Apple iOS vulnerabilities
1,765 known vulnerabilities affecting apple/ios.
Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7
Vulnerabilities
Page 55 of 89
CVE-2019-8612P4MEDIUMCVSS 6.5v12.32019-05-13
CVE-2019-8612 [MEDIUM] CVE-2019-8612: iOS 12.3
Apple Security Update: About the security content of iOS 12.3
Product: iOS
Version: 12.3
CVE: CVE-2019-8612
Component: Wi-Fi
Impact: An attacker in a privileged network position can modify driver state
Description: A logic issue was addressed with improved state management.
apple
CVE-2015-5312P4MEDIUMCVSS 5.0v9.3
CVE-2015-5312 [MEDIUM] CVE-2015-5312: iOS 9.3
Apple Security Update: About the security content of iOS 9.3
Product: iOS
Version: 9.3
CVE: CVE-2015-5312
Component: CVE-2015-1819
apple
CVE-2017-7063P4HIGHCVSS 7.5v10.3.32017-07-19
CVE-2017-7063 [HIGH] CVE-2017-7063: iOS 10.3.3
Apple Security Update: About the security content of iOS 10.3.3
Product: iOS
Version: 10.3.3
CVE: CVE-2017-7063
Component: Messages
Impact: A remote attacker may cause an unexpected application termination
Description: A memory consumption issue was addressed through improved memory handling.
apple
CVE-2015-1103P4HIGHCVSS 7.5v8.3
CVE-2015-1103 [HIGH] CVE-2015-1103: iOS 8.3
Apple Security Update: About the security content of iOS 8.3
Product: iOS
Version: 8.3
CVE: CVE-2015-1103
Component: CVE-ID
apple
CVE-2017-7007P4HIGHCVSS 7.5v10.3.32017-07-19
CVE-2017-7007 [HIGH] CVE-2017-7007: iOS 10.3.3
Apple Security Update: About the security content of iOS 10.3.3
Product: iOS
Version: 10.3.3
CVE: CVE-2017-7007
Component: EventKitUI
Impact: A remote attacker may cause an unexpected application termination
Description: A resource exhaustion issue was addressed through improved input validation.
apple
CVE-2016-1684P4HIGHCVSS 7.5v9.3.32016-07-18
CVE-2016-1684 [HIGH] CVE-2016-1684: iOS 9.3.3
Apple Security Update: About the security content of iOS 9.3.3
Product: iOS
Version: 9.3.3
CVE: CVE-2016-1684
Component: Libc
Impact: A remote attacker may be able to cause unexpected application termination or arbitrary code execution
Description: A buffer overflow existed within the "link_ntoa()" function in linkaddr.c. This issue was addressed through additional bounds checking.
apple
CVE-2014-3192P4HIGHCVSS 7.5v8.1.3
CVE-2014-3192 [HIGH] CVE-2014-3192: iOS 8.1.3
Apple Security Update: About the security content of iOS 8.1.3
Product: iOS
Version: 8.1.3
CVE: CVE-2014-3192
Component: CVE-ID
apple
CVE-2018-4371P4HIGHCVSS 7.8v12.12018-10-30
CVE-2018-4371 [HIGH] CVE-2018-4371: iOS 12.1
Apple Security Update: About the security content of iOS 12.1
Product: iOS
Version: 12.1
CVE: CVE-2018-4371
Component: IPSec
Impact: An application may be able to gain elevated privileges
Description: An out-of-bounds read was addressed with improved input validation.
apple
CVE-2015-5761P4MEDIUMCVSS 6.8v8.4.1
CVE-2015-5761 [MEDIUM] CVE-2015-5761: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-5761
Component: CVE-ID
apple
CVE-2015-5755P4MEDIUMCVSS 6.8v8.4.1
CVE-2015-5755 [MEDIUM] CVE-2015-5755: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-5755
Component: CVE-ID
apple
CVE-2015-5778P4MEDIUMCVSS 6.8v8.4.1
CVE-2015-5778 [MEDIUM] CVE-2015-5778: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-5778
Component: CVE-ID
apple
CVE-2015-5777P4MEDIUMCVSS 6.8v8.4.1
CVE-2015-5777 [MEDIUM] CVE-2015-5777: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-5777
Component: CVE-ID
apple
CVE-2016-4708P4MEDIUMCVSS 6.5v102016-09-13
CVE-2016-4708 [MEDIUM] CVE-2016-4708: iOS 10
Apple Security Update: About the security content of iOS 10
Product: iOS
Version: 10
CVE: CVE-2016-4708
Component: CFNetwork
Impact: Processing maliciously crafted web content may compromise user information
Description: An input validation issue existed in the parsing of the set-cookie header. This issue was addressed through improved validation checking.
apple
CVE-2015-1153P4MEDIUMCVSS 6.8v8.4
CVE-2015-1153 [MEDIUM] CVE-2015-1153: iOS 8.4
Apple Security Update: About the security content of iOS 8.4
Product: iOS
Version: 8.4
CVE: CVE-2015-1153
Component: CVE-ID
apple
CVE-2015-1152P4MEDIUMCVSS 6.8v8.4
CVE-2015-1152 [MEDIUM] CVE-2015-1152: iOS 8.4
Apple Security Update: About the security content of iOS 8.4
Product: iOS
Version: 8.4
CVE: CVE-2015-1152
Component: CVE-ID
apple
CVE-2016-7667P4HIGHCVSS 7.5v10.22016-12-12
CVE-2016-7667 [HIGH] CVE-2016-7667: iOS 10.2
Apple Security Update: About the security content of iOS 10.2
Product: iOS
Version: 10.2
CVE: CVE-2016-7667
Component: CoreText
Impact: Processing a maliciously crafted string may lead to a denial of service
Description: An issue when rendering overlapping ranges was addressed through improved validation.
apple
CVE-2016-4627P4HIGHCVSS 7.8v9.3.32016-07-18
CVE-2016-4627 [HIGH] CVE-2016-4627: iOS 9.3.3
Apple Security Update: About the security content of iOS 9.3.3
Product: iOS
Version: 9.3.3
CVE: CVE-2016-4627
Component: IOAcceleratorFamily
Impact: A local user may be able to execute arbitrary code with kernel privileges
Description: A null pointer dereference was addressed through improved validation.
apple
CVE-2015-6989P4MEDIUMCVSS 6.8v9.1
CVE-2015-6989 [MEDIUM] CVE-2015-6989: iOS 9.1
Apple Security Update: About the security content of iOS 9.1
Product: iOS
Version: 9.1
CVE: CVE-2015-6989
Component: CVE-ID
apple
CVE-2014-8840P4MEDIUMCVSS 6.8v8.1.3
CVE-2014-8840 [MEDIUM] CVE-2014-8840: iOS 8.1.3
Apple Security Update: About the security content of iOS 8.1.3
Product: iOS
Version: 8.1.3
CVE: CVE-2014-8840
Component: CVE-ID
apple
CVE-2019-8570P4MEDIUMCVSS 6.5≥ unspecified, < 12.12020-10-27
CVE-2019-8570 [MEDIUM] CVE-2019-8570: A logic issue was addressed with improved state management. This issue is fixed in iOS 12.1.3, iClou
A logic issue was addressed with improved state management. This issue is fixed in iOS 12.1.3, iCloud for Windows 7.10, iTunes 12.9.3 for Windows, Safari 12.0.3, tvOS 12.1.2. Processing maliciously crafted web content may disclose sensitive user information.
nvdapple