Vulnerabilities > Apple > MAC OS X > High

DATE CVE VULNERABILITY TITLE RISK
2021-12-27 CVE-2021-4173 Use After Free vulnerability in multiple products
vim is vulnerable to Use After Free
local
low complexity
vim fedoraproject apple CWE-416
7.8
2021-12-25 CVE-2021-4166 Out-of-bounds Read vulnerability in multiple products
vim is vulnerable to Out-of-bounds Read
7.1
2021-12-23 CVE-2017-13835 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple mac OS X
A memory corruption issue was addressed with improved memory handling.
local
low complexity
apple CWE-119
7.8
2021-12-23 CVE-2017-13892 Unspecified vulnerability in Apple mac OS X and Macos
An issue existed in the handling of Contact sharing.
network
low complexity
apple
7.5
2021-12-23 CVE-2017-13905 Race Condition vulnerability in Apple products
A race condition was addressed with additional validation.
network
high complexity
apple CWE-362
8.1
2021-12-23 CVE-2017-13906 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple mac OS X
A memory corruption issue was addressed with improved memory handling.
local
low complexity
apple CWE-119
7.8
2021-12-23 CVE-2017-13908 Unspecified vulnerability in Apple mac OS X
An issue in handling file permissions was addressed with improved validation.
local
low complexity
apple
7.8
2021-12-23 CVE-2018-4302 NULL Pointer Dereference vulnerability in Apple products
A null pointer dereference was addressed with improved validation.
local
low complexity
apple CWE-476
7.8
2021-12-23 CVE-2020-3886 Use After Free vulnerability in Apple mac OS X
A use after free issue was addressed with improved memory management.
local
low complexity
apple CWE-416
7.8
2021-12-20 CVE-2021-44224 NULL Pointer Dereference vulnerability in multiple products
A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery).
8.2