Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 102 of 207
CVE-2016-4594P4HIGHCVSS 7.8fixed in 9.3.32016-07-22
CVE-2016-4594 [HIGH] CWE-20 CVE-2016-4594: The Sandbox Profiles component in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, an
The Sandbox Profiles component in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows attackers to access the process list via a crafted app that makes an API call.
nvd
CVE-2014-4483P4MEDIUMCVSS 6.8≤ 8.1.22015-01-30
CVE-2014-4483 [MEDIUM] CWE-119 CVE-2014-4483: Buffer overflow in FontParser in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV bef
Buffer overflow in FontParser in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted font file in a PDF document.
nvd
CVE-2016-7584P4HIGHCVSS 7.8≤ 10.0.32017-02-20
CVE-2016-7584 [HIGH] CWE-254 CVE-2016-7584: An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "AppleMobileFileIntegrity" component, which allows remote attackers to spoof signed code by using a matching team ID.
nvd
CVE-2018-4420P4HIGHCVSS 7.8fixed in 12.12019-04-03
CVE-2018-4420 [HIGH] CWE-119 CVE-2018-4420: A memory corruption issue was addressed by removing the vulnerable code. This issue affected version
A memory corruption issue was addressed by removing the vulnerable code. This issue affected versions prior to iOS 12.1, macOS Mojave 10.14.1, tvOS 12.1, watchOS 5.1.
nvd
CVE-2016-1751P4HIGHCVSS 7.8fixed in 9.32016-03-24
CVE-2016-1751 [HIGH] CWE-264 CVE-2016-1751: The kernel in Apple iOS before 9.3, tvOS before 9.2, and watchOS before 2.2 does not properly restri
The kernel in Apple iOS before 9.3, tvOS before 9.2, and watchOS before 2.2 does not properly restrict the execute permission, which allows attackers to bypass a code-signing protection mechanism via a crafted app.
nvd
CVE-2019-8511P3HIGHCVSS 7.8fixed in 12.22019-12-18
CVE-2019-8511 [HIGH] CWE-120 CVE-2019-8511: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.2
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, watchOS 5.2. A malicious application may be able to elevate privileges.
nvd
CVE-2018-4303P4HIGHCVSS 7.8fixed in 12.1.12019-04-03
CVE-2018-4303 [HIGH] CWE-20 CVE-2018-4303: An input validation issue was addressed with improved input validation. This issue affected versions
An input validation issue was addressed with improved input validation. This issue affected versions prior to macOS Mojave 10.14, iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2.
nvd
CVE-2015-5773P4MEDIUMCVSS 6.8≤ 8.42015-08-17
CVE-2015-5773 [MEDIUM] CWE-119 CVE-2015-5773: QL Office in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbit
QL Office in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted office document.
nvd
CVE-2015-5758P4MEDIUMCVSS 6.8≤ 8.42015-08-17
CVE-2015-5758 [MEDIUM] CWE-119 CVE-2015-5758: ImageIO in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitra
ImageIO in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted TIFF image.
nvd
CVE-2015-5756P4MEDIUMCVSS 6.8≤ 8.42015-08-17
CVE-2015-5756 [MEDIUM] CVE-2015-5756: FontParser in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbi
FontParser in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-3804 and CVE-2015-5775.
nvd
CVE-2015-3689P4MEDIUMCVSS 6.8≤ 8.32015-07-03
CVE-2015-3689 [MEDIUM] CVE-2015-3689: CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrar
CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted text file, a different vulnerability than CVE-2015-3685, CVE-2015-3686, CVE-2015-3687, and CVE-2015-3688.
nvd
CVE-2015-3685P4MEDIUMCVSS 6.8≤ 8.32015-07-03
CVE-2015-3685 [MEDIUM] CWE-119 CVE-2015-3685: CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrar
CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted text file, a different vulnerability than CVE-2015-3686, CVE-2015-3687, CVE-2015-3688, and CVE-2015-3689.
nvd
CVE-2020-9826P4HIGHCVSS 7.5fixed in 13.52020-06-09
CVE-2020-9826 [HIGH] CWE-20 CVE-2020-9826: A denial of service issue was addressed with improved input validation. This issue is fixed in iOS 1
A denial of service issue was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5. A remote attacker may be able to cause a denial of service.
nvd
CVE-2016-4626P4HIGHCVSS 7.8fixed in 9.3.32016-07-22
CVE-2016-4626 [HIGH] CWE-476 CVE-2016-4626: IOHIDFamily in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.
IOHIDFamily in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors.
nvd
CVE-2013-1036P4MEDIUMCVSS 6.8≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-1036 [MEDIUM] CWE-119 CVE-2013-1036: Safari in Apple iOS before 7 allows remote attackers to execute arbitrary code or cause a denial of
Safari in Apple iOS before 7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document.
nvd
CVE-2016-4689P4HIGHCVSS 7.5≤ 10.1.12017-02-20
CVE-2016-4689 [HIGH] CWE-254 CVE-2016-4689: An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves t
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Mail" component, which does not alert the user to an S/MIME email signature that used a revoked certificate.
nvd
CVE-2015-7064P4MEDIUMCVSS 6.8≤ 9.12015-12-11
CVE-2015-7064 [MEDIUM] CWE-119 CVE-2015-7064: OpenGL in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows
OpenGL in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2015-7066.
nvd
CVE-2015-7066P4MEDIUMCVSS 6.8≤ 9.12015-12-11
CVE-2015-7066 [MEDIUM] CVE-2015-7066: OpenGL in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows
OpenGL in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2015-7064.
nvd
CVE-2011-2825P4CRITICALCVSS 9.3fixed in 5.12011-08-29
CVE-2011-2825 [CRITICAL] CWE-416 CVE-2011-2825: Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving custom fonts.
nvd
CVE-2017-13888P4HIGHCVSS 7.5fixed in 11.22019-01-11
CVE-2017-13888 [HIGH] CWE-704 CVE-2017-13888: In iOS before 11.2, a type confusion issue was addressed with improved memory handling.
In iOS before 11.2, a type confusion issue was addressed with improved memory handling.
nvd