Mac Os X
Vendor:
First CVE: Aug 1, 1997 · Active for 28 years
5,568
Total CVEs
More Total CVEs than 100% of tracked products
222.7
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 59% of tracked products
1.2%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Mac Os X over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 1, 1997
28 years ago
Most Recent CVE
Sep 11, 2024
681 days ago
CVE Severity & Scoring
Mac Os X5,568 CVEs
30%
57%
9%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1,442 (25.9%)
Network1,601 (28.8%)
Unknown2,490 (44.7%)
Physical19 (0.3%)
Adjacent Network16 (0.3%)
Attack Complexity
Low2,984 (53.6%)
High94 (1.7%)
Unknown2,490 (44.7%)
User Interaction
None1,173 (21.1%)
Unknown2,490 (44.7%)
Required1,905 (34.2%)
Privileges Required
Low319 (5.7%)
High23 (0.4%)
None2,736 (49.1%)
Unknown2,490 (44.7%)
Top CVEs
Signals from CVEs in this product scope (5568 CVEs).
5,568 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-6271CRITICAL GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cra | Sep 24, 2014 | 9.8 | 99 | YES | YES |
CVE-2012-1823CRITICAL sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) | May 11, 2012 | 9.8 | 99 | YES | YES |
CVE-2015-5119CRITICAL Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows | Jul 8, 2015 | 9.8 | 98 | YES | YES |
CVE-2015-3113CRITICAL Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attack | Jun 23, 2015 | 9.8 | 98 | YES | YES |
CVE-2015-0313CRITICAL Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote atta | Feb 2, 2015 | 9.8 | 98 | YES | YES |
CVE-2014-7169CRITICAL GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to wri | Sep 25, 2014 | 9.8 | 98 | YES | YES |
CVE-2014-0497CRITICAL Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote atta | Feb 5, 2014 | 9.8 | 98 | YES | YES |
CVE-2011-2462CRITICAL Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote att | Dec 7, 2011 | 9.8 | 98 | YES | YES |
CVE-2011-0611HIGH Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib | Apr 13, 2011 | 8.8 | 98 | YES | YES |
CVE-2015-3043CRITICAL Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or caus | Apr 14, 2015 | 9.8 | 97 | YES | YES |
Exploit Exposure
Signals from CVEs in this product scope (5568 CVEs).
CISA KEV
65 CVEs
1.2% of CVEs· 96th percentile
Metasploit
69 CVEs
1.2% of CVEs· 96th percentile
Nuclei
3 CVEs
0.1% of CVEs· 96th percentile
ExploitDB
475 CVEs
8.5% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (5568 CVEs).
Media Mentions
Signals from CVEs in this product scope (5568 CVEs).
Top CNAs Publishing CVEs For Mac Os X
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 11.0.1 | 1 | 7.8 | 1.2% | 0 | 0 |
| 10.9.5 | 10 | 6.4 | 14.5% | 0 | 1 |
| 10.9.4 | 19 | 6.8 | 1.7% | 0 | 0 |
| 10.9.3 | 30 | 6.6 | 1.8% | 0 | 0 |
| 10.9.2 | 41 | 6.8 | 1.9% | 0 | 0 |
| 10.9.1 | 51 | 6.8 | 1.8% | 0 | 1 |
| 10.9 | 61 | 6.7 | 1.8% | 0 | 2 |
| 10.8.5 | 71 | 6.3 | 2.5% | 0 | 1 |
| 10.8.4 | 59 | 5.6 | 1.4% | 0 | 0 |
| 10.8.3 | 67 | 5.5 | 1.4% | 0 | 0 |
| 10.8.2 | 78 | 5.5 | 1.4% | 0 | 0 |
| 10.8.1 | 81 | 5.4 | 1.4% | 0 | 0 |
| 10.8.0 | 81 | 5.4 | 1.4% | 0 | 0 |
| 10.7.5 | 23 | 5.7 | 1.8% | 0 | 0 |
| 10.7.4 | 21 | 5.8 | 1.9% | 0 | 0 |
| 10.7.3 | 29 | 5.6 | 1.7% | 0 | 0 |
| 10.7.2 | 42 | 5.8 | 1.8% | 0 | 1 |
| 10.7.1 | 61 | 5.8 | 2.0% | 0 | 1 |
| 10.7.0 | 73 | 5.8 | 2.0% | 0 | 1 |
| 10.6.8 | 40 | 5.8 | 3.8% | 0 | 1 |