cbcvebase.

Apple iOS vulnerabilities

1,765 known vulnerabilities affecting apple/ios.

Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7

Vulnerabilities

Page 84 of 89
CVE-2019-8906P4MEDIUMCVSS 4.4v12.22019-03-25
CVE-2019-8906 [MEDIUM] CVE-2019-8906: iOS 12.2 Apple Security Update: About the security content of iOS 12.2 Product: iOS Version: 12.2 CVE: CVE-2019-8906 Component: Feedback Assistant Impact: A malicious application may be able to overwrite arbitrary files Description: This issue was addressed with improved checks.
apple
CVE-2016-7759P4MEDIUMCVSS 4.3v102016-09-13
CVE-2016-7759 [MEDIUM] CVE-2016-7759: iOS 10 Apple Security Update: About the security content of iOS 10 Product: iOS Version: 10 CVE: CVE-2016-7759 Component: Springboard Impact: Sensitive data may be exposed in application snapshots presented in the Task Switcher Description: An issue existed in Springboard which displayed cached snapshots containing sensitive data in the Task Switcher. This issue was addressed by displaying updated snapshots.
apple
CVE-2016-7577P4LOWCVSS 3.7v10.12016-10-24
CVE-2016-7577 [LOW] CVE-2016-7577: iOS 10.1 Apple Security Update: About the security content of iOS 10.1 Product: iOS Version: 10.1 CVE: CVE-2016-7577 Component: FaceTime Impact: An attacker in a privileged network position may be able to cause a relayed call to continue transmitting audio while appearing as if the call terminated Description: User interface inconsistencies existed in the handling of relayed calls. These issues were addressed through improved protocol logic.
apple
CVE-2017-13852P4LOWCVSS 3.3v11.12017-10-31
CVE-2017-13852 [LOW] CVE-2017-13852: iOS 11.1 Apple Security Update: About the security content of iOS 11.1 Product: iOS Version: 11.1 CVE: CVE-2017-13852 Component: Kernel Impact: A malicious application may be able to learn information about the presence and operation of other applications on the device. Description: An application was able to access process information maintained by the operating system unrestricted. This issue was addressed through rate limiting.
apple
CVE-2015-7046P4LOWCVSS 2.6v9.2
CVE-2015-7046 [LOW] CVE-2015-7046: iOS 9.2 Apple Security Update: About the security content of iOS 9.2 Product: iOS Version: 9.2 CVE: CVE-2015-7046 Component: CVE-ID
apple
CVE-2018-4172P4MEDIUMCVSS 4.6v11.32018-03-29
CVE-2018-4172 [MEDIUM] CVE-2018-4172: iOS 11.3 Apple Security Update: About the security content of iOS 11.3 Product: iOS Version: 11.3 CVE: CVE-2018-4172 Component: Find My iPhone Impact: A person with physical access to the device may be able to disable Find My iPhone without entering an iCloud password Description: A state management issue existed when restoring from a back up. This issue was addressed through improved state checking during restore.
apple
CVE-2015-3759P4MEDIUMCVSS 4.6v8.4.1
CVE-2015-3759 [MEDIUM] CVE-2015-3759: iOS 8.4.1 Apple Security Update: About the security content of iOS 8.4.1 Product: iOS Version: 8.4.1 CVE: CVE-2015-3759 Component: CVE-ID
apple
CVE-2015-1087P4LOWCVSS 2.1v8.3
CVE-2015-1087 [LOW] CVE-2015-1087: iOS 8.3 Apple Security Update: About the security content of iOS 8.3 Product: iOS Version: 8.3 CVE: CVE-2015-1087 Component: CVE-ID
apple
CVE-2016-4583P4LOWCVSS 3.1v9.3.32016-07-18
CVE-2016-4583 [LOW] CVE-2016-4583: iOS 9.3.3 Apple Security Update: About the security content of iOS 9.3.3 Product: iOS Version: 9.3.3 CVE: CVE-2016-4583 Component: WebKit Impact: Visiting a malicious website may disclose image data from another website Description: A timing issue existed in the processing of SVG. This issue was addressed through improved validation.
