Apple iPadOS vulnerabilities

1,835 known vulnerabilities affecting apple/ipados.

Total CVEs
1,835
CISA KEV
79
actively exploited
Public exploits
8
Exploited in wild
62
Severity breakdown
CRITICAL105HIGH806MEDIUM800LOW124

Vulnerabilities

Page 61 of 92
CVE-2022-22621MEDIUMCVSS 4.6fixed in 15.42022-03-18
CVE-2022-22621 [MEDIUM] CVE-2022-22621: This issue was addressed with improved checks. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS This issue was addressed with improved checks. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3, watchOS 8.5. A person with physical access to an iOS device may be able to see sensitive information via keyboard suggestions.
nvd
CVE-2022-22652MEDIUMCVSS 6.1fixed in 15.42022-03-18
CVE-2022-22652 [MEDIUM] CWE-306 CVE-2022-22652: The GSMA authentication panel could be presented on the lock screen. The issue was resolved by requi The GSMA authentication panel could be presented on the lock screen. The issue was resolved by requiring device unlock to interact with the GSMA authentication panel. This issue is fixed in iOS 15.4 and iPadOS 15.4. A person with physical access may be able to view and modify the carrier account information and settings from the lock screen.
nvd
CVE-2022-22638MEDIUMCVSS 6.5fixed in 15.42022-03-18
CVE-2022-22638 [MEDIUM] CWE-476 CVE-2022-22638: A null pointer dereference was addressed with improved validation. This issue is fixed in tvOS 15.4, A null pointer dereference was addressed with improved validation. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, Security Update 2022-003 Catalina, watchOS 8.5, macOS Monterey 12.3. An attacker in a privileged position may be able to perform a denial of service attack.
nvd
CVE-2022-22671MEDIUMCVSS 4.6fixed in 15.42022-03-18
CVE-2022-22671 [MEDIUM] CVE-2022-22671: An authentication issue was addressed with improved state management. This issue is fixed in iOS 15. An authentication issue was addressed with improved state management. This issue is fixed in iOS 15.4 and iPadOS 15.4. A person with physical access to an iOS device may be able to access photos from the lock screen.
nvd
CVE-2022-22594MEDIUMCVSS 6.5fixed in 15.32022-03-18
CVE-2022-22594 [MEDIUM] CWE-346 CVE-2022-22594: A cross-origin issue in the IndexDB API was addressed with improved input validation. This issue is A cross-origin issue in the IndexDB API was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. A website may be able to track sensitive user information.
nvd
CVE-2022-22592MEDIUMCVSS 6.5fixed in 15.32022-03-18
CVE-2022-22592 [MEDIUM] CVE-2022-22592: A logic issue was addressed with improved state management. This issue is fixed in iOS 15.3 and iPad A logic issue was addressed with improved state management. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
nvd
CVE-2022-22600MEDIUMCVSS 5.5fixed in 15.42022-03-18
CVE-2022-22600 [MEDIUM] CVE-2022-22600: The issue was addressed with improved permissions logic. This issue is fixed in tvOS 15.4, iOS 15.4 The issue was addressed with improved permissions logic. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3, watchOS 8.5. A malicious application may be able to bypass certain Privacy preferences.
nvd
CVE-2022-22589MEDIUMCVSS 6.1fixed in 15.32022-03-18
CVE-2022-22589 [MEDIUM] CVE-2022-22589: A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 15.3 a A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing a maliciously crafted mail message may lead to running arbitrary javascript.
nvd
CVE-2022-22588MEDIUMCVSS 5.5fixed in 15.2.12022-03-18
CVE-2022-22588 [MEDIUM] CWE-20 CVE-2022-22588: A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 15.2.1 and iPadOS 15.2.1. Processing a maliciously crafted HomeKit accessory name may cause a denial of service.
nvd
CVE-2022-22598LOWCVSS 3.3fixed in 15.42022-03-18
CVE-2022-22598 [LOW] CVE-2022-22598: An issue with app access to camera metadata was addressed with improved logic. This issue is fixed i An issue with app access to camera metadata was addressed with improved logic. This issue is fixed in iOS 15.4 and iPadOS 15.4. An app may be able to learn information about the current camera view before being granted camera access.
nvd
CVE-2022-22670LOWCVSS 3.3fixed in 15.42022-03-18
CVE-2022-22670 [LOW] CVE-2022-22670: An access issue was addressed with improved access restrictions. This issue is fixed in tvOS 15.4, i An access issue was addressed with improved access restrictions. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, watchOS 8.5. A malicious application may be able to identify what other applications a user has installed.
nvd
CVE-2022-22599LOWCVSS 2.4fixed in 15.42022-03-18
CVE-2022-22599 [LOW] CVE-2022-22599: Description: A permissions issue was addressed with improved validation. This issue is fixed in watc Description: A permissions issue was addressed with improved validation. This issue is fixed in watchOS 8.5, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, macOS Monterey 12.3. A person with physical access to a device may be able to use Siri to obtain some location information from the lock screen.
nvd
CVE-2022-26981HIGHCVSS 7.8fixed in 15.62022-03-13
CVE-2022-26981 [HIGH] CWE-120 CVE-2022-26981: Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (cal Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (called, indirectly, by tools/lou_checktable.c).
nvd
CVE-2022-23308HIGHCVSS 7.5fixed in 15.52022-02-26
CVE-2022-23308 [HIGH] CWE-416 CVE-2022-23308: valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes. valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
nvd
CVE-2022-21658MEDIUMCVSS 6.3fixed in 15.42022-01-20
CVE-2022-21658 [MEDIUM] CWE-363 CVE-2022-21658: Rust is a multi-paradigm, general-purpose programming language designed for performance and safety, Rust is a multi-paradigm, general-purpose programming language designed for performance and safety, especially safe concurrency. The Rust Security Response WG was notified that the `std::fs::remove_dir_all` standard library function is vulnerable a race condition enabling symlink following (CWE-363). An attacker could use this security issue to trick
nvd
CVE-2021-30767MEDIUMCVSS 5.5fixed in 15.22021-12-23
CVE-2021-30767 [MEDIUM] CVE-2021-30767: A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11. A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.6.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. A local user may be able to modify protected parts of the file system.
nvd
CVE-2021-30840HIGHCVSS 7.8fixed in 15.02021-10-28
CVE-2021-30840 [HIGH] CVE-2021-30840: This issue was addressed with improved checks. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and This issue was addressed with improved checks. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted dfont file may lead to arbitrary code execution.
nvd
CVE-2021-30814HIGHCVSS 7.8fixed in 15.02021-10-28
CVE-2021-30814 [HIGH] CWE-787 CVE-2021-30814: A memory corruption issue was addressed with improved input validation. This issue is fixed in tvOS A memory corruption issue was addressed with improved input validation. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2021-30818HIGHCVSS 8.8fixed in 14.82021-10-28
CVE-2021-30818 [HIGH] CWE-843 CVE-2021-30818: A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.8 a A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, iOS 15 and iPadOS 15, Safari 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2020-9897HIGHCVSS 7.8fixed in 14.22021-10-28
CVE-2020-9897 [HIGH] CWE-787 CVE-2020-9897: An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.2 An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.2 and iPadOS 14.2, macOS Big Sur 11.0.1. Processing a maliciously crafted PDF may lead to arbitrary code execution.
nvd