cbcvebase.

Apple iOS vulnerabilities

1,765 known vulnerabilities affecting apple/ios.

Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7

Vulnerabilities

Page 85 of 89
CVE-2016-4665P4LOWCVSS 3.3v10.12016-10-24
CVE-2016-4665 [LOW] CVE-2016-4665: iOS 10.1 Apple Security Update: About the security content of iOS 10.1 Product: iOS Version: 10.1 CVE: CVE-2016-4665 Component: Sandbox Profiles Impact: An application may be able to retrieve metadata of audio recording directories Description: An access issue was addressed through additional sandbox restrictions on third party applications.
apple
CVE-2016-1790P4LOWCVSS 3.3v9.3.2
CVE-2016-1790 [LOW] CVE-2016-1790: iOS 9.3.2 Apple Security Update: About the security content of iOS 9.3.2 Product: iOS Version: 9.3.2 CVE: CVE-2016-1790 Component: CVE-ID
apple
CVE-2016-4620P4LOWCVSS 3.3v102016-09-13
CVE-2016-4620 [LOW] CVE-2016-4620: iOS 10 Apple Security Update: About the security content of iOS 10 Product: iOS Version: 10 CVE: CVE-2016-4620 Component: Sandbox Profiles Impact: A malicious application may be able to determine whom a user is texting Description: An access control issue existed in SMS draft directories. This issue was addressed by preventing apps from stat'ing the affected directories.
apple
CVE-2019-8502P4LOWCVSS 3.3≥ unspecified, < iOS 12.22019-12-18
CVE-2019-8502 [LOW] CWE-20 CVE-2019-8502: An API issue existed in the handling of dictation requests. This issue was addressed with improved v An API issue existed in the handling of dictation requests. This issue was addressed with improved validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to initiate a Dictation request without user authorization.
nvdapple
CVE-2022-32913P4LOWCVSS 3.3v162022-09-12
CVE-2022-32913 [LOW] CVE-2022-32913: iOS 16 Apple Security Update: About the security content of iOS 16 Product: iOS Version: 16 CVE: CVE-2022-32913 Component: Image Processing Impact: A sandboxed app may be able to determine which app is currently using the camera Description: The issue was addressed with additional restrictions on the observability of app states.
apple
CVE-2015-3756P4LOWCVSS 2.1v8.4.1
CVE-2015-3756 [LOW] CVE-2015-3756: iOS 8.4.1 Apple Security Update: About the security content of iOS 8.4.1 Product: iOS Version: 8.4.1 CVE: CVE-2015-3756 Component: CVE-ID
apple
CVE-2016-7657P4LOWCVSS 3.3v10.22016-12-12
CVE-2016-7657 [LOW] CVE-2016-7657: iOS 10.2 Apple Security Update: About the security content of iOS 10.2 Product: iOS Version: 10.2 CVE: CVE-2016-7657 Component: IOKit Impact: An application may be able to read kernel memory Description: A memory corruption issue was addressed through improved input validation.
apple
CVE-2020-9933P4LOWCVSS 3.3≥ unspecified, < iOS 13.6 and iPadOS 13.62020-10-16
CVE-2020-9933 [LOW] CVE-2020-9933: An authorization issue was addressed with improved state management. This issue is fixed in iOS 13.6 An authorization issue was addressed with improved state management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8. A malicious application may be able to read sensitive location information.
nvd
CVE-2019-8698P4LOWCVSS 3.3≥ unspecified, < iOS 12.42019-12-18
CVE-2019-8698 [LOW] CWE-20 CVE-2019-8698: A validation issue existed in the entitlement verification. This issue was addressed with improved v A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in iOS 12.4, tvOS 12.4. A malicious application may be able to restrict access to websites.
nvdapple
CVE-2019-8541P4LOWCVSS 3.3≥ unspecified, < iOS 12.22019-12-18
CVE-2019-8541 [LOW] CVE-2019-8541: A privacy issue existed in motion sensor calibration. This issue was addressed with improved motion A privacy issue existed in motion sensor calibration. This issue was addressed with improved motion sensor processing. This issue is fixed in iOS 12.2, watchOS 5.2. A malicious app may be able to track users between installs.
