Apple iOS vulnerabilities
1,765 known vulnerabilities affecting apple/ios.
Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7
Vulnerabilities
Page 50 of 89
CVE-2017-13832P3CRITICALCVSS 9.8v112017-09-19
CVE-2017-13832 [CRITICAL] CVE-2017-13832: iOS 11
Apple Security Update: About the security content of iOS 11
Product: iOS
Version: 11
CVE: CVE-2017-13832
Component: About Apple security updates
Impact: An attacker may be able to exploit weaknesses in TLS 1.0
Description: A protocol security issue was addressed by enabling TLS 1.1 and TLS 1.2.
apple
CVE-2018-4436P3HIGHCVSS 7.5v12.1.12018-12-05
CVE-2018-4436 [HIGH] CVE-2018-4436: iOS 12.1.1
Apple Security Update: About the security content of iOS 12.1.1
Product: iOS
Version: 12.1.1
CVE: CVE-2018-4436
Component: Profiles
Impact: An untrusted configuration profile may be incorrectly displayed as verified
Description: A certificate validation issue existed in configuration profiles. This was addressed with additional checks.
apple
CVE-2018-4274P3HIGHCVSS 7.5v11.4.12018-07-09
CVE-2018-4274 [HIGH] CVE-2018-4274: iOS 11.4.1
Apple Security Update: About the security content of iOS 11.4.1
Product: iOS
Version: 11.4.1
CVE: CVE-2018-4274
Component: WebKit
Impact: Visiting a malicious website may lead to address bar spoofing
Description: A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation.
apple
CVE-2017-2380P3HIGHCVSS 7.5v10.32017-03-27
CVE-2017-2380 [HIGH] CVE-2017-2380: iOS 10.3
Apple Security Update: About the security content of iOS 10.3
Product: iOS
Version: 10.3
CVE: CVE-2017-2380
Component: Profiles
Impact: An attacker may be able to exploit weaknesses in the DES cryptographic algorithm
Description: Support for the 3DES cryptographic algorithm was added to the SCEP client and DES was deprecated.
apple
CVE-2015-1088P3MEDIUMCVSS 6.8v8.3
CVE-2015-1088 [MEDIUM] CVE-2015-1088: iOS 8.3
Apple Security Update: About the security content of iOS 8.3
Product: iOS
Version: 8.3
CVE: CVE-2015-1088
Component: CVE-2015-1088
apple
CVE-2020-9903P3HIGHCVSS 7.5≥ unspecified, < iOS 13.6 and iPadOS 13.62020-10-16
CVE-2020-9903 [HIGH] CWE-346 CVE-2020-9903: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.6 and iPadOS 1
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.6 and iPadOS 13.6, Safari 13.1.2. A malicious attacker may cause Safari to suggest a password for the wrong domain.
nvd
CVE-2016-4483P3HIGHCVSS 7.5v9.3.32016-07-18
CVE-2016-4483 [HIGH] CVE-2016-4483: iOS 9.3.3
Apple Security Update: About the security content of iOS 9.3.3
Product: iOS
Version: 9.3.3
CVE: CVE-2016-4483
Component: Libc
Impact: A remote attacker may be able to cause unexpected application termination or arbitrary code execution
Description: A buffer overflow existed within the "link_ntoa()" function in linkaddr.c. This issue was addressed through additional bounds checking.
apple
CVE-2015-3686P3HIGHCVSS 7.8v8.4
CVE-2015-3686 [HIGH] CVE-2015-3686: iOS 8.4
Apple Security Update: About the security content of iOS 8.4
Product: iOS
Version: 8.4
CVE: CVE-2015-3686
Component: CVE-2015-1157
Impact: An attacker with a privileged network position may intercept SSL/TLS connections
Description: coreTLS accepted short ephemeral Diffie-Hellman (DH) keys, as used in export-strength ephemeral DH cipher suites. This issue, also known as Logjam, allowed an attacker with a privileged network position to downgrade securit
apple
CVE-2015-3688P3HIGHCVSS 7.8v8.4
CVE-2015-3688 [HIGH] CVE-2015-3688: iOS 8.4
Apple Security Update: About the security content of iOS 8.4
Product: iOS
Version: 8.4
CVE: CVE-2015-3688
Component: CVE-2015-1157
Impact: An attacker with a privileged network position may intercept SSL/TLS connections
Description: coreTLS accepted short ephemeral Diffie-Hellman (DH) keys, as used in export-strength ephemeral DH cipher suites. This issue, also known as Logjam, allowed an attacker with a privileged network position to downgrade securit
apple
CVE-2015-3687P3HIGHCVSS 7.8v8.4
CVE-2015-3687 [HIGH] CVE-2015-3687: iOS 8.4
Apple Security Update: About the security content of iOS 8.4
Product: iOS
Version: 8.4
CVE: CVE-2015-3687
Component: CVE-2015-1157
Impact: An attacker with a privileged network position may intercept SSL/TLS connections
Description: coreTLS accepted short ephemeral Diffie-Hellman (DH) keys, as used in export-strength ephemeral DH cipher suites. This issue, also known as Logjam, allowed an attacker with a privileged network position to downgrade securit
apple
CVE-2014-4481P3MEDIUMCVSS 6.8v8.1.3
CVE-2014-4481 [MEDIUM] CVE-2014-4481: iOS 8.1.3
Apple Security Update: About the security content of iOS 8.1.3
Product: iOS
Version: 8.1.3
CVE: CVE-2014-4481
Component: CVE-ID
Impact: A local user may be able to execute unsigned code
Description: A state management issue existed in the handling of Mach-O executable files with overlapping segments. This issue was addressed through improved validation of segment sizes.
