Apple iOS vulnerabilities
1,765 known vulnerabilities affecting apple/ios.
Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7
Vulnerabilities
Page 45 of 89
CVE-2015-1157P3HIGHCVSS 7.8v8.4
CVE-2015-1157 [HIGH] CVE-2015-1157: iOS 8.4
Apple Security Update: About the security content of iOS 8.4
Product: iOS
Version: 8.4
CVE: CVE-2015-1157
Component: CVE-2015-1157
Impact: An attacker with a privileged network position may intercept SSL/TLS connections
Description: coreTLS accepted short ephemeral Diffie-Hellman (DH) keys, as used in export-strength ephemeral DH cipher suites. This issue, also known as Logjam, allowed an attacker with a privileged network position to downgrade securit
apple
CVE-2015-5776P3HIGHCVSS 7.5v8.4.1
CVE-2015-5776 [HIGH] CVE-2015-5776: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-5776
Component: CVE-ID
Impact: A malicious application may be able to execute arbitrary code with system privileges
Description: A memory corruption issue existed in handling syscalls. This issue was addressed through improved lock state checking.
apple
CVE-2014-4484P3HIGHCVSS 7.5v8.1.3
CVE-2014-4484 [HIGH] CVE-2014-4484: iOS 8.1.3
Apple Security Update: About the security content of iOS 8.1.3
Product: iOS
Version: 8.1.3
CVE: CVE-2014-4484
Component: CVE-ID
apple
CVE-2018-4275P3HIGHCVSS 8.6v11.4.12018-07-09
CVE-2018-4275 [HIGH] CVE-2018-4275: iOS 11.4.1
Apple Security Update: About the security content of iOS 11.4.1
Product: iOS
Version: 11.4.1
CVE: CVE-2018-4275
Component: Wi-Fi
Impact: A malicious application may be able to break out of its sandbox
Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2018-4140P3HIGHCVSS 7.5v11.32018-03-29
CVE-2018-4140 [HIGH] CVE-2018-4140: iOS 11.3
Apple Security Update: About the security content of iOS 11.3
Product: iOS
Version: 11.3
CVE: CVE-2018-4140
Component: Telephony
Impact: A remote attacker can cause a device to unexpectedly restart
Description: A null pointer dereference issue existed when handling Class 0 SMS messages. This issue was addressed with improved message validation.
apple
CVE-2018-4327P3HIGHCVSS 7.8v11.4.12018-07-09
CVE-2018-4327 [HIGH] CVE-2018-4327: iOS 11.4.1
Apple Security Update: About the security content of iOS 11.4.1
Product: iOS
Version: 11.4.1
CVE: CVE-2018-4327
Component: Core Bluetooth
Impact: An application may be able to execute arbitrary code with system privileges
Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2017-2461P3HIGHCVSS 7.5v10.32017-03-27
CVE-2017-2461 [HIGH] CVE-2017-2461: iOS 10.3
Apple Security Update: About the security content of iOS 10.3
Product: iOS
Version: 10.3
CVE: CVE-2017-2461
Component: CoreText
Impact: Processing a maliciously crafted text message may lead to application denial of service
Description: A resource exhaustion issue was addressed through improved input validation.
apple
CVE-2014-4459P3MEDIUMCVSS 6.8v8.1.3
CVE-2014-4459 [MEDIUM] CVE-2014-4459: iOS 8.1.3
Apple Security Update: About the security content of iOS 8.1.3
Product: iOS
Version: 8.1.3
CVE: CVE-2014-4459
Component: CVE-2014-4459
apple
CVE-2016-1817P3HIGHCVSS 7.8v9.3.2
CVE-2016-1817 [HIGH] CVE-2016-1817: iOS 9.3.2
Apple Security Update: About the security content of iOS 9.3.2
Product: iOS
Version: 9.3.2
CVE: CVE-2016-1817
Component: CVE-ID
apple
CVE-2016-4712P3HIGHCVSS 7.8v102016-09-13
CVE-2016-4712 [HIGH] CVE-2016-4712: iOS 10
Apple Security Update: About the security content of iOS 10
Product: iOS
Version: 10
CVE: CVE-2016-4712
Component: CoreCrypto
Impact: An application may be able to execute arbitrary code
Description: An out-of-bounds write issue was addressed by removing the vulnerable code.
