Apple iOS vulnerabilities
1,765 known vulnerabilities affecting apple/ios.
Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7
Vulnerabilities
Page 68 of 89
CVE-2015-3753P4MEDIUMCVSS 5.0v8.4.1
CVE-2015-3753 [MEDIUM] CVE-2015-3753: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-3753
Component: CVE-ID
apple
CVE-2021-30769P4MEDIUMCVSS 5.5≥ unspecified, < 14.72021-09-08
CVE-2021-30769 [MEDIUM] CWE-287 CVE-2021-30769: A logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, tvOS 14
A logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
nvd
CVE-2017-7006P4MEDIUMCVSS 5.3v10.3.32017-07-19
CVE-2017-7006 [MEDIUM] CVE-2017-7006: iOS 10.3.3
Apple Security Update: About the security content of iOS 10.3.3
Product: iOS
Version: 10.3.3
CVE: CVE-2017-7006
Component: WebKit
Impact: A malicious website may exfiltrate data cross-origin
Description: Processing maliciously crafted web content may allow cross-origin data to be exfiltrated by using SVG filters to conduct a timing side-channel attack. This issue was addressed by not painting the cross-origin buffer into the frame that gets filter
apple
CVE-2015-5766P4MEDIUMCVSS 5.0v8.4.1
CVE-2015-5766 [MEDIUM] CVE-2015-5766: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-5766
Component: CVE-ID
apple
CVE-2019-8798P4MEDIUMCVSS 5.5≥ unspecified, < iOS 13.2 and iPadOS 13.22019-12-18
CVE-2019-8798 [MEDIUM] CWE-787 CVE-2019-8798: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with system privileges.
nvd
CVE-2015-5746P4MEDIUMCVSS 5.0v8.4.1
CVE-2015-5746 [MEDIUM] CVE-2015-5746: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-5746
Component: CVE-ID
apple
CVE-2020-9894P4MEDIUMCVSS 4.3≥ unspecified, < iOS 13.6 and iPadOS 13.62020-10-16
CVE-2020-9894 [MEDIUM] CWE-125 CVE-2020-9894: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.6
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
nvd
CVE-2016-4743P4HIGHCVSS 7.1v10.22016-12-12
CVE-2016-4743 [HIGH] CVE-2016-4743: iOS 10.2
Apple Security Update: About the security content of iOS 10.2
Product: iOS
Version: 10.2
CVE: CVE-2016-4743
Component: WebKit
Impact: Processing maliciously crafted web content may result in the disclosure of process memory
Description: A memory corruption issue was addressed through improved input validation.
apple
CVE-2016-4776P4HIGHCVSS 7.1v102016-09-13
CVE-2016-4776 [HIGH] CVE-2016-4776: iOS 10
Apple Security Update: About the security content of iOS 10
Product: iOS
Version: 10
CVE: CVE-2016-4776
Component: Kernel
Impact: An application may be able to determine kernel memory layout
Description: Multiple out-of-bounds read issues existed that led to the disclosure of kernel memory. These were addressed through improved input validation.
apple
CVE-2016-4774P4HIGHCVSS 7.1v102016-09-13
CVE-2016-4774 [HIGH] CVE-2016-4774: iOS 10
Apple Security Update: About the security content of iOS 10
Product: iOS
Version: 10
CVE: CVE-2016-4774
Component: Kernel
Impact: An application may be able to determine kernel memory layout
Description: Multiple out-of-bounds read issues existed that led to the disclosure of kernel memory. These were addressed through improved input validation.
apple
CVE-2016-4773P4HIGHCVSS 7.1v102016-09-13
CVE-2016-4773 [HIGH] CVE-2016-4773: iOS 10
Apple Security Update: About the security content of iOS 10
Product: iOS
Version: 10
CVE: CVE-2016-4773
Component: Kernel
Impact: An application may be able to determine kernel memory layout
Description: Multiple out-of-bounds read issues existed that led to the disclosure of kernel memory. These were addressed through improved input validation.
apple
CVE-2016-3619P4MEDIUMCVSS 6.5v10.32017-03-27
CVE-2016-3619 [MEDIUM] CVE-2016-3619: iOS 10.3
Apple Security Update: About the security content of iOS 10.3
Product: iOS
Version: 10.3
CVE: CVE-2016-3619
Component: CVE-2016-3619
Impact: An attacker in a privileged network position may be able to tamper with iTunes network traffic
Description: Requests to iTunes sandbox web services were sent in cleartext. This was addressed by enabling HTTPS.
apple
CVE-2015-3800P4HIGHCVSS 7.2v8.4.1
CVE-2015-3800 [HIGH] CVE-2015-3800: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-3800
Component: CVE-ID
apple
CVE-2015-3802P4HIGHCVSS 7.2v8.4.1
CVE-2015-3802 [HIGH] CVE-2015-3802: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-3802
Component: CVE-ID
apple
CVE-2015-3805P4HIGHCVSS 7.2v8.4.1
CVE-2015-3805 [HIGH] CVE-2015-3805: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-3805
Component: CVE-ID
apple
CVE-2016-4605P4MEDIUMCVSS 6.5v9.3.32016-07-18
CVE-2016-4605 [MEDIUM] CVE-2016-4605: iOS 9.3.3
Apple Security Update: About the security content of iOS 9.3.3
Product: iOS
Version: 9.3.3
CVE: CVE-2016-4605
Component: Calendar
Impact: A maliciously crafted calendar invite may cause a device to unexpectedly restart
Description: A null pointer dereference was addressed through improved memory handling.
apple
CVE-2016-1837P4MEDIUMCVSS 5.5v9.3.2
CVE-2016-1837 [MEDIUM] CVE-2016-1837: iOS 9.3.2
Apple Security Update: About the security content of iOS 9.3.2
Product: iOS
Version: 9.3.2
CVE: CVE-2016-1837
Component: CVE-ID
Impact: Visiting a maliciously crafted website may lead to arbitrary code execution
Description: A memory corruption issue was addressed through improved memory handling.
apple
CVE-2016-1836P4MEDIUMCVSS 5.5v9.3.22016-07-18
CVE-2016-1836 [MEDIUM] CVE-2016-1836: iOS 9.3.2
Apple Security Update: About the security content of iOS 9.3.2
Product: iOS
Version: 9.3.2
CVE: CVE-2016-1836
Component: CVE-ID
Impact: Visiting a maliciously crafted website may lead to arbitrary code execution
Description: A memory corruption issue was addressed through improved memory handling.
apple
CVE-2017-7060P4MEDIUMCVSS 6.5v10.3.32017-07-19
CVE-2017-7060 [MEDIUM] CVE-2017-7060: iOS 10.3.3
Apple Security Update: About the security content of iOS 10.3.3
Product: iOS
Version: 10.3.3
CVE: CVE-2017-7060
Component: Safari Printing
Impact: Processing maliciously crafted web content may lead to an infinite number of print dialogs
Description: An issue existed where a malicious or compromised website could show infinite print dialogs and make users believe their browser was locked. The issue was addressed through throttling of print dialogs
apple
CVE-2015-8242P4MEDIUMCVSS 5.0v9.3
CVE-2015-8242 [MEDIUM] CVE-2015-8242: iOS 9.3
Apple Security Update: About the security content of iOS 9.3
Product: iOS
Version: 9.3
CVE: CVE-2015-8242
Component: CVE-2015-7499
apple