apple
CVE-2016-4725P3HIGHCVSS 8.1v102016-09-13
CVE-2016-4725 [HIGH] CVE-2016-4725: iOS 10
Apple Security Update: About the security content of iOS 10
Product: iOS
Version: 10
CVE: CVE-2016-4725
Component: IOAcceleratorFamily
Impact: Processing maliciously crafted web content may result in the disclosure of process memory
Description: A memory corruption issue was addressed through improved input validation.
apple
CVE-2018-4142P3HIGHCVSS 7.5v11.32018-03-29
CVE-2018-4142 [HIGH] CVE-2018-4142: iOS 11.3
Apple Security Update: About the security content of iOS 11.3
Product: iOS
Version: 11.3
CVE: CVE-2018-4142
Component: CoreText
Impact: Processing a maliciously crafted string may lead to a denial of service
Description: A denial of service issue was addressed with improved memory handling.
apple
CVE-2017-13815P4CRITICALCVSS 9.8v112017-09-19
CVE-2017-13815 [CRITICAL] CVE-2017-13815: iOS 11
Apple Security Update: About the security content of iOS 11
Product: iOS
Version: 11
CVE: CVE-2017-13815
Component: Exchange ActiveSync
Impact: An attacker in a privileged network position may be able to erase a device during Exchange account setup
Description: A validation issue existed in AutoDiscover V1. This was addressed by requiring TLS for AutoDiscover V1. AutoDiscover V2 is now supported.
apple
CVE-2019-8741P3HIGHCVSS 7.5≥ unspecified, < iOS 132020-02-28
CVE-2019-8741 [HIGH] CWE-835 CVE-2019-8741: A denial of service issue was addressed with improved input validation.
A denial of service issue was addressed with improved input validation.
nvdapple
CVE-2017-13812P3HIGHCVSS 7.8v112017-09-19
CVE-2017-13812 [HIGH] CVE-2017-13812: iOS 11
Apple Security Update: About the security content of iOS 11
Product: iOS
Version: 11
CVE: CVE-2017-13812
Component: Keyboard Suggestions
Impact: Keyboard autocorrect suggestions may reveal sensitive information
Description: The iOS keyboard was inadvertently caching sensitive information. This issue was addressed with improved heuristics.
apple
CVE-2017-13814P3HIGHCVSS 7.8v112017-09-19
CVE-2017-13814 [HIGH] CVE-2017-13814: iOS 11
Apple Security Update: About the security content of iOS 11
Product: iOS
Version: 11
CVE: CVE-2017-13814
Component: ImageIO
Impact: Processing a maliciously crafted image may lead to arbitrary code execution
Description: A memory corruption issue was addressed with improved input validation.
apple
CVE-2016-1831P3HIGHCVSS 7.8v9.3.2
CVE-2016-1831 [HIGH] CVE-2016-1831: iOS 9.3.2
Apple Security Update: About the security content of iOS 9.3.2
Product: iOS
Version: 9.3.2
CVE: CVE-2016-1831
Component: CVE-ID
Impact: A local attacker may be able to cause unexpected application termination or arbitrary code execution
Description: A memory corruption issue was addressed through improved input validation.
apple
CVE-2018-4347P3HIGHCVSS 7.8v122018-09-17
CVE-2018-4347 [HIGH] CVE-2018-4347: iOS 12
Apple Security Update: About the security content of iOS 12
Product: iOS
Version: 12
CVE: CVE-2018-4347
Component: CoreText
Impact: Processing a maliciously crafted text file may lead to arbitrary code execution
Description: A use after free issue was addressed with improved memory management.
apple
CVE-2016-1683P3HIGHCVSS 7.5v9.3.32016-07-18
CVE-2016-1683 [HIGH] CVE-2016-1683: iOS 9.3.3
Apple Security Update: About the security content of iOS 9.3.3
Product: iOS
Version: 9.3.3
CVE: CVE-2016-1683
Component: Libc
Impact: A remote attacker may be able to cause unexpected application termination or arbitrary code execution
Description: A buffer overflow existed within the "link_ntoa()" function in linkaddr.c. This issue was addressed through additional bounds checking.
apple