cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 131 of 207
CVE-2015-7023P4MEDIUMCVSS 5.8≤ 9.0.22015-10-23
CVE-2015-7023 [MEDIUM] CWE-17 CVE-2015-7023: CFNetwork in Apple iOS before 9.1 and OS X before 10.11.1 does not properly consider the uppercase-v CFNetwork in Apple iOS before 9.1 and OS X before 10.11.1 does not properly consider the uppercase-versus-lowercase distinction during cookie parsing, which allows remote web servers to overwrite cookies via unspecified vectors.
nvd
CVE-2017-2497P4MEDIUMCVSS 6.1≤ 10.3.12017-05-22
CVE-2017-2497 [MEDIUM] CWE-601 CVE-2017-2497: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "iBooks" component. It allows remote attackers to trigger visits to arbitrary URLs via a crafted book.
nvd
CVE-2019-15165P4MEDIUMCVSS 5.3v13.32019-10-03
CVE-2019-15165 [MEDIUM] CWE-770 CVE-2019-15165: sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocati sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.
nvd
CVE-2025-43448P4MEDIUMCVSS 6.3fixed in 26.12025-11-04
CVE-2025-43448 [MEDIUM] CWE-59 CVE-2025-43448: This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18.7.2 and This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. An app may be able to break out of its sandbox.
nvd
CVE-2024-27840P4MEDIUMCVSS 6.3fixed in 16.7.8≥ 17.0, < 17.52024-06-10
CVE-2024-27840 [MEDIUM] CWE-786 CVE-2024-27840: The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.2, watchOS 10.5. An attacker that has already achieved kernel code execution may be able to bypass kernel memory protections.
nvd
CVE-2015-5770P4MEDIUMCVSS 5.8≤ 8.42015-08-17
CVE-2015-5770 [MEDIUM] CWE-264 CVE-2015-5770: MobileInstallation in Apple iOS before 8.4.1 does not ensure the uniqueness of universal provisionin MobileInstallation in Apple iOS before 8.4.1 does not ensure the uniqueness of universal provisioning profile bundle IDs, which allows attackers to replace arbitrary extensions via a crafted enterprise app.
nvd
CVE-2019-8762P4MEDIUMCVSS 6.1fixed in 13.12020-10-27
CVE-2019-8762 [MEDIUM] CWE-79 CVE-2019-8762: A validation issue was addressed with improved logic. This issue is fixed in Safari 13.0.1, iOS 13.1 A validation issue was addressed with improved logic. This issue is fixed in Safari 13.0.1, iOS 13.1 and iPadOS 13.1, iCloud for Windows 10.7, tvOS 13, iCloud for Windows 7.14, iTunes 12.10.1 for Windows. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd
CVE-2023-32445P4MEDIUMCVSS 6.1fixed in 15.7.8≥ 16.0, < 16.62023-07-28
CVE-2023-32445 [MEDIUM] CWE-79 CVE-2023-32445: This issue was addressed with improved checks. This issue is fixed in Safari 16.6, watchOS 9.6, iOS This issue was addressed with improved checks. This issue is fixed in Safari 16.6, watchOS 9.6, iOS 15.7.8 and iPadOS 15.7.8, tvOS 16.6, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. Processing a document may lead to a cross site scripting attack.
nvd
CVE-2017-7164P4MEDIUMCVSS 5.9fixed in 11.22018-04-03
CVE-2017-7164 [MEDIUM] CWE-20 CVE-2017-7164: An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is affected. The issue involves the "App Store" component. It allows man-in-the-middle attackers to spoof password prompts.
nvd
CVE-2017-2412P4MEDIUMCVSS 5.9≤ 10.2.12017-04-02
CVE-2017-2412 [MEDIUM] CWE-319 CVE-2017-2412: An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves t An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "iTunes Store" component. It allows man-in-the-middle attackers to modify the client-server data stream to iTunes sandbox web services by leveraging use of cleartext HTTP.
nvd
CVE-2024-40826P4MEDIUMCVSS 6.1fixed in 18.02024-09-17
CVE-2024-40826 [MEDIUM] CVE-2024-40826: A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 18 and iPa A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An unencrypted document may be written to a temporary file when using print preview.
nvd
CVE-2017-2414P4MEDIUMCVSS 5.3≤ 10.2.12017-04-02
CVE-2017-2414 [MEDIUM] CWE-20 CVE-2017-2414: An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves t An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "DataAccess" component. It allows remote attackers to access Exchange traffic in opportunistic circumstances by leveraging a mistake in typing an e-mail address.
nvd
CVE-2014-4364P4MEDIUMCVSS 5.6≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4364 [MEDIUM] CWE-310 CVE-2014-4364: The 802.1X subsystem in Apple iOS before 8 and Apple TV before 7 does not require strong authenticat The 802.1X subsystem in Apple iOS before 8 and Apple TV before 7 does not require strong authentication methods, which allows remote attackers to calculate credentials by offering LEAP authentication from a crafted Wi-Fi AP and then performing a cryptographic attack against the MS-CHAPv1 hash.
nvd
CVE-2021-30720P4MEDIUMCVSS 5.4fixed in 14.62021-09-08
CVE-2021-30720 [MEDIUM] CWE-287 CVE-2021-30720: A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 a A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. A malicious website may be able to access restricted ports on arbitrary servers.
nvd
CVE-2011-1296P4HIGHCVSS 7.5fixed in 5.02011-03-25
CVE-2011-1296 [HIGH] CWE-20 CVE-2011-1296: Google Chrome before 10.0.648.204 does not properly handle SVG text, which allows remote attackers t Google Chrome before 10.0.648.204 does not properly handle SVG text, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-1115P4HIGHCVSS 7.5fixed in 5.02011-03-01
CVE-2011-1115 [HIGH] CVE-2011-1115: Google Chrome before 9.0.597.107 does not properly render tables, which allows remote attackers to c Google Chrome before 9.0.597.107 does not properly render tables, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-1451P4HIGHCVSS 7.5fixed in 5.02011-05-03
CVE-2011-1451 [HIGH] CWE-20 CVE-2011-1451: Google Chrome before 11.0.696.57 does not properly handle DOM id maps, which allows remote attackers Google Chrome before 11.0.696.57 does not properly handle DOM id maps, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "dangling pointers."
nvd
CVE-2011-1295P4HIGHCVSS 7.5fixed in 5.02011-03-25
CVE-2011-1295 [HIGH] CWE-20 CVE-2011-1295: WebKit, as used in Google Chrome before 10.0.648.204 and Apple Safari before 5.0.6, does not properl WebKit, as used in Google Chrome before 10.0.648.204 and Apple Safari before 5.0.6, does not properly handle node parentage, which allows remote attackers to cause a denial of service (DOM tree corruption), conduct cross-site scripting (XSS) attacks, or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2015-7037P4MEDIUMCVSS 5.0≤ 9.12015-12-11
CVE-2015-7037 [MEDIUM] CWE-22 CVE-2015-7037: Directory traversal vulnerability in Mobile Backup in Photos in Apple iOS before 9.2 allows attacker Directory traversal vulnerability in Mobile Backup in Photos in Apple iOS before 9.2 allows attackers to read arbitrary files via a crafted pathname.
nvd
CVE-2024-44167P4MEDIUMCVSS 5.5fixed in 18.02024-09-17
CVE-2024-44167 [MEDIUM] CWE-22 CVE-2024-44167: This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18 and iPadOS 1 This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7, visionOS 2. An app may be able to overwrite arbitrary files.
nvd
Apple iOS vulnerabilities | cvebase