cbcvebase.

Apple iOS vulnerabilities

1,765 known vulnerabilities affecting apple/ios.

Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7

Vulnerabilities

Page 77 of 89
CVE-2018-4225P4MEDIUMCVSS 5.5v11.42018-05-29
CVE-2018-4225 [MEDIUM] CVE-2018-4225: iOS 11.4 Apple Security Update: About the security content of iOS 11.4 Product: iOS Version: 11.4 CVE: CVE-2018-4225 Component: Security Impact: A local user may be able to modify the state of the Keychain Description: An authorization issue was addressed with improved state management.
apple
CVE-2018-4226P4MEDIUMCVSS 5.5v11.42018-05-29
CVE-2018-4226 [MEDIUM] CVE-2018-4226: iOS 11.4 Apple Security Update: About the security content of iOS 11.4 Product: iOS Version: 11.4 CVE: CVE-2018-4226 Component: Security Impact: A local user may be able to view sensitive user information Description: An authorization issue was addressed with improved state management.
apple
CVE-2018-4380P4MEDIUMCVSS 5.5v12.0.12018-10-08
CVE-2018-4380 [MEDIUM] CVE-2018-4380: iOS 12.0.1 Apple Security Update: About the security content of iOS 12.0.1 Product: iOS Version: 12.0.1 CVE: CVE-2018-4380 Component: VoiceOver Impact: A local attacker may be able to view photos and contacts from the lock screen Description: A lock screen issue allowed access to photos and contacts on a locked device. This issue was addressed by restricting options offered on a locked device.
apple
CVE-2019-8546P4MEDIUMCVSS 5.5≥ unspecified, < iOS 12.22019-12-18
CVE-2019-8546 [MEDIUM] CVE-2019-8546: An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 12.2, An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, watchOS 5.2. A local user may be able to view sensitive user information.
nvdapple
CVE-2020-9772P4MEDIUMCVSS 5.5≥ unspecified, < iOS 13.4 and iPadOS 13.42020-10-22
CVE-2020-9772 [MEDIUM] CVE-2020-9772: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 1 A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. A sandboxed process may be able to circumvent sandbox restrictions.
nvd
CVE-2019-8704P4MEDIUMCVSS 5.5v132019-09-19
CVE-2019-8704 [MEDIUM] CVE-2019-8704: iOS 13 Apple Security Update: About the security content of iOS 13 Product: iOS Version: 13 CVE: CVE-2019-8704 Component: Keyboards Impact: A local user may be able to leak sensitive user information Description: An authentication issue was addressed with improved state management.
apple
CVE-2017-13817P4MEDIUMCVSS 5.5v112017-09-19
CVE-2017-13817 [MEDIUM] CVE-2017-13817: iOS 11 Apple Security Update: About the security content of iOS 11 Product: iOS Version: 11 CVE: CVE-2017-13817 Component: Kernel Impact: A local user may be able to read kernel memory Description: An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed through improved input validation.
apple
CVE-2020-3874P4MEDIUMCVSS 5.3≥ unspecified, < iOS 13.3.1 and iPadOS 13.3.12020-02-27
CVE-2020-3874 [MEDIUM] CWE-212 CVE-2020-3874: An issued existed in the naming of screenshots. The issue was corrected with improved naming. This i An issued existed in the naming of screenshots. The issue was corrected with improved naming. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1. Screenshots of the Messages app may reveal additional message content.
nvd
CVE-2019-8793P4MEDIUMCVSS 5.5≥ unspecified, < iOS 13.2 and iPadOS 13.22019-12-18
CVE-2019-8793 [MEDIUM] CVE-2019-8793: A consistency issue existed in deciding when to show the screen recording indicator. The issue was r A consistency issue existed in deciding when to show the screen recording indicator. The issue was resolved with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2. A local user may be able to record the screen without a visible screen recording indicator.
nvd
CVE-2017-7113P4MEDIUMCVSS 5.5v11.12017-10-31
