Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 121 of 207
CVE-2011-3261P4MEDIUMCVSS 6.8v3.0v3.1+17 more2011-10-14
CVE-2011-3261 [MEDIUM] CWE-94 CVE-2011-3261: Double free vulnerability in OfficeImport in Apple iOS before 5 allows remote attackers to execute a
Double free vulnerability in OfficeImport in Apple iOS before 5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Excel spreadsheet.
nvd
CVE-2014-4379P4HIGHCVSS 7.1≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4379 [HIGH] CWE-119 CVE-2014-4379: An unspecified IOHIDFamily function in Apple iOS before 8 and Apple TV before 7 lacks proper bounds
An unspecified IOHIDFamily function in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking to prevent reading of kernel pointers, which allows attackers to bypass the ASLR protection mechanism via a crafted application.
nvd
CVE-2012-3722P4MEDIUMCVSS 6.8≤ 5.1.1v1.0.0+38 more2012-09-20
CVE-2012-3722 [MEDIUM] CWE-399 CVE-2012-3722: The Sorenson codec in QuickTime in Apple Mac OS X before 10.7.5, and in CoreMedia in iOS before 6, a
The Sorenson codec in QuickTime in Apple Mac OS X before 10.7.5, and in CoreMedia in iOS before 6, accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with Sorenson encoding.
nvd
CVE-2014-4412P4MEDIUMCVSS 6.8≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4412 [MEDIUM] CWE-119 CVE-2014-4412: WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote attackers to execute arbi
WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-09-17-1 and APPLE-SA-2014-09-17-2.
nvd
CVE-2014-1349P4MEDIUMCVSS 6.8≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1349 [MEDIUM] CVE-2014-1349: Use-after-free vulnerability in Safari in Apple iOS before 7.1.2 allows remote attackers to execute
Use-after-free vulnerability in Safari in Apple iOS before 7.1.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an invalid URL.
nvd
CVE-2014-4411P4MEDIUMCVSS 6.8≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4411 [MEDIUM] CWE-119 CVE-2014-4411: WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote attackers to execute arbi
WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-09-17-1 and APPLE-SA-2014-09-17-2.
nvd
CVE-2014-4493P4HIGHCVSS 7.5≤ 8.1.22015-01-30
CVE-2014-4493 [HIGH] CWE-264 CVE-2014-4493: The app-installation functionality in MobileInstallation in Apple iOS before 8.1.3 allows attackers
The app-installation functionality in MobileInstallation in Apple iOS before 8.1.3 allows attackers to obtain control of the local app container by leveraging access to an enterprise distribution certificate for signing a crafted app.
nvd
CVE-2015-1069P4MEDIUMCVSS 6.8≤ 8.22015-03-18
CVE-2015-1069 [MEDIUM] CWE-399 CVE-2015-1069: WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote
WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.
nvd
CVE-2014-4414P4MEDIUMCVSS 6.8≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4414 [MEDIUM] CWE-119 CVE-2014-4414: WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote attackers to execute arbi
WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-09-17-1 and APPLE-SA-2014-09-17-2.
nvd
CVE-2014-4413P4MEDIUMCVSS 6.8≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4413 [MEDIUM] CWE-119 CVE-2014-4413: WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote attackers to execute arbi
WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-09-17-1 and APPLE-SA-2014-09-17-2.
nvd
CVE-2014-4415P4MEDIUMCVSS 6.8≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4415 [MEDIUM] CWE-119 CVE-2014-4415: WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote attackers to execute arbi
WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-09-17-1 and APPLE-SA-2014-09-17-2.
nvd
CVE-2014-4410P4MEDIUMCVSS 6.8≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4410 [MEDIUM] CWE-119 CVE-2014-4410: WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote attackers to execute arbi
WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-09-17-1 and APPLE-SA-2014-09-17-2.
nvd
CVE-2015-5928P4MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-5928 [MEDIUM] CWE-119 CVE-2015-5928: WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remot
WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3, and APPLE-SA-20
nvd
CVE-2015-1082P4MEDIUMCVSS 6.8≤ 8.22015-03-18
CVE-2015-1082 [MEDIUM] CWE-399 CVE-2015-1082: WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote
WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.
nvd
CVE-2015-1073P4MEDIUMCVSS 6.8≤ 8.22015-03-18
CVE-2015-1073 [MEDIUM] CWE-399 CVE-2015-1073: WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote
WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.
nvd
CVE-2015-1077P4MEDIUMCVSS 6.8≤ 8.22015-03-18
CVE-2015-1077 [MEDIUM] CWE-399 CVE-2015-1077: WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote
WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.
nvd
CVE-2015-1079P4MEDIUMCVSS 6.8≤ 8.22015-03-18
CVE-2015-1079 [MEDIUM] CWE-399 CVE-2015-1079: WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote
WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.
nvd
CVE-2015-1080P4MEDIUMCVSS 6.8≤ 8.22015-03-18
CVE-2015-1080 [MEDIUM] CWE-399 CVE-2015-1080: WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote
WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.
nvd
CVE-2015-1074P4MEDIUMCVSS 6.8≤ 8.22015-03-18
CVE-2015-1074 [MEDIUM] CWE-399 CVE-2015-1074: WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote
WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.
nvd
CVE-2015-1068P4MEDIUMCVSS 6.8≤ 8.22015-03-18
CVE-2015-1068 [MEDIUM] CWE-399 CVE-2015-1068: WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote
WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.
nvd