cbcvebase.

Apple iOS vulnerabilities

1,765 known vulnerabilities affecting apple/ios.

Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7

Vulnerabilities

Page 72 of 89
CVE-2022-32833P4MEDIUMCVSS 5.3≥ unspecified, < 162022-12-15
CVE-2022-32833 [MEDIUM] CWE-922 CVE-2022-32833: An issue existed with the file paths used to store website data. The issue was resolved by improving An issue existed with the file paths used to store website data. The issue was resolved by improving how website data is stored. This issue is fixed in iOS 16. An unauthorized user may be able to access browsing history.
nvdapple
CVE-2022-32859P4MEDIUMCVSS 5.3≥ unspecified, < 162022-11-01
CVE-2022-32859 [MEDIUM] CWE-642 CVE-2022-32859: A logic issue was addressed with improved state management. This issue is fixed in iOS 16. Deleted c A logic issue was addressed with improved state management. This issue is fixed in iOS 16. Deleted contacts may still appear in spotlight search results.
nvdapple
CVE-2017-13831P4HIGHCVSS 7.1v112017-09-19
CVE-2017-13831 [HIGH] CVE-2017-13831: iOS 11 Apple Security Update: About the security content of iOS 11 Product: iOS Version: 11 CVE: CVE-2017-13831 Component: ImageIO Impact: Processing a maliciously crafted image may lead to a denial of service Description: A memory corruption issue was addressed with improved input validation.
apple
CVE-2016-1784P4MEDIUMCVSS 6.5v9.3
CVE-2016-1784 [MEDIUM] CVE-2016-1784: iOS 9.3 Apple Security Update: About the security content of iOS 9.3 Product: iOS Version: 9.3 CVE: CVE-2016-1784 Component: CVE-ID
apple
CVE-2016-7601P4MEDIUMCVSS 6.8v10.22016-12-12
CVE-2016-7601 [MEDIUM] CVE-2016-7601: iOS 10.2 Apple Security Update: About the security content of iOS 10.2 Product: iOS Version: 10.2 CVE: CVE-2016-7601 Component: Local Authentication Impact: The device may not lock the screen after the idle timeout Description: A logic issue existed in the handling of the idle timer when the Touch ID prompt is shown. This issue was addressed through improved handling of the idle timer.
apple
CVE-2017-2495P4MEDIUMCVSS 6.5v10.3.22017-05-15
CVE-2017-2495 [MEDIUM] CVE-2017-2495: iOS 10.3.2 Apple Security Update: About the security content of iOS 10.3.2 Product: iOS Version: 10.3.2 CVE: CVE-2017-2495 Component: Safari Impact: Visiting a maliciously crafted webpage may lead to an application denial of service Description: An issue in Safari's history menu was addressed through improved memory handling.
apple
CVE-2015-7995P4MEDIUMCVSS 5.0v9.2.1
CVE-2015-7995 [MEDIUM] CVE-2015-7995: iOS 9.2.1 Apple Security Update: About the security content of iOS 9.2.1 Product: iOS Version: 9.2.1 CVE: CVE-2015-7995 Component: CVE-ID Impact: A local user may be able to execute arbitrary code with root privileges Description: A memory corruption issue was addressed through improved memory handling.
apple
CVE-2016-7636P4MEDIUMCVSS 5.9v10.22016-12-12
CVE-2016-7636 [MEDIUM] CVE-2016-7636: iOS 10.2 Apple Security Update: About the security content of iOS 10.2 Product: iOS Version: 10.2 CVE: CVE-2016-7636 Component: Security Impact: An attacker in a privileged network position may be able to cause a denial of service Description: A validation issue existed in the handling of OCSP responder URLs. This issue was addressed by verifying OCSP revocation status after CA validation and limiting the number of OCSP requests per certificate.
apple
CVE-2019-6228P4MEDIUMCVSS 6.1≥ unspecified, < iOS 12.1.32019-03-05
CVE-2019-6228 [MEDIUM] CWE-79 CVE-2019-6228: A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validatio A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue is fixed in iOS 12.1.3, Safari 12.0.3. Processing maliciously crafted web content may lead to a cross site scripting attack.
nvdapple
CVE-2016-7762P4MEDIUMCVSS 6.1v10.22016-12-12