apple
CVE-2017-13877P4LOWCVSS 3.3v112017-09-19
CVE-2017-13877 [LOW] CVE-2017-13877: iOS 11 Apple Security Update: About the security content of iOS 11 Product: iOS Version: 11 CVE: CVE-2017-13877 Component: Sandbox Profiles Impact: A malicious application may be able to learn information about the presence of other applications on the device. Description: An application was able to determine the existence of files outside of its sandbox. This issue was addressed through additional sandbox checks.
apple
CVE-2020-9792P4MEDIUMCVSS 4.6≥ unspecified, < iOS 13.5 and iPadOS 13.52020-06-09
CVE-2020-9792 [MEDIUM] CWE-20 CVE-2020-9792: A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.5 a A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5. A USB device may be able to cause a denial of service.
nvd
CVE-2015-1099P4MEDIUMCVSS 4.0v8.3
CVE-2015-1099 [MEDIUM] CVE-2015-1099: iOS 8.3 Apple Security Update: About the security content of iOS 8.3 Product: iOS Version: 8.3 CVE: CVE-2015-1099 Component: CVE-ID
apple
CVE-2016-1763P4LOWCVSS 3.5v9.3
CVE-2016-1763 [LOW] CVE-2016-1763: iOS 9.3 Apple Security Update: About the security content of iOS 9.3 Product: iOS Version: 9.3 CVE: CVE-2016-1763 Component: CVE-ID
apple
CVE-2016-4747P4LOWCVSS 3.7v102016-09-13
CVE-2016-4747 [LOW] CVE-2016-4747: iOS 10 Apple Security Update: About the security content of iOS 10 Product: iOS Version: 10 CVE: CVE-2016-4747 Component: Mail Impact: An attacker with a privileged network position may be able to intercept mail credentials Description: An issue existed when handling untrusted certificates. This was addressed by terminating untrusted connections.
apple
CVE-2015-3778P4LOWCVSS 3.3v8.4.1
CVE-2015-3778 [LOW] CVE-2015-3778: iOS 8.4.1 Apple Security Update: About the security content of iOS 8.4.1 Product: iOS Version: 8.4.1 CVE: CVE-2015-3778 Component: CVE-ID
apple
CVE-2016-1748P4LOWCVSS 3.3v9.3
CVE-2016-1748 [LOW] CVE-2016-1748: iOS 9.3 Apple Security Update: About the security content of iOS 9.3 Product: iOS Version: 9.3 CVE: CVE-2016-1748 Component: CVE-ID
apple
CVE-2020-3894P4LOWCVSS 3.1≥ unspecified, < iOS 13.4 and iPadOS 13.42020-04-01
CVE-2020-3894 [LOW] CWE-362 CVE-2020-3894: A race condition was addressed with additional validation. This issue is fixed in iOS 13.4 and iPadO A race condition was addressed with additional validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. An application may be able to read restricted memory.
nvd
CVE-2016-4670P4LOWCVSS 3.3v10.12016-10-24
CVE-2016-4670 [LOW] CVE-2016-4670: iOS 10.1 Apple Security Update: About the security content of iOS 10.1 Product: iOS Version: 10.1 CVE: CVE-2016-4670 Component: Security Impact: A local attacker can observe the length of a login password when a user logs in Description: A logging issue existed in the handling of passwords. This issue was addressed by removing password length logging.
apple
CVE-2015-7094P4LOWCVSS 2.6v9.2
CVE-2015-7094 [LOW] CVE-2015-7094: iOS 9.2 Apple Security Update: About the security content of iOS 9.2 Product: iOS Version: 9.2 CVE: CVE-2015-7094 Component: CVE-ID
apple
CVE-2016-4664P4LOWCVSS 3.3v10.12016-10-24
CVE-2016-4664 [LOW] CVE-2016-4664: iOS 10.1 Apple Security Update: About the security content of iOS 10.1 Product: iOS Version: 10.1 CVE: CVE-2016-4664 Component: Sandbox Profiles Impact: An application may be able to retrieve metadata of photo directories Description: An access issue was addressed through additional sandbox restrictions on third party applications.
apple
Apple iOS vulnerabilities | cvebase