cbcvebase.

Apple iOS vulnerabilities

1,765 known vulnerabilities affecting apple/ios.

Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7

Vulnerabilities

Page 71 of 89
CVE-2022-32891P4MEDIUMCVSS 6.1≥ unspecified, < 162023-02-27
CVE-2022-32891 [MEDIUM] CWE-1021 CVE-2022-32891: The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchO The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchOS 9, iOS 16. Visiting a website that frames malicious content may lead to UI spoofing.
nvdapple
CVE-2017-2411P4MEDIUMCVSS 5.9v11.22017-12-02
CVE-2017-2411 [MEDIUM] CVE-2017-2411: iOS 11.2 Apple Security Update: About the security content of iOS 11.2 Product: iOS Version: 11.2 CVE: CVE-2017-2411 Component: Calculator Impact: An attacker with a privileged network position may be able to alter currency conversion rates Description: Exchange rates were retrieved from HTTP rather than HTTPS. This was addressed by enabling HTTPS for exchange rates.
apple
CVE-2019-8540P4MEDIUMCVSS 5.5≥ unspecified, < iOS 12.22019-12-18
CVE-2019-8540 [MEDIUM] CWE-665 CVE-2019-8540: A memory initialization issue was addressed with improved memory handling. This issue is fixed in iO A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to determine kernel memory layout.
nvdapple
CVE-2015-3752P4MEDIUMCVSS 5.0v8.4.1
CVE-2015-3752 [MEDIUM] CVE-2015-3752: iOS 8.4.1 Apple Security Update: About the security content of iOS 8.4.1 Product: iOS Version: 8.4.1 CVE: CVE-2015-3752 Component: CVE-ID
apple
CVE-2017-13804P4MEDIUMCVSS 5.5v11.12017-10-31
CVE-2017-13804 [MEDIUM] CVE-2017-13804: iOS 11.1 Apple Security Update: About the security content of iOS 11.1 Product: iOS Version: 11.1 CVE: CVE-2017-13804 Component: StreamingZip Impact: A malicious zip file may be able modify restricted areas of the file system Description: A path handling issue was addressed with improved validation.
apple
CVE-2016-4590P4MEDIUMCVSS 5.4v9.3.32016-07-18
CVE-2016-4590 [MEDIUM] CVE-2016-4590: iOS 9.3.3 Apple Security Update: About the security content of iOS 9.3.3 Product: iOS Version: 9.3.3 CVE: CVE-2016-4590 Component: WebKit Impact: Visiting a malicious website may lead to user interface spoofing Description: An origin inheritance issue existed in parsing of about: URLs. This was addressed through improved validation of security origins.
apple
CVE-2021-30773P4MEDIUMCVSS 5.5≥ unspecified, < 14.72021-09-08
CVE-2021-30773 [MEDIUM] CVE-2021-30773: An issue in code signature validation was addressed with improved checks. This issue is fixed in iOS An issue in code signature validation was addressed with improved checks. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. A malicious application may be able to bypass code signing checks.
nvd
CVE-2017-2400P4MEDIUMCVSS 5.3v10.32017-03-27
CVE-2017-2400 [MEDIUM] CVE-2017-2400: iOS 10.3 Apple Security Update: About the security content of iOS 10.3 Product: iOS Version: 10.3 CVE: CVE-2017-2400 Component: SafariViewController Impact: Cache state is not properly kept in sync between Safari and SafariViewController when a user clears Safari cache Description: An issue existed in clearing Safari cache information from SafariViewController. This issue was addressed by improving cache state handling.
apple
CVE-2014-4496P4MEDIUMCVSS 5.0v8.1.3
CVE-2014-4496 [MEDIUM] CVE-2014-4496: iOS 8.1.3 Apple Security Update: About the security content of iOS 8.1.3 Product: iOS Version: 8.1.3 CVE: CVE-2014-4496 Component: CVE-ID Impact: A malicious, sandboxed app can compromise the networkd daemon Description: Multiple type confusion issues existed in networkd's handling of interprocess communication. By sending a maliciously formatted message to networkd, it may have been possible to execute arbitrary code as the networkd process. The issue is ad
apple
CVE-2015-1089P4MEDIUMCVSS 5.0v8.3
