VendorsApplemacosall versions
Vulnerabilities

Apple MACOS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7076CVEs
CVE-2022-27790
Adobe Acrobat Reader DC Font Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.119
CVE-2022-28238
Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.119
CVE-2022-28236
Adobe Acrobat Reader DC Annotation Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.116
CVE-2021-44710
Adobe Acrobat Reader Use-after-free could lead to Arbitrary code execution
Published 2022-01-14 · Modified
9.3EPSS 0.116
CVE-2010-0987
Heap-based buffer overflow in Adobe Shockwave Player before 11.5.7.609 might allow remote attackers to execute arbitrary code via crafted embedded fonts in a Shockwave file.
Published 2010-05-13 · Modified
9.3EPSS 0.114
CVE-2022-24104
Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.111
CVE-2022-28243
Adobe Acrobat Reader DC Doc Object Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.110
CVE-2021-44704
Adobe Acrobat Reader Use-After-Free could lead to Arbitrary code execution
Published 2022-01-14 · Modified
9.3EPSS 0.108
CVE-2020-27932
A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. A malicious application may be able to execute arbitrary code with kernel privileges.
Published 2020-12-08 · Analyzed
9.3KEVEPSS 0.103
CVE-2022-27787
Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.103
CVE-2020-3757
Adobe Flash Player versions 32.0.0.321 and earlier, 32.0.0.314 and earlier, 32.0.0.321 and earlier, and 32.0.0.255 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2020-02-13 · Modified
9.3EPSS 0.102
CVE-2021-44711
Adobe Acrobat Reader DC annotation gestures integer overflow vulnerability
Published 2022-01-14 · Modified
9.3EPSS 0.100
CVE-2020-11581
An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, allows a man-in-the-middle attacker to perform OS command injection attacks (against a client) via shell metacharacters to the doCustomRemediateInstructions method, because Runtime.getRuntime().exec() is used.
Published 2020-04-06 · Modified
9.3EPSS 0.098
CVE-2022-27792
Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.098
CVE-2022-27793
Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.098
CVE-2021-44706
Adobe Acrobat Reader Collab.registerReview Use-After-Free Remote Execution Vulnerability
Published 2022-01-14 · Modified
9.3EPSS 0.087
CVE-2021-45060
Adobe Acrobat Reader DC TTF Font Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2022-01-14 · Modified
9.3EPSS 0.086
CVE-2021-44707
Adobe Acrobat Reader DC OTF Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2022-01-14 · Modified
9.3EPSS 0.084
CVE-2021-45061
Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2022-01-14 · Modified
9.3EPSS 0.079
CVE-2012-2034
Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x, and Adobe AIR before 3.3.0.3610, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2037.
Published 2012-06-09 · Analyzed
9.3KEVEPSS 0.078
CVE-2010-1281
iml32.dll in Adobe Shockwave Player before 11.5.7.609 does not validate a certain value from a file before using it in file-pointer calculations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file.
Published 2010-05-13 · Modified
9.3EPSS 0.075
CVE-2021-21051
Adobe Photoshop Buffer Overflow Vulnerability Could Lead To Remote Code Execution Vulnerability
Published 2021-02-11 · Modified
9.3EPSS 0.074
CVE-2021-44705
Adobe Acrobat Reader Use-After-Free could lead to Arbitrary code execution
Published 2022-01-14 · Modified
9.3EPSS 0.074
CVE-2010-0130
Integer overflow in Adobe Shockwave Player before 11.5.7.609 might allow remote attackers to execute arbitrary code via a crafted .dir (aka Director) file.
Published 2010-05-13 · Modified
9.3EPSS 0.073
CVE-2015-0312
Double free vulnerability in Adobe Flash Player before 13.0.0.264 and 14.x through 16.x before 16.0.0.296 on Windows and OS X and before 11.2.202.440 on Linux allows attackers to execute arbitrary code via unspecified vectors.
Published 2015-01-28 · Modified
9.3EPSS 0.071
CVE-2021-36005
Adobe Photoshop PSD File Parsing Stack Overflow Vulnerability
Published 2021-08-20 · Modified
9.3EPSS 0.068
CVE-2022-30661
Adobe InDesign Font Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2022-06-16 · Modified
9.3EPSS 0.064
CVE-2022-30658
Adobe InDesign Font Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2022-06-16 · Modified
9.3EPSS 0.064
CVE-2022-30654
Adobe InCopy Font Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2022-06-16 · Modified
9.3EPSS 0.064
CVE-2022-30650
Adobe InCopy Font Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2022-06-16 · Modified
9.3EPSS 0.064
CVE-2019-7976
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2019-08-26 · Modified
9.3EPSS 0.064
CVE-2019-7994
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2019-08-26 · Modified
9.3EPSS 0.064
CVE-2010-1292
The implementation of pami RIFF chunk parsing in Adobe Shockwave Player before 11.5.7.609 does not validate a certain value from a file before using it in file-pointer calculations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file.
Published 2010-05-13 · Modified
9.3EPSS 0.064
CVE-2010-0129
Multiple integer overflows in Adobe Shockwave Player before 11.5.7.609 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .dir (aka Director) file that triggers an array index error.
Published 2010-05-13 · Modified
9.3EPSS 0.063
CVE-2010-1283
Adobe Shockwave Player before 11.5.7.609 does not properly parse 3D objects in .dir (aka Director) files, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a modified field in a 0xFFFFFF49 record.
Published 2010-05-13 · Modified
9.3EPSS 0.063
CVE-2021-42631
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below deserializes attacker controlled leading to pre-auth remote code execution.
Published 2022-01-31 · Modified
9.3EPSS 0.062
CVE-2012-2035
Stack-based buffer overflow in Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x, and Adobe AIR before 3.3.0.3610, allows attackers to execute arbitrary code via unspecified vectors.
Published 2012-06-09 · Modified
9.3EPSS 0.059
CVE-2020-9722
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .
Published 2020-08-19 · Modified
9.3EPSS 0.058
CVE-2010-1288
Buffer overflow in Adobe Shockwave Player before 11.5.7.609 might allow attackers to execute arbitrary code via unspecified vectors.
Published 2010-05-13 · Modified
9.3EPSS 0.058
CVE-2015-4451
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-4435, CVE-2015-4438, CVE-2015-4441, CVE-2015-4445, CVE-2015-4447, CVE-2015-4452, CVE-2015-5085, and CVE-2015-5086.
Published 2015-07-15 · Modified
9.3EPSS 0.058
← Prev16 / 177Next →