Apple iOS vulnerabilities
1,765 known vulnerabilities affecting apple/ios.
Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7
Vulnerabilities
Page 69 of 89
CVE-2018-4309P4MEDIUMCVSS 6.1v122018-09-17
CVE-2018-4309 [MEDIUM] CVE-2018-4309: iOS 12
Apple Security Update: About the security content of iOS 12
Product: iOS
Version: 12
CVE: CVE-2018-4309
Component: WebKit
Impact: A malicious website may be able to execute scripts in the context of another website
Description: A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation.
apple
CVE-2018-4345P4MEDIUMCVSS 6.1v122018-09-17
CVE-2018-4345 [MEDIUM] CVE-2018-4345: iOS 12
Apple Security Update: About the security content of iOS 12
Product: iOS
Version: 12
CVE: CVE-2018-4345
Component: WebKit
Impact: A malicious website may exfiltrate image data cross-origin
Description: A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation.
apple
CVE-2016-4722P4MEDIUMCVSS 5.9v102016-09-13
CVE-2016-4722 [MEDIUM] CVE-2016-4722: iOS 10
Apple Security Update: About the security content of iOS 10
Product: iOS
Version: 10
CVE: CVE-2016-4722
Component: IDS - Connectivity
Impact: An attacker in a privileged network position may be able to cause a denial of service
Description: A spoofing issue existed in the handling of Call Relay. This issue was addressed through improved input validation.
apple
CVE-2018-4377P4MEDIUMCVSS 6.1v12.12018-10-30
CVE-2018-4377 [MEDIUM] CVE-2018-4377: iOS 12.1
Apple Security Update: About the security content of iOS 12.1
Product: iOS
Version: 12.1
CVE: CVE-2018-4377
Component: Safari Reader
Impact: Enabling the Safari Reader feature on a maliciously crafted webpage may lead to universal cross site scripting
Description: A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation.
apple
CVE-2019-8674P4MEDIUMCVSS 6.1≥ unspecified, < iOS 132019-12-18
CVE-2019-8674 [MEDIUM] CWE-79 CVE-2019-8674: A logic issue was addressed with improved state management. This issue is fixed in iOS 13, Safari 13
A logic issue was addressed with improved state management. This issue is fixed in iOS 13, Safari 13. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
CVE-2019-6204P4MEDIUMCVSS 6.1≥ unspecified, < iOS 12.22019-12-18
CVE-2019-6204 [MEDIUM] CWE-79 CVE-2019-6204: A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, Safari 12.1.
A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, Safari 12.1. Enabling the Safari Reader feature on a maliciously crafted webpage may lead to universal cross site scripting.
nvdapple
CVE-2019-8505P4MEDIUMCVSS 6.1≥ unspecified, < iOS 12.22019-12-18
CVE-2019-8505 [MEDIUM] CWE-79 CVE-2019-8505: A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, Safari 12.1.
A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, Safari 12.1. Enabling the Safari Reader feature on a maliciously crafted webpage may lead to universal cross site scripting.
nvdapple
CVE-2016-4746P4MEDIUMCVSS 5.3v102016-09-13
CVE-2016-4746 [MEDIUM] CVE-2016-4746: iOS 10
Apple Security Update: About the security content of iOS 10
Product: iOS
Version: 10
CVE: CVE-2016-4746
Component: Keyboards
Impact: Keyboard auto correct suggestions may reveal sensitive information
Description: The iOS keyboard was inadvertently caching sensitive information. This issue was addressed through improved heuristics.
apple
CVE-2017-7142P4MEDIUMCVSS 5.3v112017-09-19
CVE-2017-7142 [MEDIUM] CVE-2017-7142: iOS 11
Apple Security Update: About the security content of iOS 11
Product: iOS
Version: 11
CVE: CVE-2017-7142
Component: WebKit Storage
Impact: Website data may persist after a Safari Private browsing session
Description: An information leakage issue existed in the handling of website data in Safari Private windows. This issue was addressed with improved data handling.
