Mac Os

Vendor:

First CVE: Aug 1, 1997 · Active for 28 years

6,599
Total CVEs
More Total CVEs than 64% of tracked products
275.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 26% of tracked products
1.4%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Mac Os over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 1, 1997
28 years ago
Most Recent CVE
Jul 17, 2026
7 days ago

CVE Severity & Scoring

Mac Os6,599 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local3,612 (54.7%)
Network2,718 (41.2%)
Unknown165 (2.5%)
Physical57 (0.9%)
Adjacent Network47 (0.7%)
Attack Complexity
Low6,006 (91.0%)
High428 (6.5%)
Unknown165 (2.5%)
User Interaction
None1,858 (28.2%)
Unknown165 (2.5%)
Required4,576 (69.3%)
Privileges Required
Low747 (11.3%)
High77 (1.2%)
None5,610 (85.0%)
Unknown165 (2.5%)

Top CVEs

Signals from CVEs in this product scope (6599 CVEs).

6,599 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 1
Jul 14, 20159.898YESYES
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote atta
Feb 5, 20149.898YESYES
Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary c
Sep 9, 20107.397YESYES
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media pla
Feb 6, 20187.896YESYES
Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; a
Mar 15, 20117.895YESYES
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap-based buffer overflow vulnera
Feb 11, 20218.894YESNO
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Jul 28, 20228.891YESNO
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekee
Sep 8, 20215.591YESYES
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.
Aug 24, 20217.891YESNO
Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adob
Oct 15, 20149.391NOYES

Exploit Exposure

Signals from CVEs in this product scope (6599 CVEs).

CISA KEV
95 CVEs
1.4% of CVEs· Bottom 1%
Metasploit
12 CVEs
0.2% of CVEs· Bottom 1%
Nuclei
8 CVEs
0.1% of CVEs· Bottom 1%
ExploitDB
49 CVEs
0.7% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (6599 CVEs).

Media Mentions

Signals from CVEs in this product scope (6599 CVEs).

Top CNAs Publishing CVEs For Mac Os

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.015.01.4%00
924.60.4%00
8.624.60.7%01
8.524.60.7%01
8.114.60.8%01
8.014.60.8%01
7.6.114.60.8%01
7.614.60.8%01
7.5.314.60.8%01
26.056.51.6%20
15.075.20.3%00
14.117.80.6%00
14.0306.00.4%00
13.415.50.3%00
13.3.316.37.9%00
13.115.31.8%00
13.0167.41.0%00
12.6.716.37.9%00
12.0.127.21.3%00
12.0.0106.90.8%00