Apple iOS vulnerabilities
1,765 known vulnerabilities affecting apple/ios.
Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7
Vulnerabilities
Page 65 of 89
CVE-2017-7088P4MEDIUMCVSS 5.9v112017-09-19
CVE-2017-7088 [MEDIUM] CVE-2017-7088: iOS 11
Apple Security Update: About the security content of iOS 11
Product: iOS
Version: 11
CVE: CVE-2017-7088
Component: Exchange ActiveSync
Impact: An attacker in a privileged network position may be able to erase a device during Exchange account setup
Description: A validation issue existed in AutoDiscover V1. This was addressed by requiring TLS for AutoDiscover V1. AutoDiscover V2 is now supported.
apple
CVE-2018-4266P4MEDIUMCVSS 5.9v11.4.12018-07-09
CVE-2018-4266 [MEDIUM] CVE-2018-4266: iOS 11.4.1
Apple Security Update: About the security content of iOS 11.4.1
Product: iOS
Version: 11.4.1
CVE: CVE-2018-4266
Component: WebKit
Impact: A malicious website may be able to cause a denial of service
Description: A race condition was addressed with additional validation.
apple
CVE-2019-8658P4MEDIUMCVSS 6.1≥ unspecified, < iOS 12.42019-12-18
CVE-2019-8658 [MEDIUM] CWE-79 CVE-2019-8658: A logic issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS M
A logic issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
CVE-2017-2549P4MEDIUMCVSS 6.1v10.3.22017-05-15
CVE-2017-2549 [MEDIUM] CVE-2017-2549: iOS 10.3.2
Apple Security Update: About the security content of iOS 10.3.2
Product: iOS
Version: 10.3.2
CVE: CVE-2017-2549
Component: WebKit
Impact: Processing maliciously crafted web content may lead to universal cross site scripting
Description: A logic issue existed in frame loading. This issue was addressed with improved state management.
apple
CVE-2020-9925P4MEDIUMCVSS 6.1≥ unspecified, < iOS 13.6 and iPadOS 13.62020-10-16
CVE-2020-9925 [MEDIUM] CWE-79 CVE-2020-9925: A logic issue was addressed with improved state management. This issue is fixed in iOS 13.6 and iPad
A logic issue was addressed with improved state management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd
CVE-2017-13860P4MEDIUMCVSS 5.9v11.22017-12-02
CVE-2017-13860 [MEDIUM] CVE-2017-13860: iOS 11.2
Apple Security Update: About the security content of iOS 11.2
Product: iOS
Version: 11.2
CVE: CVE-2017-13860
Component: Mail Drafts
Impact: An attacker with a privileged network position may be able to intercept mail
Description: An encryption issue existed with S/MIME credentials. The issue was addressed with additional checks and user control.
apple
CVE-2017-13078P4MEDIUMCVSS 5.3v11.12017-10-31
CVE-2017-13078 [MEDIUM] CVE-2017-13078: iOS 11.1
Apple Security Update: About the security content of iOS 11.1
Product: iOS
Version: 11.1
CVE: CVE-2017-13078
Component: Wi-Fi
Impact: An attacker in Wi-Fi range may force nonce reuse in WPA unicast/PTK clients (Key Reinstallation Attacks - KRACK)
Description: A logic issue existed in the handling of state transitions. This was addressed with improved state management.
apple
CVE-2020-9916P4MEDIUMCVSS 5.3≥ unspecified, < iOS 13.6 and iPadOS 13.62020-10-16
CVE-2020-9916 [MEDIUM] CVE-2020-9916: A URL Unicode encoding issue was addressed with improved state management. This issue is fixed in iO
A URL Unicode encoding issue was addressed with improved state management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A malicious attacker may be able to conceal the destination of a URL.
nvd
CVE-2015-1065P4MEDIUMCVSS 5.4v8.2
CVE-2015-1065 [MEDIUM] CVE-2015-1065: iOS 8.2
Apple Security Update: About the security content of iOS 8.2
Product: iOS
Version: 8.2
CVE: CVE-2015-1065
Component: CVE-ID
apple
CVE-2015-5774P4HIGHCVSS 7.2v8.4.1
CVE-2015-5774 [HIGH] CVE-2015-5774: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-5774
Component: CVE-ID
apple
CVE-2019-8545P4HIGHCVSS 7.1≥ unspecified, < iOS 12.22019-12-18
CVE-2019-8545 [HIGH] CWE-787 CVE-2019-8545: A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 1
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A local user may be able to cause unexpected system termination or read kernel memory.
