Apple iOS vulnerabilities
1,765 known vulnerabilities affecting apple/ios.
Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
227
Exploited in wild
30
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7
Vulnerabilities
Page 27 of 89
CVE-2019-6213HIGHCVSS 7.8PoC≥ unspecified, < iOS 12.1.32019-03-05
CVE-2019-6213 [HIGH] CWE-119 CVE-2019-6213: A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, ma
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. An application may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2019-6205HIGHCVSS 7.8PoC≥ unspecified, < iOS 12.1.32019-03-05
CVE-2019-6205 [HIGH] CWE-787 CVE-2019-6205: A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iO
A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A malicious application may cause unexpected changes in memory shared between processes.
nvdapple
CVE-2019-6217HIGHCVSS 8.8≥ unspecified, < iOS 12.1.32019-03-05
CVE-2019-6217 [HIGH] CWE-787 CVE-2019-6217: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, watchOS 5.1.3, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2019-6227HIGHCVSS 8.8≥ unspecified, < iOS 12.1.32019-03-05
CVE-2019-6227 [HIGH] CWE-787 CVE-2019-6227: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, watchOS 5.1.3, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2019-6216HIGHCVSS 8.8≥ unspecified, < iOS 12.1.32019-03-05
CVE-2019-6216 [HIGH] CWE-787 CVE-2019-6216: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, watchOS 5.1.3, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2019-6200HIGHCVSS 8.8≥ unspecified, < iOS 12.1.32019-03-05
CVE-2019-6200 [HIGH] CWE-125 CVE-2019-6200: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.1.
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3. An attacker in a privileged network position may be able to execute arbitrary code.
nvdapple
CVE-2019-6226HIGHCVSS 8.8≥ unspecified, < iOS 12.1.32019-03-05
CVE-2019-6226 [HIGH] CWE-787 CVE-2019-6226: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, watchOS 5.1.3, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2019-6229MEDIUMCVSS 6.1≥ unspecified, < iOS 12.1.32019-03-05
CVE-2019-6229 [MEDIUM] CWE-79 CVE-2019-6229: A logic issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, tvOS 12.1.2
A logic issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
CVE-2019-6208MEDIUMCVSS 5.5PoC≥ unspecified, < iOS 12.1.32019-03-05
CVE-2019-6208 [MEDIUM] CWE-665 CVE-2019-6208: A memory initialization issue was addressed with improved memory handling. This issue is fixed in iO
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A malicious application may cause unexpected changes in memory shared between processes.
nvdapple
CVE-2019-6231MEDIUMCVSS 5.5≥ unspecified, < iOS 12.1.32019-03-05
CVE-2019-6231 [MEDIUM] CWE-125 CVE-2019-6231: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to read restricted memory.
nvdapple
CVE-2019-6209MEDIUMCVSS 5.5PoC≥ unspecified, < iOS 12.1.32019-03-05
CVE-2019-6209 [MEDIUM] CWE-125 CVE-2019-6209: An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to determine kernel memory layout.
nvdapple
CVE-2019-6228MEDIUMCVSS 6.1≥ unspecified, < iOS 12.1.32019-03-05
CVE-2019-6228 [MEDIUM] CWE-79 CVE-2019-6228: A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validatio
A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue is fixed in iOS 12.1.3, Safari 12.0.3. Processing maliciously crafted web content may lead to a cross site scripting attack.
nvdapple
CVE-2019-6235CRITICALCVSS 10.0≥ unspecified, < iOS 12.1.32019-03-04
CVE-2019-6235 [CRITICAL] CWE-787 CVE-2019-6235: A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3,
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3, iTunes 12.9.3 for Windows. A sandboxed process may be able to circumvent sandbox restrictions.
nvdapple
CVE-2019-6206CRITICALCVSS 9.8≥ unspecified, < iOS 12.1.32019-03-04
CVE-2019-6206 [CRITICAL] CWE-200 CVE-2019-6206: An issue existed with autofill resuming after it was canceled. The issue was addressed with improved
An issue existed with autofill resuming after it was canceled. The issue was addressed with improved state management. This issue is fixed in iOS 12.1.3. Password autofill may fill in passwords after they were manually cleared.
nvdapple
CVE-2018-20506HIGHCVSS 8.1v12.1.32019-01-22
CVE-2018-20506 [HIGH] CVE-2018-20506: iOS 12.1.3
Apple Security Update: About the security content of iOS 12.1.3
Product: iOS
Version: 12.1.3
CVE: CVE-2018-20506
Component: SQLite
Impact: A maliciously crafted SQL query may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved input validation.
apple
CVE-2018-20346HIGHCVSS 8.1v12.1.32019-01-22
CVE-2018-20346 [HIGH] CVE-2018-20346: iOS 12.1.3
Apple Security Update: About the security content of iOS 12.1.3
Product: iOS
Version: 12.1.3
CVE: CVE-2018-20346
Component: SQLite
Impact: A maliciously crafted SQL query may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved input validation.
apple
CVE-2018-20505HIGHCVSS 7.5v12.1.32019-01-22
CVE-2018-20505 [HIGH] CVE-2018-20505: iOS 12.1.3
Apple Security Update: About the security content of iOS 12.1.3
Product: iOS
Version: 12.1.3
CVE: CVE-2018-20505
Component: SQLite
Impact: A maliciously crafted SQL query may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved input validation.
apple
CVE-2018-4464HIGHCVSS 8.8v12.1.12018-12-05
CVE-2018-4464 [HIGH] CVE-2018-4464: iOS 12.1.1
Apple Security Update: About the security content of iOS 12.1.1
Product: iOS
Version: 12.1.1
CVE: CVE-2018-4464
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2018-4436HIGHCVSS 7.5v12.1.12018-12-05
CVE-2018-4436 [HIGH] CVE-2018-4436: iOS 12.1.1
Apple Security Update: About the security content of iOS 12.1.1
Product: iOS
Version: 12.1.1
CVE: CVE-2018-4436
Component: Profiles
Impact: An untrusted configuration profile may be incorrectly displayed as verified
Description: A certificate validation issue existed in configuration profiles. This was addressed with additional checks.
apple
CVE-2018-4435HIGHCVSS 7.8PoCv12.1.12018-12-05
CVE-2018-4435 [HIGH] CVE-2018-4435: iOS 12.1.1
Apple Security Update: About the security content of iOS 12.1.1
Product: iOS
Version: 12.1.1
CVE: CVE-2018-4435
Component: Kernel
Impact: A malicious application may be able to elevate privileges
Description: A logic issue was addressed with improved restrictions.
apple