apple
CVE-2019-8512P4MEDIUMCVSS 5.7≥ unspecified, < iOS 12.22019-12-18
CVE-2019-8512 [MEDIUM] CWE-863 CVE-2019-8512: This issue was addressed with improved transparency. This issue is fixed in iOS 12.2. A user may aut
This issue was addressed with improved transparency. This issue is fixed in iOS 12.2. A user may authorize an enterprise administrator to remotely wipe their device without appropriate disclosure.
nvdapple
CVE-2019-8768P4MEDIUMCVSS 5.3v132019-09-19
CVE-2019-8768 [MEDIUM] CVE-2019-8768: iOS 13
Apple Security Update: About the security content of iOS 13
Product: iOS
Version: 13
CVE: CVE-2019-8768
Component: WebKit
Impact: A user may be unable to delete browsing history items
Description: "Clear History and Website Data" did not fully clear the history. The issue was addressed with improved data deletion.
apple
CVE-2016-1730P4MEDIUMCVSS 5.4v9.2.1
CVE-2016-1730 [MEDIUM] CVE-2016-1730: iOS 9.2.1
Apple Security Update: About the security content of iOS 9.2.1
Product: iOS
Version: 9.2.1
CVE: CVE-2016-1730
Component: CVE-ID
apple
CVE-2014-4465P4MEDIUMCVSS 5.0v8.1.3
CVE-2014-4465 [MEDIUM] CVE-2014-4465: iOS 8.1.3
Apple Security Update: About the security content of iOS 8.1.3
Product: iOS
Version: 8.1.3
CVE: CVE-2014-4465
Component: CVE-ID
apple
CVE-2019-8530P4MEDIUMCVSS 5.5≥ unspecified, < iOS 12.22019-12-18
CVE-2019-8530 [MEDIUM] CVE-2019-8530: This issue was addressed with improved checks. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4
This issue was addressed with improved checks. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2. A malicious application may be able to overwrite arbitrary files.
nvdapple
CVE-2015-1110P4MEDIUMCVSS 5.0v8.3
CVE-2015-1110 [MEDIUM] CVE-2015-1110: iOS 8.3
Apple Security Update: About the security content of iOS 8.3
Product: iOS
Version: 8.3
CVE: CVE-2015-1110
Component: CVE-ID
apple
CVE-2018-4293P4MEDIUMCVSS 5.3v11.4.12018-07-09
CVE-2018-4293 [MEDIUM] CVE-2018-4293: iOS 11.4.1
Apple Security Update: About the security content of iOS 11.4.1
Product: iOS
Version: 11.4.1
CVE: CVE-2018-4293
Component: CFNetwork
Impact: Cookies may unexpectedly persist in Safari
Description: A cookie management issue was addressed with improved checks.
apple
CVE-2019-8521P4MEDIUMCVSS 5.5≥ unspecified, < iOS 12.22019-12-18
CVE-2019-8521 [MEDIUM] CVE-2019-8521: This issue was addressed with improved checks. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4
This issue was addressed with improved checks. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4. A malicious application may be able to overwrite arbitrary files.
nvdapple
CVE-2018-4321P4MEDIUMCVSS 5.3v122018-09-17
CVE-2018-4321 [MEDIUM] CVE-2018-4321: iOS 12
Apple Security Update: About the security content of iOS 12
Product: iOS
Version: 12
CVE: CVE-2018-4321
Component: Auto Unlock
Impact: A malicious application may be able to access local users AppleIDs
Description: A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement.
apple
CVE-2020-9787P4MEDIUMCVSS 5.3≥ unspecified, < iOS 13.4 and iPadOS 13.42020-10-22
CVE-2020-9787 [MEDIUM] CVE-2020-9787: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 1
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. Some websites may not have appeared in Safari Preferences.
nvd
CVE-2016-4635P4MEDIUMCVSS 5.3v9.3.32016-07-18
CVE-2016-4635 [MEDIUM] CVE-2016-4635: iOS 9.3.3
Apple Security Update: About the security content of iOS 9.3.3
Product: iOS
Version: 9.3.3
CVE: CVE-2016-4635
Component: FaceTime
Impact: An attacker in a privileged network position may be able to cause a relayed call to continue transmitting audio while appearing as if the call terminated
Description: User interface inconsistencies existed in the handling of relayed calls. These issues were addressed through improved FaceTime display logic.
apple