Apple iOS vulnerabilities
1,765 known vulnerabilities affecting apple/ios.
Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7
Vulnerabilities
Page 70 of 89
CVE-2015-5752P4MEDIUMCVSS 5.0v8.4.1
CVE-2015-5752 [MEDIUM] CVE-2015-5752: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-5752
Component: CVE-ID
Impact: An attacker may be able to determine Wi-Fi networks a device has previously accessed
Description: Upon connecting to a Wi-Fi network, MAC addresses of previously accessed networks may have been broadcast. This issue was addressed by broadcasting only MAC addresses associated with the current SSID.
apple
CVE-2019-8708P4MEDIUMCVSS 5.5≥ unspecified, < 132020-10-27
CVE-2019-8708 [MEDIUM] CVE-2019-8708: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, macOS Catalina 10.15, iOS 13. A local user may be able to check for the existence of arbitrary files.
nvdapple
CVE-2022-32928P4MEDIUMCVSS 5.3v162022-09-12
CVE-2022-32928 [MEDIUM] CVE-2022-32928: iOS 16
Apple Security Update: About the security content of iOS 16
Product: iOS
Version: 16
CVE: CVE-2022-32928
Component: Exchange
Impact: A user in a privileged network position may be able to intercept mail credentials
Description: A logic issue was addressed with improved restrictions.
apple
CVE-2015-7004P4HIGHCVSS 7.1v9.1
CVE-2015-7004 [HIGH] CVE-2015-7004: iOS 9.1
Apple Security Update: About the security content of iOS 9.1
Product: iOS
Version: 9.1
CVE: CVE-2015-7004
Component: CVE-ID
apple
CVE-2017-2450P4HIGHCVSS 7.1v10.32017-03-27
CVE-2017-2450 [HIGH] CVE-2017-2450: iOS 10.3
Apple Security Update: About the security content of iOS 10.3
Product: iOS
Version: 10.3
CVE: CVE-2017-2450
Component: CoreText
Impact: Processing a maliciously crafted font may result in the disclosure of process memory
Description: An out-of-bounds read was addressed through improved input validation.
apple
CVE-2017-2439P4HIGHCVSS 7.1v10.32017-03-27
CVE-2017-2439 [HIGH] CVE-2017-2439: iOS 10.3
Apple Security Update: About the security content of iOS 10.3
Product: iOS
Version: 10.3
CVE: CVE-2017-2439
Component: FontParser
Impact: Processing a maliciously crafted font may result in the disclosure of process memory
Description: An out-of-bounds read was addressed through improved input validation.
apple
CVE-2015-7500P4MEDIUMCVSS 5.0v9.3
CVE-2015-7500 [MEDIUM] CVE-2015-7500: iOS 9.3
Apple Security Update: About the security content of iOS 9.3
Product: iOS
Version: 9.3
CVE: CVE-2015-7500
Component: CVE-2015-7499
apple
CVE-2015-3803P4HIGHCVSS 7.2v8.4.1
CVE-2015-3803 [HIGH] CVE-2015-3803: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-3803
Component: CVE-ID
apple
CVE-2015-3806P4HIGHCVSS 7.2v8.4.1
CVE-2015-3806 [HIGH] CVE-2015-3806: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-3806
Component: CVE-ID
apple
CVE-2015-3726P4MEDIUMCVSS 4.6v8.4
CVE-2015-3726 [MEDIUM] CVE-2015-3726: iOS 8.4
Apple Security Update: About the security content of iOS 8.4
Product: iOS
Version: 8.4
CVE: CVE-2015-3726
Component: CVE-ID
apple
CVE-2016-7627P4MEDIUMCVSS 6.5v10.22016-12-12
CVE-2016-7627 [MEDIUM] CVE-2016-7627: iOS 10.2
Apple Security Update: About the security content of iOS 10.2
Product: iOS
Version: 10.2
CVE: CVE-2016-7627
Component: CoreGraphics
Impact: Processing a maliciously crafted font file may lead to unexpected application termination
Description: A null pointer dereference was addressed through improved input validation.