nvdapple
CVE-2022-32925P4HIGHCVSS 7.1≥ unspecified, < 162022-11-01
CVE-2022-32925 [HIGH] CWE-787 CVE-2022-32925: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvO
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 16, iOS 16, watchOS 9. An app may be able to cause unexpected system termination or write kernel memory.
nvdapple
CVE-2015-1101P4MEDIUMCVSS 6.9v8.3
CVE-2015-1101 [MEDIUM] CVE-2015-1101: iOS 8.3
Apple Security Update: About the security content of iOS 8.3
Product: iOS
Version: 8.3
CVE: CVE-2015-1101
Component: CVE-ID
apple
CVE-2018-4146P4MEDIUMCVSS 6.5v11.32018-03-29
CVE-2018-4146 [MEDIUM] CVE-2018-4146: iOS 11.3
Apple Security Update: About the security content of iOS 11.3
Product: iOS
Version: 11.3
CVE: CVE-2018-4146
Component: WebKit
Impact: Processing maliciously crafted web content may lead to a denial of service
Description: A memory corruption issue was addressed through improved input validation
apple
CVE-2018-4374P4MEDIUMCVSS 6.1v12.12018-10-30
CVE-2018-4374 [MEDIUM] CVE-2018-4374: iOS 12.1
Apple Security Update: About the security content of iOS 12.1
Product: iOS
Version: 12.1
CVE: CVE-2018-4374
Component: Safari Reader
Impact: Enabling the Safari Reader feature on a maliciously crafted webpage may lead to universal cross site scripting
Description: A logic issue was addressed with improved validation.
apple
CVE-2016-4690P4MEDIUMCVSS 6.8v10.22016-12-12
CVE-2016-4690 [MEDIUM] CVE-2016-4690: iOS 10.2
Apple Security Update: About the security content of iOS 10.2
Product: iOS
Version: 10.2
CVE: CVE-2016-4690
Component: Image Capture
Impact: A malicious HID device may be able to cause arbitrary code execution
Description: A validation issue existed in the handling of USB image devices. This issue was addressed through improved input validation.
apple
CVE-2019-8554P4MEDIUMCVSS 6.5≥ unspecified, < iOS 12.22019-12-18
CVE-2019-8554 [MEDIUM] CVE-2019-8554: A permissions issue existed in the handling of motion and orientation data. This issue was addressed
A permissions issue existed in the handling of motion and orientation data. This issue was addressed with improved restrictions. This issue is fixed in iOS 12.2. A website may be able to access sensor information without user consent.
nvdapple
CVE-2019-8626P4MEDIUMCVSS 6.5≥ unspecified, < iOS 12.32019-12-18
CVE-2019-8626 [MEDIUM] CWE-20 CVE-2019-8626: An input validation issue was addressed with improved input validation. This issue is fixed in iOS 1
An input validation issue was addressed with improved input validation. This issue is fixed in iOS 12.3, watchOS 5.2.1. Processing a maliciously crafted message may lead to a denial of service.
nvdapple
CVE-2018-4362P4MEDIUMCVSS 6.5v122018-09-17
CVE-2018-4362 [MEDIUM] CVE-2018-4362: iOS 12
Apple Security Update: About the security content of iOS 12
Product: iOS
Version: 12
CVE: CVE-2018-4362
Component: SafariViewController
Impact: Visiting a malicious website may lead to address bar spoofing
Description: An inconsistent user interface issue was addressed with improved state management.
apple
CVE-2019-8664P4MEDIUMCVSS 6.5≥ unspecified, < 12.32020-10-27
CVE-2019-8664 [MEDIUM] CWE-20 CVE-2019-8664: An input validation issue was addressed with improved input validation. This issue is fixed in iOS 1
An input validation issue was addressed with improved input validation. This issue is fixed in iOS 12.3, watchOS 5.2.1. Processing a maliciously crafted message may lead to a denial of service.
nvdapple