Apple iOS vulnerabilities

479 known vulnerabilities affecting apple/ios.

Total CVEs
479
CISA KEV
18
actively exploited
Public exploits
36
Exploited in wild
19
Severity breakdown
CRITICAL32HIGH288MEDIUM132LOW27

Vulnerabilities

Page 5 of 24
CVE-2019-8573HIGHCVSS 7.5≥ unspecified, < 12.32020-10-27
CVE-2019-8573 [HIGH] CWE-20 CVE-2019-8573: An input validation issue was addressed with improved input validation. This issue is fixed in macOS An input validation issue was addressed with improved input validation. This issue is fixed in macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, iOS 12.3, watchOS 5.2.1. A remote attacker may be able to cause a system denial of service.
cvelistv5nvd
CVE-2019-8638HIGHCVSS 8.8≥ unspecified, < 12.22020-10-27
CVE-2019-8638 [HIGH] CWE-787 CVE-2019-8638: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in watchOS 5.2, iCloud for Windows 7.11, iOS 12.2, iTunes 12.9.4 for Windows, Safari 12.1. Processing maliciously crafted web content may lead to arbitrary code execution.
cvelistv5nvd
CVE-2019-8618HIGHCVSS 7.5≥ unspecified, < 12.22020-10-27
CVE-2019-8618 [HIGH] CVE-2019-8618: A logic issue was addressed with improved restrictions. This issue is fixed in watchOS 5.2, macOS Mo A logic issue was addressed with improved restrictions. This issue is fixed in watchOS 5.2, macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, iOS 12.2. A sandboxed process may be able to circumvent sandbox restrictions.
cvelistv5nvd
CVE-2019-8854HIGHCVSS 7.5≥ unspecified, < 132020-10-27
CVE-2019-8854 [HIGH] CVE-2019-8854: A user privacy issue was addressed by removing the broadcast MAC address. This issue is fixed in mac A user privacy issue was addressed by removing the broadcast MAC address. This issue is fixed in macOS Catalina 10.15, watchOS 6, iOS 13, tvOS 13. A device may be passively tracked by its Wi-Fi MAC address.
cvelistv5nvd
CVE-2019-8592HIGHCVSS 7.8≥ unspecified, < 12.32020-10-27
CVE-2019-8592 [HIGH] CWE-20 CVE-2019-8592: A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15, tvOS 12.3, watchOS 5.2.1, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, iOS 12.3, iOS 13. Playing a mal
cvelistv5nvd
CVE-2018-4428HIGHCVSS 7.1≥ unspecified, < 12.12020-10-27
CVE-2018-4428 [HIGH] CVE-2018-4428: A lock screen issue allowed access to the share function on a locked device. This issue was addresse A lock screen issue allowed access to the share function on a locked device. This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 12.1.1. A local attacker may be able to share items from the lock screen.
cvelistv5nvd
CVE-2019-8734HIGHCVSS 8.8≥ unspecified, < 132020-10-27
CVE-2019-8734 [HIGH] CWE-787 CVE-2019-8734: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13, iCloud for Windows 7.14, iCloud for Windows 10.7, Safari 13, tvOS 13, watchOS 6, iTunes 12.10.1 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.
cvelistv5nvd
CVE-2019-8830HIGHCVSS 8.8≥ unspecified, < 12.42020-10-27
CVE-2019-8830 [HIGH] CWE-125 CVE-2019-8830: An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 13.3 An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, iOS 13.3 and iPadOS 13.3, iOS 12.4.4, watchOS 5.3.4. Processing malicious video via FaceTime may lead to arbitrary code execution.
cvelistv5nvd
CVE-2019-8633HIGHCVSS 7.5≥ unspecified, < 12.32020-10-27
CVE-2019-8633 [HIGH] CWE-20 CVE-2019-8633: A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Moja A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, iOS 12.3, tvOS 12.3, watchOS 5.3. An application may be able to read restricted memory.
cvelistv5nvd
CVE-2019-8718HIGHCVSS 7.8PoC≥ unspecified, < 132020-10-27
CVE-2019-8718 [HIGH] CWE-787 CVE-2019-8718: A memory corruption issue was addressed with improved memory handling. This issue is fixed in watchO A memory corruption issue was addressed with improved memory handling. This issue is fixed in watchOS 6, iOS 13, tvOS 13. An application may be able to execute arbitrary code with kernel privileges.
cvelistv5nvd
CVE-2018-4474HIGHCVSS 7.5≥ unspecified, < 122020-10-27
