Apple
Apple MAC OS X: vulnerabilidades y CVE
Apple MAC OS X tiene 3212 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 142 son críticas y 26 figuran en el catálogo de explotación activa de CISA.
CVE3212
Últimos 12 meses0
Críticas142
Explotadas activamente26
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2019-8526 | Alta (7.8) | 0.70% | ⚠ Explotación activa | 18 dic 2019 | A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.4. An application may be able to gain elevated privileges. |
| CVE-2020-9934 | Media (5.5) | 3.2% | ⚠ Explotación activa | 16 oct 2020 | An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6. A local user may be able to view… |
| CVE-2022-2294 | Alta (8.8) | 70% | ⚠ Explotación activa | 28 jul 2022 | Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2021-31010 | Alta (7.5) | 3.7% | ⚠ Explotación activa | 24 ago 2021 | A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. A sandboxed process… |
| CVE-2018-4344 | Alta (7.8) | 2.4% | ⚠ Explotación activa | 3 abr 2019 | A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5. |
| CVE-2019-8605 | Alta (7.8) | 18% | ⚠ Explotación activa | 18 dic 2019 | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to execute arbitrary code with… |
| CVE-2020-3837 | Alta (7.8) | 15% | ⚠ Explotación activa | 27 feb 2020 | A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute… |
| CVE-2019-7286 | Alta (7.8) | 16% | ⚠ Explotación activa | 18 dic 2019 | A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. An application may be able to gain elevated privileges. |
| CVE-2021-1789 | Alta (8.8) | 14% | ⚠ Explotación activa | 2 abr 2021 | A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and… |
| CVE-2022-22674 | Media (5.5) | 1.1% | ⚠ Explotación activa | 26 may 2022 | An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Monterey 12.3.1, Security Update 2022-004 Catalina, macOS… |
| CVE-2012-1823 | Crítica (9.8) | 100% | ⚠ Explotación activa | 11 may 2012 | sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote… |
| CVE-2014-4404 | Alta (7.8) | 49% | ⚠ Explotación activa | 18 sept 2014 | Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context via an application that provides crafted key-mapping properties. |
| CVE-2015-1130 | Alta (7.8) | 9.9% | ⚠ Explotación activa | 10 abr 2015 | The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via unspecified vectors. |
| CVE-2014-7169 | Crítica (9.8) | 100% | ⚠ Explotación activa | 25 sept 2014 | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown… |
| CVE-2014-6271 | Crítica (9.8) | 100% | ⚠ Explotación activa | 24 sept 2014 | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by… |
| CVE-2020-9859 | Alta (7.8) | 0.83% | ⚠ Explotación activa | 5 jun 2020 | A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5 Supplemental Update, tvOS 13.4.6, watchOS 6.2.6. An application may be… |
| CVE-2019-6223 | Alta (7.5) | 2.6% | ⚠ Explotación activa | 5 mar 2019 | A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. The initiator of a… |
| CVE-2020-27932 | Alta (7.8) | 10% | ⚠ Explotación activa | 8 dic 2020 | A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006… |
| CVE-2020-27930 | Alta (7.8) | 22% | ⚠ Explotación activa | 8 dic 2020 | A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006… |
| CVE-2021-1870 | Crítica (9.8) | 7.7% | ⚠ Explotación activa | 2 abr 2021 | A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-46706 | Alta (7.8) | 0.24% | — | 14 ago 2023 | A type confusion issue was addressed with improved state handling. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to execute arbitrary… |
| CVE-2022-22630 | Crítica (9.8) | 1.4% | — | 23 jun 2023 | A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.6.6, macOS Monterey 12.3, Security Update 2022-004 Catalina. A remote user may cause an unexpected app… |
| CVE-2023-27960 | Alta (7.8) | 0.22% | — | 8 may 2023 | This issue was addressed by removing the vulnerable code. This issue is fixed in GarageBand for macOS 10.4.8. An app may be able to gain elevated privileges during the installation of GarageBand. |
| CVE-2022-22582 | Media (5.5) | 18% | — | 27 feb 2023 | A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Security Update 2022-003 Catalina, macOS Big Sur 11.6.5, macOS Monterey 12.3.… |
| CVE-2022-32910 | Alta (7.5) | 0.97% | — | 1 nov 2022 | A logic issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.8, macOS Monterey 12.5, Security Update 2022-005 Catalina. An archive may be able to bypass Gatekeeper. |
