VendorsApplemacosall versions
Vulnerabilities

Apple MACOS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7076CVEs
CVE-2015-4452
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-4435, CVE-2015-4438, CVE-2015-4441, CVE-2015-4445, CVE-2015-4447, CVE-2015-4451, CVE-2015-5085, and CVE-2015-5086.
Published 2015-07-15 · Modified
9.3EPSS 0.058
CVE-2021-21099
Adobe InDesign PCX file parsing out-of-bounds write vulnerability could lead to remote code execution
Published 2021-06-28 · Modified
9.3EPSS 0.058
CVE-2021-36065
Adobe Photoshop Heap-Based Buffer Overflow Could Lead To Arbitrary Code Execution
Published 2021-09-01 · Modified
9.3EPSS 0.057
CVE-2021-42635
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use a hardcoded APP_KEY value, leading to pre-auth remote code execution.
Published 2022-01-31 · Modified
9.3EPSS 0.056
CVE-2021-42638
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below do not sanitize user input resulting in pre-auth remote code execution.
Published 2022-02-01 · Modified
9.3EPSS 0.055
CVE-2021-30900
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 14.8.1 and iPadOS 14.8.1, iOS 15.1 and iPadOS 15.1. A malicious application may be able to execute arbitrary code with kernel privileges.
Published 2021-08-24 · Analyzed
9.3KEVEPSS 0.052
CVE-2021-42731
Adobe Indesign Buffer Overflow Could Lead to Remote Code Execution
Published 2021-11-16 · Modified
9.3EPSS 0.052
CVE-2022-28234
Adobe Acrobat Reader DC Heap Overflow Could Lead to RCE
Published 2022-05-11 · Modified
9.3EPSS 0.051
CVE-2010-0127
Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted FFFFFF45h Shockwave 3D blocks in a Shockwave file.
Published 2010-05-13 · Modified
9.3EPSS 0.051
CVE-2010-0986
Adobe Shockwave Player before 11.5.7.609 does not properly process asset entries, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted Shockwave file.
Published 2010-05-13 · Modified
9.3EPSS 0.051
CVE-2010-0128
Integer signedness error in dirapi.dll in Adobe Shockwave Player before 11.5.7.609 and Adobe Director before 11.5.7.609 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .dir file that triggers an invalid read operation.
Published 2010-05-13 · Modified
9.3EPSS 0.050
CVE-2020-9693
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .
Published 2020-08-19 · Modified
9.3EPSS 0.050
CVE-2012-2036
Integer overflow in Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x, and Adobe AIR before 3.3.0.3610, allows attackers to execute arbitrary code via unspecified vectors.
Published 2012-06-09 · Modified
9.3EPSS 0.049
CVE-2016-4156
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
Published 2016-06-16 · Modified
9.3EPSS 0.048
CVE-2012-2039
Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x, and Adobe AIR before 3.3.0.3610, allows attackers to execute arbitrary code or cause a denial of service (NULL pointer dereference) via unspecified vectors.
Published 2012-06-09 · Modified
9.3EPSS 0.047
CVE-2021-40709
Adobe Photoshop Buffer Overflow leads to Arbitrary Code Execution
Published 2021-09-27 · Modified
9.3EPSS 0.046
CVE-2022-24092
Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2022-03-18 · Modified
9.3EPSS 0.045
CVE-2020-9704
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution .
Published 2020-08-19 · Modified
9.3EPSS 0.043
CVE-2020-9701
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution .
Published 2020-08-19 · Modified
9.3EPSS 0.043
CVE-2020-9699
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution .
Published 2020-08-19 · Modified
9.3EPSS 0.043
CVE-2020-9700
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution .
Published 2020-08-19 · Modified
9.3EPSS 0.043
CVE-2022-23187
Adobe Illustrator 2022 Buffer Overflow could lead to Arbitrary code execution
Published 2022-03-11 · Modified
9.3EPSS 0.043
CVE-2010-1290
Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1286, CVE-2010-1287, CVE-2010-1289, and CVE-2010-1291.
Published 2010-05-13 · Modified
9.3EPSS 0.043
CVE-2020-9746
Exploitable NULL pointer deref could lead to arbitrary code execution
Published 2020-10-14 · Modified
9.3EPSS 0.043
CVE-2020-9698
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution .
Published 2020-08-19 · Modified
9.3EPSS 0.042
CVE-2021-30869
A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 12.5.5, iOS 14.4 and iPadOS 14.4, macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, Security Update 2021-006 Catalina. A malicious application may be able to execute arbitrary code with kernel privileges. Apple is aware of reports that an exploit for this issue exists in the wild.
Published 2021-08-24 · Analyzed
9.3KEVEPSS 0.041
CVE-2022-24091
Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2022-03-18 · Modified
9.3EPSS 0.041
CVE-2012-2040
Untrusted search path vulnerability in the installer in Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x, and Adobe AIR before 3.3.0.3610, allows local users to gain privileges via a Trojan horse executable file in an unspecified directory.
Published 2012-06-09 · Modified
9.3EPSS 0.040
CVE-2011-4374
Integer overflow in Adobe Reader 9.x before 9.4.6 on Linux allows attackers to execute arbitrary code via unspecified vectors.
Published 2012-01-19 · Modified
9.3EPSS 0.040
CVE-2010-1284
Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1286, CVE-2010-1287, CVE-2010-1289, CVE-2010-1290, and CVE-2010-1291.
Published 2010-05-13 · Modified
9.3EPSS 0.040
CVE-2010-1289
Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1286, CVE-2010-1287, CVE-2010-1290, and CVE-2010-1291.
Published 2010-05-13 · Modified
9.3EPSS 0.040
CVE-2016-4132
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
Published 2016-06-16 · Modified
9.3EPSS 0.040
CVE-2021-21054
Adobe Illustrator Out-Of-Bounds Write Vulnerability Could Lead To Remote Code Execution Vulnerability
Published 2021-02-11 · Modified
9.3EPSS 0.040
CVE-2022-24095
Adobe After Effects Stack-based Buffer Overflow Arbitrary code execution
Published 2022-03-11 · Modified
9.3EPSS 0.039
CVE-2022-24096
Adobe After Effects Heap-based Buffer Overflow Arbitrary code execution
Published 2022-03-11 · Modified
9.3EPSS 0.039
CVE-2022-24094
Adobe After Effects Stack-based Buffer Overflow Arbitrary code execution
Published 2022-03-11 · Modified
9.3EPSS 0.039
CVE-2022-27783
Adobe After Effects Stack Buffer Overflow Could Lead To RCE
Published 2022-05-06 · Modified
9.3EPSS 0.039
CVE-2021-28565
Adobe Acrobat Reader out-of-bounds read could lead to information exposure
Published 2021-09-02 · Modified
9.3EPSS 0.039
CVE-2022-27784
Adobe After Effects Stack Buffer Overflow Could Lead To RCE
Published 2022-05-06 · Modified
9.3EPSS 0.039
CVE-2019-7042
Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution .
Published 2019-05-24 · Modified
9.3EPSS 0.039
← Prev17 / 177Next →