Apple iOS vulnerabilities
1,765 known vulnerabilities affecting apple/ios.
Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7
Vulnerabilities
Page 21 of 89
CVE-2017-7062P3CRITICALCVSS 9.8v10.3.32017-07-19
CVE-2017-7062 [CRITICAL] CVE-2017-7062: iOS 10.3.3
Apple Security Update: About the security content of iOS 10.3.3
Product: iOS
Version: 10.3.3
CVE: CVE-2017-7062
Component: Contacts
Impact: A remote attacker may be able to cause unexpected application termination or arbitrary code execution
Description: A buffer overflow issue was addressed through improved memory handling.
apple
CVE-2016-4631P3HIGHCVSS 8.8v9.3.32016-07-18
CVE-2016-4631 [HIGH] CVE-2016-4631: iOS 9.3.3
Apple Security Update: About the security content of iOS 9.3.3
Product: iOS
Version: 9.3.3
CVE: CVE-2016-4631
Component: ImageIO
Impact: A remote attacker may be able to execute arbitrary code
Description: Multiple memory corruption issues were addressed through improved memory handling.
apple
CVE-2016-4637P3HIGHCVSS 8.8v9.3.32016-07-18
CVE-2016-4637 [HIGH] CVE-2016-4637: iOS 9.3.3
Apple Security Update: About the security content of iOS 9.3.3
Product: iOS
Version: 9.3.3
CVE: CVE-2016-4637
Component: CoreGraphics
Impact: A remote attacker may be able to execute arbitrary code
Description: A memory corruption issue was addressed through improved memory handling.
apple
CVE-2016-1778P3HIGHCVSS 8.8v9.3
CVE-2016-1778 [HIGH] CVE-2016-1778: iOS 9.3
Apple Security Update: About the security content of iOS 9.3
Product: iOS
Version: 9.3
CVE: CVE-2016-1778
Component: CVE-ID
apple
CVE-2015-7055P3CRITICALCVSS 9.3v9.2
CVE-2015-7055 [CRITICAL] CVE-2015-7055: iOS 9.2
Apple Security Update: About the security content of iOS 9.2
Product: iOS
Version: 9.2
CVE: CVE-2015-7055
Component: CVE-ID
apple
CVE-2018-4190P3HIGHCVSS 8.8v11.42018-05-29
CVE-2018-4190 [HIGH] CVE-2018-4190: iOS 11.4
Apple Security Update: About the security content of iOS 11.4
Product: iOS
Version: 11.4
CVE: CVE-2018-4190
Component: WebKit
Impact: Visiting a maliciously crafted website may leak sensitive data
Description: Credentials were unexpectedly sent when fetching CSS mask images. This was addressed by using a CORS-enabled fetch method.
apple
CVE-2020-9883P3HIGHCVSS 7.8≥ unspecified, < iOS 13.6 and iPadOS 13.62020-10-22
CVE-2020-9883 [HIGH] CWE-120 CVE-2020-9883: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2017-2485P3HIGHCVSS 8.8v10.32017-03-27
CVE-2017-2485 [HIGH] CVE-2017-2485: iOS 10.3
Apple Security Update: About the security content of iOS 10.3
Product: iOS
Version: 10.3
CVE: CVE-2017-2485
Component: Security
Impact: Processing a maliciously crafted x509 certificate may lead to arbitrary code execution
Description: A memory corruption issue existed in the parsing of certificates. This issue was addressed through improved input validation.
apple
CVE-2016-4688P3HIGHCVSS 8.8v10.12016-10-24
CVE-2016-4688 [HIGH] CVE-2016-4688: iOS 10.1
Apple Security Update: About the security content of iOS 10.1
Product: iOS
Version: 10.1
CVE: CVE-2016-4688
Component: FontParser
Impact: Processing a maliciously crafted font file may lead to arbitrary code execution
Description: A buffer overflow existed in the handling of font files. This issue was addressed through improved bounds checking.
apple
CVE-2018-4201P3HIGHCVSS 8.8v11.42018-05-29
CVE-2018-4201 [HIGH] CVE-2018-4201: iOS 11.4
Apple Security Update: About the security content of iOS 11.4
Product: iOS
Version: 11.4
CVE: CVE-2018-4201
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2017-13884P3HIGHCVSS 8.8v11.22017-12-02
CVE-2017-13884 [HIGH] CVE-2017-13884: iOS 11.2
Apple Security Update: About the security content of iOS 11.2
Product: iOS
Version: 11.2
CVE: CVE-2017-13884
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2017-7165P3HIGHCVSS 8.8v11.22017-12-02
CVE-2017-7165 [HIGH] CVE-2017-7165: iOS 11.2
Apple Security Update: About the security content of iOS 11.2
Product: iOS
Version: 11.2
CVE: CVE-2017-7165
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed through improved memory handling.
apple
CVE-2016-4728P3HIGHCVSS 8.8v102016-09-13
CVE-2016-4728 [HIGH] CVE-2016-4728: iOS 10
Apple Security Update: About the security content of iOS 10
Product: iOS
Version: 10
CVE: CVE-2016-4728
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: A parsing issue existed in the handling of error prototypes. This was addressed through improved validation.
apple
CVE-2019-8745P3HIGHCVSS 8.8v132019-09-19
CVE-2019-8745 [HIGH] CVE-2019-8745: iOS 13
Apple Security Update: About the security content of iOS 13
Product: iOS
Version: 13
CVE: CVE-2019-8745
Component: UIFoundation
Impact: Processing a maliciously crafted text file may lead to arbitrary code execution
Description: A buffer overflow was addressed with improved bounds checking.
apple
CVE-2018-4129P3HIGHCVSS 8.8v11.32018-03-29
CVE-2018-4129 [HIGH] CVE-2018-4129: iOS 11.3
Apple Security Update: About the security content of iOS 11.3
Product: iOS
Version: 11.3
CVE: CVE-2018-4129
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2018-4122P3HIGHCVSS 8.8v11.32018-03-29
CVE-2018-4122 [HIGH] CVE-2018-4122: iOS 11.3
Apple Security Update: About the security content of iOS 11.3
Product: iOS
Version: 11.3
CVE: CVE-2018-4122
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2018-4163P3HIGHCVSS 8.8v11.32018-03-29
CVE-2018-4163 [HIGH] CVE-2018-4163: iOS 11.3
Apple Security Update: About the security content of iOS 11.3
Product: iOS
Version: 11.3
CVE: CVE-2018-4163
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2018-4114P3HIGHCVSS 8.8v11.32018-03-29
CVE-2018-4114 [HIGH] CVE-2018-4114: iOS 11.3
Apple Security Update: About the security content of iOS 11.3
Product: iOS
Version: 11.3
CVE: CVE-2018-4114
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2018-4125P3HIGHCVSS 8.8v11.32018-03-29
CVE-2018-4125 [HIGH] CVE-2018-4125: iOS 11.3
Apple Security Update: About the security content of iOS 11.3
Product: iOS
Version: 11.3
CVE: CVE-2018-4125
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2019-8523P3HIGHCVSS 8.8≥ unspecified, < iOS 12.22019-12-18
CVE-2019-8523 [HIGH] CWE-787 CVE-2019-8523: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple