Apple iOS vulnerabilities
1,765 known vulnerabilities affecting apple/ios.
Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7
Vulnerabilities
Page 12 of 89
CVE-2019-8690P3MEDIUMCVSS 6.1PoC≥ unspecified, < iOS 12.42019-12-18
CVE-2019-8690 [MEDIUM] CWE-79 CVE-2019-8690: A logic issue existed in the handling of document loads. This issue was addressed with improved stat
A logic issue existed in the handling of document loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to universal cross site script
nvdapple
CVE-2017-2445P3MEDIUMCVSS 6.1PoCv10.32017-03-27
CVE-2017-2445 [MEDIUM] CVE-2017-2445: iOS 10.3
Apple Security Update: About the security content of iOS 10.3
Product: iOS
Version: 10.3
CVE: CVE-2017-2445
Component: WebKit
Impact: Processing maliciously crafted web content may lead to universal cross site scripting
Description: A logic issue existed in the handling of frame objects. This issue was addressed with improved state management.
apple
CVE-2017-2510P3MEDIUMCVSS 6.1PoCv10.3.22017-05-15
CVE-2017-2510 [MEDIUM] CVE-2017-2510: iOS 10.3.2
Apple Security Update: About the security content of iOS 10.3.2
Product: iOS
Version: 10.3.2
CVE: CVE-2017-2510
Component: WebKit
Impact: Processing maliciously crafted web content may lead to universal cross site scripting
Description: A logic issue existed in the handling of pageshow events. This issue was addressed with improved state management.
apple
CVE-2017-2504P3MEDIUMCVSS 6.1PoCv10.3.22017-05-15
CVE-2017-2504 [MEDIUM] CVE-2017-2504: iOS 10.3.2
Apple Security Update: About the security content of iOS 10.3.2
Product: iOS
Version: 10.3.2
CVE: CVE-2017-2504
Component: WebKit
Impact: Processing maliciously crafted web content may lead to universal cross site scripting
Description: A logic issue existed in the handling of WebKit Editor commands. This issue was addressed with improved state management.
apple
CVE-2017-5754P3MEDIUMCVSS 5.6v11.22017-12-02
CVE-2017-5754 [MEDIUM] CVE-2017-5754: iOS 11.2
Apple Security Update: About the security content of iOS 11.2
Product: iOS
Version: 11.2
CVE: CVE-2017-5754
Component: Kernel
Impact: An application may be able to read kernel memory (Meltdown)
Description: Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.
apple
CVE-2017-6979P3HIGHCVSS 7.0PoCv10.3.22017-05-15
CVE-2017-6979 [HIGH] CVE-2017-6979: iOS 10.3.2
Apple Security Update: About the security content of iOS 10.3.2
Product: iOS
Version: 10.3.2
CVE: CVE-2017-6979
Component: IOSurface
Impact: An application may be able to gain kernel privileges
Description: A race condition was addressed through improved locking.
apple
CVE-2016-1863P3HIGHCVSS 7.8PoCv9.3.32016-07-18
CVE-2016-1863 [HIGH] CVE-2016-1863: iOS 9.3.3
Apple Security Update: About the security content of iOS 9.3.3
Product: iOS
Version: 9.3.3
CVE: CVE-2016-1863
Component: Kernel
Impact: A local user may be able to execute arbitrary code with kernel privileges
Description: Multiple memory corruption issues were addressed through improved memory handling.
apple
CVE-2017-2508P3MEDIUMCVSS 6.1PoCv10.3.22017-05-15
CVE-2017-2508 [MEDIUM] CVE-2017-2508: iOS 10.3.2
Apple Security Update: About the security content of iOS 10.3.2
Product: iOS
Version: 10.3.2
CVE: CVE-2017-2508
Component: WebKit
Impact: Processing maliciously crafted web content may lead to universal cross site scripting
Description: A logic issue existed in the handling of WebKit container nodes. This issue was addressed with improved state management.
apple
CVE-2016-7661P3HIGHCVSS 7.8PoCv10.22016-12-12
CVE-2016-7661 [HIGH] CVE-2016-7661: iOS 10.2
Apple Security Update: About the security content of iOS 10.2
Product: iOS
Version: 10.2
CVE: CVE-2016-7661
Component: Power Management
Impact: A local user may be able to gain root privileges
Description: An issue in mach port name references was addressed through improved validation.
