cbcvebase.

Apple iOS vulnerabilities

1,765 known vulnerabilities affecting apple/ios.

Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7

Vulnerabilities

Page 70 of 89
CVE-2015-5752P4MEDIUMCVSS 5.0v8.4.1
CVE-2015-5752 [MEDIUM] CVE-2015-5752: iOS 8.4.1 Apple Security Update: About the security content of iOS 8.4.1 Product: iOS Version: 8.4.1 CVE: CVE-2015-5752 Component: CVE-ID Impact: An attacker may be able to determine Wi-Fi networks a device has previously accessed Description: Upon connecting to a Wi-Fi network, MAC addresses of previously accessed networks may have been broadcast. This issue was addressed by broadcasting only MAC addresses associated with the current SSID.
apple
CVE-2019-8708P4MEDIUMCVSS 5.5≥ unspecified, < 132020-10-27
CVE-2019-8708 [MEDIUM] CVE-2019-8708: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15. A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, macOS Catalina 10.15, iOS 13. A local user may be able to check for the existence of arbitrary files.
nvdapple
CVE-2022-32928P4MEDIUMCVSS 5.3v162022-09-12
CVE-2022-32928 [MEDIUM] CVE-2022-32928: iOS 16 Apple Security Update: About the security content of iOS 16 Product: iOS Version: 16 CVE: CVE-2022-32928 Component: Exchange Impact: A user in a privileged network position may be able to intercept mail credentials Description: A logic issue was addressed with improved restrictions.
apple
CVE-2015-7004P4HIGHCVSS 7.1v9.1
CVE-2015-7004 [HIGH] CVE-2015-7004: iOS 9.1 Apple Security Update: About the security content of iOS 9.1 Product: iOS Version: 9.1 CVE: CVE-2015-7004 Component: CVE-ID
apple
CVE-2017-2450P4HIGHCVSS 7.1v10.32017-03-27
CVE-2017-2450 [HIGH] CVE-2017-2450: iOS 10.3 Apple Security Update: About the security content of iOS 10.3 Product: iOS Version: 10.3 CVE: CVE-2017-2450 Component: CoreText Impact: Processing a maliciously crafted font may result in the disclosure of process memory Description: An out-of-bounds read was addressed through improved input validation.
apple
CVE-2017-2439P4HIGHCVSS 7.1v10.32017-03-27
CVE-2017-2439 [HIGH] CVE-2017-2439: iOS 10.3 Apple Security Update: About the security content of iOS 10.3 Product: iOS Version: 10.3 CVE: CVE-2017-2439 Component: FontParser Impact: Processing a maliciously crafted font may result in the disclosure of process memory Description: An out-of-bounds read was addressed through improved input validation.
apple
CVE-2015-7500P4MEDIUMCVSS 5.0v9.3
CVE-2015-7500 [MEDIUM] CVE-2015-7500: iOS 9.3 Apple Security Update: About the security content of iOS 9.3 Product: iOS Version: 9.3 CVE: CVE-2015-7500 Component: CVE-2015-7499
apple
CVE-2015-3803P4HIGHCVSS 7.2v8.4.1
CVE-2015-3803 [HIGH] CVE-2015-3803: iOS 8.4.1 Apple Security Update: About the security content of iOS 8.4.1 Product: iOS Version: 8.4.1 CVE: CVE-2015-3803 Component: CVE-ID
apple
CVE-2015-3806P4HIGHCVSS 7.2v8.4.1
CVE-2015-3806 [HIGH] CVE-2015-3806: iOS 8.4.1 Apple Security Update: About the security content of iOS 8.4.1 Product: iOS Version: 8.4.1 CVE: CVE-2015-3806 Component: CVE-ID
apple
CVE-2015-3726P4MEDIUMCVSS 4.6v8.4
CVE-2015-3726 [MEDIUM] CVE-2015-3726: iOS 8.4 Apple Security Update: About the security content of iOS 8.4 Product: iOS Version: 8.4 CVE: CVE-2015-3726 Component: CVE-ID
apple
CVE-2016-7627P4MEDIUMCVSS 6.5v10.22016-12-12
CVE-2016-7627 [MEDIUM] CVE-2016-7627: iOS 10.2 Apple Security Update: About the security content of iOS 10.2 Product: iOS Version: 10.2 CVE: CVE-2016-7627 Component: CoreGraphics Impact: Processing a maliciously crafted font file may lead to unexpected application termination Description: A null pointer dereference was addressed through improved input validation.
apple
CVE-2018-4250P4MEDIUMCVSS 6.5v11.42018-05-29