apple
CVE-2018-4250P4MEDIUMCVSS 6.5v11.42018-05-29
CVE-2018-4250 [MEDIUM] CVE-2018-4250: iOS 11.4
Apple Security Update: About the security content of iOS 11.4
Product: iOS
Version: 11.4
CVE: CVE-2018-4250
Component: Messages
Impact: Processing a maliciously crafted message may lead to a denial of service
Description: This issue was addressed with improved message validation.
apple
CVE-2017-6975P4MEDIUMCVSS 6.8v10.3.12017-04-03
CVE-2017-6975 [MEDIUM] CVE-2017-6975: iOS 10.3.1
Apple Security Update: About the security content of iOS 10.3.1
Product: iOS
Version: 10.3.1
CVE: CVE-2017-6975
Component: Wi-Fi
Impact: An attacker within range may be able to execute arbitrary code on the Wi-Fi chip
Description: A stack buffer overflow was addressed through improved input validation.
apple
CVE-2016-4651P4MEDIUMCVSS 6.1v9.3.32016-07-18
CVE-2016-4651 [MEDIUM] CVE-2016-4651: iOS 9.3.3
Apple Security Update: About the security content of iOS 9.3.3
Product: iOS
Version: 9.3.3
CVE: CVE-2016-4651
Component: WebKit JavaScript Bindings
Impact: Visiting a maliciously crafted website may lead to script execution in the context of a non-HTTP service
Description: A cross-protocol cross-site scripting (XPXSS) issue existed in Safari when submitting forms to non-HTTP services compatible with HTTP/0.9. This issue was addressed by disabling s
apple
CVE-2016-4585P4MEDIUMCVSS 6.1v9.3.32016-07-18
CVE-2016-4585 [MEDIUM] CVE-2016-4585: iOS 9.3.3
Apple Security Update: About the security content of iOS 9.3.3
Product: iOS
Version: 9.3.3
CVE: CVE-2016-4585
Component: WebKit Page Loading
Impact: A malicious website may exfiltrate data cross-origin
Description: A cross-site scripting issue existed in Safari URL redirection. This issue was addressed through improved URL validation on redirection.
apple
CVE-2018-4305P4MEDIUMCVSS 6.5v122018-09-17
CVE-2018-4305 [MEDIUM] CVE-2018-4305: iOS 12
Apple Security Update: About the security content of iOS 12
Product: iOS
Version: 12
CVE: CVE-2018-4305
Component: IOUserEthernet
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2019-8764P4MEDIUMCVSS 6.1v132019-09-19
CVE-2019-8764 [MEDIUM] CVE-2019-8764: iOS 13
Apple Security Update: About the security content of iOS 13
Product: iOS
Version: 13
CVE: CVE-2019-8764
Component: WebKit
Impact: Processing maliciously crafted web content may lead to universal cross site scripting
Description: A logic issue was addressed with improved state management.
apple
CVE-2017-7109P4MEDIUMCVSS 6.1v112017-09-19
CVE-2017-7109 [MEDIUM] CVE-2017-7109: iOS 11
Apple Security Update: About the security content of iOS 11
Product: iOS
Version: 11
CVE: CVE-2017-7109
Component: WebKit
Impact: Processing maliciously crafted web content may lead to a cross site scripting attack
Description: Application Cache policy may be unexpectedly applied.
apple
CVE-2017-7059P4MEDIUMCVSS 6.1v10.3.32017-07-19
CVE-2017-7059 [MEDIUM] CVE-2017-7059: iOS 10.3.3
Apple Security Update: About the security content of iOS 10.3.3
Product: iOS
Version: 10.3.3
CVE: CVE-2017-7059
Component: WebKit
Impact: Processing maliciously crafted web content with DOMParser may lead to cross site scripting
Description: A logic issue existed in the handling of DOMParser. This issue was addressed with improved state management.
apple
CVE-2016-4741P4MEDIUMCVSS 5.9v102016-09-13
CVE-2016-4741 [MEDIUM] CVE-2016-4741: iOS 10
Apple Security Update: About the security content of iOS 10
Product: iOS
Version: 10
CVE: CVE-2016-4741
Component: Assets
Impact: An attacker in a privileged network position may be able to block a device from receiving software updates
Description: An issue existed in iOS updates, which did not properly secure user communications. This issue was addressed by using HTTPS for software updates.
apple