Apple iOS vulnerabilities
1,765 known vulnerabilities affecting apple/ios.
Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7
Vulnerabilities
Page 54 of 89
CVE-2018-4303P4HIGHCVSS 7.8v12.1.12018-12-05
CVE-2018-4303 [HIGH] CVE-2018-4303: iOS 12.1.1
Apple Security Update: About the security content of iOS 12.1.1
Product: iOS
Version: 12.1.1
CVE: CVE-2018-4303
Component: Airport
Impact: A malicious application may be able to elevate privileges
Description: A type confusion issue was addressed with improved memory handling.
apple
CVE-2015-5773P4MEDIUMCVSS 6.8v8.4.1
CVE-2015-5773 [MEDIUM] CVE-2015-5773: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-5773
Component: CVE-ID
apple
CVE-2015-5756P4MEDIUMCVSS 6.8v8.4.1
CVE-2015-5756 [MEDIUM] CVE-2015-5756: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-5756
Component: CVE-ID
apple
CVE-2015-5758P4MEDIUMCVSS 6.8v8.4.1
CVE-2015-5758 [MEDIUM] CVE-2015-5758: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-5758
Component: CVE-ID
apple
CVE-2020-9826P4HIGHCVSS 7.5≥ unspecified, < iOS 13.5 and iPadOS 13.52020-06-09
CVE-2020-9826 [HIGH] CWE-20 CVE-2020-9826: A denial of service issue was addressed with improved input validation. This issue is fixed in iOS 1
A denial of service issue was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5. A remote attacker may be able to cause a denial of service.
nvd
CVE-2016-4626P4HIGHCVSS 7.8v9.3.32016-07-18
CVE-2016-4626 [HIGH] CVE-2016-4626: iOS 9.3.3
Apple Security Update: About the security content of iOS 9.3.3
Product: iOS
Version: 9.3.3
CVE: CVE-2016-4626
Component: IOHIDFamily
Impact: A local user may be able to execute arbitrary code with kernel privileges
Description: A null pointer dereference was addressed through improved input validation.
apple
CVE-2016-4689P4HIGHCVSS 7.5v10.22016-12-12
CVE-2016-4689 [HIGH] CVE-2016-4689: iOS 10.2
Apple Security Update: About the security content of iOS 10.2
Product: iOS
Version: 10.2
CVE: CVE-2016-4689
Component: Mail
Impact: An email signed with a revoked certificate may appear valid
Description: S/MIME policy failed to check if a certificate was valid. This issue was addressed by notifying a user if an email was signed with a revoked certificate.
apple
CVE-2015-7064P4MEDIUMCVSS 6.8v9.2
CVE-2015-7064 [MEDIUM] CVE-2015-7064: iOS 9.2
Apple Security Update: About the security content of iOS 9.2
Product: iOS
Version: 9.2
CVE: CVE-2015-7064
Component: CVE-ID
apple
CVE-2015-7066P4MEDIUMCVSS 6.8v9.2
CVE-2015-7066 [MEDIUM] CVE-2015-7066: iOS 9.2
Apple Security Update: About the security content of iOS 9.2
Product: iOS
Version: 9.2
CVE: CVE-2015-7066
Component: CVE-ID
apple
CVE-2017-13888P4HIGHCVSS 7.5v11.22017-12-02
CVE-2017-13888 [HIGH] CVE-2017-13888: iOS 11.2
Apple Security Update: About the security content of iOS 11.2
Product: iOS
Version: 11.2
CVE: CVE-2017-13888
Component: ReplayKit
Impact: A user may not have control over their screen broadcast
Description: A type confusion issue was addressed with improved memory handling.
apple
CVE-2015-5925P4MEDIUMCVSS 6.8v9.1
CVE-2015-5925 [MEDIUM] CVE-2015-5925: iOS 9.1
Apple Security Update: About the security content of iOS 9.1
Product: iOS
Version: 9.1
CVE: CVE-2015-5925
Component: CVE-ID
apple
CVE-2015-5926P4MEDIUMCVSS 6.8v9.1
CVE-2015-5926 [MEDIUM] CVE-2015-5926: iOS 9.1
Apple Security Update: About the security content of iOS 9.1
Product: iOS
Version: 9.1
CVE: CVE-2015-5926
Component: CVE-ID
apple
CVE-2015-7065P4MEDIUMCVSS 6.8v9.2
CVE-2015-7065 [MEDIUM] CVE-2015-7065: iOS 9.2
Apple Security Update: About the security content of iOS 9.2
Product: iOS
Version: 9.2
CVE: CVE-2015-7065
Component: CVE-ID
apple
CVE-2017-13077P4MEDIUMCVSS 6.8v11.12017-10-31
CVE-2017-13077 [MEDIUM] CVE-2017-13077: iOS 11.1
Apple Security Update: About the security content of iOS 11.1
Product: iOS
Version: 11.1
CVE: CVE-2017-13077
Component: Wi-Fi
Impact: An attacker in Wi-Fi range may force nonce reuse in WPA unicast/PTK clients (Key Reinstallation Attacks - KRACK)
Description: A logic issue existed in the handling of state transitions. This was addressed with improved state management.
apple
CVE-2015-1104P4MEDIUMCVSS 5.0v8.3
CVE-2015-1104 [MEDIUM] CVE-2015-1104: iOS 8.3
Apple Security Update: About the security content of iOS 8.3
Product: iOS
Version: 8.3
CVE: CVE-2015-1104
Component: CVE-ID
apple
CVE-2015-5940P4MEDIUMCVSS 6.8v9.1
CVE-2015-5940 [MEDIUM] CVE-2015-5940: iOS 9.1
Apple Security Update: About the security content of iOS 9.1
Product: iOS
Version: 9.1
CVE: CVE-2015-5940
Component: CVE-ID
apple
CVE-2015-5924P4MEDIUMCVSS 6.8v9.1
CVE-2015-5924 [MEDIUM] CVE-2015-5924: iOS 9.1
Apple Security Update: About the security content of iOS 9.1
Product: iOS
Version: 9.1
CVE: CVE-2015-5924
Component: CVE-ID
apple
CVE-2020-9952P4HIGHCVSS 7.1≥ unspecified, < iOS 14.0 and iPadOS 14.02020-10-16
CVE-2020-9952 [HIGH] CWE-79 CVE-2020-9952: An input validation issue was addressed with improved input validation. This issue is fixed in iOS 1
An input validation issue was addressed with improved input validation. This issue is fixed in iOS 14.0 and iPadOS 14.0, tvOS 14.0, watchOS 7.0, Safari 14.0, iCloud for Windows 11.4, iCloud for Windows 7.21. Processing maliciously crafted web content may lead to a cross site scripting attack.
nvd
CVE-2016-1779P3MEDIUMCVSS 6.5v9.3
CVE-2016-1779 [MEDIUM] CVE-2016-1779: iOS 9.3
Apple Security Update: About the security content of iOS 9.3
Product: iOS
Version: 9.3
CVE: CVE-2016-1779
Component: CVE-ID
apple
CVE-2018-4188P3MEDIUMCVSS 6.5v11.42018-05-29
CVE-2018-4188 [MEDIUM] CVE-2018-4188: iOS 11.4
Apple Security Update: About the security content of iOS 11.4
Product: iOS
Version: 11.4
CVE: CVE-2018-4188
Component: WebKit
Impact: Visiting a malicious website may lead to address bar spoofing
Description: An inconsistent user interface issue was addressed with improved state management.
apple