cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 122 of 207
CVE-2015-1072P4MEDIUMCVSS 6.8≤ 8.22015-03-18
CVE-2015-1072 [MEDIUM] CWE-399 CVE-2015-1072: WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.
nvd
CVE-2015-1078P4MEDIUMCVSS 6.8≤ 8.22015-03-18
CVE-2015-1078 [MEDIUM] CWE-399 CVE-2015-1078: WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.
nvd
CVE-2015-1070P4MEDIUMCVSS 6.8≤ 8.22015-03-18
CVE-2015-1070 [MEDIUM] CWE-399 CVE-2015-1070: WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.
nvd
CVE-2015-7002P4MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-7002 [MEDIUM] CWE-119 CVE-2015-7002: WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remot WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3, and APPLE-SA-20
nvd
CVE-2015-5929P4MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-5929 [MEDIUM] CWE-119 CVE-2015-5929: WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remot WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3, and APPLE-SA-20
nvd
CVE-2015-7014P4MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-7014 [MEDIUM] CWE-119 CVE-2015-7014: WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remot WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3, and APPLE-SA-20
nvd
CVE-2015-5930P4MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-5930 [MEDIUM] CWE-119 CVE-2015-5930: WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remot WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3, and APPLE-SA-20
nvd
CVE-2015-7012P4MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-7012 [MEDIUM] CWE-119 CVE-2015-7012: WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remot WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3, and APPLE-SA-20
nvd
CVE-2016-4660P4HIGHCVSS 7.1≤ 10.0.32017-02-20
CVE-2016-4660 [HIGH] CWE-200 CVE-2016-4660: An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "FontParser" component. It allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash)
nvd
CVE-2015-7013P4MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-7013 [MEDIUM] CWE-119 CVE-2015-7013: WebKit, as used in Apple Safari before 9.0.1 and iTunes before 12.3.1, allows remote attackers to ex WebKit, as used in Apple Safari before 9.0.1 and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-3 and APPLE-SA-2015-10-21-5.
nvd
CVE-2014-1292P4MEDIUMCVSS 6.8≤ 7.0.6v7.0+5 more2014-03-14
CVE-2014-1292 [MEDIUM] CVE-2014-1292: WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1290, CVE-2014-1291, CVE-2014-1293, and CVE-2014-1294.
nvd
CVE-2014-1290P4MEDIUMCVSS 6.8≤ 7.0.6v7.0+5 more2014-03-14
CVE-2014-1290 [MEDIUM] CVE-2014-1290: WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1291, CVE-2014-1292, CVE-2014-1293, and CVE-2014-1294.
nvd
CVE-2014-1291P4MEDIUMCVSS 6.8≤ 7.0.6v7.0+5 more2014-03-14
CVE-2014-1291 [MEDIUM] CVE-2014-1291: WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1290, CVE-2014-1292, CVE-2014-1293, and CVE-2014-1294.
nvd
CVE-2014-1289P4MEDIUMCVSS 6.8≤ 7.0.6v7.0+5 more2014-03-14
CVE-2014-1289 [MEDIUM] CWE-119 CVE-2014-1289: WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1290, CVE-2014-1291, CVE-2014-1292, CVE-2014-1293, and CVE-2014-1294.
nvd
CVE-2014-1294P4MEDIUMCVSS 6.8≤ 7.0.6v7.0+5 more2014-03-14
CVE-2014-1294 [MEDIUM] CVE-2014-1294: WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1290, CVE-2014-1291, CVE-2014-1292, and CVE-2014-1293.
nvd
CVE-2014-1293P4MEDIUMCVSS 6.8≤ 7.0.6v7.0+5 more2014-03-14
CVE-2014-1293 [MEDIUM] CVE-2014-1293: WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1290, CVE-2014-1291, CVE-2014-1292, and CVE-2014-1294.
nvd
CVE-2020-9994P4HIGHCVSS 7.1fixed in 13.52020-10-22
CVE-2020-9994 [HIGH] CVE-2020-9994: A path handling issue was addressed with improved validation. This issue is fixed in iOS 13.5 and iP A path handling issue was addressed with improved validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A malicious application may be able to overwrite arbitrary files.
nvd
CVE-2019-13118P4MEDIUMCVSS 5.3fixed in 12.42019-07-01
CVE-2019-13118 [MEDIUM] CWE-843 CVE-2019-13118: In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.
nvd
CVE-2011-2819P4MEDIUMCVSS 6.8fixed in 5.02011-08-03
CVE-2011-2819 [MEDIUM] CVE-2011-2819: Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same Origin Policy via vecto Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same Origin Policy via vectors related to handling of the base URI.
nvd
CVE-2009-2795P4HIGHCVSS 7.2fixed in 3.1fixed in 3.1.12009-09-10
CVE-2009-2795 [HIGH] CWE-119 CVE-2009-2795: Heap-based buffer overflow in the Recovery Mode component in Apple iPhone OS before 3.1, and iPhone Heap-based buffer overflow in the Recovery Mode component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, allows local users to bypass the passcode requirement and access arbitrary data via vectors related to "command parsing."
nvd
Apple iOS vulnerabilities | cvebase