cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 101 of 207
CVE-2015-3724P3MEDIUMCVSS 6.8≤ 8.32015-07-03
CVE-2015-3724 [MEDIUM] CVE-2015-3724: CoreGraphics in Apple iOS before 8.4 allows remote attackers to execute arbitrary code or cause a de CoreGraphics in Apple iOS before 8.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted ICC profile in a PDF document, a different vulnerability than CVE-2015-3723.
nvd
CVE-2019-8617P4CRITICALCVSS 9.6fixed in 12.32019-12-18
CVE-2019-8617 [CRITICAL] CVE-2019-8617: An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 12.3. An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 12.3. A sandboxed process may be able to circumvent sandbox restrictions.
nvd
CVE-2026-43725P3HIGHCVSS 7.1fixed in 26.5.22026-06-29
CVE-2026-43725 [HIGH] CWE-20 CVE-2026-43725: The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26 The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to process restricted web content outside the sandbox.
nvd
CVE-2015-1067P4MEDIUMCVSS 4.3≤ 8.1.32015-03-11
CVE-2015-1067 [MEDIUM] CVE-2015-1067: Secure Transport in Apple iOS before 8.2, Apple OS X through 10.10.2, and Apple TV before 7.1 does n Secure Transport in Apple iOS before 8.2, Apple OS X through 10.10.2, and Apple TV before 7.1 does not properly restrict TLS state transitions, which makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" issue, a different vulnerability than CVE-2015-0204 and CVE-2015-163
nvd
CVE-2026-28950P3MEDIUMCVSS 6.2fixed in 18.7.8≥ 26.0, < 26.4.22026-04-22
CVE-2026-28950 [MEDIUM] CWE-359 CVE-2026-28950: A logging issue was addressed with improved data redaction. This issue is fixed in iOS 15.8.8 and iP A logging issue was addressed with improved data redaction. This issue is fixed in iOS 15.8.8 and iPadOS 15.8.8, iOS 16.7.16 and iPadOS 16.7.16, iOS 18.7.8 and iPadOS 18.7.8, iOS 26.4.2 and iPadOS 26.4.2, iPadOS 17.7.11. Notifications marked for deletion could be unexpectedly retained on the device.
nvd
CVE-2019-8597P3MEDIUMCVSS 6.5fixed in 12.32019-12-18
CVE-2019-8597 [MEDIUM] CWE-787 CVE-2019-8597: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8615P3MEDIUMCVSS 6.5fixed in 12.32019-12-18
CVE-2019-8615 [MEDIUM] CWE-125 CVE-2019-8615: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2021-1799P3MEDIUMCVSS 6.5fixed in 14.42021-04-02
CVE-2021-1799 [MEDIUM] CVE-2021-1799: A port redirection issue was addressed with additional port validation. This issue is fixed in macOS A port redirection issue was addressed with additional port validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4, Safari 14.0.3. A malicious website may be able to access restricted ports on arbitrary servers.
nvd
CVE-2024-23263P3MEDIUMCVSS 6.5fixed in 16.7.6≥ 17.0, < 17.42024-03-08
CVE-2024-23263 [MEDIUM] CWE-20 CVE-2024-23263: A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
nvd
CVE-2024-23284P3MEDIUMCVSS 6.5fixed in 16.7.6≥ 17.0, < 17.42024-03-08
CVE-2024-23284 [MEDIUM] CWE-693 CVE-2024-23284: A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
nvd
CVE-2016-4644P3MEDIUMCVSS 6.5fixed in 9.3.32019-01-11
CVE-2016-4644 [MEDIUM] CWE-200 CVE-2016-4644: In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016 In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a downgrade issue existed with HTTP authentication credentials saved in Keychain. This issue was addressed by storing the authentication types with the credentials.
nvd
CVE-2026-28878P3MEDIUMCVSS 6.5fixed in 18.7.7≥ 26.0, < 26.42026-03-25
CVE-2026-28878 [MEDIUM] CWE-200 CVE-2026-28878: A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.7.7 and iPad A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.7, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to enumerate a user's installed apps.
nvd
CVE-2010-2806P3MEDIUMCVSS 6.8fixed in 4.22010-08-19
CVE-2010-2806 [MEDIUM] CWE-129 CVE-2010-2806: Array index error in the t42_parse_sfnts function in type42/t42parse.c in FreeType before 2.4.2 allo Array index error in the t42_parse_sfnts function in type42/t42parse.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via negative size values for certain strings in FontType42 font files, leading to a heap-based buffer overflow.
nvd
CVE-2015-5312P4HIGHCVSS 7.1≤ 9.2.12015-12-15
CVE-2015-5312 [HIGH] CVE-2015-5312: The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly preven The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.
nvd
CVE-2015-5522P4MEDIUMCVSS 6.8≤ 8.22015-08-11
CVE-2015-5522 [MEDIUM] CWE-119 CVE-2015-5522: Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving a command character in an href.
nvd
CVE-2016-7643P4HIGHCVSS 8.1≤ 10.1.12017-02-20
CVE-2016-7643 [HIGH] CWE-125 CVE-2016-7643: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "ImageIO" component. It allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and application crash) via a crafte
nvd
CVE-2018-4319P3HIGHCVSS 8.1fixed in 12.02019-04-03
CVE-2018-4319 [HIGH] CWE-346 CVE-2018-4319: A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of se A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue affected versions prior to iOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
nvd
CVE-2016-4724P4HIGHCVSS 7.8≤ 9.3.52016-09-25
CVE-2016-4724 [HIGH] CWE-476 CVE-2016-4724: IOAcceleratorFamily in Apple iOS before 10 and OS X before 10.12 allows attackers to execute arbitra IOAcceleratorFamily in Apple iOS before 10 and OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.
nvd
CVE-2016-4654P4HIGHCVSS 7.8v9.3.32016-08-18
CVE-2016-4654 [HIGH] CWE-119 CVE-2016-4654: IOMobileFrameBuffer in Apple iOS before 9.3.4 allows attackers to execute arbitrary code in a privil IOMobileFrameBuffer in Apple iOS before 9.3.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2016-1756P4HIGHCVSS 7.8≤ 9.2.12016-03-24
CVE-2016-1756 [HIGH] CVE-2016-1756: The kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to execute arbitrary cod The kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.
nvd
Apple iOS vulnerabilities | cvebase