which allows local users to l...Show more
Certain system calls in Apple Mac OS X 10.4.1 do not properly enforce the permissions of certain directories without the POSIX read bit set, but with the execute bits set for group or other, which allows local users to list files in otherwise restricted directories.Show less
4Apple
BzipCanonical+1 more
4Bzip2
Debian LinuxMac Os X+1 more
Apr 16, 2026
May 19, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (a.k.a "decompression bomb").
2Adobe
Apple
2Mac Os X
Version Cue
Apr 16, 2026
May 17, 2005
N/A· v4
N/A· v3
7.2 HIGH· v2
The (1) stopserver.sh and (2) startserver.sh scripts in Adobe Version Cue on Mac OS X uses the current working directory to find and execute the productname.sh script, which allows local users to execute arbitrary code b...Show more
The (1) stopserver.sh and (2) startserver.sh scripts in Adobe Version Cue on Mac OS X uses the current working directory to find and execute the productname.sh script, which allows local users to execute arbitrary code by copying and calling the scripts from a user-controlled directory.Show less
1Apple
1Itunes
Apr 16, 2026
May 16, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in Apple iTunes before 4.8 allows remote attackers to execute arbitrary code via a crafted MPEG4 file.
1Apple
1Quicktime
Apr 16, 2026
May 12, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Apple QuickTime Player 7.0 on Mac OS X 10.4 allows remote attackers to obtain sensitive information via a .mov file with a Quartz Composer composition (.qtz) file that uses certain patches to read local information, then...Show more
Apple QuickTime Player 7.0 on Mac OS X 10.4 allows remote attackers to obtain sensitive information via a .mov file with a Quartz Composer composition (.qtz) file that uses certain patches to read local information, then other patches to send the information to the attacker.Show less
1Apple
1Mac Os X
Apr 16, 2026
May 12, 2005
N/A· v4
N/A· v3
7.2 HIGH· v2
Unknown vulnerability in the nfs_mount call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments.
1Apple
1Mac Os X
Apr 16, 2026
May 12, 2005
N/A· v4
N/A· v3
2.1 LOW· v2
Unknown vulnerability in the setsockopt system call in Mac OS X 10.3.9 and earlier allows local users to cause a denial of service (memory exhaustion) via crafted arguments.
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
May 12, 2005
N/A· v4
N/A· v3
7.2 HIGH· v2
Integer overflow in the searchfs system call in Mac OS X 10.3.9 and earlier allows local users to execute arbitrary code via crafted parameters.
1Apple
1Mac Os X
Apr 16, 2026
May 12, 2005
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Stack-based buffer overflow in the semop system call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments.