Vulnerabilities > Apple > MAC OS X > 10.14.6

DATE CVE VULNERABILITY TITLE RISK
2019-12-18 CVE-2019-8755 NULL Pointer Dereference vulnerability in Apple mac OS X
A logic issue was addressed with improved restrictions.
local
low complexity
apple CWE-476
7.2
2019-12-18 CVE-2019-8748 Out-of-bounds Write vulnerability in Apple mac OS X
A memory corruption issue was addressed with improved memory handling.
local
low complexity
apple CWE-787
7.2
2019-12-18 CVE-2019-8745 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple products
A buffer overflow was addressed with improved bounds checking.
network
apple CWE-119
6.8
2019-12-18 CVE-2019-8730 Incomplete Cleanup vulnerability in Apple mac OS X
The contents of locked notes sometimes appeared in search results.
local
low complexity
apple CWE-459
2.1
2019-12-18 CVE-2019-8717 Out-of-bounds Write vulnerability in Apple mac OS X
A memory corruption issue was addressed with improved memory handling.
local
low complexity
apple CWE-787
7.2
2019-12-18 CVE-2019-8705 Out-of-bounds Write vulnerability in Apple mac OS X
A memory corruption issue was addressed with improved validation.
network
apple CWE-787
4.3
2019-12-18 CVE-2019-8701 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple mac OS X
A memory corruption issue was addressed with improved memory handling.
local
low complexity
apple CWE-119
7.2
2019-12-11 CVE-2019-14899 Man-in-the-Middle vulnerability in multiple products
A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences about the websites they are visiting, and determine the correct sequence and acknowledgement numbers in use, allowing the bad actor to inject data into the TCP stream.
low complexity
freebsd linux openbsd apple CWE-300
7.4
2019-10-03 CVE-2019-15165 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.
5.3
2019-10-03 CVE-2019-15166 Classic Buffer Overflow vulnerability in multiple products
lmp_print_data_link_subobjs() in print-lmp.c in tcpdump before 4.9.3 lacks certain bounds checks.
7.5