CVE-2017-7113 [MEDIUM] CVE-2017-7113: iOS 11.1 Apple Security Update: About the security content of iOS 11.1 Product: iOS Version: 11.1 CVE: CVE-2017-7113 Component: UIKit Impact: Characters in a secure text field might be revealed Description: The characters in a secure text field were revealed during focus change events. This issue was addressed through improved state management.
apple
CVE-2022-32858P4MEDIUMCVSS 5.5v162022-09-12
CVE-2022-32858 [MEDIUM] CVE-2022-32858: iOS 16 Apple Security Update: About the security content of iOS 16 Product: iOS Version: 16 CVE: CVE-2022-32858 Impact: An app may be able to leak sensitive kernel state Description: The issue was addressed with improved memory handling.
apple
CVE-2021-30871P4MEDIUMCVSS 5.5≥ unspecified, < 14.72021-08-24
CVE-2021-30871 [MEDIUM] CVE-2021-30871: This issue was addressed with a new entitlement. This issue is fixed in iOS 14.7, watchOS 7.6, macOS This issue was addressed with a new entitlement. This issue is fixed in iOS 14.7, watchOS 7.6, macOS Big Sur 11.5. A local attacker may be able to access analytics data.
nvd
CVE-2022-32881P4MEDIUMCVSS 5.5v162022-09-12
CVE-2022-32881 [MEDIUM] CVE-2022-32881: iOS 16 Apple Security Update: About the security content of iOS 16 Product: iOS Version: 16 CVE: CVE-2022-32881 Component: Sandbox Impact: An app may be able to modify protected parts of the file system Description: A logic issue was addressed with improved restrictions.
apple
CVE-2019-8702P4MEDIUMCVSS 5.5≥ unspecified, < 12.42021-12-23
CVE-2019-8702 [MEDIUM] CWE-668 CVE-2019-8702: This issue was addressed with a new entitlement. This issue is fixed in macOS Mojave 10.14.6, Securi This issue was addressed with a new entitlement. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra, iOS 12.4, tvOS 12.4. A local user may be able to read a persistent account identifier.
nvdapple
CVE-2015-1111P4MEDIUMCVSS 5.0v8.3
CVE-2015-1111 [MEDIUM] CVE-2015-1111: iOS 8.3 Apple Security Update: About the security content of iOS 8.3 Product: iOS Version: 8.3 CVE: CVE-2015-1111 Component: CVE-ID
apple
CVE-2022-32916P4MEDIUMCVSS 5.5≥ unspecified, < 162022-12-15
CVE-2022-32916 [MEDIUM] CWE-125 CVE-2022-32916: An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in iOS 16. An app may be able to disclose kernel memory.
nvdapple
CVE-2015-1112P4MEDIUMCVSS 5.0v8.3
CVE-2015-1112 [MEDIUM] CVE-2015-1112: iOS 8.3 Apple Security Update: About the security content of iOS 8.3 Product: iOS Version: 8.3 CVE: CVE-2015-1112 Component: CVE-ID
apple
CVE-2022-32909P4MEDIUMCVSS 5.5≥ unspecified, < 162022-11-01
CVE-2022-32909 [MEDIUM] CWE-524 CVE-2022-32909: The issue was addressed with improved handling of caches. This issue is fixed in iOS 16. An app may The issue was addressed with improved handling of caches. This issue is fixed in iOS 16. An app may be able to access user-sensitive data.
nvdapple
CVE-2017-7083P4MEDIUMCVSS 4.9v112017-09-19
CVE-2017-7083 [MEDIUM] CVE-2017-7083: iOS 11 Apple Security Update: About the security content of iOS 11 Product: iOS Version: 11 CVE: CVE-2017-7083 Component: CFNetwork Proxies Impact: An attacker in a privileged network position may be able to cause a denial of service Description: Multiple denial of service issues were addressed through improved memory handling.
apple
CVE-2015-3807P4MEDIUMCVSS 4.3v8.4.1
CVE-2015-3807 [MEDIUM] CVE-2015-3807: iOS 8.4.1 Apple Security Update: About the security content of iOS 8.4.1 Product: iOS Version: 8.4.1 CVE: CVE-2015-3807 Component: CVE-ID Impact: Multiple vulnerabilities existed in libxml2 versions prior to 2.9.2, the most serious of which may allow a remote attacker to cause a denial of service Description: Multiple vulnerabilities existed in libxml2 versions prior to 2.9.2. These were addressed by updating libxml2 to version 2.9.2.
apple
Apple iOS vulnerabilities | cvebase