← Back

Apple

apple

8,695 CVEs • 196 products

Products (196)

Click to collapse
Toggle
Iphone Os
iphone_os
Mac Os X
mac_os_x
Macos
macos
Tvos
tvos
Ipados
ipados
Watchos
watchos
Safari
safari
Itunes
itunes
Icloud
icloud
Visionos
visionos
Webkit
webkit
Quicktime
quicktime
Xcode
xcode
Ipad Os
ipad_os
Cups
cups
Apple Tv
apple_tv
Ipod Touch
ipod_touch
Os X Server
os_x_server
Swiftnio
swiftnio
Iphone
iphone
Garageband
garageband
Ichat
ichat
Imageio
imageio
Music
music
Keynote
keynote
Pages
pages
Tv Os
tv_os
Mail
mail
Iphoto
iphoto
Cfnetwork
cfnetwork
Terminal
terminal
Afp Server
afp_server
Time Capsule
time_capsule
Numbers
numbers
Iwork
iwork
Swift
swift
Webobjects
webobjects
Ical
ical
Webcore
webcore
Mdnsresponder
mdnsresponder
Coregraphics
coregraphics
Bonjour
bonjour
Watch Os
watch_os
Logic Pro X
logic_pro_x
Mac Os
mac_os
Appleshare
appleshare
Applescript
applescript
Xsan
xsan
Installer
installer
Imovie
imovie
A Ux
a_ux
Carboncore
carboncore
Java 1.5
java_1.5
Java 1.6
java_1.6
Ipad2
ipad2
Ichat Server
ichat_server
Boot Camp
boot_camp
Apple Support
apple_support
Shortcuts
shortcuts
Shazam
shazam
Files
files
Container
container
Claris Emailer
claris_emailer
802.11n
Ichat Av
ichat_av
Airport Card
airport_card
Weblog Server
weblog_server
Textedit
textedit
Preview
preview
Server Manager
server_manager
Pdfkit
pdfkit

CVEs (8,695)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
1Darwin Streaming Server
Apr 16, 2026
Aug 27, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
parse_xml.cgi in Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to obtain the source code for parseable files via the filename parameter.
1Apple
1Darwin Streaming Server
Apr 16, 2026
Aug 27, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to cause a denial of service (crash) via a request to view_broadcast.cgi that does not contain the required parameters.
1Apple
1Darwin Streaming Server
Apr 16, 2026
Aug 27, 2003
N/A· v4
N/A· v3
10.0 HIGH· v2
Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to cause a denial of service (crash) via an MS-DOS device name (e.g. AUX) in a request to HTTP port 1220, a different vulnerability than CVE...Show more
Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to cause a denial of service (crash) via an MS-DOS device name (e.g. AUX) in a request to HTTP port 1220, a different vulnerability than CVE-2003-0502.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Aug 18, 2003
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The screen saver in MacOS X allows users with physical access to cause the screen saver to crash and gain access to the underlying session via a large number of characters in the password field, possibly triggering a buf...Show more
The screen saver in MacOS X allows users with physical access to cause the screen saver to crash and gain access to the underlying session via a large number of characters in the password field, possibly triggering a buffer overflow.Show less
1Apple
1Afp Server
Apr 16, 2026
Jul 24, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unknown vulnerability in Apple File Service (AFP Server) for Mac OS X Server, when sharing files on a UFS or re-shared NFS volume, allows remote attackers to overwrite arbitrary files.
1Apple
1Mac Os X
Apr 16, 2026
Jun 16, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
The Kerberos login authentication feature in Mac OS X, when used with an LDAPv3 server and LDAP bind authentication, may send cleartext passwords to the LDAP server when the AuthenticationAuthority attribute is not set.
4Apple
KdeRedhat+1 more
6Kde
Konqueror EmbeddedLinux+3 more
Apr 16, 2026
Jun 16, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle attack.
1Apple
1802.11n
Apr 16, 2026
Jun 16, 2003
N/A· v4
N/A· v3
7.6 HIGH· v2
The administration capability for Apple AirPort 802.11 wireless access point devices uses weak encryption (XOR with a fixed key) for protecting authentication credentials, which could allow remote attackers to obtain adm...Show more
The administration capability for Apple AirPort 802.11 wireless access point devices uses weak encryption (XOR with a fixed key) for protecting authentication credentials, which could allow remote attackers to obtain administrative access via sniffing when the capability is available via Ethernet or non-WEP connections.Show less
1Apple
1Mac Os X Server
Apr 16, 2026
Jun 13, 2003
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Information leak in dsimportexport for Apple Macintosh OS X Server 10.2.6 allows local users to obtain the username and password of the account running the tool.
2Apple
Kde
2Konqueror Embedded
Safari
Apr 16, 2026
Jun 9, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Safari 1.0 Beta 2 (v73) and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates.
1Apple
1Mac Os X
Apr 16, 2026
Jun 9, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
IPSec in Mac OS X before 10.2.6 does not properly handle certain incoming security policies that match by port, which could allow traffic that is not explicitly allowed by the policies.
6Apple
CompaqHp+3 more
8Cifs 9000 Server
Hp UxMac Os X+5 more
Apr 16, 2026
May 5, 2003
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
May 5, 2003
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Mac OS X before 10.2.5 allows guest users to modify the permissions of the DropBox folder and read unauthorized files.
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
May 5, 2003
N/A· v4
N/A· v3
7.2 HIGH· v2
DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitrary commands by modifying the PATH to point to a directory containing a...Show more
DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitrary commands by modifying the PATH to point to a directory containing a malicious touch program.Show less
1Apple
1Quicktime
Apr 16, 2026
Apr 2, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in Apple QuickTime Player 5.x and 6.0 for Windows allows remote attackers to execute arbitrary code via a long QuickTime URL.
1Apple
1Quicktime Darwin Mp3 Broadcaster
Apr 16, 2026
Mar 7, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in the MP3 broadcasting module of Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via a long filename.
1Apple
2Darwin Streaming Server
Quicktime Streaming Server
Apr 16, 2026
Mar 7, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to the rtsp DESCRIBE metho...Show more
Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to the rtsp DESCRIBE method, which is inserted into a log file and executed when the log is viewed using a browser.Show less
1Apple
2Darwin Streaming Server
Quicktime Streaming Server
Apr 16, 2026
Mar 7, 2003
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to insert arbitrary script via the filename par...Show more
Cross-site scripting (XSS) vulnerability in parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to insert arbitrary script via the filename parameter, which is inserted into an error message.Show less
1Apple
2Darwin Streaming Server
Quicktime Streaming Server
Apr 16, 2026
Mar 7, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to list arbitrary directories.
1Apple
2Darwin Streaming Server
Quicktime Streaming Server
Apr 16, 2026
Mar 7, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to obtain the physical path of the server's installation path via a NULL file parameter.