cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 120 of 207
CVE-2016-4679P4MEDIUMCVSS 5.5fixed in 10.12017-02-20
CVE-2016-4679 [MEDIUM] CWE-59 CVE-2016-4679: An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "libarchive" component, which allows remote attackers to write to arbitrary files via a crafted archive containing a symlink.
nvd
CVE-2024-23218P4MEDIUMCVSS 5.9fixed in 17.32024-01-23
CVE-2024-23218 [MEDIUM] CWE-203 CVE-2024-23218: A timing side-channel issue was addressed with improvements to constant-time computation in cryptogr A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.4, macOS Sonoma 14.3, macOS Ventura 13.6.5, tvOS 17.3, watchOS 10.3. An attacker may be able to decrypt legacy RSA PKCS#1 v1.5 cipherte
nvd
CVE-2024-44176P4MEDIUMCVSS 5.5fixed in 17.72024-09-17
CVE-2024-44176 [MEDIUM] CWE-400 CVE-2024-44176: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7, tvOS 18, visionOS 2, watchOS 11. Processing an image may lead to a denial-of-service.
nvd
CVE-2024-54494P4MEDIUMCVSS 5.9fixed in 18.22024-12-12
CVE-2024-54494 [MEDIUM] CWE-362 CVE-2024-54494: A race condition was addressed with additional validation. This issue is fixed in iOS 18.2 and iPadO A race condition was addressed with additional validation. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. An attacker may be able to create a read-only memory mapping that can be written to.
nvd
CVE-2024-40777P4MEDIUMCVSS 5.5fixed in 17.62024-07-29
CVE-2024-40777 [MEDIUM] CWE-787 CVE-2024-40777: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing a maliciously crafted file may lead to unexpected app termination.
nvd
CVE-2026-28886P4MEDIUMCVSS 5.9fixed in 18.7.7≥ 26.0, < 26.42026-03-25
CVE-2026-28886 [MEDIUM] CWE-476 CVE-2026-28886: A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. A user in a privileged network position may be able to cause a denial-of-service.
nvd
CVE-2022-26706P4MEDIUMCVSS 5.5fixed in 15.52022-05-26
CVE-2022-26706 [MEDIUM] CVE-2022-26706: An access issue was addressed with additional sandbox restrictions on third-party applications. This An access issue was addressed with additional sandbox restrictions on third-party applications. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. A sandboxed process may be able to circumvent sandbox restrictions.
nvd
CVE-2015-3784P4MEDIUMCVSS 5.0≤ 8.42015-08-16
CVE-2015-3784 [MEDIUM] CWE-200 CVE-2015-3784: Office Viewer in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to read arbi Office Viewer in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
nvd
CVE-2011-3256P4MEDIUMCVSS 4.3v3.0v3.1+17 more2011-10-14
CVE-2011-3256 [MEDIUM] CVE-2011-3256: FreeType 2 before 2.4.7, as used in CoreGraphics in Apple iOS before 5, Mandriva Enterprise Server 5 FreeType 2 before 2.4.7, as used in CoreGraphics in Apple iOS before 5, Mandriva Enterprise Server 5, and possibly other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font, a different vulnerability than CVE-2011-0226.
nvd
CVE-2015-1092P4MEDIUMCVSS 5.0≤ 8.22015-04-10
CVE-2015-1092 [MEDIUM] CVE-2015-1092: NSXMLParser in Foundation in Apple iOS before 8.3 and Apple TV before 7.2 allows remote attackers to NSXMLParser in Foundation in Apple iOS before 8.3 and Apple TV before 7.2 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
nvd
CVE-2011-3885P4HIGHCVSS 7.5fixed in 5.12011-10-25
CVE-2011-3885 [HIGH] CWE-416 CVE-2011-3885: Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to stale Cascading Style Sheets (CSS) token-sequence data.
nvd
CVE-2011-3966P4HIGHCVSS 7.5fixed in 6.02012-02-09
CVE-2011-3966 [HIGH] CWE-416 CVE-2011-3966: Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to error handling for Cascading Style Sheets (CSS) token-sequence data.
nvd
CVE-2014-1271P4HIGHCVSS 7.8≤ 7.0.6v7.0+5 more2014-03-14
CVE-2014-1271 [HIGH] CWE-20 CVE-2014-1271: CoreCapture in Apple iOS before 7.1 and Apple TV before 6.1 does not properly validate IOKit API cal CoreCapture in Apple iOS before 7.1 and Apple TV before 6.1 does not properly validate IOKit API calls, which allows attackers to cause a denial of service (assertion failure and device crash) via a crafted app.
nvd
CVE-2015-7081P4MEDIUMCVSS 5.0≤ 9.12015-12-11
CVE-2015-7081 [MEDIUM] CVE-2015-7081: iBooks in Apple iOS before 9.2 and OS X before 10.11.2 allows remote attackers to read arbitrary fil iBooks in Apple iOS before 9.2 and OS X before 10.11.2 allows remote attackers to read arbitrary files via an iBooks file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
nvd
CVE-2011-2860P4HIGHCVSS 7.5fixed in 5.12011-09-19
CVE-2011-2860 [HIGH] CWE-416 CVE-2011-2860: Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to table styles.
nvd
CVE-2011-3913P4HIGHCVSS 7.5fixed in 6.02011-12-13
CVE-2011-3913 [HIGH] CWE-416 CVE-2011-3913: Use-after-free vulnerability in Google Chrome before 16.0.912.63 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 16.0.912.63 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to Range handling.
nvd
CVE-2018-4215P4HIGHCVSS 7.8fixed in 11.42018-06-08
CVE-2018-4215 [HIGH] CWE-119 CVE-2018-4215: An issue was discovered in certain Apple products. iOS before 11.4 is affected. The issue involves t An issue was discovered in certain Apple products. iOS before 11.4 is affected. The issue involves the "Bluetooth" component. It allows attackers to gain privileges or cause a denial of service (buffer overflow) via a crafted app.
nvd
CVE-2011-2823P4HIGHCVSS 7.5fixed in 5.02011-08-29
CVE-2011-2823 [HIGH] CWE-416 CVE-2011-2823: Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a line box.
nvd
CVE-2011-3260P4MEDIUMCVSS 6.8v3.0v3.1+17 more2011-10-14
CVE-2011-3260 [MEDIUM] CWE-94 CVE-2011-3260: Buffer overflow in OfficeImport in Apple iOS before 5 allows remote attackers to execute arbitrary c Buffer overflow in OfficeImport in Apple iOS before 5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Word document.
nvd
CVE-2010-1817P4MEDIUMCVSS 6.8fixed in 4.12010-09-09
CVE-2010-1817 [MEDIUM] CWE-119 CVE-2010-1817: Buffer overflow in ImageIO in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attack Buffer overflow in ImageIO in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted GIF file.
nvd
Apple iOS vulnerabilities | cvebase