CVE-2018-4474 [HIGH] CWE-400 CVE-2018-4474: A memory consumption issue was addressed with improved memory handling. This issue is fixed in iClou A memory consumption issue was addressed with improved memory handling. This issue is fixed in iCloud for Windows 7.7, watchOS 5, Safari 12, iOS 12, iTunes 12.9 for Windows, tvOS 12. Unexpected interaction causes an ASSERT failure.
cvelistv5nvd
CVE-2019-8709HIGHCVSS 7.8≥ unspecified, < 132020-10-27
CVE-2019-8709 [HIGH] CWE-787 CVE-2019-8709: A memory corruption issue was addressed with improved state management. This issue is fixed in macOS A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, watchOS 6, iOS 13. An application may be able to execute arbitrary code with kernel privileges.
cvelistv5nvd
CVE-2018-4339MEDIUMCVSS 5.5≥ unspecified, < 12.12020-10-27
CVE-2018-4339 [MEDIUM] CVE-2018-4339: This issue was addressed with a new entitlement. This issue is fixed in iOS 12.1. A local user may b This issue was addressed with a new entitlement. This issue is fixed in iOS 12.1. A local user may be able to read a persistent device identifier.
cvelistv5nvd
CVE-2018-4381MEDIUMCVSS 5.5≥ unspecified, < 12.12020-10-27
CVE-2018-4381 [MEDIUM] CWE-400 CVE-2018-4381: A resource exhaustion issue was addressed with improved input validation. This issue is fixed in tvO A resource exhaustion issue was addressed with improved input validation. This issue is fixed in tvOS 12.1, iOS 12.1. Processing a maliciously crafted message may lead to a denial of service.
cvelistv5nvd
CVE-2018-4448MEDIUMCVSS 5.5≥ unspecified, < 12.12020-10-27
CVE-2018-4448 [MEDIUM] CVE-2018-4448: A memory initialization issue was addressed with improved memory handling. This issue is fixed in ma A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, iOS 12.1.1, watchOS 5.1.2, macOS Mojave 10.14.2, Security Update 2018-003 High Sierra, Security Update 2018-006 Sierra, tvOS 12.1.1. A local user may be able to read kern
cvelistv5nvd
CVE-2019-8525MEDIUMCVSS 6.7≥ unspecified, < 12.22020-10-27
CVE-2019-8525 [MEDIUM] CWE-787 CVE-2019-8525: A memory corruption issue was addressed with improved state management. This issue is fixed in macOS A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, watchOS 5.2, macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, iOS 12.2. An application may be able to execute arbitrary c
cvelistv5nvd
CVE-2019-8664MEDIUMCVSS 6.5≥ unspecified, < 12.32020-10-27
CVE-2019-8664 [MEDIUM] CWE-20 CVE-2019-8664: An input validation issue was addressed with improved input validation. This issue is fixed in iOS 1 An input validation issue was addressed with improved input validation. This issue is fixed in iOS 12.3, watchOS 5.2.1. Processing a maliciously crafted message may lead to a denial of service.
cvelistv5nvd
CVE-2019-8532MEDIUMCVSS 5.5≥ unspecified, < 12.22020-10-27
CVE-2019-8532 [MEDIUM] CVE-2019-8532: A permissions issue was addressed by removing vulnerable code and adding additional checks. This iss A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in watchOS 5.2, iOS 12.2. A malicious application may be able to access restricted files.
cvelistv5nvd
CVE-2019-8744MEDIUMCVSS 5.5≥ unspecified, < 132020-10-27
CVE-2019-8744 [MEDIUM] CWE-787 CVE-2019-8744: A memory corruption issue existed in the handling of IPv6 packets. This issue was addressed with imp A memory corruption issue existed in the handling of IPv6 packets. This issue was addressed with improved memory management. This issue is fixed in macOS Catalina 10.15, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, watchOS 6, iOS 13. A malicious application may be able to determine kernel memory layout.
cvelistv5nvd
CVE-2019-8528MEDIUMCVSS 6.7≥ unspecified, < 12.22020-10-27
CVE-2019-8528 [MEDIUM] CWE-416 CVE-2019-8528: A use after free issue was addressed with improved memory management. This issue is fixed in watchOS A use after free issue was addressed with improved memory management. This issue is fixed in watchOS 5.2, macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, iOS 12.2. An application may be able to execute arbitrary code with kernel privileges.
cvelistv5nvd
Apple iOS vulnerabilities | cvebase