VendorsApplemacosany version
Vulnerabilities

Apple MACOS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7031CVEs
CVE-2021-28548
Adobe Photoshop parsing JS buffer overflow vulnerability could lead to arbitrary code execution
Published 2021-04-15 · Modified
7.8EPSS 0.064
CVE-2022-34219
Adobe Acrobat Reader DC Font Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2022-07-15 · Modified
7.8EPSS 0.062
CVE-2022-34216
Adobe Acrobat Reader DC PDF Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2022-07-15 · Modified
7.8EPSS 0.062
CVE-2020-9883
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing a maliciously crafted image may lead to arbitrary code execution.
Published 2020-10-22 · Modified
7.8EPSS 0.060
CVE-2024-30279
ZDI-CAN-22887: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2024-05-23 · Analyzed
7.8EPSS 0.059
CVE-2022-40304
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.
Published 2022-11-23 · Modified
7.8EPSS 0.058
CVE-2022-32917
The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..
Published 2022-09-20 · Analyzed
7.8KEVEPSS 0.056
CVE-2023-29320
ZDI-CAN-20712: Adobe Acrobat Blacklist Bypass Design flaw
Published 2023-08-10 · Modified
7.8EPSS 0.054
CVE-2019-8066
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .
Published 2020-07-06 · Modified
7.8EPSS 0.053
CVE-2021-40725
Adobe Acrobat Reader DC AcroForm listbox Use-After-Free Remote Code Execution Vulnerability
Published 2021-10-07 · Modified
7.8EPSS 0.053
CVE-2021-40726
Adobe Acrobat Reader DC AcroForm Field Use-After-Free Remote Code Execution Vulnerability
Published 2021-10-07 · Modified
7.8EPSS 0.053
CVE-2021-28632
ZDI-CAN-13471: Adobe Acrobat Reader DC AcroForm Field Use-After-Free Remote Code Execution Vulnerability
Published 2021-08-24 · Modified
7.8EPSS 0.052
CVE-2022-34226
Adobe Acrobat Reader DC PDF Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2022-07-15 · Modified
7.8EPSS 0.050
CVE-2023-21579
Adobe Acrobat Reader DC Font Parsing Integer Overflow Remote Code Execution Vulnerability
Published 2023-01-18 · Modified
7.8EPSS 0.049
CVE-2023-44371
ZDI-CAN-21998: Adobe Acrobat Reader DC Font Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2023-11-16 · Modified
7.8EPSS 0.049
CVE-2020-9607
Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .
Published 2020-06-25 · Modified
7.8EPSS 0.047
CVE-2021-21086
Adobe Reader CoolType Arbitrary Stack Manipulation
Published 2021-09-02 · Modified
7.8EPSS 0.047
CVE-2021-28552
Adobe Acrobat Reader DC XFA Template Use-After-Free Remote Code Execution Vulnerability
Published 2021-08-24 · Modified
7.8EPSS 0.047
CVE-2021-28631
Adobe Acrobat Reader DC AcroForm Field Use-After-Free Remote Code Execution Vulnerability
Published 2021-08-24 · Modified
7.8EPSS 0.047
CVE-2015-5091
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to cause a denial of service via invalid data.
Published 2015-07-15 · Modified
7.8EPSS 0.047
CVE-2023-21607
Adobe Acrobat Reader Improper Input Validation Remote Code Execution Vulnerability
Published 2023-01-18 · Modified
7.8EPSS 0.047
CVE-2023-26421
ZDI-CAN-19832: Adobe Acrobat Reader DC Doc Object Integer Underflow Remote Code Execution Vulnerability
Published 2023-04-12 · Modified
7.8EPSS 0.046
CVE-2024-41830
Talos Security Advisory for Adobe (TALOS-2024-2009)
Published 2024-08-14 · Modified
7.8EPSS 0.046
CVE-2020-9694
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .
Published 2020-08-19 · Modified
7.8EPSS 0.045
CVE-2024-20730
TALOS-2023-1906 - Adobe Acrobat Reader Font CPAL integer overflow vulnerability
Published 2024-02-15 · Modified
7.8EPSS 0.044
CVE-2022-23188
Adobe Illustrator Buffer Overflow could lead to Arbitrary code execution
Published 2022-02-16 · Modified
7.8EPSS 0.044
CVE-2024-20755
Adobe Bridge PDF Parsing Heap Memory Corruption Remote Code Execution Vulnerability
Published 2024-03-18 · Analyzed
7.8EPSS 0.044
CVE-2017-8665
The Xamarin.iOS update component on systems running macOS allows an attacker to run arbitrary code as root, aka "Xamarin.iOS Elevation Of Privilege Vulnerability."
Published 2017-08-15 · Modified
7.81 PoCEPSS 0.043
CVE-2023-49314
Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode and EnableNodeCliInspectArguments, and thus r3ggi/electroniz3r can be used to perform an attack.
Published 2023-11-28 · Modified
7.8EPSS 0.043
CVE-2023-26408
ZDI-CAN-20712: AnnotsString Object prototype pollution Restrictions Bypass Vulnerability
Published 2023-04-12 · Modified
7.8EPSS 0.043
CVE-2022-34220
Acrobat Reader DC Font Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2022-07-15 · Modified
7.8EPSS 0.043
CVE-2023-26407
ZDI-CAN-20712: Net.HTTP.request Arbitrary Command Execution
Published 2023-04-12 · Modified
7.8EPSS 0.043
CVE-2023-26405
ZDI-CAN-20712: Object Prototype pollution which leads to API Restrictions Bypass
Published 2023-04-12 · Modified
7.8EPSS 0.043
CVE-2024-30284
ZDI-CAN-23466: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2024-05-15 · Analyzed
7.8EPSS 0.043
CVE-2023-26406
ZDI-CAN-20712: Net.HTTP.request URL restriction bypass
Published 2023-04-12 · Modified
7.8EPSS 0.042
CVE-2020-9604
Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution .
Published 2020-06-25 · Modified
7.8EPSS 0.041
CVE-2020-9605
Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution .
Published 2020-06-25 · Modified
7.8EPSS 0.041
CVE-2024-20756
Adobe Bridge 2024 Out of Bound Write Remote Code Execution Vulnerability
Published 2024-03-18 · Analyzed
7.8EPSS 0.041
CVE-2021-30939
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing a maliciously crafted image may lead to arbitrary code execution.
Published 2021-08-24 · Modified
7.8EPSS 0.041
CVE-2023-26396
Adobe Acrobat Reader DC for macOS installer (AcroRdrDC_2200220191_MUI.pkg) contains a local privilege escalation vulnerability.
Published 2023-04-12 · Modified
7.8EPSS 0.040
← Prev52 / 176Next →