VendorsApplemacosall versions
Vulnerabilities

Apple MACOS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7076CVEs
CVE-2023-0976
A command Injection Vulnerability in TA for mac-OS prior to version 5.7.9 allows local users to place an arbitrary file into the /Library/Trellix/Agent/bin/ folder. The malicious file is executed by running the TA deployment feature located in the System Tree.
Published 2023-06-07 · Modified
7.8EPSS 0.006
CVE-2020-29620
This issue was addressed with improved entitlements. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may be able to elevate privileges.
Published 2021-04-02 · Modified
7.8EPSS 0.006
CVE-2022-38403
Adobe InCopy SVG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2022-09-16 · Modified
7.8EPSS 0.006
CVE-2022-38404
Adobe InCopy SVG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2022-09-16 · Modified
7.8EPSS 0.006
CVE-2022-38405
Adobe InCopy SVG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2022-09-16 · Modified
7.8EPSS 0.006
CVE-2022-35708
Adobe Bridge SGI File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2022-09-19 · Modified
7.8EPSS 0.006
CVE-2022-38432
Adobe Photoshop SVG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2022-09-16 · Modified
7.8EPSS 0.006
CVE-2024-27829
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.5. Processing a file may lead to unexpected app termination or arbitrary code execution.
Published 2024-05-13 · Modified
7.8EPSS 0.006
CVE-2023-32428
This issue was addressed with improved file handling. This issue is fixed in macOS Ventura 13.4, tvOS 16.5, iOS 16.5 and iPadOS 16.5, watchOS 9.5. An app may be able to gain root privileges.
Published 2023-09-06 · Modified
7.8EPSS 0.006
CVE-2019-12577
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The macOS binary openvpn_launcher.64 is setuid root. This binary creates /tmp/pia_upscript.sh when executed. Because the file creation mask (umask) is not reset, the umask value is inherited from the calling process. This value can be manipulated to cause the privileged binary to create files with world writable permissions. A local unprivileged user can modify /tmp/pia_upscript.sh during the connect process to execute arbitrary code as the root user.
Published 2019-07-11 · Modified
7.8EPSS 0.006
CVE-2024-34094
ZDI-CAN-23474: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2024-05-15 · Analyzed
7.8EPSS 0.006
CVE-2022-32840
This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5, watchOS 8.7, iOS 15.6 and iPadOS 15.6. An app may be able to execute arbitrary code with kernel privileges.
Published 2022-08-24 · Modified
7.8EPSS 0.006
CVE-2022-32812
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina. An app may be able to execute arbitrary code with kernel privileges.
Published 2022-08-24 · Modified
7.8EPSS 0.006
CVE-2024-27856
The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing a file may lead to unexpected app termination or arbitrary code execution.
Published 2025-01-15 · Modified
7.8EPSS 0.006
CVE-2022-32829
This issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to execute arbitrary code with kernel privileges.
Published 2022-09-23 · Modified
7.8EPSS 0.006
CVE-2022-35702
Adobe Bridge SVG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2022-09-19 · Modified
7.8EPSS 0.006
CVE-2022-35703
Adobe Bridge SVG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2022-09-19 · Modified
7.8EPSS 0.006
CVE-2022-32947
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. An app may be able to execute arbitrary code with kernel privileges.
Published 2022-11-01 · Modified
7.8EPSS 0.006
CVE-2023-4781
Heap-based Buffer Overflow in vim/vim
Published 2023-09-05 · Analyzed
7.8EPSS 0.006
CVE-2024-20739
ZDI-CAN-22647: Adobe Audition AVI File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2024-02-15 · Analyzed
7.8EPSS 0.006
CVE-2024-20772
Adobe Media Encoder 2024 AI file parsing Stack based buffer overflow
Published 2024-04-10 · Analyzed
7.8EPSS 0.006
CVE-2022-1733
Heap-based Buffer Overflow in vim/vim
Published 2022-05-17 · Modified
7.8EPSS 0.006
CVE-2024-34095
ZDI-CAN-23475: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2024-05-15 · Analyzed
7.8EPSS 0.006
CVE-2024-34097
ZDI-CAN-23473: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2024-05-15 · Analyzed
7.8EPSS 0.006
CVE-2024-34096
ZDI-CAN-23472: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2024-05-15 · Analyzed
7.8EPSS 0.006
CVE-2023-4735
Out-of-bounds Write in vim/vim
Published 2023-09-02 · Modified
7.8EPSS 0.006
CVE-2023-4738
Heap-based Buffer Overflow in vim/vim
Published 2023-09-02 · Analyzed
7.8EPSS 0.006
CVE-2019-5013
An exploitable privilege escalation vulnerability exists in the Wacom, driver version 6.3.32-3, update helper service in the start/stopLaunchDProcess command. The command takes a user-supplied string argument and executes launchctl under root context. A user with local access can use this vulnerability to raise load arbitrary launchD agents. An attacker would need local access to the machine for a successful exploit.
Published 2019-10-24 · Modified
7.8EPSS 0.006
CVE-2023-4734
Integer Overflow or Wraparound in vim/vim
Published 2023-09-02 · Analyzed
7.8EPSS 0.006
CVE-2020-27897
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1. An application may be able to execute arbitrary code with kernel privileges.
Published 2021-04-02 · Modified
7.8EPSS 0.006
CVE-2022-24960
Use after free vulnerability in PDFTron SDK
Published 2022-03-09 · Modified
7.8EPSS 0.006
CVE-2022-38434
Adobe Photoshop SVG File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2022-09-16 · Modified
7.8EPSS 0.006
CVE-2023-48633
ZDI-CAN-22173: Adobe After Effects AEP File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2023-12-13 · Modified
7.8EPSS 0.006
CVE-2023-0049
Out-of-bounds Read in vim/vim
Published 2023-01-04 · Analyzed
7.8EPSS 0.006
CVE-2022-32842
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in Security Update 2022-005 Catalina, macOS Monterey 12.5. An app may be able to gain elevated privileges.
Published 2022-09-23 · Modified
7.8EPSS 0.006
CVE-2023-4752
Use After Free in vim/vim
Published 2023-09-04 · Analyzed
7.8EPSS 0.006
CVE-2024-30305
ZDI-CAN-23043: Adobe Acrobat Reader DC AcroForm Use-After-Free Remote Code Execution Vulnerability
Published 2024-05-02 · Analyzed
7.8EPSS 0.006
CVE-2024-30304
ZDI-CAN-23040: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2024-05-02 · Analyzed
7.8EPSS 0.006
CVE-2024-30301
ZDI-CAN-23042: Adobe Acrobat Reader DC AcroForm Use-After-Free Remote Code Execution Vulnerability
Published 2024-05-02 · Analyzed
7.8EPSS 0.006
CVE-2024-20765
ZDI-CAN-22674: Adobe Acrobat Reader DC PDF File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2024-02-29 · Analyzed
7.8EPSS 0.006
← Prev61 / 177Next →