Apple iOS vulnerabilities
1,765 known vulnerabilities affecting apple/ios.
Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7
Vulnerabilities
Page 9 of 89
CVE-2017-7376P2CRITICALCVSS 9.8v112017-09-19
CVE-2017-7376 [CRITICAL] CVE-2017-7376: iOS 11
Apple Security Update: About the security content of iOS 11
Product: iOS
Version: 11
CVE: CVE-2017-7376
Component: CVE-2017-9233
Impact: Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution
Description: A buffer overflow issue was addressed with improved memory handling.
apple
CVE-2019-6214P3HIGHCVSS 8.6PoC≥ unspecified, < iOS 12.1.32019-03-05
CVE-2019-6214 [HIGH] CWE-843 CVE-2019-6214: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to break out of its sandbox.
nvdapple
CVE-2017-2483P3HIGHCVSS 7.8PoCv10.32017-03-27
CVE-2017-2483 [HIGH] CVE-2017-2483: iOS 10.3
Apple Security Update: About the security content of iOS 10.3
Product: iOS
Version: 10.3
CVE: CVE-2017-2483
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A buffer overflow issue was addressed through improved memory handling.
apple
CVE-2019-6213P3HIGHCVSS 7.8PoC≥ unspecified, < iOS 12.1.32019-03-05
CVE-2019-6213 [HIGH] CWE-119 CVE-2019-6213: A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, ma
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. An application may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2017-2482P3HIGHCVSS 7.8PoCv10.32017-03-27
CVE-2017-2482 [HIGH] CVE-2017-2482: iOS 10.3
Apple Security Update: About the security content of iOS 10.3
Product: iOS
Version: 10.3
CVE: CVE-2017-2482
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A buffer overflow issue was addressed through improved memory handling.
apple
CVE-2017-13847P3HIGHCVSS 7.8PoCv11.22017-12-02
CVE-2017-13847 [HIGH] CVE-2017-13847: iOS 11.2
Apple Security Update: About the security content of iOS 11.2
Product: iOS
Version: 11.2
CVE: CVE-2017-13847
Component: IOKit
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: Multiple memory corruption issues were addressed through improved state management.
apple
CVE-2016-1819P3HIGHCVSS 7.8PoCv9.3.2
CVE-2016-1819 [HIGH] CVE-2016-1819: iOS 9.3.2
Apple Security Update: About the security content of iOS 9.3.2
Product: iOS
Version: 9.3.2
CVE: CVE-2016-1819
Component: CVE-ID
apple
CVE-2017-2473P3HIGHCVSS 7.8PoCv10.32017-03-27
CVE-2017-2473 [HIGH] CVE-2017-2473: iOS 10.3
Apple Security Update: About the security content of iOS 10.3
Product: iOS
Version: 10.3
CVE: CVE-2017-2473
Component: Kernel
Impact: A malicious application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed through improved input validation.
apple
CVE-2016-1757P3HIGHCVSS 7.0PoCv9.3
CVE-2016-1757 [HIGH] CVE-2016-1757: iOS 9.3
Apple Security Update: About the security content of iOS 9.3
Product: iOS
Version: 9.3
CVE: CVE-2016-1757
Component: CVE-ID
apple
CVE-2017-6999P3HIGHCVSS 7.8PoCv10.3.22017-05-15
CVE-2017-6999 [HIGH] CVE-2017-6999: iOS 10.3.2
Apple Security Update: About the security content of iOS 10.3.2
Product: iOS
Version: 10.3.2
CVE: CVE-2017-6999
Component: AVEVideoEncoder
Impact: An application may be able to gain kernel privileges
Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2017-6997P3HIGHCVSS 7.8PoCv10.3.22017-05-15
CVE-2017-6997 [HIGH] CVE-2017-6997: iOS 10.3.2
Apple Security Update: About the security content of iOS 10.3.2
Product: iOS
Version: 10.3.2
CVE: CVE-2017-6997
Component: AVEVideoEncoder
Impact: An application may be able to gain kernel privileges
Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2017-2472P3HIGHCVSS 7.8PoCv10.32017-03-27
CVE-2017-2472 [HIGH] CVE-2017-2472: iOS 10.3
Apple Security Update: About the security content of iOS 10.3
Product: iOS
Version: 10.3
CVE: CVE-2017-2472
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A use after free issue was addressed through improved memory management.
apple
CVE-2017-2490P3HIGHCVSS 7.8PoCv10.32017-03-27
CVE-2017-2490 [HIGH] CVE-2017-2490: iOS 10.3
Apple Security Update: About the security content of iOS 10.3
Product: iOS
Version: 10.3
CVE: CVE-2017-2490
Component: Kernel
Impact: An application may be able to execute arbitrary code with elevated privileges
Description: A memory corruption issue was addressed through improved memory handling.
apple
CVE-2017-2360P3HIGHCVSS 7.8PoCv10.2.12017-01-23
CVE-2017-2360 [HIGH] CVE-2017-2360: iOS 10.2.1
Apple Security Update: About the security content of iOS 10.2.1
Product: iOS
Version: 10.2.1
CVE: CVE-2017-2360
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A use after free issue was addressed through improved memory management.
apple
CVE-2017-2365P3MEDIUMCVSS 6.5PoCv10.2.12017-01-23
CVE-2017-2365 [MEDIUM] CVE-2017-2365: iOS 10.2.1
Apple Security Update: About the security content of iOS 10.2.1
Product: iOS
Version: 10.2.1
CVE: CVE-2017-2365
Component: WebKit
Impact: Processing maliciously crafted web content may exfiltrate data cross-origin
Description: A validation issue existed in the handling of variable handling. This issue was addressed through improved validation.
apple
CVE-2017-2363P3MEDIUMCVSS 6.5PoCv10.2.12017-01-23
CVE-2017-2363 [MEDIUM] CVE-2017-2363: iOS 10.2.1
Apple Security Update: About the security content of iOS 10.2.1
Product: iOS
Version: 10.2.1
CVE: CVE-2017-2363
Component: WebKit
Impact: Processing maliciously crafted web content may exfiltrate data cross-origin
Description: A validation issue existed in the handling of page loading. This issue was addressed through improved logic.
apple
CVE-2019-8565P3HIGHCVSS 7.0PoC≥ unspecified, < iOS 12.22019-12-18
CVE-2019-8565 [HIGH] CWE-362 CVE-2019-8565: A race condition was addressed with additional validation. This issue is fixed in iOS 12.2, macOS Mo
A race condition was addressed with additional validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4. A malicious application may be able to gain root privileges.
nvdapple
CVE-2019-6218P3HIGHCVSS 7.8PoC≥ unspecified, < iOS 12.1.32019-03-05
CVE-2019-6218 [HIGH] CWE-787 CVE-2019-6218: A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 1
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A malicious application may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2017-2474P3HIGHCVSS 7.8PoCv10.32017-03-27
CVE-2017-2474 [HIGH] CVE-2017-2474: iOS 10.3
Apple Security Update: About the security content of iOS 10.3
Product: iOS
Version: 10.3
CVE: CVE-2017-2474
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: An off-by-one issue was addressed through improved bounds checking.
apple
CVE-2016-7612P3HIGHCVSS 7.8PoCv10.22016-12-12
CVE-2016-7612 [HIGH] CVE-2016-7612: iOS 10.2
Apple Security Update: About the security content of iOS 10.2
Product: iOS
Version: 10.2
CVE: CVE-2016-7612
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: Multiple memory corruption issues were addressed through improved input validation.
apple