CVE-2018-4250 [MEDIUM] CVE-2018-4250: iOS 11.4 Apple Security Update: About the security content of iOS 11.4 Product: iOS Version: 11.4 CVE: CVE-2018-4250 Component: Messages Impact: Processing a maliciously crafted message may lead to a denial of service Description: This issue was addressed with improved message validation.
apple
CVE-2017-6975P4MEDIUMCVSS 6.8v10.3.12017-04-03
CVE-2017-6975 [MEDIUM] CVE-2017-6975: iOS 10.3.1 Apple Security Update: About the security content of iOS 10.3.1 Product: iOS Version: 10.3.1 CVE: CVE-2017-6975 Component: Wi-Fi Impact: An attacker within range may be able to execute arbitrary code on the Wi-Fi chip Description: A stack buffer overflow was addressed through improved input validation.
apple
CVE-2016-4651P4MEDIUMCVSS 6.1v9.3.32016-07-18
CVE-2016-4651 [MEDIUM] CVE-2016-4651: iOS 9.3.3 Apple Security Update: About the security content of iOS 9.3.3 Product: iOS Version: 9.3.3 CVE: CVE-2016-4651 Component: WebKit JavaScript Bindings Impact: Visiting a maliciously crafted website may lead to script execution in the context of a non-HTTP service Description: A cross-protocol cross-site scripting (XPXSS) issue existed in Safari when submitting forms to non-HTTP services compatible with HTTP/0.9. This issue was addressed by disabling s
apple
CVE-2016-4585P4MEDIUMCVSS 6.1v9.3.32016-07-18
CVE-2016-4585 [MEDIUM] CVE-2016-4585: iOS 9.3.3 Apple Security Update: About the security content of iOS 9.3.3 Product: iOS Version: 9.3.3 CVE: CVE-2016-4585 Component: WebKit Page Loading Impact: A malicious website may exfiltrate data cross-origin Description: A cross-site scripting issue existed in Safari URL redirection. This issue was addressed through improved URL validation on redirection.
apple
CVE-2018-4305P4MEDIUMCVSS 6.5v122018-09-17
CVE-2018-4305 [MEDIUM] CVE-2018-4305: iOS 12 Apple Security Update: About the security content of iOS 12 Product: iOS Version: 12 CVE: CVE-2018-4305 Component: IOUserEthernet Impact: An application may be able to execute arbitrary code with kernel privileges Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2019-8764P4MEDIUMCVSS 6.1v132019-09-19
CVE-2019-8764 [MEDIUM] CVE-2019-8764: iOS 13 Apple Security Update: About the security content of iOS 13 Product: iOS Version: 13 CVE: CVE-2019-8764 Component: WebKit Impact: Processing maliciously crafted web content may lead to universal cross site scripting Description: A logic issue was addressed with improved state management.
apple
CVE-2017-7109P4MEDIUMCVSS 6.1v112017-09-19
CVE-2017-7109 [MEDIUM] CVE-2017-7109: iOS 11 Apple Security Update: About the security content of iOS 11 Product: iOS Version: 11 CVE: CVE-2017-7109 Component: WebKit Impact: Processing maliciously crafted web content may lead to a cross site scripting attack Description: Application Cache policy may be unexpectedly applied.
apple
CVE-2017-7059P4MEDIUMCVSS 6.1v10.3.32017-07-19
CVE-2017-7059 [MEDIUM] CVE-2017-7059: iOS 10.3.3 Apple Security Update: About the security content of iOS 10.3.3 Product: iOS Version: 10.3.3 CVE: CVE-2017-7059 Component: WebKit Impact: Processing maliciously crafted web content with DOMParser may lead to cross site scripting Description: A logic issue existed in the handling of DOMParser. This issue was addressed with improved state management.
apple
CVE-2016-4741P4MEDIUMCVSS 5.9v102016-09-13
CVE-2016-4741 [MEDIUM] CVE-2016-4741: iOS 10 Apple Security Update: About the security content of iOS 10 Product: iOS Version: 10 CVE: CVE-2016-4741 Component: Assets Impact: An attacker in a privileged network position may be able to block a device from receiving software updates Description: An issue existed in iOS updates, which did not properly secure user communications. This issue was addressed by using HTTPS for software updates.
apple
Apple iOS vulnerabilities | cvebase