Apple iOS vulnerabilities
1,765 known vulnerabilities affecting apple/ios.
Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7
Vulnerabilities
Page 53 of 89
CVE-2015-7061P3MEDIUMCVSS 6.8v9.1
CVE-2015-7061 [MEDIUM] CVE-2015-7061: iOS 9.1
Apple Security Update: About the security content of iOS 9.1
Product: iOS
Version: 9.1
CVE: CVE-2015-7061
Component: CVE-ID
apple
CVE-2015-7060P3MEDIUMCVSS 6.8v9.1
CVE-2015-7060 [MEDIUM] CVE-2015-7060: iOS 9.1
Apple Security Update: About the security content of iOS 9.1
Product: iOS
Version: 9.1
CVE: CVE-2015-7060
Component: CVE-ID
apple
CVE-2019-8617P4CRITICALCVSS 9.6≥ unspecified, < iOS 12.32019-12-18
CVE-2019-8617 [CRITICAL] CVE-2019-8617: An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 12.3.
An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 12.3. A sandboxed process may be able to circumvent sandbox restrictions.
nvdapple
CVE-2015-1067P4MEDIUMCVSS 4.3v8.2
CVE-2015-1067 [MEDIUM] CVE-2015-1067: iOS 8.2
Apple Security Update: About the security content of iOS 8.2
Product: iOS
Version: 8.2
CVE: CVE-2015-1067
Component: CVE-ID
apple
CVE-2019-8597P3MEDIUMCVSS 6.5≥ unspecified, < iOS 12.32019-12-18
CVE-2019-8597 [MEDIUM] CWE-787 CVE-2019-8597: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2019-8615P3MEDIUMCVSS 6.5≥ unspecified, < iOS 12.32019-12-18
CVE-2019-8615 [MEDIUM] CWE-125 CVE-2019-8615: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2016-4644P3MEDIUMCVSS 6.5v9.3.32016-07-18
CVE-2016-4644 [MEDIUM] CVE-2016-4644: iOS 9.3.3
Apple Security Update: About the security content of iOS 9.3.3
Product: iOS
Version: 9.3.3
CVE: CVE-2016-4644
Component: CFNetwork Credentials
Impact: An attacker in a privileged network position may be able to leak sensitive user information
Description: A downgrade issue existed with HTTP authentication credentials saved in Keychain. This issue was addressed by storing the authentication types with the credentials.
apple
CVE-2015-3689P4HIGHCVSS 7.8v8.4
CVE-2015-3689 [HIGH] CVE-2015-3689: iOS 8.4
Apple Security Update: About the security content of iOS 8.4
Product: iOS
Version: 8.4
CVE: CVE-2015-3689
Component: CVE-2015-1157
Impact: An attacker with a privileged network position may intercept SSL/TLS connections
Description: coreTLS accepted short ephemeral Diffie-Hellman (DH) keys, as used in export-strength ephemeral DH cipher suites. This issue, also known as Logjam, allowed an attacker with a privileged network position to downgrade securit
apple
CVE-2015-3685P4HIGHCVSS 7.8v8.4
CVE-2015-3685 [HIGH] CVE-2015-3685: iOS 8.4
Apple Security Update: About the security content of iOS 8.4
Product: iOS
Version: 8.4
CVE: CVE-2015-3685
Component: CVE-2015-1157
Impact: An attacker with a privileged network position may intercept SSL/TLS connections
Description: coreTLS accepted short ephemeral Diffie-Hellman (DH) keys, as used in export-strength ephemeral DH cipher suites. This issue, also known as Logjam, allowed an attacker with a privileged network position to downgrade securit
apple
CVE-2016-9643P4HIGHCVSS 7.5v10.32017-03-27
CVE-2016-9643 [HIGH] CVE-2016-9643: iOS 10.3
Apple Security Update: About the security content of iOS 10.3
Product: iOS
Version: 10.3
CVE: CVE-2016-9643
Component: WebKit
Impact: Processing maliciously crafted web content may lead to high memory consumption
Description: An uncontrolled resource consumption issue was addressed through improved regex processing.