nvdapple
CVE-2017-2384P4LOWCVSS 3.3v10.32017-03-27
CVE-2017-2384 [LOW] CVE-2017-2384: iOS 10.3 Apple Security Update: About the security content of iOS 10.3 Product: iOS Version: 10.3 CVE: CVE-2017-2384 Component: CVE-2017-2384
apple
CVE-2019-8809P4LOWCVSS 3.3≥ unspecified, < 132020-10-27
CVE-2019-8809 [LOW] CVE-2019-8809: A validation issue was addressed with improved logic. This issue is fixed in macOS Catalina 10.15, i A validation issue was addressed with improved logic. This issue is fixed in macOS Catalina 10.15, iOS 13.1 and iPadOS 13.1, tvOS 13, watchOS 6, iOS 13. A local app may be able to read a persistent account identifier.
nvdapple
CVE-2017-2375P4LOWCVSS 3.3≥ unspecified, < 10.22021-12-23
CVE-2017-2375 [LOW] CVE-2017-2375: An issue existed in preventing the uploading of CallKit call history to iCloud. This issue was addre An issue existed in preventing the uploading of CallKit call history to iCloud. This issue was addressed through improved logic. This issue is fixed in iOS 10.2.1. Updates for CallKit call history are sent to iCloud.
nvdapple
CVE-2017-2383P4LOWCVSS 3.1v10.2.12017-01-23
CVE-2017-2383 [LOW] CVE-2017-2383: iOS 10.2.1 Apple Security Update: About the security content of iOS 10.2.1 Product: iOS Version: 10.2.1 CVE: CVE-2017-2383 Component: APNs Server Impact: An attacker in a privileged network position can track a user's activity Description: A client certificate was sent in plaintext. This issue was addressed through improved certificate handling.
apple
CVE-2016-4593P4LOWCVSS 2.4v9.3.32016-07-18
CVE-2016-4593 [LOW] CVE-2016-4593: iOS 9.3.3 Apple Security Update: About the security content of iOS 9.3.3 Product: iOS Version: 9.3.3 CVE: CVE-2016-4593 Component: Siri Contacts Impact: A person with physical access to a device may be able to see private contact information Description: A privacy issue existed in the handling of Contact cards. This was addressed through improved state management.
apple
CVE-2015-1085P4LOWCVSS 1.9v8.3
CVE-2015-1085 [LOW] CVE-2015-1085: iOS 8.3 Apple Security Update: About the security content of iOS 8.3 Product: iOS Version: 8.3 CVE: CVE-2015-1085 Component: CVE-ID
apple
CVE-2021-30804P4LOWCVSS 3.3≥ unspecified, < 14.72021-09-08
CVE-2021-30804 [LOW] CVE-2021-30804: A permissions issue was addressed with improved validation. This issue is fixed in iOS 14.7. A malic A permissions issue was addressed with improved validation. This issue is fixed in iOS 14.7. A malicious application may be able to access Find My data.
nvd
CVE-2019-8566P4LOWCVSS 3.3≥ unspecified, < iOS 12.22019-12-18
CVE-2019-8566 [LOW] CWE-20 CVE-2019-8566: An API issue existed in the handling of microphone data. This issue was addressed with improved vali An API issue existed in the handling of microphone data. This issue was addressed with improved validation. This issue is fixed in iOS 12.2. A malicious application may be able to access the microphone without indication to the user.
nvdapple
CVE-2017-7148P4LOWCVSS 3.3v112017-09-19
CVE-2017-7148 [LOW] CVE-2017-7148: iOS 11 Apple Security Update: About the security content of iOS 11 Product: iOS Version: 11 CVE: CVE-2017-7148 Component: Location Framework Impact: An application may be able to read sensitive location information Description: A permissions issue existed in the handling of the location variable. This was addressed with additional ownership checks.
apple
CVE-2020-9773P4LOWCVSS 3.3≥ unspecified, < iOS 14.0 and iPadOS 14.02020-04-01
CVE-2020-9773 [LOW] CVE-2020-9773: The issue was addressed with improved handling of icon caches. This issue is fixed in iOS 14.0 and i The issue was addressed with improved handling of icon caches. This issue is fixed in iOS 14.0 and iPadOS 14.0. A malicious application may be able to identify what other applications a user has installed.
nvd
Apple iOS vulnerabilities | cvebase