cbcvebase.

Apple iOS vulnerabilities

1,765 known vulnerabilities affecting apple/ios.

Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7

Vulnerabilities

Page 67 of 89
CVE-2016-1811P4MEDIUMCVSS 6.5v9.3.2
CVE-2016-1811 [MEDIUM] CVE-2016-1811: iOS 9.3.2 Apple Security Update: About the security content of iOS 9.3.2 Product: iOS Version: 9.3.2 CVE: CVE-2016-1811 Component: CVE-ID
apple
CVE-2016-1734P4MEDIUMCVSS 6.8v9.3
CVE-2016-1734 [MEDIUM] CVE-2016-1734: iOS 9.3 Apple Security Update: About the security content of iOS 9.3 Product: iOS Version: 9.3 CVE: CVE-2016-1734 Component: CVE-ID
apple
CVE-2016-4587P4MEDIUMCVSS 6.5v9.3.32016-07-18
CVE-2016-4587 [MEDIUM] CVE-2016-4587: iOS 9.3.3 Apple Security Update: About the security content of iOS 9.3.3 Product: iOS Version: 9.3.3 CVE: CVE-2016-4587 Component: WebKit Impact: Visiting a maliciously crafted website may result in the disclosure of process memory Description: A memory initialization issue was addressed through improved memory handling.
apple
CVE-2017-2412P4MEDIUMCVSS 6.5v10.32017-03-27
CVE-2017-2412 [MEDIUM] CVE-2017-2412: iOS 10.3 Apple Security Update: About the security content of iOS 10.3 Product: iOS Version: 10.3 CVE: CVE-2017-2412 Component: CVE-2016-3619 Impact: An attacker in a privileged network position may be able to tamper with iTunes network traffic Description: Requests to iTunes sandbox web services were sent in cleartext. This was addressed by enabling HTTPS.
apple
CVE-2017-2475P4MEDIUMCVSS 6.1v10.32017-03-27
CVE-2017-2475 [MEDIUM] CVE-2017-2475: iOS 10.3 Apple Security Update: About the security content of iOS 10.3 Product: iOS Version: 10.3 CVE: CVE-2017-2475 Component: WebKit Impact: Processing maliciously crafted web content may lead to universal cross site scripting Description: A logic issue existed in frame handling. This issue was addressed through improved state management.
apple
CVE-2019-8674P4MEDIUMCVSS 6.1≥ unspecified, < iOS 132019-12-18
CVE-2019-8674 [MEDIUM] CWE-79 CVE-2019-8674: A logic issue was addressed with improved state management. This issue is fixed in iOS 13, Safari 13 A logic issue was addressed with improved state management. This issue is fixed in iOS 13, Safari 13. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
CVE-2017-2492P4MEDIUMCVSS 6.1v10.32017-03-27
CVE-2017-2492 [MEDIUM] CVE-2017-2492: iOS 10.3 Apple Security Update: About the security content of iOS 10.3 Product: iOS Version: 10.3 CVE: CVE-2017-2492 Component: JavaScriptCore Impact: Processing a maliciously crafted web page may lead to universal cross site scripting Description: A prototype issue was addressed through improved logic.
apple
CVE-2016-1760P4MEDIUMCVSS 6.2v9.3
CVE-2016-1760 [MEDIUM] CVE-2016-1760: iOS 9.3 Apple Security Update: About the security content of iOS 9.3 Product: iOS Version: 9.3 CVE: CVE-2016-1760 Component: CVE-ID Impact: Processing maliciously crafted XML may lead to unexpected application termination or arbitrary code execution Description: Multiple memory corruption issues were addressed through improved memory handling.
apple
CVE-2015-1067P4MEDIUMCVSS 4.3v8.2
CVE-2015-1067 [MEDIUM] CVE-2015-1067: iOS 8.2 Apple Security Update: About the security content of iOS 8.2 Product: iOS Version: 8.2 CVE: CVE-2015-1067 Component: CVE-ID
apple
CVE-2018-4232P4MEDIUMCVSS 4.3v11.42018-05-29
CVE-2018-4232 [MEDIUM] CVE-2018-4232: iOS 11.4 Apple Security Update: About the security content of iOS 11.4 Product: iOS Version: 11.4 CVE: CVE-2018-4232 Component: WebKit Impact: Visiting a maliciously crafted website may lead to cookies being overwritten Description: A permissions issue existed in the handling of web browser cookies. This issue was addressed with improved restrictions.
apple
CVE-2015-7023P4MEDIUMCVSS 5.8v9.1
