cbcvebase.

Apple iOS vulnerabilities

1,765 known vulnerabilities affecting apple/ios.

Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7

Vulnerabilities

Page 34 of 89
CVE-2019-8779P3CRITICALCVSS 10.0≥ unspecified, < iOS 13.1.1 and iPadOS 13.1.12019-12-18
CVE-2019-8779 [CRITICAL] CWE-668 CVE-2019-8779: A logic issue applied the incorrect restrictions. This issue was addressed by updating the logic to A logic issue applied the incorrect restrictions. This issue was addressed by updating the logic to apply the correct restrictions. This issue is fixed in iOS 13.1.1 and iPadOS 13.1.1. Third party app extensions may not receive the correct sandbox restrictions.
nvd
CVE-2020-9898P3CRITICALCVSS 9.8≥ unspecified, < iOS 13.6 and iPadOS 13.62020-10-22
CVE-2020-9898 [CRITICAL] CVE-2020-9898: This issue was addressed with improved entitlements. This issue is fixed in iOS 13.6 and iPadOS 13.6 This issue was addressed with improved entitlements. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6. A sandboxed process may be able to circumvent sandbox restrictions.
nvd
CVE-2015-6986P3CRITICALCVSS 9.3v9.1
CVE-2015-6986 [CRITICAL] CVE-2015-6986: iOS 9.1 Apple Security Update: About the security content of iOS 9.1 Product: iOS Version: 9.1 CVE: CVE-2015-6986 Component: CVE-ID
apple
CVE-2018-20505P3HIGHCVSS 7.5v12.1.32019-01-22
CVE-2018-20505 [HIGH] CVE-2018-20505: iOS 12.1.3 Apple Security Update: About the security content of iOS 12.1.3 Product: iOS Version: 12.1.3 CVE: CVE-2018-20505 Component: SQLite Impact: A maliciously crafted SQL query may lead to arbitrary code execution Description: Multiple memory corruption issues were addressed with improved input validation.
apple
CVE-2015-1100P4MEDIUMCVSS 5.4PoCv8.3
CVE-2015-1100 [MEDIUM] CVE-2015-1100: iOS 8.3 Apple Security Update: About the security content of iOS 8.3 Product: iOS Version: 8.3 CVE: CVE-2015-1100 Component: CVE-ID
apple
CVE-2016-9843P3CRITICALCVSS 9.8v112017-09-19
CVE-2016-9843 [CRITICAL] CVE-2016-9843: iOS 11 Apple Security Update: About the security content of iOS 11 Product: iOS Version: 11 CVE: CVE-2016-9843 Component: CVE-2016-9843
apple
CVE-2018-4214P3HIGHCVSS 8.8v11.42018-05-29
CVE-2018-4214 [HIGH] CVE-2018-4214: iOS 11.4 Apple Security Update: About the security content of iOS 11.4 Product: iOS Version: 11.4 CVE: CVE-2018-4214 Component: WebKit Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash Description: A memory corruption issue was addressed with improved input validation.
apple
CVE-2018-4208P3HIGHCVSS 8.8v11.32018-03-29
CVE-2018-4208 [HIGH] CVE-2018-4208: iOS 11.3 Apple Security Update: About the security content of iOS 11.3 Product: iOS Version: 11.3 CVE: CVE-2018-4208 Component: WebKit Impact: Unexpected interaction causes an ASSERT failure Description: This issue was addressed with improved checks.
apple
CVE-2018-4209P3HIGHCVSS 8.8v11.32018-03-29
CVE-2018-4209 [HIGH] CVE-2018-4209: iOS 11.3 Apple Security Update: About the security content of iOS 11.3 Product: iOS Version: 11.3 CVE: CVE-2018-4209 Component: WebKit Impact: Unexpected interaction causes an ASSERT failure Description: This issue was addressed with improved checks.
apple
CVE-2018-4212P3HIGHCVSS 8.8v11.32018-03-29
CVE-2018-4212 [HIGH] CVE-2018-4212: iOS 11.3 Apple Security Update: About the security content of iOS 11.3 Product: iOS Version: 11.3 CVE: CVE-2018-4212 Component: WebKit Impact: Unexpected interaction causes an ASSERT failure Description: This issue was addressed with improved checks.
