VulnSea

macos vulnerabilities

CVEs whose affected-version data names the macos package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

336 CVEsRSS

CVE-2025-43445Medium· 4.3
10mo ago

An out-of-bounds read was addressed with improved input validation

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, wat…

▾ Sunlitapple · ipadosEPSS 1.0%via NVD
CVE-2025-43423Low· 2.0
10mo ago

A logging issue was addressed with improved data redaction

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, visionOS 26.1. An attacker with physical access to an unlo…

▾ Sunlitapple · ipadosEPSS 0.23%via NVD
CVE-2025-43399High· 7.5
10mo ago

This issue was addressed with improved redaction of sensitive information

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, macOS Sequoia 15.7.2, macOS Tahoe 26.1. An app may be able to access protected user data.

▾ Twilightapple · macosEPSS 0.55%via NVD
CVE-2025-43389Medium· 5.5
10mo ago

A privacy issue was addressed by removing the vulnerable code

A privacy issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, visionOS 26.1. An app may be able …

▾ Sunlitapple · ipadosEPSS 0.18%via NVD
CVE-2025-43385Medium· 4.3
10mo ago

An out-of-bounds access issue was addressed with improved bounds checking

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing a mali…

▾ Sunlitapple · ipadosEPSS 0.94%via NVD
CVE-2025-43384Medium· 4.3
10mo ago

An out-of-bounds access issue was addressed with improved bounds checking

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing a mali…

▾ Sunlitapple · ipadosEPSS 0.94%via NVD
CVE-2025-43383Medium· 4.3
10mo ago

An out-of-bounds access issue was addressed with improved bounds checking

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing a mali…

▾ Sunlitapple · ipadosEPSS 0.94%via NVD
CVE-2025-43377Medium· 5.5
10mo ago

An out-of-bounds read was addressed with improved bounds checking

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, macOS Sequoia 15.7.2, macOS Tahoe 26.1. An app may be able to cause a denial-of-service.

▾ Sunlitapple · macosEPSS 0.18%via NVD
CVE-2025-43214Medium· 6.5
1y ago

The issue was addressed with improved memory handling

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an une…

▾ Sunlitapple · safariEPSS 1.00%via NVD
CVE-2025-43213Medium· 6.5
1y ago

The issue was addressed with improved memory handling

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an une…

▾ Sunlitapple · safariEPSS 0.76%via NVD
CVE-2025-31277High· 8.8CISA KEVPoC
1y ago

The issue was addressed with improved memory handling

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory…

▾ Abyssalapple · safariEPSS 1.6%via NVD
CVE-2025-6558High· 8.8CISA KEVPoC
1y ago

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

▾ Abyssalgoogle · chromeEPSS 9.6%via NVD
CVE-2025-6965High· 7.7PoC
1y ago

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.

▾ Midnightsqlite · sqliteEPSS 73%via NVD
CVE-2025-43200Medium· 4.2CISA KEV0day
1y ago

This issue was addressed with improved checks

This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.…

▾ Midnightapple · ipadosEPSS 1.2%via NVD
CVE-2025-31223High· 8.0
1y ago

The issue was addressed with improved checks

The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to memory corruption.

▾ Twilightapple · safariEPSS 0.57%via NVD
CVE-2025-24259None
1y ago

This issue was addressed with additional entitlement checks

This issue was addressed with additional entitlement checks. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to retrieve Safari bookmarks without an entitlement check.

▾ Sunlitapple · macosEPSS 0.76%via NVD
CVE-2024-6387High· 8.1PoC
2y ago

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd)

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by f…

▾ Midnightopenbsd · opensshEPSS 100%via NVD
CVE-2023-4781High· 7.8
3y ago

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.

▾ Twilightneovim · neovimEPSS 0.61%via NVD
CVE-2023-4752High· 7.8
3y ago

Use After Free in GitHub repository vim/vim prior to 9.0.1858.

Use After Free in GitHub repository vim/vim prior to 9.0.1858.

▾ Twilightneovim · neovimEPSS 0.56%via NVD
CVE-2023-4750High· 7.8
3y ago

Use After Free in GitHub repository vim/vim prior to 9.0.1857.

Use After Free in GitHub repository vim/vim prior to 9.0.1857.

▾ Twilightneovim · neovimEPSS 0.53%via NVD
CVE-2023-4733High· 7.8
3y ago

Use After Free in GitHub repository vim/vim prior to 9.0.1840.

Use After Free in GitHub repository vim/vim prior to 9.0.1840.

▾ Twilightneovim · neovimEPSS 0.54%via NVD
CVE-2023-4751High· 7.8
3y ago

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331.

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331.

▾ Twilightneovim · neovimEPSS 0.56%via NVD
CVE-2023-4738High· 7.8
3y ago

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.

▾ Twilightneovim · neovimEPSS 0.60%via NVD
CVE-2023-4736High· 7.8
3y ago

Untrusted Search Path in GitHub repository vim/vim prior to 9.0.1833.

Untrusted Search Path in GitHub repository vim/vim prior to 9.0.1833.

▾ Twilightvim · vimEPSS 0.51%via NVD
CVE-2023-4735High· 7.8
3y ago

Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1847.

Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1847.

▾ Twilightvim · vimEPSS 0.60%via NVD
CVE-2023-4734High· 7.8
3y ago

Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846.

Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846.

▾ Twilightneovim · neovimEPSS 0.58%via NVD
CVE-2023-2426Medium· 5.3
3y ago

Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 9.0.1499.

Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 9.0.1499.

▾ Sunlitneovim · neovimEPSS 0.41%via NVD
CVE-2023-0433High· 7.8
3y ago

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225.

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225.

▾ Twilightneovim · neovimEPSS 0.56%via NVD
CVE-2023-0288High· 7.8
3y ago

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189.

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189.

▾ Twilightneovim · neovimEPSS 0.47%via NVD
CVE-2023-0049High· 7.8
3y ago

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.

▾ Twilightneovim · neovimEPSS 0.47%via NVD
macos vulnerabilities (CVEs) — page 11 · VulnSea