CVE-2015-1089 [MEDIUM] CVE-2015-1089: iOS 8.3 Apple Security Update: About the security content of iOS 8.3 Product: iOS Version: 8.3 CVE: CVE-2015-1089 Component: CVE-ID
apple
CVE-2022-32883P4MEDIUMCVSS 5.5≥ unspecified, < 162022-09-20
CVE-2022-32883 [MEDIUM] CWE-284 CVE-2022-32883: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.6, A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to read sensitive location information.
nvdapple
CVE-2019-8796P4MEDIUMCVSS 5.3v12.4.32019-10-28
CVE-2019-8796 [MEDIUM] CVE-2019-8796: iOS 12.4.3 Apple Security Update: About the security content of iOS 12.4.3 Product: iOS Version: 12.4.3 CVE: CVE-2019-8796 Component: Accounts Impact: AirDrop transfers may be unexpectedly accepted while in Everyone mode Description: A logic issue was addressed with improved validation.
apple
CVE-2017-7078P4MEDIUMCVSS 5.3v112017-09-19
CVE-2017-7078 [MEDIUM] CVE-2017-7078: iOS 11 Apple Security Update: About the security content of iOS 11 Product: iOS Version: 11 CVE: CVE-2017-7078 Component: Mail Drafts Impact: An attacker with a privileged network position may be able to intercept mail contents Description: An encryption issue existed in the handling of mail drafts. This issue was addressed with improved handling of mail drafts meant to be sent encrypted.
apple
CVE-2021-30770P4MEDIUMCVSS 5.5≥ unspecified, < 14.72021-09-08
CVE-2021-30770 [MEDIUM] CWE-287 CVE-2021-30770: A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, tvOS 14.7, wa A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. An attacker that has already achieved kernel code execution may be able to bypass kernel memory mitigations.
nvd
CVE-2017-2390P4MEDIUMCVSS 5.5v10.32017-03-27
CVE-2017-2390 [MEDIUM] CVE-2017-2390: iOS 10.3 Apple Security Update: About the security content of iOS 10.3 Product: iOS Version: 10.3 CVE: CVE-2017-2390 Component: Keychain Impact: An attacker who is able to intercept TLS connections may be able to read secrets protected by iCloud Keychain. Description: In certain circumstances, iCloud Keychain failed to validate the authenticity of OTR packets. This issue was addressed through improved validation.
apple
CVE-2017-7146P4MEDIUMCVSS 5.3v112017-09-19
CVE-2017-7146 [MEDIUM] CVE-2017-7146: iOS 11 Apple Security Update: About the security content of iOS 11 Product: iOS Version: 11 CVE: CVE-2017-7146 Component: Security Impact: A malicious app may be able to track users between installs Description: A permission checking issue existed in the handling of an app's Keychain data. This issue was addressed with improved permission checking.
apple
CVE-2016-7619P4MEDIUMCVSS 5.5v10.22016-12-12
CVE-2016-7619 [MEDIUM] CVE-2016-7619: iOS 10.2 Apple Security Update: About the security content of iOS 10.2 Product: iOS Version: 10.2 CVE: CVE-2016-7619 Component: Kernel Impact: A malicious application may gain access to a device's MAC address Description: An access issue was addressed through additional sandbox restrictions on third party applications.
apple
CVE-2022-32864P4MEDIUMCVSS 5.5≥ unspecified, < 162022-09-20
CVE-2022-32864 [MEDIUM] CVE-2022-32864: The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6, i The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to disclose kernel memory.
nvdapple
CVE-2017-7145P4MEDIUMCVSS 5.3v112017-09-19
CVE-2017-7145 [MEDIUM] CVE-2017-7145: iOS 11 Apple Security Update: About the security content of iOS 11 Product: iOS Version: 11 CVE: CVE-2017-7145 Component: Time Impact: "Setting Time Zone" may incorrectly indicate that it is using location Description: A permissions issue existed in the process that handles time zone information. The issue was resolved by modifying permissions.
apple
CVE-2015-1062P4MEDIUMCVSS 5.0v8.2
CVE-2015-1062 [MEDIUM] CVE-2015-1062: iOS 8.2 Apple Security Update: About the security content of iOS 8.2 Product: iOS Version: 8.2 CVE: CVE-2015-1062 Component: CVE-ID
apple
Apple iOS vulnerabilities | cvebase