Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 108 of 207
CVE-2010-1809P4CRITICALCVSS 10.0fixed in 4.12010-09-09
CVE-2010-1809 [CRITICAL] CVE-2010-1809: The Accessibility component in Apple iOS before 4.1 on the iPhone and iPod touch does not perform th
The Accessibility component in Apple iOS before 4.1 on the iPhone and iPod touch does not perform the expected VoiceOver announcement associated with the location services icon, which has unspecified impact and attack vectors.
nvd
CVE-2010-2807P4MEDIUMCVSS 6.8fixed in 4.22010-08-19
CVE-2010-2807 [MEDIUM] CWE-681 CVE-2010-2807: FreeType before 2.4.2 uses incorrect integer data types during bounds checking, which allows remote
FreeType before 2.4.2 uses incorrect integer data types during bounds checking, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
nvd
CVE-2011-3064P4HIGHCVSS 7.5fixed in 6.02012-03-30
CVE-2011-3064 [HIGH] CWE-416 CVE-2011-3064: Use-after-free vulnerability in Google Chrome before 18.0.1025.142 allows remote attackers to cause
Use-after-free vulnerability in Google Chrome before 18.0.1025.142 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG clipping.
nvd
CVE-2011-1293P4HIGHCVSS 7.5fixed in 5.02011-03-25
CVE-2011-1293 [HIGH] CWE-416 CVE-2011-1293: Use-after-free vulnerability in the HTMLCollection implementation in Google Chrome before 10.0.648.2
Use-after-free vulnerability in the HTMLCollection implementation in Google Chrome before 10.0.648.204 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2010-1752P4MEDIUMCVSS 6.8fixed in 4.02010-06-22
CVE-2010-1752 [MEDIUM] CWE-119 CVE-2010-1752: Stack-based buffer overflow in CFNetwork in Apple iOS before 4 on the iPhone and iPod touch allows r
Stack-based buffer overflow in CFNetwork in Apple iOS before 4 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to URL handling.
nvd
CVE-2011-0157P4HIGHCVSS 7.5≤ 4.2v1.0.0+28 more2011-03-11
CVE-2011-0157 [HIGH] CWE-119 CVE-2011-0157: WebKit, as used in Apple iOS before 4.3, allows remote attackers to execute arbitrary code or cause
WebKit, as used in Apple iOS before 4.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-09-1.
nvd
CVE-2011-3081P4CRITICALCVSS 9.3fixed in 6.02012-05-01
CVE-2011-3081 [CRITICAL] CVE-2011-3081: Use-after-free vulnerability in Google Chrome before 18.0.1025.168 allows remote attackers to cause
Use-after-free vulnerability in Google Chrome before 18.0.1025.168 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the floating of elements, a different vulnerability than CVE-2011-3078.
nvd
CVE-2012-3727P4MEDIUMCVSS 6.8≤ 5.1.1v1.0.0+38 more2012-09-20
CVE-2012-3727 [MEDIUM] CWE-119 CVE-2012-3727: Buffer overflow in the IPsec component in Apple iOS before 6 allows remote attackers to execute arbi
Buffer overflow in the IPsec component in Apple iOS before 6 allows remote attackers to execute arbitrary code via a crafted racoon configuration file.
nvd
CVE-2013-1026P4MEDIUMCVSS 6.8≤ 6.1.4v1.0.0+46 more2013-09-16
CVE-2013-1026 [MEDIUM] CWE-119 CVE-2013-1026: Buffer overflow in ImageIO in Apple Mac OS X before 10.8.5 allows remote attackers to execute arbitr
Buffer overflow in ImageIO in Apple Mac OS X before 10.8.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted JPEG2000 data in a PDF document.
nvd
CVE-2013-1025P4MEDIUMCVSS 6.8≤ 6.1.4v1.0.0+46 more2013-09-16
CVE-2013-1025 [MEDIUM] CWE-119 CVE-2013-1025: Buffer overflow in CoreGraphics in Apple Mac OS X before 10.8.5 allows remote attackers to execute a
Buffer overflow in CoreGraphics in Apple Mac OS X before 10.8.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted JBIG2 data in a PDF document.
nvd
CVE-2015-1122P4MEDIUMCVSS 6.8≤ 8.22015-04-10
CVE-2015-1122 [MEDIUM] CVE-2015-1122: WebKit, as used in Apple iOS before 8.3, Apple TV before 7.2, and Apple Safari before 6.2.5, 7.x bef
WebKit, as used in Apple iOS before 8.3, Apple TV before 7.2, and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-04-08-1, A
nvd
CVE-2015-1120P4MEDIUMCVSS 6.8≤ 8.22015-04-10
CVE-2015-1120 [MEDIUM] CVE-2015-1120: WebKit, as used in Apple iOS before 8.3, Apple TV before 7.2, and Apple Safari before 6.2.5, 7.x bef
WebKit, as used in Apple iOS before 8.3, Apple TV before 7.2, and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-04-08-1, A
nvd
CVE-2014-1354P4MEDIUMCVSS 6.8≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1354 [MEDIUM] CWE-399 CVE-2014-1354: CoreGraphics in Apple iOS before 7.1.2 does not properly restrict allocation of stack memory for pro
CoreGraphics in Apple iOS before 7.1.2 does not properly restrict allocation of stack memory for processing of XBM images, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted image data.
nvd
CVE-2015-5822P4MEDIUMCVSS 6.8≤ 8.4.12015-09-18
CVE-2015-5822 [MEDIUM] CWE-119 CVE-2015-5822: WebKit, as used in JavaScriptCore in Apple iOS before 9 and iTunes before 12.3, allows remote attack
WebKit, as used in JavaScriptCore in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.
nvd
CVE-2015-3659P4MEDIUMCVSS 6.8≤ 8.32015-07-03
CVE-2015-3659 [MEDIUM] CWE-264 CVE-2015-3659: The SQLite authorizer in the Storage functionality in WebKit in Apple Safari before 6.2.7, 7.x befor
The SQLite authorizer in the Storage functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly restrict access to SQL functions, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted
nvd
CVE-2014-4477P4MEDIUMCVSS 6.8≤ 8.1.22015-01-30
CVE-2014-4477 [MEDIUM] CVE-2014-4477: WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x befo
WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-4476 and CVE-2014-4479.
nvd
CVE-2014-4476P4MEDIUMCVSS 6.8≤ 8.1.22015-01-30
CVE-2014-4476 [MEDIUM] CWE-119 CVE-2014-4476: WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x befo
WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-4477 and CVE-2014-4479.
nvd
CVE-2014-4479P4MEDIUMCVSS 6.8≤ 8.1.22015-01-30
CVE-2014-4479 [MEDIUM] CVE-2014-4479: WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x befo
WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-4476 and CVE-2014-4477.
nvd
CVE-2015-7001P4MEDIUMCVSS 6.8≤ 9.12015-12-11
CVE-2015-7001 [MEDIUM] CWE-264 CVE-2015-7001: AppSandbox in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 mis
AppSandbox in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 mishandles hard links, which allows attackers to bypass Contacts access revocation via a crafted app.
nvd
CVE-2020-9805P4HIGHCVSS 7.1fixed in 13.52020-06-09
CVE-2020-9805 [HIGH] CWE-79 CVE-2020-9805: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 1
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd