Apple iPadOS vulnerabilities

1,835 known vulnerabilities affecting apple/ipados.

Total CVEs
1,835
CISA KEV
79
actively exploited
Public exploits
8
Exploited in wild
62
Severity breakdown
CRITICAL105HIGH806MEDIUM800LOW124

Vulnerabilities

Page 51 of 92
CVE-2022-42842CRITICALCVSS 9.8fixed in 16.22022-12-15
CVE-2022-42842 [CRITICAL] CWE-787 CVE-2022-42842: The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monte The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. A remote user may be able to cause kernel code execution.
nvd
CVE-2022-42837CRITICALCVSS 9.8≥ 15.0, < 15.7.2≥ 16.0, < 16.22022-12-15
CVE-2022-42837 [CRITICAL] CWE-20 CVE-2022-42837: An issue existed in the parsing of URLs. This issue was addressed with improved input validation. Th An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, watchOS 9.2. A remote user may be able to cause unexpected app termination or arbitrary code execution.
nvd
CVE-2022-42861HIGHCVSS 8.8fixed in 15.7.2≥ 16.0, < 16.22022-12-15
CVE-2022-42861 [HIGH] CWE-284 CVE-2022-42861: This issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macO This issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2. An app may be able to break out of its sandbox.
nvd
CVE-2022-42845HIGHCVSS 7.2fixed in 16.22022-12-15
CVE-2022-42845 [HIGH] CWE-787 CVE-2022-42845: The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monte The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app with root privileges may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2022-42863HIGHCVSS 8.8fixed in 16.22022-12-15
CVE-2022-42863 [HIGH] CWE-787 CVE-2022-42863: A memory corruption issue was addressed with improved state management. This issue is fixed in Safar A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2022-46699HIGHCVSS 8.8fixed in 16.22022-12-15
CVE-2022-46699 [HIGH] CWE-787 CVE-2022-46699: A memory corruption issue was addressed with improved state management. This issue is fixed in Safar A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2022-42840HIGHCVSS 7.8fixed in 15.7.2≥ 16.0, < 16.22022-12-15
CVE-2022-42840 [HIGH] CWE-787 CVE-2022-42840: The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.2, The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2022-46690HIGHCVSS 7.8fixed in 16.22022-12-15
CVE-2022-46690 [HIGH] CWE-787 CVE-2022-46690: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iO An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2022-46689HIGHCVSS 7.0PoCfixed in 15.7.22022-12-15
CVE-2022-46689 [HIGH] CWE-362 CVE-2022-46689: A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS M A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2022-46694HIGHCVSS 7.8fixed in 15.7.2≥ 16.0, < 16.22022-12-15
CVE-2022-46694 [HIGH] CWE-787 CVE-2022-46694: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iO An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, iOS 15.7.2 and iPadOS 15.7.2, tvOS 16.2, watchOS 9.2. Parsing a maliciously crafted video file may lead to kernel code execution.
nvd
CVE-2022-42844HIGHCVSS 8.6fixed in 16.22022-12-15
CVE-2022-42844 [HIGH] CWE-119 CVE-2022-42844: The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16 The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2. An app may be able to break out of its sandbox.
nvd
CVE-2022-46701HIGHCVSS 7.8≥ 16.0, < 16.22022-12-15
CVE-2022-46701 [HIGH] CWE-20 CVE-2022-46701: The issue was addressed with improved bounds checks. This issue is fixed in iOS 16.2 and iPadOS 16.2 The issue was addressed with improved bounds checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2. Connecting to a malicious NFS server may lead to arbitrary code execution with kernel privileges.
nvd
CVE-2022-42855HIGHCVSS 7.1fixed in 15.7.2≥ 16.0, < 16.22022-12-15
CVE-2022-42855 [HIGH] CWE-269 CVE-2022-42855: A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.2, macOS A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to use arbitrary entitlements.
nvd
CVE-2022-42856HIGHCVSS 8.8KEVfixed in 15.7.22022-12-15
CVE-2022-42856 [HIGH] CWE-843 CVE-2022-42856: A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16. A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of
nvd
CVE-2022-46700HIGHCVSS 8.8≥ 15.0, < 15.7.2≥ 16.0, < 16.22022-12-15
CVE-2022-46700 [HIGH] CWE-787 CVE-2022-46700: A memory corruption issue was addressed with improved input validation. This issue is fixed in Safar A memory corruption issue was addressed with improved input validation. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2022-42849HIGHCVSS 7.8fixed in 16.22022-12-15
CVE-2022-42849 [HIGH] CWE-269 CVE-2022-42849: An access issue existed with privileged API calls. This issue was addressed with additional restrict An access issue existed with privileged API calls. This issue was addressed with additional restrictions. This issue is fixed in iOS 16.2 and iPadOS 16.2, tvOS 16.2, watchOS 9.2. A user may be able to elevate privileges.
nvd
CVE-2022-46696HIGHCVSS 8.8fixed in 16.22022-12-15
CVE-2022-46696 [HIGH] CWE-787 CVE-2022-46696: A memory corruption issue was addressed with improved input validation. This issue is fixed in Safar A memory corruption issue was addressed with improved input validation. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2022-42848HIGHCVSS 7.8fixed in 15.7.2≥ 16.0, < 16.22022-12-15
CVE-2022-42848 [HIGH] CWE-693 CVE-2022-42848: A logic issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, i A logic issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, iOS 15.7.2 and iPadOS 15.7.2, tvOS 16.2. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2022-42867HIGHCVSS 8.8fixed in 16.22022-12-15
CVE-2022-42867 [HIGH] CWE-416 CVE-2022-42867: A use after free issue was addressed with improved memory management. This issue is fixed in Safari A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2022-46691HIGHCVSS 8.8fixed in 15.7.2≥ 16.0, < 16.22022-12-15
CVE-2022-46691 [HIGH] CWE-787 CVE-2022-46691: A memory consumption issue was addressed with improved memory handling. This issue is fixed in Safar A memory consumption issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
Apple iPadOS vulnerabilities | cvebase