cbcvebase.

Apple iOS vulnerabilities

1,765 known vulnerabilities affecting apple/ios.

Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
227
Exploited in wild
30
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7

Vulnerabilities

Page 5 of 89
CVE-2021-30759HIGHCVSS 7.8≥ unspecified, < 14.72021-09-08
CVE-2021-30759 [HIGH] CWE-787 CVE-2021-30759: A stack overflow was addressed with improved input validation. This issue is fixed in iOS 14.7, macO A stack overflow was addressed with improved input validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-005 Mojave, Security Update 2021-004 Catalina. Processing a maliciously crafted font file may lead to arbitrary code execution.
nvd
CVE-2021-30788HIGHCVSS 7.1≥ unspecified, < 14.72021-09-08
CVE-2021-30788 [HIGH] CVE-2021-30788: This issue was addressed with improved checks. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, This issue was addressed with improved checks. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-005 Mojave, Security Update 2021-004 Catalina. Processing a maliciously crafted tiff file may lead to a denial-of-service or potentially disclose memory contents.
nvd
CVE-2021-30758HIGHCVSS 8.8≥ unspecified, < 14.72021-09-08
CVE-2021-30758 [HIGH] CWE-843 CVE-2021-30758: A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.7, A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2021-30792HIGHCVSS 7.8≥ unspecified, < 14.72021-09-08
CVE-2021-30792 [HIGH] CWE-787 CVE-2021-30792: An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.7 An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2021-30799HIGHCVSS 8.8≥ unspecified, < 14.72021-09-08
CVE-2021-30799 [HIGH] CWE-787 CVE-2021-30799: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2021-30800HIGHCVSS 8.8≥ unspecified, < 14.72021-09-08
CVE-2021-30800 [HIGH] CVE-2021-30800: This issue was addressed with improved checks. This issue is fixed in iOS 14.7. Joining a malicious This issue was addressed with improved checks. This issue is fixed in iOS 14.7. Joining a malicious Wi-Fi network may result in a denial of service or arbitrary code execution.
nvd
CVE-2021-30798HIGHCVSS 7.5≥ unspecified, < 14.72021-09-08
CVE-2021-30798 [HIGH] CVE-2021-30798: A logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, macOS B A logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6. A malicious application may be able to bypass certain Privacy preferences.
nvd
CVE-2021-30791MEDIUMCVSS 5.5≥ unspecified, < 14.72021-09-08
CVE-2021-30791 [MEDIUM] CWE-125 CVE-2021-30791: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 14.7, An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 14.7, macOS Big Sur 11.5. Processing a maliciously crafted file may disclose user information.
nvd
CVE-2021-30770MEDIUMCVSS 5.5≥ unspecified, < 14.72021-09-08
CVE-2021-30770 [MEDIUM] CWE-287 CVE-2021-30770: A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, tvOS 14.7, wa A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. An attacker that has already achieved kernel code execution may be able to bypass kernel memory mitigations.
nvd
CVE-2021-30773MEDIUMCVSS 5.5≥ unspecified, < 14.72021-09-08
CVE-2021-30773 [MEDIUM] CVE-2021-30773: An issue in code signature validation was addressed with improved checks. This issue is fixed in iOS An issue in code signature validation was addressed with improved checks. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. A malicious application may be able to bypass code signing checks.
nvd
CVE-2021-30776MEDIUMCVSS 5.5≥ unspecified, < 14.72021-09-08
CVE-2021-30776 [MEDIUM] CVE-2021-30776: A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-004 Catalina. Playing a malicious audio file may lead to an unexpected application termination.
nvd
CVE-2021-30768MEDIUMCVSS 5.5≥ unspecified, < 14.72021-09-08
CVE-2021-30768 [MEDIUM] CVE-2021-30768: A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-004 Catalina. A sandboxed process may be able to circumvent sandbox restrictions.
nvd
CVE-2021-30763MEDIUMCVSS 5.5≥ unspecified, < 14.72021-09-08
CVE-2021-30763 [MEDIUM] CWE-20 CVE-2021-30763: An input validation issue was addressed with improved input validation. This issue is fixed in iOS 1 An input validation issue was addressed with improved input validation. This issue is fixed in iOS 14.7, watchOS 7.6. A shortcut may be able to bypass Internet permission requirements.
nvd
CVE-2021-30796MEDIUMCVSS 6.5≥ unspecified, < 14.72021-09-08
CVE-2021-30796 [MEDIUM] CVE-2021-30796: A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. Processing a maliciously crafted image may lead to a denial of service.
nvd
CVE-2021-30769MEDIUMCVSS 5.5≥ unspecified, < 14.72021-09-08
CVE-2021-30769 [MEDIUM] CWE-287 CVE-2021-30769: A logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, tvOS 14 A logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
nvd
CVE-2021-30804LOWCVSS 3.3≥ unspecified, < 14.72021-09-08
CVE-2021-30804 [LOW] CVE-2021-30804: A permissions issue was addressed with improved validation. This issue is fixed in iOS 14.7. A malic A permissions issue was addressed with improved validation. This issue is fixed in iOS 14.7. A malicious application may be able to access Find My data.
nvd
CVE-2021-30858HIGHCVSS 8.8KEV≥ unspecified, < 14.82021-08-24
CVE-2021-30858 [HIGH] CWE-416 CVE-2021-30858: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14. A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
nvdapple
CVE-2021-30871MEDIUMCVSS 5.5≥ unspecified, < 14.72021-08-24
CVE-2021-30871 [MEDIUM] CVE-2021-30871: This issue was addressed with a new entitlement. This issue is fixed in iOS 14.7, watchOS 7.6, macOS This issue was addressed with a new entitlement. This issue is fixed in iOS 14.7, watchOS 7.6, macOS Big Sur 11.5. A local attacker may be able to access analytics data.
nvd
CVE-2021-30737HIGHCVSS 8.8v12.5.42021-06-14
CVE-2021-30737 [HIGH] CVE-2021-30737: iOS 12.5.4 Apple Security Update: About the security content of iOS 12.5.4 Product: iOS Version: 12.5.4 CVE: CVE-2021-30737 Component: Security Impact: Processing a maliciously crafted certificate may lead to arbitrary code execution Description: A memory corruption issue in the ASN.1 decoder was addressed by removing the vulnerable code.
apple
CVE-2020-27951HIGHCVSS 7.8≥ unspecified, < 12.52021-04-02
CVE-2020-27951 [HIGH] CVE-2020-27951: This issue was addressed with improved checks. This issue is fixed in watchOS 6.3, iOS 12.5, iOS 14. This issue was addressed with improved checks. This issue is fixed in watchOS 6.3, iOS 12.5, iOS 14.3 and iPadOS 14.3, watchOS 7.2. Unauthorized code execution may lead to an authentication policy violation.
nvd