VendorsApplemacosall versions
Vulnerabilities

Apple MACOS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7077CVEs
CVE-2026-34701
InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
Published 2026-06-09 · Analyzed
7.8EPSS 0.003
CVE-2026-81992
Acrobat Reader | Heap-based Buffer Overflow (CWE-122)
Published 2026-09-08 · Analyzed
7.8EPSS 0.003
CVE-2026-34699
InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
Published 2026-06-09 · Analyzed
7.8EPSS 0.003
CVE-2026-27310
Bridge | Heap-based Buffer Overflow (CWE-122)
Published 2026-04-14 · Analyzed
7.8EPSS 0.003
CVE-2026-34707
InCopy | Heap-based Buffer Overflow (CWE-122)
Published 2026-06-09 · Analyzed
7.8EPSS 0.003
CVE-2026-27313
Bridge | Heap-based Buffer Overflow (CWE-122)
Published 2026-04-14 · Analyzed
7.8EPSS 0.003
CVE-2026-27238
InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
Published 2026-04-14 · Modified
7.8EPSS 0.003
CVE-2026-34630
Bridge | Heap-based Buffer Overflow (CWE-122)
Published 2026-04-14 · Analyzed
7.8EPSS 0.003
CVE-2026-47952
Acrobat Reader | Heap-based Buffer Overflow (CWE-122)
Published 2026-06-09 · Analyzed
7.8EPSS 0.003
CVE-2026-34687
Illustrator | Heap-based Buffer Overflow (CWE-122)
Published 2026-05-12 · Analyzed
7.8EPSS 0.003
CVE-2021-1840
A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. A local attacker may be able to elevate their privileges.
Published 2021-09-08 · Modified
7.8EPSS 0.003
CVE-2026-34698
InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
Published 2026-06-09 · Analyzed
7.8EPSS 0.003
CVE-2025-24228
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to execute arbitrary code with kernel privileges.
Published 2025-03-31 · Modified
7.8EPSS 0.003
CVE-2019-5780
Insufficient restrictions on what can be done with Apple Events in Google Chrome on macOS prior to 72.0.3626.81 allowed a local attacker to execute JavaScript via Apple Events.
Published 2019-02-19 · Modified
7.8EPSS 0.003
CVE-2024-41851
Adobe InDesign (Beta) has an integer overflow vulnerability when parsing SVG file
Published 2024-08-14 · Analyzed
7.8EPSS 0.003
CVE-2025-30317
InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
Published 2025-06-10 · Analyzed
7.8EPSS 0.003
CVE-2024-20754
Lightroom Desktop | Untrusted Search Path (CWE-426)
Published 2024-03-18 · Analyzed
7.8EPSS 0.003
CVE-2023-26370
ZDI-CAN-21257: Adobe Photoshop PSD File Parsing Uninitialized Variable Remote Code Execution Vulnerability
Published 2023-10-11 · Modified
7.8EPSS 0.003
CVE-2024-43758
Illustrator | Use After Free (CWE-416)
Published 2024-09-13 · Analyzed
7.8EPSS 0.003
CVE-2024-43760
Photoshop Desktop | Out-of-bounds Write (CWE-787)
Published 2024-09-13 · Analyzed
7.8EPSS 0.003
CVE-2025-43589
InDesign Desktop | Use After Free (CWE-416)
Published 2025-06-10 · Analyzed
7.8EPSS 0.003
CVE-2025-61819
Photoshop Desktop | Heap-based Buffer Overflow (CWE-122)
Published 2025-11-11 · Analyzed
7.8EPSS 0.003
CVE-2021-30703
A double free issue was addressed with improved memory management. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave, macOS Big Sur 11.4, watchOS 7.5. An application may be able to execute arbitrary code with kernel privileges.
Published 2021-09-08 · Modified
7.8EPSS 0.003
CVE-2023-25863
Adobe Substance 3D Stager USDC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2023-03-27 · Modified
7.8EPSS 0.003
CVE-2023-25865
Adobe Substance 3D Stager OBJ File Parsing Memory Corruption Remote Code Execution Vulnerability
Published 2023-03-27 · Modified
7.8EPSS 0.003
CVE-2023-25867
Adobe Substance 3D Stager PCX File Parsing Memory Corruption Remote Code Execution Vulnerability
Published 2023-03-27 · Modified
7.8EPSS 0.003
CVE-2023-25869
Adobe Substance 3D Stager SVG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2023-03-27 · Modified
7.8EPSS 0.003
CVE-2023-25873
Adobe Substance 3D Stager SVG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2023-03-27 · Modified
7.8EPSS 0.003
CVE-2021-30922
Multiple out-of-bounds write issues were addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.6.1. A malicious application may be able to execute arbitrary code with kernel privileges.
Published 2021-08-24 · Modified
7.8EPSS 0.003
CVE-2024-39393
Adobe Indesign 2024 PCT File Parsing Memory Corruption Remote Code Execution Vulnerability
Published 2024-08-14 · Analyzed
7.8EPSS 0.003
CVE-2023-32396
This issue was addressed with improved checks. This issue is fixed in Xcode 15, tvOS 17, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to gain elevated privileges.
Published 2023-09-26 · Modified
7.8EPSS 0.003
CVE-2023-42926
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
Published 2023-12-12 · Modified
7.8EPSS 0.003
CVE-2024-49544
InDesign Desktop | Out-of-bounds Write (CWE-787)
Published 2024-12-10 · Analyzed
7.8EPSS 0.003
CVE-2026-35558
Improper neutralization of special elements in authentication components in Amazon Athena ODBC driver
Published 2026-04-03 · Analyzed
7.8EPSS 0.003
CVE-2024-49538
Illustrator | Out-of-bounds Write (CWE-787)
Published 2024-12-10 · Analyzed
7.8EPSS 0.003
CVE-2023-42882
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2. Processing an image may lead to arbitrary code execution.
Published 2023-12-12 · Modified
7.8EPSS 0.003
CVE-2024-40809
A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, visionOS 1.3, watchOS 10.6. A shortcut may be able to bypass Internet permission requirements.
Published 2024-07-29 · Modified
7.8EPSS 0.003
CVE-2023-36854
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.8, macOS Ventura 13.5, macOS Big Sur 11.7.9. Processing a file may lead to unexpected app termination or arbitrary code execution.
Published 2023-07-26 · Modified
7.8EPSS 0.003
CVE-2019-16471
Use-After-Free in app.measureDialog - Tianfu Cup
Published 2023-09-11 · Modified
7.8EPSS 0.003
CVE-2024-54529
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.
Published 2024-12-11 · Modified
7.8EPSS 0.003
← Prev72 / 177Next →