Apple iOS vulnerabilities
3,940 known vulnerabilities affecting apple/iphone_os.
Total CVEs
3,940
CISA KEV
92
actively exploited
Public exploits
248
Exploited in wild
79
Severity breakdown
CRITICAL313HIGH1610MEDIUM1730LOW287
Vulnerabilities
Page 113 of 197
CVE-2018-4273MEDIUMCVSS 6.5fixed in 11.4.12019-04-03
CVE-2018-4273 [MEDIUM] CWE-119 CVE-2018-4273: Multiple memory corruption issues were addressed with improved input validation. This issue affected
Multiple memory corruption issues were addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvd
CVE-2018-4388MEDIUMCVSS 4.6fixed in 12.12019-04-03
CVE-2018-4388 [MEDIUM] CWE-200 CVE-2018-4388: A lock screen issue allowed access to the share function on a locked device. This issue was addresse
A lock screen issue allowed access to the share function on a locked device. This issue was addressed by restricting options offered on a locked device. This issue affected versions prior to iOS 12.1.
nvd
CVE-2018-4413MEDIUMCVSS 5.5fixed in 12.12019-04-03
CVE-2018-4413 [MEDIUM] CWE-119 CVE-2018-4413: A memory initialization issue was addressed with improved memory handling. This issue affected versi
A memory initialization issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1, macOS Mojave 10.14.1, tvOS 12.1, watchOS 5.1.
nvd
CVE-2018-4363MEDIUMCVSS 5.5fixed in 12.02019-04-03
CVE-2018-4363 [MEDIUM] CWE-20 CVE-2018-4363: An input validation issue existed in the kernel. This issue was addressed with improved input valida
An input validation issue existed in the kernel. This issue was addressed with improved input validation. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5.
nvd
CVE-2018-4293MEDIUMCVSS 5.3fixed in 11.4.12019-04-03
CVE-2018-4293 [MEDIUM] CWE-20 CVE-2018-4293: A cookie management issue was addressed with improved checks. This issue affected versions prior to
A cookie management issue was addressed with improved checks. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvd
CVE-2018-4431MEDIUMCVSS 5.5fixed in 12.1.12019-04-03
CVE-2018-4431 [MEDIUM] CWE-200 CVE-2018-4431: A memory initialization issue was addressed with improved memory handling. This issue affected versi
A memory initialization issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2.
nvd
CVE-2018-4216MEDIUMCVSS 5.5fixed in 11.4.12019-04-03
CVE-2018-4216 [MEDIUM] CVE-2018-4216: A logic issue existed in the handling of call URLs. This issue was addressed with improved state man
A logic issue existed in the handling of call URLs. This issue was addressed with improved state management. This issue affected versions prior to iOS 11.4.1.
nvd
CVE-2018-4321MEDIUMCVSS 5.3fixed in 12.02019-04-03
CVE-2018-4321 [MEDIUM] CWE-20 CVE-2018-4321: A validation issue existed in the entitlement verification. This issue was addressed with improved v
A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12.
nvd
CVE-2018-4260MEDIUMCVSS 6.5fixed in 11.4.12019-04-03
CVE-2018-4260 [MEDIUM] CWE-20 CVE-2018-4260: An inconsistent user interface issue was addressed with improved state management. This issue affect
An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to iOS 11.4.1, Safari 11.1.2.
nvd
CVE-2018-4266MEDIUMCVSS 5.9fixed in 11.4.12019-04-03
CVE-2018-4266 [MEDIUM] CWE-362 CVE-2018-4266: A race condition was addressed with additional validation. This issue affected versions prior toiVer
A race condition was addressed with additional validation. This issue affected versions prior toiVersions prior to: OS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvd
CVE-2018-4304MEDIUMCVSS 5.0fixed in 12.02019-04-03
CVE-2018-4304 [MEDIUM] CWE-20 CVE-2018-4304: A denial of service issue was addressed with improved validation. This issue affected versions prior
A denial of service issue was addressed with improved validation. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
nvd
CVE-2018-4271MEDIUMCVSS 6.5fixed in 11.4.12019-04-03
CVE-2018-4271 [MEDIUM] CWE-119 CVE-2018-4271: Multiple memory corruption issues were addressed with improved input validation. This issue affected
Multiple memory corruption issues were addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvd
CVE-2018-4333MEDIUMCVSS 5.5fixed in 12.02019-04-03
CVE-2018-4333 [MEDIUM] CWE-20 CVE-2018-4333: A validation issue was addressed with improved input sanitization. This issue affected versions prio
A validation issue was addressed with improved input sanitization. This issue affected versions prior to iOS 12, macOS Mojave 10.14.
nvd
CVE-2018-4309MEDIUMCVSS 6.1fixed in 12.02019-04-03
CVE-2018-4309 [MEDIUM] CWE-79 CVE-2018-4309: A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validatio
A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
nvd
CVE-2018-4270MEDIUMCVSS 6.5fixed in 11.4.12019-04-03
CVE-2018-4270 [MEDIUM] CWE-119 CVE-2018-4270: A memory corruption issue was addressed with improved memory handling. This issue affected versions
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvd
CVE-2018-4439MEDIUMCVSS 6.5fixed in 12.1.12019-04-03
CVE-2018-4439 [MEDIUM] CWE-20 CVE-2018-4439: A logic issue was addressed with improved validation. This issue affected versions prior to iOS 12.1
A logic issue was addressed with improved validation. This issue affected versions prior to iOS 12.1.1, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.
nvd
CVE-2018-4313MEDIUMCVSS 5.5fixed in 12.02019-04-03
CVE-2018-4313 [MEDIUM] CWE-20 CVE-2018-4313: A consistency issue existed in the handling of application snapshots. The issue was addressed with i
A consistency issue existed in the handling of application snapshots. The issue was addressed with improved handling of message deletions. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5.
nvd
CVE-2018-4365MEDIUMCVSS 5.5fixed in 12.12019-04-03
CVE-2018-4365 [MEDIUM] CWE-125 CVE-2018-4365: An out-of-bounds read was addressed with improved bounds checking. This issue affected versions prio
An out-of-bounds read was addressed with improved bounds checking. This issue affected versions prior to iOS 12.1.
nvd
CVE-2018-4305MEDIUMCVSS 6.5fixed in 12.02019-04-03
CVE-2018-4305 [MEDIUM] CWE-20 CVE-2018-4305: An input validation issue was addressed with improved input validation. This issue affected versions
An input validation issue was addressed with improved input validation. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5.
nvd
CVE-2018-4335MEDIUMCVSS 5.5fixed in 12.02019-04-03
CVE-2018-4335 [MEDIUM] CWE-20 CVE-2018-4335: A validation issue was addressed with improved input sanitization. This issue affected versions prio
A validation issue was addressed with improved input sanitization. This issue affected versions prior to iOS 12.
nvd