VendorsApplemacosall versions
Vulnerabilities

Apple MACOS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7077CVEs
CVE-2023-25897
ZDI-CAN-19520: Adobe Dimension USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-03-28 · Modified
7.8EPSS 0.004
CVE-2023-25898
ZDI-CAN-19521: Adobe Dimension USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-03-28 · Modified
7.8EPSS 0.004
CVE-2023-26337
ZDI-CAN-20285: Adobe Dimension USDA File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-03-28 · Modified
7.8EPSS 0.004
CVE-2023-47074
ZDI-CAN-21812: Adobe Illustrator JP2 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2023-12-13 · Modified
7.8EPSS 0.004
CVE-2024-34100
Use-After-Free vulnerability in the latest Adobe Acrobat Reader DC when open malicious PDF file
Published 2024-05-15 · Analyzed
7.8EPSS 0.004
CVE-2024-27802
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
Published 2024-06-10 · Modified
7.8EPSS 0.004
CVE-2022-32802
A logic issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, tvOS 15.6, macOS Monterey 12.5. Processing a maliciously crafted file may lead to arbitrary code execution.
Published 2022-09-20 · Modified
7.8EPSS 0.004
CVE-2022-32911
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to execute arbitrary code with kernel privileges.
Published 2022-09-20 · Modified
7.8EPSS 0.004
CVE-2022-38416
Adobe InDesign SVG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2022-09-16 · Modified
7.8EPSS 0.004
CVE-2022-38417
Adobe InDesign SVG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2022-09-16 · Modified
7.8EPSS 0.004
CVE-2021-35538
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.28. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. Note: This vulnerability does not apply to Windows systems. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published 2021-10-20 · Modified
7.8EPSS 0.004
CVE-2023-26412
ZDI-CAN-20314: Adobe Substance 3D Designer USDA File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-04-13 · Modified
7.8EPSS 0.004
CVE-2023-21587
Adobe InDesign Font Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-01-13 · Modified
7.8EPSS 0.004
CVE-2023-25872
Adobe Substance 3D Stager SVG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-03-27 · Modified
7.8EPSS 0.004
CVE-2023-26383
ZDI-CAN-20287: Adobe Substance 3D Stager USDA File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-04-12 · Modified
7.8EPSS 0.004
CVE-2023-26390
ZDI-CAN-20255: Adobe Substance 3D Stager USDA File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-04-12 · Modified
7.8EPSS 0.004
CVE-2023-26394
ZDI-CAN-20236: Adobe Substance 3D Stager USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-04-12 · Modified
7.8EPSS 0.004
CVE-2023-26413
ZDI-CAN-20315: Adobe Substance 3D Designer USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-04-13 · Modified
7.8EPSS 0.004
CVE-2023-26416
ZDI-CAN-20318: Adobe Substance 3D Designer DAE File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-04-13 · Modified
7.8EPSS 0.004
CVE-2022-38445
Adobe Dimension SKP File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2022-10-14 · Modified
7.8EPSS 0.004
CVE-2022-38446
Adobe Dimension SKP File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2022-10-14 · Modified
7.8EPSS 0.004
CVE-2022-38447
Adobe Dimension SKP File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2022-10-14 · Modified
7.8EPSS 0.004
CVE-2022-38448
Adobe Dimension SKP File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2022-10-14 · Modified
7.8EPSS 0.004
CVE-2023-21594
Adobe InCopy Font Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-01-13 · Modified
7.8EPSS 0.004
CVE-2025-27195
Media Encoder | Heap-based Buffer Overflow (CWE-122)
Published 2025-04-08 · Analyzed
7.8EPSS 0.004
CVE-2024-47413
Animate | Use After Free (CWE-416)
Published 2024-10-09 · Analyzed
7.8EPSS 0.004
CVE-2024-47414
Animate | Use After Free (CWE-416)
Published 2024-10-09 · Analyzed
7.8EPSS 0.004
CVE-2024-49545
InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
Published 2024-12-10 · Analyzed
7.8EPSS 0.004
CVE-2024-47412
Animate | Use After Free (CWE-416)
Published 2024-10-09 · Analyzed
7.8EPSS 0.004
CVE-2024-47415
Animate | Use After Free (CWE-416)
Published 2024-10-09 · Analyzed
7.8EPSS 0.004
CVE-2024-47418
Animate | Use After Free (CWE-416)
Published 2024-10-09 · Analyzed
7.8EPSS 0.004
CVE-2025-27198
Photoshop Desktop | Heap-based Buffer Overflow (CWE-122)
Published 2025-04-08 · Analyzed
7.8EPSS 0.004
CVE-2024-49543
InDesign Desktop | Stack-based Buffer Overflow (CWE-121)
Published 2024-12-10 · Analyzed
7.8EPSS 0.004
CVE-2025-27199
Animate | Heap-based Buffer Overflow (CWE-122)
Published 2025-04-08 · Analyzed
7.8EPSS 0.004
CVE-2025-21159
Illustrator | Use After Free (CWE-416)
Published 2025-02-11 · Analyzed
7.8EPSS 0.004
CVE-2021-28644
Adobe Acrobat SpellDictionaryCreate Path Traversal Remote Code Execution Vulnerability
Published 2023-09-06 · Modified
7.8EPSS 0.004
CVE-2021-35980
Adobe Acrobat Reader SpellDictionaryExport Path Traversal Remote Code Execution Vulnerability
Published 2023-09-06 · Modified
7.8EPSS 0.004
CVE-2020-5180
Viscosity 1.8.2 on Windows and macOS allows an unprivileged user to set a subset of OpenVPN parameters, which can be used to load a malicious library into the memory of the OpenVPN process, leading to limited local privilege escalation. (When a VPN connection is initiated using a TLS/SSL client profile, the privileges are dropped, and the library will be loaded, resulting in arbitrary code execution as a user with limited privileges. This greatly reduces the impact of the vulnerability.)
Published 2020-01-14 · Modified
7.8EPSS 0.004
CVE-2022-28831
Adobe InDesign Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2023-09-11 · Modified
7.8EPSS 0.004
CVE-2022-28833
Adobe InDesign Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2023-09-11 · Modified
7.8EPSS 0.004
← Prev65 / 177Next →