apple
CVE-2018-4207P3HIGHCVSS 8.8v11.32018-03-29
CVE-2018-4207 [HIGH] CVE-2018-4207: iOS 11.3 Apple Security Update: About the security content of iOS 11.3 Product: iOS Version: 11.3 CVE: CVE-2018-4207 Component: WebKit Impact: Unexpected interaction causes an ASSERT failure Description: This issue was addressed with improved checks.
apple
CVE-2018-4213P3HIGHCVSS 8.8v11.32018-03-29
CVE-2018-4213 [HIGH] CVE-2018-4213: iOS 11.3 Apple Security Update: About the security content of iOS 11.3 Product: iOS Version: 11.3 CVE: CVE-2018-4213 Component: WebKit Impact: Unexpected interaction causes an ASSERT failure Description: This issue was addressed with improved checks.
apple
CVE-2018-4149P3HIGHCVSS 8.8v11.32018-03-29
CVE-2018-4149 [HIGH] CVE-2018-4149: iOS 11.3 Apple Security Update: About the security content of iOS 11.3 Product: iOS Version: 11.3 CVE: CVE-2018-4149 Component: SafariViewController Impact: Visiting a malicious website may lead to user interface spoofing Description: A state management issue was addressed by disabling text input until the destination page loads.
apple
CVE-2018-4134P3HIGHCVSS 8.8v11.32018-03-29
CVE-2018-4134 [HIGH] CVE-2018-4134: iOS 11.3 Apple Security Update: About the security content of iOS 11.3 Product: iOS Version: 11.3 CVE: CVE-2018-4134 Component: Safari Impact: Visiting a malicious website by clicking a link may lead to user interface spoofing Description: An inconsistent user interface issue was addressed with improved state management.
apple
CVE-2018-4437P3HIGHCVSS 8.8v12.1.12018-12-05
CVE-2018-4437 [HIGH] CVE-2018-4437: iOS 12.1.1 Apple Security Update: About the security content of iOS 12.1.1 Product: iOS Version: 12.1.1 CVE: CVE-2018-4437 Component: WebKit Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2018-4464P3HIGHCVSS 8.8v12.1.12018-12-05
CVE-2018-4464 [HIGH] CVE-2018-4464: iOS 12.1.1 Apple Security Update: About the security content of iOS 12.1.1 Product: iOS Version: 12.1.1 CVE: CVE-2018-4464 Component: WebKit Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2018-4392P3HIGHCVSS 8.8v12.12018-10-30
CVE-2018-4392 [HIGH] CVE-2018-4392: iOS 12.1 Apple Security Update: About the security content of iOS 12.1 Product: iOS Version: 12.1 CVE: CVE-2018-4392 Component: WebKit Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2016-4591P3HIGHCVSS 7.5v9.3.32016-07-18
CVE-2016-4591 [HIGH] CVE-2016-4591: iOS 9.3.3 Apple Security Update: About the security content of iOS 9.3.3 Product: iOS Version: 9.3.3 CVE: CVE-2016-4591 Component: WebKit Impact: Visiting a maliciously crafted website may leak sensitive data Description: A permissions issue existed in the handling of the location variable. This was addressed though additional ownership checks.
apple
CVE-2014-4485P3HIGHCVSS 7.5v8.1.3
CVE-2014-4485 [HIGH] CVE-2014-4485: iOS 8.1.3 Apple Security Update: About the security content of iOS 8.1.3 Product: iOS Version: 8.1.3 CVE: CVE-2014-4485 Component: CVE-ID
apple
CVE-2020-9865P3HIGHCVSS 8.6≥ unspecified, < iOS 13.6 and iPadOS 13.62020-10-16
CVE-2020-9865 [HIGH] CWE-787 CVE-2020-9865: A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A malicious application may be able to break out of its sandbox.
nvd
Apple iOS vulnerabilities | cvebase