apple
CVE-2016-7637P3HIGHCVSS 7.8PoCv10.22016-12-12
CVE-2016-7637 [HIGH] CVE-2016-7637: iOS 10.2
Apple Security Update: About the security content of iOS 10.2
Product: iOS
Version: 10.2
CVE: CVE-2016-7637
Component: Kernel
Impact: A local user may be able to gain root privileges
Description: A memory corruption issue was addressed through improved input validation.
apple
CVE-2016-7660P3HIGHCVSS 7.8PoCv10.22016-12-12
CVE-2016-7660 [HIGH] CVE-2016-7660: iOS 10.2
Apple Security Update: About the security content of iOS 10.2
Product: iOS
Version: 10.2
CVE: CVE-2016-7660
Component: SpringBoard
Impact: A person with physical access to an iOS device may be able to keep the device unlocked
Description: A cleanup issue existed in the handling of Handoff with Siri. This was addressed through improved state management.
apple
CVE-2017-2528P3MEDIUMCVSS 6.1PoCv10.3.22017-05-15
CVE-2017-2528 [MEDIUM] CVE-2017-2528: iOS 10.3.2
Apple Security Update: About the security content of iOS 10.3.2
Product: iOS
Version: 10.3.2
CVE: CVE-2017-2528
Component: WebKit
Impact: Processing maliciously crafted web content may lead to universal cross site scripting
Description: A logic issue existed in the handling of WebKit cached frames. This issue was addressed with improved state management.
apple
CVE-2019-8591P3HIGHCVSS 7.1PoC≥ unspecified, < iOS 12.32019-12-18
CVE-2019-8591 [HIGH] CWE-843 CVE-2019-8591: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.3,
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. An application may be able to cause unexpected system termination or write kernel memory.
nvdapple
CVE-2015-1155P3MEDIUMCVSS 4.3PoCv8.4
CVE-2015-1155 [MEDIUM] CVE-2015-1155: iOS 8.4
Apple Security Update: About the security content of iOS 8.4
Product: iOS
Version: 8.4
CVE: CVE-2015-1155
Component: CVE-ID
apple
CVE-2020-9839P3HIGHCVSS 7.0PoC≥ unspecified, < iOS 13.5 and iPadOS 13.52020-06-09
CVE-2020-9839 [HIGH] CWE-362 CVE-2020-9839: A race condition was addressed with improved state handling. This issue is fixed in iOS 13.5 and iPa
A race condition was addressed with improved state handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. An application may be able to gain elevated privileges.
nvd
CVE-2016-4622P3HIGHCVSS 8.8v9.3.32016-07-18
CVE-2016-4622 [HIGH] CVE-2016-4622: iOS 9.3.3
Apple Security Update: About the security content of iOS 9.3.3
Product: iOS
Version: 9.3.3
CVE: CVE-2016-4622
Component: WebKit
Impact: Visiting a maliciously crafted website may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed through improved memory handling.
apple
CVE-2015-7036P3HIGHCVSS 7.5v8.4
CVE-2015-7036 [HIGH] CVE-2015-7036: iOS 8.4
Apple Security Update: About the security content of iOS 8.4
Product: iOS
Version: 8.4
CVE: CVE-2015-7036
Component: CVE-ID
apple
CVE-2015-1126P3MEDIUMCVSS 4.3PoCv8.3
CVE-2015-1126 [MEDIUM] CVE-2015-1126: iOS 8.3
Apple Security Update: About the security content of iOS 8.3
Product: iOS
Version: 8.3
CVE: CVE-2015-1126
Component: CVE-ID
apple
CVE-2015-6988P3CRITICALCVSS 10.0v9.1
CVE-2015-6988 [CRITICAL] CVE-2015-6988: iOS 9.1
Apple Security Update: About the security content of iOS 9.1
Product: iOS
Version: 9.1
CVE: CVE-2015-6988
Component: CVE-ID
apple
CVE-2018-20346P3HIGHCVSS 8.1v12.1.32019-01-22
CVE-2018-20346 [HIGH] CVE-2018-20346: iOS 12.1.3
Apple Security Update: About the security content of iOS 12.1.3
Product: iOS
Version: 12.1.3
CVE: CVE-2018-20346
Component: SQLite
Impact: A maliciously crafted SQL query may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved input validation.
apple