Apple iOS vulnerabilities
1,765 known vulnerabilities affecting apple/ios.
Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7
Vulnerabilities
Page 36 of 89
CVE-2016-1777P3HIGHCVSS 7.5v122018-09-17
CVE-2016-1777 [HIGH] CVE-2016-1777: iOS 12
Apple Security Update: About the security content of iOS 12
Product: iOS
Version: 12
CVE: CVE-2016-1777
Component: Security
Impact: An attacker may be able to exploit weaknesses in the RC4 cryptographic algorithm
Description: This issue was addressed by removing RC4.
apple
CVE-2021-30789P3HIGHCVSS 7.8≥ unspecified, < 14.72021-09-08
CVE-2021-30789 [HIGH] CWE-125 CVE-2021-30789: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.7,
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-004 Catalina. Processing a maliciously crafted font file may lead to arbitrary code execution.
nvd
CVE-2016-4447P3HIGHCVSS 7.5v9.3.32016-07-18
CVE-2016-4447 [HIGH] CVE-2016-4447: iOS 9.3.3
Apple Security Update: About the security content of iOS 9.3.3
Product: iOS
Version: 9.3.3
CVE: CVE-2016-4447
Component: Libc
Impact: A remote attacker may be able to cause unexpected application termination or arbitrary code execution
Description: A buffer overflow existed within the "link_ntoa()" function in linkaddr.c. This issue was addressed through additional bounds checking.
apple
CVE-2020-9980P3HIGHCVSS 7.8≥ unspecified, < iOS 13.6 and iPadOS 13.62020-10-22
CVE-2020-9980 [HIGH] CWE-787 CVE-2020-9980: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. Processing a maliciously crafted font file may lead to arbitrary code execution.
nvd
CVE-2018-4227P3HIGHCVSS 7.5v11.42018-05-29
CVE-2018-4227 [HIGH] CVE-2018-4227: iOS 11.4
Apple Security Update: About the security content of iOS 11.4
Product: iOS
Version: 11.4
CVE: CVE-2018-4227
Component: Mail
Impact: An attacker may be able to exfiltrate the contents of S/MIME-encrypted e-mail
Description: An issue existed in the handling of encrypted Mail. This issue was addressed with improved isolation of MIME in Mail.
apple
CVE-2020-9844P3HIGHCVSS 7.5≥ unspecified, < iOS 13.5 and iPadOS 13.52020-06-09
CVE-2020-9844 [HIGH] CWE-415 CVE-2020-9844: A double free issue was addressed with improved memory management. This issue is fixed in iOS 13.5 a
A double free issue was addressed with improved memory management. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2015-5757P3CRITICALCVSS 9.3v8.4.1
CVE-2015-5757 [CRITICAL] CVE-2015-5757: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-5757
Component: CVE-ID
Impact: Parsing a maliciously crafted XML document may lead to disclosure of user information
Description: A memory corruption issue existed in parsing of XML files. This issue was addressed through improved memory handling.
apple
CVE-2019-8562P3CRITICALCVSS 9.6≥ unspecified, < iOS 12.22019-12-18
CVE-2019-8562 [CRITICAL] CWE-787 CVE-2019-8562: A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.2, t
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12.9.4 for Windows. A sandboxed process may be able to circumvent sandbox restrictions.
nvdapple
CVE-2018-4210P3HIGHCVSS 8.8v11.32018-03-29
CVE-2018-4210 [HIGH] CVE-2018-4210: iOS 11.3
Apple Security Update: About the security content of iOS 11.3
Product: iOS
Version: 11.3
CVE: CVE-2018-4210
Component: WebKit
Impact: Unexpected interaction with indexing types caused a failure
Description: An array indexing issue existed in the handling of a function in javascript core. This issue was addressed with improved checks.