| CVE-2022-32794 | Alta (7.8) | 0.24% | — | 1 nov 2022 | A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. An app may be able to gain elevated privileges. |
| CVE-2022-32853 | Alta (7.1) | 0.59% | — | 23 sept 2022 | An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing a maliciously crafted AppleScript… |
| CVE-2022-32851 | Alta (7.1) | 0.59% | — | 23 sept 2022 | An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing a maliciously crafted AppleScript… |
| CVE-2022-32849 | Media (5.5) | 0.26% | — | 23 sept 2022 | An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An… |
| CVE-2022-32847 | Crítica (9.1) | 3.5% | — | 23 sept 2022 | This issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. A remote user may be… |
| CVE-2022-32843 | Alta (7.1) | 0.59% | — | 23 sept 2022 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing a maliciously crafted Postscript… |
| CVE-2022-32842 | Alta (7.8) | 0.56% | — | 23 sept 2022 | An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in Security Update 2022-005 Catalina, macOS Monterey 12.5. An app may be able to gain elevated privileges. |
| CVE-2022-32832 | Media (6.7) | 1.00% | — | 23 sept 2022 | The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app with… |
| CVE-2022-32831 | Alta (7.1) | 0.59% | — | 23 sept 2022 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing a maliciously crafted AppleScript binary… |
| CVE-2022-32826 | Alta (7.8) | 0.27% | — | 23 sept 2022 | An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina.… |
| CVE-2022-32823 | Media (5.5) | 0.25% | — | 23 sept 2022 | A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005… |
| CVE-2022-32820 | Alta (7.8) | 0.29% | — | 23 sept 2022 | An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005… |
| CVE-2022-32819 | Alta (7.8) | 0.36% | — | 23 sept 2022 | A logic issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app… |
| CVE-2022-32815 | Alta (7.8) | 0.35% | — | 23 sept 2022 | The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app with… |
| CVE-2022-32807 | Alta (7.1) | 0.74% | — | 23 sept 2022 | This issue was addressed with improved file handling. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. An app may be able to overwrite arbitrary files. |
| CVE-2022-32805 | Media (5.5) | 0.71% | — | 23 sept 2022 | The issue was addressed with improved handling of caches. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. An app may be able to access sensitive user information. |
| CVE-2022-32800 | Media (5.5) | 3.0% | — | 23 sept 2022 | This issue was addressed with improved checks. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. An app may be able to modify protected parts of the file system. |
| CVE-2022-32799 | Media (5.9) | 1.6% | — | 23 sept 2022 | An out-of-bounds read issue was addressed with improved bounds checking. This issue is fixed in Security Update 2022-005 Catalina, macOS Monterey 12.5. A user in a privileged network position may be able to leak… |
| CVE-2022-32797 | Alta (7.1) | 1.1% | — | 23 sept 2022 | This issue was addressed with improved checks. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing a maliciously crafted AppleScript binary may result in… |
| CVE-2022-32790 | Alta (7.5) | 2.1% | — | 23 sept 2022 | This issue was addressed with improved checks. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, macOS Big Sur 11.6.6, Security Update 2022-004 Catalina. A remote user may be… |
| CVE-2022-32787 | Alta (8.8) | 1.6% | — | 23 sept 2022 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005… |
| CVE-2022-32786 | Media (5.5) | 3.0% | — | 23 sept 2022 | An issue in the handling of environment variables was addressed with improved validation. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. An app may be able to modify… |
| CVE-2022-32785 | Media (5.5) | 0.72% | — | 23 sept 2022 | A null pointer dereference was addressed with improved validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing an image may… |
| CVE-2022-32781 | Media (4.4) | 0.29% | — | 23 sept 2022 | This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5, Security Update 2022-005 Catalina, macOS Big Sur 11.6.8. An app with root privileges may be… |
| CVE-2022-32857 | Media (4.3) | 0.26% | — | 24 ago 2022 | This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6, tvOS… |