VendorsApplemacosall versions
Vulnerabilities

Apple MACOS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7076CVEs
CVE-2024-30366
Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability
Published 2024-04-03 · Analyzed
7.8EPSS 0.008
CVE-2020-3803
Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and 2015.006.30510 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.
Published 2020-03-25 · Modified
7.8EPSS 0.008
CVE-2024-30365
Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability
Published 2024-04-02 · Analyzed
7.8EPSS 0.008
CVE-2021-30679
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. An application may be able to gain elevated privileges.
Published 2021-09-08 · Modified
7.8EPSS 0.008
CVE-2024-30361
Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability
Published 2024-04-02 · Analyzed
7.8EPSS 0.008
CVE-2024-30336
Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability
Published 2024-04-02 · Analyzed
7.8EPSS 0.008
CVE-2024-30351
Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability
Published 2024-04-02 · Analyzed
7.8EPSS 0.008
CVE-2024-30345
Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability
Published 2024-04-02 · Analyzed
7.8EPSS 0.008
CVE-2024-30344
Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability
Published 2024-04-02 · Analyzed
7.8EPSS 0.008
CVE-2024-30346
Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability
Published 2024-04-02 · Analyzed
7.8EPSS 0.008
CVE-2021-30724
This issue was addressed with improved checks. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. A local attacker may be able to elevate their privileges.
Published 2021-09-08 · Modified
7.8EPSS 0.008
CVE-2019-12579
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux and macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The PIA Linux/macOS binary openvpn_launcher.64 binary is setuid root. This binary accepts several parameters to update the system configuration. These parameters are passed to operating system commands using a "here" document. The parameters are not sanitized, which allow for arbitrary commands to be injected using shell metacharacters. A local unprivileged user can pass special crafted parameters that will be interpolated by the operating system calls.
Published 2019-07-11 · Modified
7.8EPSS 0.008
CVE-2022-22612
A memory consumption issue was addressed with improved memory handling. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, iTunes 12.12.3 for Windows, watchOS 8.5, macOS Monterey 12.3. Processing a maliciously crafted image may lead to heap corruption.
Published 2022-03-18 · Modified
7.8EPSS 0.008
CVE-2024-30362
Foxit PDF Reader PDF File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2024-04-02 · Analyzed
7.8EPSS 0.008
CVE-2020-24559
A vulnerability in Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services on macOS may allow an attacker to manipulate a certain binary to load and run a script from a user-writable folder, which then would allow them to execute arbitrary code as root. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Published 2020-09-01 · Modified
7.8EPSS 0.008
CVE-2024-30342
Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2024-04-02 · Analyzed
7.8EPSS 0.008
CVE-2020-29614
This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. Processing a maliciously crafted file may lead to heap corruption.
Published 2021-04-02 · Modified
7.8EPSS 0.008
CVE-2020-29617
An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 14.3, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, iCloud for Windows 12.0, watchOS 7.2. Processing a maliciously crafted image may lead to heap corruption.
Published 2021-04-02 · Modified
7.8EPSS 0.008
CVE-2020-29619
An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 14.3, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, iCloud for Windows 12.0, watchOS 7.2. Processing a maliciously crafted image may lead to heap corruption.
Published 2021-04-02 · Modified
7.8EPSS 0.008
CVE-2024-30354
Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability
Published 2024-04-02 · Analyzed
7.8EPSS 0.008
CVE-2024-30343
Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2024-04-02 · Analyzed
7.8EPSS 0.008
CVE-2022-32837
This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5, tvOS 15.6, iOS 15.6 and iPadOS 15.6. An app may be able to cause unexpected system termination or write kernel memory.
Published 2022-08-24 · Modified
7.8EPSS 0.008
CVE-2020-24556
A vulnerability in Trend Micro Apex One, OfficeScan XG SP1, Worry-Free Business Security 10 SP1 and Worry-Free Business Security Services on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. Please note that version 1909 (OS Build 18363.719) of Microsoft Windows 10 mitigates hard links, but previous versions are affected.
Published 2020-09-01 · Modified
7.8EPSS 0.008
CVE-2019-7962
Adobe Illustrator CC versions 23.1 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.
Published 2019-11-14 · Modified
7.8EPSS 0.008
CVE-2021-30873
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1. A malicious application may be able to elevate privileges.
Published 2021-08-24 · Modified
7.8EPSS 0.008
CVE-2019-7960
Adobe Animate CC versions 19.2.1 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.
Published 2019-11-14 · Modified
7.8EPSS 0.008
CVE-2024-30357
Foxit PDF Reader AcroForm Annotation Type Confusion Remote Code Execution Vulnerability
Published 2024-04-02 · Analyzed
7.8EPSS 0.008
CVE-2024-30348
Foxit PDF Reader U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2024-04-02 · Analyzed
7.8EPSS 0.008
CVE-2019-4000
Improper neutralization of directives in dynamically evaluated code in Druva inSync Mac OS Client 6.5.0 allows a local, authenticated attacker to execute arbitrary Python expressions with root privileges.
Published 2020-02-25 · Modified
7.8EPSS 0.007
CVE-2022-38411
Adobe Animate SVG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2022-09-16 · Modified
7.8EPSS 0.007
CVE-2020-27945
An integer overflow was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, macOS Big Sur 11.0.1. Processing maliciously crafted web content may lead to arbitrary code execution.
Published 2021-04-02 · Modified
7.8EPSS 0.007
CVE-2024-27818
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An attacker may be able to cause unexpected app termination or arbitrary code execution.
Published 2024-05-13 · Modified
7.8EPSS 0.007
CVE-2020-7851
Innorix File Transfer Solution File Download and Execution Vulnerability
Published 2021-04-19 · Modified
7.8EPSS 0.007
CVE-2019-17387
An authentication flaw in the AVPNC_RP service in Aviatrix VPN Client through 2.2.10 allows an attacker to gain elevated privileges through arbitrary code execution on Windows, Linux, and macOS.
Published 2019-12-05 · Modified
7.8EPSS 0.007
CVE-2022-35706
Adobe Bridge SVG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2022-09-19 · Modified
7.8EPSS 0.007
CVE-2023-23514
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura 13.2.1, macOS Big Sur 11.7.5. An app may be able to execute arbitrary code with kernel privileges.
Published 2023-02-27 · Modified
7.8EPSS 0.007
CVE-2022-32821
A memory corruption issue was addressed with improved validation. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to execute arbitrary code with kernel privileges.
Published 2022-09-23 · Modified
7.8EPSS 0.007
CVE-2022-26718
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. An application may be able to gain elevated privileges.
Published 2022-05-26 · Modified
7.8EPSS 0.007
CVE-2020-24425
Privilege escalation vulnerability in Dreamweaver version 20.2
Published 2020-10-21 · Modified
7.8EPSS 0.007
CVE-2022-32810
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.5, watchOS 8.7, iOS 15.6 and iPadOS 15.6. An app may be able to execute arbitrary code with kernel privileges.
Published 2022-08-24 · Modified
7.8EPSS 0.007
← Prev60 / 177Next →