VulnSea

macOS vulnerabilities

CVEs whose affected-version data names the macOS package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

320 CVEsRSS

CVE-2025-31277High· 8.8CISA KEVPoC
1y ago

The issue was addressed with improved memory handling

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory…

Abyssalapple · safariEPSS 1.5%via NVD
CVE-2025-6965High· 7.7PoC
1y ago

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.

Midnightsqlite · sqliteEPSS 73%via NVD
CVE-2025-31223High· 8.0
1y ago

The issue was addressed with improved checks

The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to memory corruption.

Twilightapple · safariEPSS 0.57%via NVD
CVE-2025-24259None
1y ago

This issue was addressed with additional entitlement checks

This issue was addressed with additional entitlement checks. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to retrieve Safari bookmarks without an entitlement check.

Sunlitapple · macosEPSS 0.76%via NVD
CVE-2024-6387High· 8.1PoC
2y ago

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd)

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by f…

Midnightopenbsd · opensshEPSS 100%via NVD
CVE-2023-4781High· 7.8
3y ago

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.

Twilightneovim · neovimEPSS 0.61%via NVD
CVE-2023-4752High· 7.8
3y ago

Use After Free in GitHub repository vim/vim prior to 9.0.1858.

Use After Free in GitHub repository vim/vim prior to 9.0.1858.

Twilightneovim · neovimEPSS 0.56%via NVD
CVE-2023-4750High· 7.8
3y ago

Use After Free in GitHub repository vim/vim prior to 9.0.1857.

Use After Free in GitHub repository vim/vim prior to 9.0.1857.

Twilightneovim · neovimEPSS 0.53%via NVD
CVE-2023-4733High· 7.8
3y ago

Use After Free in GitHub repository vim/vim prior to 9.0.1840.

Use After Free in GitHub repository vim/vim prior to 9.0.1840.

Twilightneovim · neovimEPSS 0.54%via NVD
CVE-2023-4751High· 7.8
3y ago

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331.

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331.

Twilightneovim · neovimEPSS 0.56%via NVD
CVE-2023-4738High· 7.8
3y ago

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.

Twilightneovim · neovimEPSS 0.60%via NVD
CVE-2023-4736High· 7.8
3y ago

Untrusted Search Path in GitHub repository vim/vim prior to 9.0.1833.

Untrusted Search Path in GitHub repository vim/vim prior to 9.0.1833.

Twilightvim · vimEPSS 0.51%via NVD
CVE-2023-4735High· 7.8
3y ago

Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1847.

Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1847.

Twilightvim · vimEPSS 0.60%via NVD
CVE-2023-4734High· 7.8
3y ago

Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846.

Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846.

Twilightneovim · neovimEPSS 0.58%via NVD
CVE-2022-37434Critical· 9.8PoC⚖ disputed
4y ago

zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field

zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the af…

Abyssalzlib · zlibEPSS 18%via NVD
CVE-2022-2294High· 8.8CISA KEV0day
4y ago

Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Abyssalgoogle · chromeEPSS 70%via NVD
CVE-2022-29458High· 7.1
4y ago

ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.

ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.

Twilightgnu · ncursesEPSS 1.3%via NVD
CVE-2018-25032High· 7.5PoC
4y ago

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

Midnightnokogiri · nokogiriEPSS 52%via NVD
CVE-2021-39537High· 8.8
5y ago

An issue was discovered in ncurses through v6.2-1

An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.

Twilightinvisible-island · ncursesEPSS 3.2%via NVD
CVE-2025-31200High· 7.5CISA KEV0dayPoC

Memory corruption in CoreAudio via crafted media file

A maliciously crafted media file processed by Apple CoreAudio can trigger heap corruption leading to remote code execution. Reported as exploited in the wild against targeted individuals.

AbyssalApple · CoreAudioiOS, iPadOS, macOSEPSS 19%via NVD
macOS vulnerabilities (CVEs) — page 11 · VulnSea