apple
CVE-2016-7643P4HIGHCVSS 8.1v10.22016-12-12
CVE-2016-7643 [HIGH] CVE-2016-7643: iOS 10.2
Apple Security Update: About the security content of iOS 10.2
Product: iOS
Version: 10.2
CVE: CVE-2016-7643
Component: ImageIO
Impact: A remote attacker may be able to leak memory
Description: An out-of-bounds read was addressed through improved bounds checking.
apple
CVE-2018-4319P3HIGHCVSS 8.1v122018-09-17
CVE-2018-4319 [HIGH] CVE-2018-4319: iOS 12
Apple Security Update: About the security content of iOS 12
Product: iOS
Version: 12
CVE: CVE-2018-4319
Component: WebKit
Impact: A malicious website may cause unexepected cross-origin behavior
Description: A cross-origin issue existed with iframe elements. This was addressed with improved tracking of security origins.
apple
CVE-2016-4724P4HIGHCVSS 7.8v102016-09-13
CVE-2016-4724 [HIGH] CVE-2016-4724: iOS 10
Apple Security Update: About the security content of iOS 10
Product: iOS
Version: 10
CVE: CVE-2016-4724
Component: IOAcceleratorFamily
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A null pointer dereference was addressed through improved input validation.
apple
CVE-2016-4654P4HIGHCVSS 7.8v9.3.42016-08-04
CVE-2016-4654 [HIGH] CVE-2016-4654: iOS 9.3.4
Apple Security Update: About the security content of iOS 9.3.4
Product: iOS
Version: 9.3.4
CVE: CVE-2016-4654
Component: IOMobileFrameBuffer
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed through improved memory handling.
apple
CVE-2016-1756P4HIGHCVSS 7.8v9.3
CVE-2016-1756 [HIGH] CVE-2016-1756: iOS 9.3
Apple Security Update: About the security content of iOS 9.3
Product: iOS
Version: 9.3
CVE: CVE-2016-1756
Component: CVE-ID
apple
CVE-2016-4594P4HIGHCVSS 7.8v9.3.32016-07-18
CVE-2016-4594 [HIGH] CVE-2016-4594: iOS 9.3.3
Apple Security Update: About the security content of iOS 9.3.3
Product: iOS
Version: 9.3.3
CVE: CVE-2016-4594
Component: Sandbox Profiles
Impact: A local application may be able to access the process list
Description: An access issue existed with privileged API calls. This issue was addressed through additional restrictions.
apple
CVE-2014-4483P4MEDIUMCVSS 6.8v8.1.3
CVE-2014-4483 [MEDIUM] CVE-2014-4483: iOS 8.1.3
Apple Security Update: About the security content of iOS 8.1.3
Product: iOS
Version: 8.1.3
CVE: CVE-2014-4483
Component: CVE-ID
apple
CVE-2016-7584P4HIGHCVSS 7.8v10.12016-10-24
CVE-2016-7584 [HIGH] CVE-2016-7584: iOS 10.1
Apple Security Update: About the security content of iOS 10.1
Product: iOS
Version: 10.1
CVE: CVE-2016-7584
Component: AppleMobileFileIntegrity
Impact: A signed executable may substitute code with the same team ID
Description: A validation issue existed in the handling of code signatures. This issue was addressed through additional validation.
apple
CVE-2018-4420P4HIGHCVSS 7.8v12.12018-10-30
CVE-2018-4420 [HIGH] CVE-2018-4420: iOS 12.1
Apple Security Update: About the security content of iOS 12.1
Product: iOS
Version: 12.1
CVE: CVE-2018-4420
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed by removing the vulnerable code.
apple
CVE-2016-1751P4HIGHCVSS 7.8v9.3
CVE-2016-1751 [HIGH] CVE-2016-1751: iOS 9.3
Apple Security Update: About the security content of iOS 9.3
Product: iOS
Version: 9.3
CVE: CVE-2016-1751
Component: CVE-ID
apple