apple
CVE-2016-1775P3HIGHCVSS 7.8v9.3
CVE-2016-1775 [HIGH] CVE-2016-1775: iOS 9.3
Apple Security Update: About the security content of iOS 9.3
Product: iOS
Version: 9.3
CVE: CVE-2016-1775
Component: CVE-ID
apple
CVE-2016-1740P3HIGHCVSS 7.8v9.3
CVE-2016-1740 [HIGH] CVE-2016-1740: iOS 9.3
Apple Security Update: About the security content of iOS 9.3
Product: iOS
Version: 9.3
CVE: CVE-2016-1740
Component: CVE-ID
apple
CVE-2018-4375P3HIGHCVSS 8.8v12.12018-10-30
CVE-2018-4375 [HIGH] CVE-2018-4375: iOS 12.1
Apple Security Update: About the security content of iOS 12.1
Product: iOS
Version: 12.1
CVE: CVE-2018-4375
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2018-4376P3HIGHCVSS 8.8v12.12018-10-30
CVE-2018-4376 [HIGH] CVE-2018-4376: iOS 12.1
Apple Security Update: About the security content of iOS 12.1
Product: iOS
Version: 12.1
CVE: CVE-2018-4376
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2017-9050P3HIGHCVSS 7.5v112017-09-19
CVE-2017-9050 [HIGH] CVE-2017-9050: iOS 11
Apple Security Update: About the security content of iOS 11
Product: iOS
Version: 11
CVE: CVE-2017-9050
Component: CVE-2017-9233
Impact: Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution
Description: A buffer overflow issue was addressed with improved memory handling.
apple
CVE-2020-3883P3HIGHCVSS 8.8≥ unspecified, < iOS 13.4 and iPadOS 13.42020-04-01
CVE-2020-3883 [HIGH] CVE-2020-3883: This issue was addressed with improved checks. This issue is fixed in iOS 13.4 and iPadOS 13.4, macO
This issue was addressed with improved checks. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. An application may be able to use arbitrary entitlements.
nvd
CVE-2015-6992P3HIGHCVSS 7.5v9.1
CVE-2015-6992 [HIGH] CVE-2015-6992: iOS 9.1
Apple Security Update: About the security content of iOS 9.1
Product: iOS
Version: 9.1
CVE: CVE-2015-6992
Component: CVE-ID
apple
CVE-2015-6975P3HIGHCVSS 7.5v9.1
CVE-2015-6975 [HIGH] CVE-2015-6975: iOS 9.1
Apple Security Update: About the security content of iOS 9.1
Product: iOS
Version: 9.1
CVE: CVE-2015-6975
Component: CVE-ID
apple
CVE-2015-7017P3HIGHCVSS 7.5v9.1
CVE-2015-7017 [HIGH] CVE-2015-7017: iOS 9.1
Apple Security Update: About the security content of iOS 9.1
Product: iOS
Version: 9.1
CVE: CVE-2015-7017
Component: CVE-ID
apple
CVE-2019-2102P3HIGHCVSS 8.8v12.32019-05-13
CVE-2019-2102 [HIGH] CVE-2019-2102: iOS 12.3
Apple Security Update: About the security content of iOS 12.3
Product: iOS
Version: 12.3
CVE: CVE-2019-2102
Component: Bluetooth
Impact: Due to a misconfiguration in the Bluetooth pairing protocols of a Bluetooth Low Energy (BLE) version of FIDO Security Keys it may be possible for an attacker with physical proximity to be able to intercept Bluetooth traffic during pairing
Description: This issue was addressed by disabling accessories with insecure Bl
apple
CVE-2017-2441P3HIGHCVSS 7.8v10.32017-03-27
CVE-2017-2441 [HIGH] CVE-2017-2441: iOS 10.3
Apple Security Update: About the security content of iOS 10.3
Product: iOS
Version: 10.3
CVE: CVE-2017-2441
Component: CVE-2017-2441
Impact: Multiple vulnerabilities in libxslt
Description: Multiple memory corruption issues were addressed through improved memory handling.
apple