CVE-2016-7762 [MEDIUM] CVE-2016-7762: iOS 10.2 Apple Security Update: About the security content of iOS 10.2 Product: iOS Version: 10.2 CVE: CVE-2016-7762 Component: WebKit Impact: Processing maliciously crafted web content may lead to cross site scripting Description: An issue existed in displaying documents in Safari. This issue was addressed through improved input validation.
apple
CVE-2019-8582P4MEDIUMCVSS 5.5≥ unspecified, < 12.32020-10-27
CVE-2019-8582 [MEDIUM] CWE-125 CVE-2019-8582: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iCloud for An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iCloud for Windows 7.12, tvOS 12.3, iTunes 12.9.5 for Windows, macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, iOS 12.3. Processing a maliciously crafted font may result in the disclosure of process memory.
nvdapple
CVE-2019-8789P4MEDIUMCVSS 5.5≥ unspecified, < iOS 13.2 and iPadOS 13.22019-12-18
CVE-2019-8789 [MEDIUM] CWE-59 CVE-2019-8789: A validation issue existed in the handling of symlinks. This issue was addressed with improved valid A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1. Parsing a maliciously crafted iBooks file may lead to disclosure of user information.
nvd
CVE-2020-9968P4MEDIUMCVSS 5.5≥ unspecified, < iOS 14.0 and iPadOS 14.02020-10-16
CVE-2020-9968 [MEDIUM] CVE-2020-9968: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 14.0 and iPadOS 1 A logic issue was addressed with improved restrictions. This issue is fixed in iOS 14.0 and iPadOS 14.0, macOS Catalina 10.15.7, tvOS 14.0, watchOS 7.0. A malicious application may be able to access restricted files.
nvd
CVE-2020-9902P4MEDIUMCVSS 5.5≥ unspecified, < iOS 13.6 and iPadOS 13.62020-10-22
CVE-2020-9902 [MEDIUM] CWE-125 CVE-2020-9902: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.6 a An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A malicious application may be able to determine kernel memory layout.
nvd
CVE-2016-4604P4MEDIUMCVSS 5.4v9.3.32016-07-18
CVE-2016-4604 [MEDIUM] CVE-2016-4604: iOS 9.3.3 Apple Security Update: About the security content of iOS 9.3.3 Product: iOS Version: 9.3.3 CVE: CVE-2016-4604 Component: Safari Impact: Visiting a malicious website may lead to user interface spoofing Description: Redirect responses to invalid ports may have allowed a malicious website to display an arbitrary domain while displaying arbitrary content. This issue was addressed through improved URL display logic.
apple
CVE-2016-1786P4MEDIUMCVSS 5.4v9.3
CVE-2016-1786 [MEDIUM] CVE-2016-1786: iOS 9.3 Apple Security Update: About the security content of iOS 9.3 Product: iOS Version: 9.3 CVE: CVE-2016-1786 Component: CVE-ID
apple
CVE-2019-8744P4MEDIUMCVSS 5.5≥ unspecified, < 132020-10-27
CVE-2019-8744 [MEDIUM] CWE-787 CVE-2019-8744: A memory corruption issue existed in the handling of IPv6 packets. This issue was addressed with imp A memory corruption issue existed in the handling of IPv6 packets. This issue was addressed with improved memory management. This issue is fixed in macOS Catalina 10.15, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, watchOS 6, iOS 13. A malicious application may be able to determine kernel memory layout.
nvdapple
CVE-2019-6207P4MEDIUMCVSS 5.5≥ unspecified, < iOS 12.22019-12-18
CVE-2019-6207 [MEDIUM] CWE-125 CVE-2019-6207: An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to determine kernel memory layout.
nvdapple
CVE-2015-1084P4MEDIUMCVSS 5.0v8.3
CVE-2015-1084 [MEDIUM] CVE-2015-1084: iOS 8.3 Apple Security Update: About the security content of iOS 8.3 Product: iOS Version: 8.3 CVE: CVE-2015-1084 Component: CVE-ID
apple
CVE-2018-4356P4MEDIUMCVSS 5.3v122018-09-17
CVE-2018-4356 [MEDIUM] CVE-2018-4356: iOS 12 Apple Security Update: About the security content of iOS 12 Product: iOS Version: 12 CVE: CVE-2018-4356 Component: CoreMedia Impact: An app may be able to learn information about the current camera view before being granted camera access Description: A permissions issue existed. This issue was addressed with improved permission validation.
apple
Apple iOS vulnerabilities | cvebase