Apple iOS vulnerabilities
3,940 known vulnerabilities affecting apple/iphone_os.
Total CVEs
3,940
CISA KEV
92
actively exploited
Public exploits
248
Exploited in wild
79
Severity breakdown
CRITICAL313HIGH1610MEDIUM1730LOW287
Vulnerabilities
Page 127 of 197
CVE-2017-7109MEDIUMCVSS 6.1≤ 10.3.32017-10-23
CVE-2017-7109 [MEDIUM] CWE-79 CVE-2017-7109: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. A cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web
nvd
CVE-2017-7131MEDIUMCVSS 5.5≤ 10.3.32017-10-23
CVE-2017-7131 [MEDIUM] CWE-200 CVE-2017-7131: An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Bluetooth" component. It allows attackers to obtain sensitive Contact card information via a crafted app.
nvd
CVE-2017-7145MEDIUMCVSS 5.3≤ 10.3.32017-10-23
CVE-2017-7145 [MEDIUM] CWE-275 CVE-2017-7145: An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Time" component. The "Setting Time Zone" feature mishandles the possibility of using location data.
nvd
CVE-2017-7085MEDIUMCVSS 6.5≤ 10.3.32017-10-23
CVE-2017-7085 [MEDIUM] CWE-20 CVE-2017-7085: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar.
nvd
CVE-2017-7083MEDIUMCVSS 4.9≤ 10.3.32017-10-23
CVE-2017-7083 [MEDIUM] CWE-20 CVE-2017-7083: An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is
An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "CFNetwork Proxies" component. It allows remote attackers to cause a denial of service.
nvd
CVE-2017-7089MEDIUMCVSS 6.1PoC≤ 10.3.32017-10-23
CVE-2017-7089 [MEDIUM] CWE-79 CVE-2017-7089: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that is mishandled during parent-tab processing.
nvd
CVE-2017-7088MEDIUMCVSS 5.9≤ 10.3.32017-10-23
CVE-2017-7088 [MEDIUM] CWE-275 CVE-2017-7088: An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Exchange ActiveSync" component. It allows remote attackers to erase a device in opportunistic circumstances by hijacking a cleartext AutoDiscover V1 session during the setup of an Exchange account.
nvd
CVE-2017-7106MEDIUMCVSS 6.5≤ 10.3.32017-10-23
CVE-2017-7106 [MEDIUM] CWE-20 CVE-2017-7106: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. The issue involves the "WebKit" component. It allows remote attackers to spoof the address bar.
nvd
CVE-2017-7146MEDIUMCVSS 5.3≤ 10.3.32017-10-23
CVE-2017-7146 [MEDIUM] CWE-732 CVE-2017-7146: An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Security" component. It allows attackers to track users across installs via a crafted app that leverages Keychain data mishandling.
nvd
CVE-2017-7140MEDIUMCVSS 5.3≤ 10.3.32017-10-23
CVE-2017-7140 [MEDIUM] CWE-200 CVE-2017-7140: An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Keyboard Suggestions" component. It allows attackers to obtain sensitive information by reading keyboard autocorrect suggestions.
nvd
CVE-2017-7072MEDIUMCVSS 5.5≤ 10.3.32017-10-23
CVE-2017-7072 [MEDIUM] CWE-20 CVE-2017-7072: An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "iBooks" component. It allows remote attackers to cause a denial of service (persistent outage) via a crafted iBooks file.
nvd
CVE-2017-7078MEDIUMCVSS 5.3≤ 10.3.32017-10-23
CVE-2017-7078 [MEDIUM] CWE-319 CVE-2017-7078: An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is
An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. The issue involves the "Mail Drafts" component. It allows remote attackers to obtain sensitive information by reading unintended cleartext transmissions.
nvd
CVE-2017-7144MEDIUMCVSS 4.3≤ 10.3.32017-10-23
CVE-2017-7144 [MEDIUM] CWE-275 CVE-2017-7144: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to track Safari Private Browsing users by leveraging cookie mishandling.
nvd
CVE-2017-7148LOWCVSS 3.3v10.3.32017-10-23
CVE-2017-7148 [LOW] CWE-200 CVE-2017-7148: An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Location Framework" component. It allows attackers to obtain sensitive location information via a crafted app that reads the location variable.
nvd
CVE-2017-7139LOWCVSS 2.4≤ 10.3.32017-10-23
CVE-2017-7139 [LOW] CWE-200 CVE-2017-7139: An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Phone" component. It allows attackers to obtain sensitive information by leveraging a timing bug to read a secure-content screenshot that occurred during a locking action.
nvd
CVE-2017-11122HIGHCVSS 7.5≤ 10.3.32017-10-04
CVE-2017-11122 [HIGH] CWE-200 CVE-2017-11122: On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56, an attacker can trigger an information leak due
On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56, an attacker can trigger an information leak due to insufficient length validation, related to ICMPv6 router advertisement offloading.
nvd
CVE-2017-11121CRITICALCVSS 9.8fixed in 11.02017-09-28
CVE-2017-11121 [CRITICAL] CWE-119 CVE-2017-11121: On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, properly crafted malicious over
On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, properly crafted malicious over-the-air Fast Transition frames can potentially trigger internal Wi-Fi firmware heap and/or stack overflows, leading to denial of service or other effects, aka B-V2017061205.
nvd
CVE-2017-11120CRITICALCVSS 9.8PoCfixed in 11.02017-09-28
CVE-2017-11120 [CRITICAL] CWE-119 CVE-2017-11120: On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, an attacker can craft a malform
On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, an attacker can craft a malformed RRM neighbor report frame to trigger an internal buffer overflow in the Wi-Fi firmware, aka B-V2017061204.
nvd
CVE-2017-14315HIGHCVSS 7.5v7.0v7.0.1+28 more2017-09-12
CVE-2017-14315 [HIGH] CWE-119 CVE-2017-14315: In Apple iOS 7 through 9, due to a BlueBorne flaw in the implementation of LEAP (Low Energy Audio Pr
In Apple iOS 7 through 9, due to a BlueBorne flaw in the implementation of LEAP (Low Energy Audio Protocol), a large audio command can be sent to a targeted device and lead to a heap overflow with attacker-controlled data. Since the audio commands sent via LEAP are not properly validated, an attacker can use this overflow to gain full control of the d
nvd
CVE-2017-8248CRITICALCVSS 9.8≤ 10.3.22017-08-16
CVE-2017-8248 [CRITICAL] CWE-119 CVE-2017-8248: A buffer overflow may occur in the processing of a downlink NAS message in Qualcomm Telephony as use
A buffer overflow may occur in the processing of a downlink NAS message in Qualcomm Telephony as used in Apple iPhone 5 and later, iPad 4th generation and later, iPod touch 6th generation.
nvd