Apple iOS vulnerabilities
1,765 known vulnerabilities affecting apple/ios.
Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7
Vulnerabilities
Page 53 of 89
CVE-2015-6994P4HIGHCVSS 7.1v9.1
CVE-2015-6994 [HIGH] CVE-2015-6994: iOS 9.1
Apple Security Update: About the security content of iOS 9.1
Product: iOS
Version: 9.1
CVE: CVE-2015-6994
Component: CVE-ID
Impact: A remote attacker may be able to cause unexpected application termination or arbitrary code execution
Description: Multiple memory corruption issues existed in DNS data parsing. These issues were addressed through improved bounds checking.
apple
CVE-2014-4459P3MEDIUMCVSS 6.8v8.1.3
CVE-2014-4459 [MEDIUM] CVE-2014-4459: iOS 8.1.3
Apple Security Update: About the security content of iOS 8.1.3
Product: iOS
Version: 8.1.3
CVE: CVE-2014-4459
Component: CVE-2014-4459
apple
CVE-2015-7053P3MEDIUMCVSS 6.8v9.2
CVE-2015-7053 [MEDIUM] CVE-2015-7053: iOS 9.2
Apple Security Update: About the security content of iOS 9.2
Product: iOS
Version: 9.2
CVE: CVE-2015-7053
Component: CVE-ID
apple
CVE-2015-7073P3MEDIUMCVSS 6.8v9.2
CVE-2015-7073 [MEDIUM] CVE-2015-7073: iOS 9.2
Apple Security Update: About the security content of iOS 9.2
Product: iOS
Version: 9.2
CVE: CVE-2015-7073
Component: CVE-ID
apple
CVE-2015-7075P3MEDIUMCVSS 6.8v9.2
CVE-2015-7075 [MEDIUM] CVE-2015-7075: iOS 9.2
Apple Security Update: About the security content of iOS 9.2
Product: iOS
Version: 9.2
CVE: CVE-2015-7075
Component: CVE-2015-7075
Impact: A malicious application may be able to execute arbitrary code with system privileges
Description: Multiple segment validation issues existed in dyld. These were addressed through improved environment sanitization.
apple
CVE-2016-4660P4HIGHCVSS 7.1v10.12016-10-24
CVE-2016-4660 [HIGH] CVE-2016-4660: iOS 10.1
Apple Security Update: About the security content of iOS 10.1
Product: iOS
Version: 10.1
CVE: CVE-2016-4660
Component: FontParser
Impact: Parsing a maliciously crafted font may disclose sensitive user information
Description: An out-of-bounds read was addressed through improved bounds checking.
apple
CVE-2015-1095P4HIGHCVSS 7.2v8.3
CVE-2015-1095 [HIGH] CVE-2015-1095: iOS 8.3
Apple Security Update: About the security content of iOS 8.3
Product: iOS
Version: 8.3
CVE: CVE-2015-1095
Component: CVE-ID
apple
CVE-2015-5774P4HIGHCVSS 7.2v8.4.1
CVE-2015-5774 [HIGH] CVE-2015-5774: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-5774
Component: CVE-ID
apple
CVE-2015-5769P4HIGHCVSS 7.1v8.4.1
CVE-2015-5769 [HIGH] CVE-2015-5769: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-5769
Component: CVE-ID
apple
CVE-2015-3800P4HIGHCVSS 7.2v8.4.1
CVE-2015-3800 [HIGH] CVE-2015-3800: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-3800
Component: CVE-ID
apple
CVE-2020-9843P4HIGHCVSS 7.1≥ unspecified, < iOS 13.5 and iPadOS 13.52020-06-09
CVE-2020-9843 [HIGH] CWE-79 CVE-2020-9843: An input validation issue was addressed with improved input validation. This issue is fixed in iOS 1
An input validation issue was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously crafted web content may lead to a cross site scripting attack.
nvd
CVE-2020-9805P4HIGHCVSS 7.1≥ unspecified, < iOS 13.5 and iPadOS 13.52020-06-09
CVE-2020-9805 [HIGH] CWE-79 CVE-2020-9805: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 1
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd
CVE-2015-3803P4HIGHCVSS 7.2v8.4.1
CVE-2015-3803 [HIGH] CVE-2015-3803: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-3803
Component: CVE-ID
apple
CVE-2015-3802P4HIGHCVSS 7.2v8.4.1
CVE-2015-3802 [HIGH] CVE-2015-3802: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-3802
Component: CVE-ID
apple
CVE-2015-3805P4HIGHCVSS 7.2v8.4.1
CVE-2015-3805 [HIGH] CVE-2015-3805: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-3805
Component: CVE-ID
apple
CVE-2015-3806P4HIGHCVSS 7.2v8.4.1
CVE-2015-3806 [HIGH] CVE-2015-3806: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-3806
Component: CVE-ID
apple
CVE-2020-9952P4HIGHCVSS 7.1≥ unspecified, < iOS 14.0 and iPadOS 14.02020-10-16
CVE-2020-9952 [HIGH] CWE-79 CVE-2020-9952: An input validation issue was addressed with improved input validation. This issue is fixed in iOS 1
An input validation issue was addressed with improved input validation. This issue is fixed in iOS 14.0 and iPadOS 14.0, tvOS 14.0, watchOS 7.0, Safari 14.0, iCloud for Windows 11.4, iCloud for Windows 7.21. Processing maliciously crafted web content may lead to a cross site scripting attack.
nvd
CVE-2017-2439P4HIGHCVSS 7.1v10.32017-03-27
CVE-2017-2439 [HIGH] CVE-2017-2439: iOS 10.3
Apple Security Update: About the security content of iOS 10.3
Product: iOS
Version: 10.3
CVE: CVE-2017-2439
Component: FontParser
Impact: Processing a maliciously crafted font may result in the disclosure of process memory
Description: An out-of-bounds read was addressed through improved input validation.
apple
CVE-2017-2450P4HIGHCVSS 7.1v10.32017-03-27
CVE-2017-2450 [HIGH] CVE-2017-2450: iOS 10.3
Apple Security Update: About the security content of iOS 10.3
Product: iOS
Version: 10.3
CVE: CVE-2017-2450
Component: CoreText
Impact: Processing a maliciously crafted font may result in the disclosure of process memory
Description: An out-of-bounds read was addressed through improved input validation.
apple
CVE-2015-5935P3MEDIUMCVSS 6.8v9.1
CVE-2015-5935 [MEDIUM] CVE-2015-5935: iOS 9.1
Apple Security Update: About the security content of iOS 9.1
Product: iOS
Version: 9.1
CVE: CVE-2015-5935
Component: CVE-ID
apple