apple
CVE-2016-1829P3HIGHCVSS 7.8v9.3.2
CVE-2016-1829 [HIGH] CVE-2016-1829: iOS 9.3.2
Apple Security Update: About the security content of iOS 9.3.2
Product: iOS
Version: 9.3.2
CVE: CVE-2016-1829
Component: CVE-ID
Impact: A local attacker may be able to cause unexpected application termination or arbitrary code execution
Description: A memory corruption issue was addressed through improved input validation.
apple
CVE-2017-2451P3HIGHCVSS 7.8v10.32017-03-27
CVE-2017-2451 [HIGH] CVE-2017-2451: iOS 10.3
Apple Security Update: About the security content of iOS 10.3
Product: iOS
Version: 10.3
CVE: CVE-2017-2451
Component: Security
Impact: An application may be able to execute arbitrary code with root privileges
Description: A buffer overflow was addressed through improved bounds checking.
apple
CVE-2017-7008P3HIGHCVSS 7.8v10.3.32017-07-19
CVE-2017-7008 [HIGH] CVE-2017-7008: iOS 10.3.3
Apple Security Update: About the security content of iOS 10.3.3
Product: iOS
Version: 10.3.3
CVE: CVE-2017-7008
Component: CoreAudio
Impact: Processing a maliciously crafted movie file may lead to arbitrary code execution
Description: A memory corruption issue was addressed with improved bounds checking.
apple
CVE-2016-4778P3HIGHCVSS 7.8v102016-09-13
CVE-2016-4778 [HIGH] CVE-2016-4778: iOS 10
Apple Security Update: About the security content of iOS 10
Product: iOS
Version: 10
CVE: CVE-2016-4778
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: Multiple memory corruption issues were addressed through improved memory handling.
apple
CVE-2016-4726P3HIGHCVSS 7.8v102016-09-13
CVE-2016-4726 [HIGH] CVE-2016-4726: iOS 10
Apple Security Update: About the security content of iOS 10
Product: iOS
Version: 10
CVE: CVE-2016-4726
Component: IOAcceleratorFamily
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed through improved memory handling.
apple
CVE-2017-7086P3HIGHCVSS 7.5v112017-09-19
CVE-2017-7086 [HIGH] CVE-2017-7086: iOS 11
Apple Security Update: About the security content of iOS 11
Product: iOS
Version: 11
CVE: CVE-2017-7086
Component: Keyboard Suggestions
Impact: Keyboard autocorrect suggestions may reveal sensitive information
Description: The iOS keyboard was inadvertently caching sensitive information. This issue was addressed with improved heuristics.
apple
CVE-2017-2440P3HIGHCVSS 7.8v10.32017-03-27
CVE-2017-2440 [HIGH] CVE-2017-2440: iOS 10.3
Apple Security Update: About the security content of iOS 10.3
Product: iOS
Version: 10.3
CVE: CVE-2017-2440
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: An integer overflow was addressed through improved input validation.
apple
CVE-2017-6981P3HIGHCVSS 7.8v10.3.22017-05-15
CVE-2017-6981 [HIGH] CVE-2017-6981: iOS 10.3.2
Apple Security Update: About the security content of iOS 10.3.2
Product: iOS
Version: 10.3.2
CVE: CVE-2017-6981
Component: Foundation
Impact: Parsing maliciously crafted data may lead to arbitrary code execution
Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2016-7616P3HIGHCVSS 7.8v10.22016-12-12
CVE-2016-7616 [HIGH] CVE-2016-7616: iOS 10.2
Apple Security Update: About the security content of iOS 10.2
Product: iOS
Version: 10.2
CVE: CVE-2016-7616
Component: Disk Images
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed through improved input validation.
apple
CVE-2016-7606P3HIGHCVSS 7.8v10.22016-12-12
CVE-2016-7606 [HIGH] CVE-2016-7606: iOS 10.2
Apple Security Update: About the security content of iOS 10.2
Product: iOS
Version: 10.2
CVE: CVE-2016-7606
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: Multiple memory corruption issues were addressed through improved input validation.
apple