CVE-2015-7023 [MEDIUM] CVE-2015-7023: iOS 9.1 Apple Security Update: About the security content of iOS 9.1 Product: iOS Version: 9.1 CVE: CVE-2015-7023 Component: CVE-ID Impact: A malicious application may be able to elevate privileges Description: A heap based buffer overflow issue existed in the DNS client library. A malicious application with the ability to spoof responses from the local configd service may have been able to cause arbitrary code execution in DNS clients.
apple
CVE-2016-4721P4MEDIUMCVSS 5.9v10.12016-10-24
CVE-2016-4721 [MEDIUM] CVE-2016-4721: iOS 10.1 Apple Security Update: About the security content of iOS 10.1 Product: iOS Version: 10.1 CVE: CVE-2016-4721 Component: IDS - Connectivity Impact: An attacker in a privileged network position may be able to trick a user on a multi-party call into believing they are talking to the other party Description: An impersonation issue existed in the handling of call switching. This issue was addressed through improved handling of "switch caller" notification
apple
CVE-2016-4685P4MEDIUMCVSS 5.9v10.12016-10-24
CVE-2016-4685 [MEDIUM] CVE-2016-4685: iOS 10.1 Apple Security Update: About the security content of iOS 10.1 Product: iOS Version: 10.1 CVE: CVE-2016-4685 Component: IDS - Connectivity Impact: An attacker in a privileged network position may be able to trick a user on a multi-party call into believing they are talking to the other party Description: An impersonation issue existed in the handling of call switching. This issue was addressed through improved handling of "switch caller" notification
apple
CVE-2015-5770P4MEDIUMCVSS 5.8v8.4.1
CVE-2015-5770 [MEDIUM] CVE-2015-5770: iOS 8.4.1 Apple Security Update: About the security content of iOS 8.4.1 Product: iOS Version: 8.4.1 CVE: CVE-2015-5770 Component: CVE-ID
apple
CVE-2017-13080P4MEDIUMCVSS 5.3v11.22017-12-02
CVE-2017-13080 [MEDIUM] CVE-2017-13080: iOS 11.2 Apple Security Update: About the security content of iOS 11.2 Product: iOS Version: 11.2 CVE: CVE-2017-13080 Component: Wi-Fi Impact: An attacker in Wi-Fi range may force nonce reuse in WPA multicast/GTK clients (Key Reinstallation Attacks - KRACK) Description: A logic issue existed in the handling of state transitions. This was addressed with improved state management.
apple
CVE-2019-8530P4MEDIUMCVSS 5.5≥ unspecified, < iOS 12.22019-12-18
CVE-2019-8530 [MEDIUM] CVE-2019-8530: This issue was addressed with improved checks. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4 This issue was addressed with improved checks. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2. A malicious application may be able to overwrite arbitrary files.
nvdapple
CVE-2019-8798P4MEDIUMCVSS 5.5≥ unspecified, < iOS 13.2 and iPadOS 13.22019-12-18
CVE-2019-8798 [MEDIUM] CWE-787 CVE-2019-8798: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13 A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with system privileges.
nvd
CVE-2017-7006P4MEDIUMCVSS 5.3v10.3.32017-07-19
CVE-2017-7006 [MEDIUM] CVE-2017-7006: iOS 10.3.3 Apple Security Update: About the security content of iOS 10.3.3 Product: iOS Version: 10.3.3 CVE: CVE-2017-7006 Component: WebKit Impact: A malicious website may exfiltrate data cross-origin Description: Processing maliciously crafted web content may allow cross-origin data to be exfiltrated by using SVG filters to conduct a timing side-channel attack. This issue was addressed by not painting the cross-origin buffer into the frame that gets filter
apple
CVE-2021-30769P4MEDIUMCVSS 5.5≥ unspecified, < 14.72021-09-08
CVE-2021-30769 [MEDIUM] CWE-287 CVE-2021-30769: A logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, tvOS 14 A logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
nvd
CVE-2022-32928P4MEDIUMCVSS 5.3v162022-09-12
CVE-2022-32928 [MEDIUM] CVE-2022-32928: iOS 16 Apple Security Update: About the security content of iOS 16 Product: iOS Version: 16 CVE: CVE-2022-32928 Component: Exchange Impact: A user in a privileged network position may be able to intercept mail credentials Description: A logic issue was addressed with improved restrictions.
apple
Apple iOS vulnerabilities | cvebase