VulnSea

macos vulnerabilities

CVEs whose affected-version data names the macos package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

336 CVEsRSS

CVE-2022-37434Critical· 9.8PoC⚖ disputed
4y ago

zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field

zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the af…

▾ Abyssalzlib · zlibEPSS 18%via NVD
CVE-2022-2294High· 8.8CISA KEV0day
4y ago

Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

▾ Abyssalgoogle · chromeEPSS 70%via NVD
CVE-2022-29458High· 7.1
4y ago

ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.

ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.

▾ Twilightgnu · ncursesEPSS 1.3%via NVD
CVE-2018-25032High· 7.5PoC
4y ago

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

▾ Midnightnokogiri · nokogiriEPSS 52%via NVD
CVE-2021-39537High· 8.8
5y ago

An issue was discovered in ncurses through v6.2-1

An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.

▾ Twilightinvisible-island · ncursesEPSS 3.2%via NVD
CVE-2025-31200High· 7.5CISA KEV0dayPoC

Memory corruption in CoreAudio via crafted media file

A maliciously crafted media file processed by Apple CoreAudio can trigger heap corruption leading to remote code execution. Reported as exploited in the wild against targeted individuals.

▾ AbyssalApple · CoreAudioiOS, iPadOS, macOSEPSS 19%via NVD
macos vulnerabilities (CVEs) — page 12 · VulnSea