cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 136 of 207
CVE-2016-4685P4MEDIUMCVSS 5.9≤ 10.0.32017-02-20
CVE-2016-4685 [MEDIUM] CWE-326 CVE-2016-4685: An issue was discovered in certain Apple products. iOS before 10.1 is affected. The issue involves t An issue was discovered in certain Apple products. iOS before 10.1 is affected. The issue involves the "iTunes Backup" component, which improperly hashes passwords, making it easier to decrypt files.
nvd
CVE-2017-13863P4MEDIUMCVSS 5.9fixed in 11.02018-04-03
CVE-2017-13863 [MEDIUM] CWE-295 CVE-2017-13863: An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "APNs" component. It allows man-in-the-middle attackers to track users by leveraging the transmission of client certificates.
nvd
CVE-2015-3751P4MEDIUMCVSS 5.0fixed in 8.4.12015-08-16
CVE-2015-3751 [MEDIUM] CWE-254 CVE-2015-3751: WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8 WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, allows remote attackers to bypass a Content Security Policy protection mechanism by using a video control in conjunction with an IMG element within an OBJECT element.
nvd
CVE-2015-3753P4MEDIUMCVSS 5.0fixed in 8.4.12015-08-16
CVE-2015-3753 [MEDIUM] CWE-200 CVE-2015-3753: WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8 WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly perform taint checking for CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive image data by leveraging a redirect to a data:image resource.
nvd
CVE-2021-30769P4MEDIUMCVSS 5.5fixed in 14.72021-09-08
CVE-2021-30769 [MEDIUM] CWE-287 CVE-2021-30769: A logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, tvOS 14 A logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
nvd
CVE-2014-4452P4MEDIUMCVSS 5.4≥ 8.0, < 8.1.12014-11-18
CVE-2014-4452 [MEDIUM] CWE-399 CVE-2014-4452: WebKit, as used in Apple iOS before 8.1.1 and Apple TV before 7.0.2, allows remote attackers to exec WebKit, as used in Apple iOS before 8.1.1 and Apple TV before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-4462.
nvd
CVE-2011-1117P4HIGHCVSS 7.5fixed in 5.02011-03-01
CVE-2011-1117 [HIGH] CVE-2011-1117: Google Chrome before 9.0.597.107 does not properly handle XHTML documents, which allows remote attac Google Chrome before 9.0.597.107 does not properly handle XHTML documents, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale nodes."
nvd
CVE-2011-1114P4HIGHCVSS 7.5fixed in 5.02011-03-01
CVE-2011-1114 [HIGH] CVE-2011-1114: Google Chrome before 9.0.597.107 does not properly handle tables, which allows remote attackers to c Google Chrome before 9.0.597.107 does not properly handle tables, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale node."
nvd
CVE-2017-7006P4MEDIUMCVSS 5.3fixed in 10.3.32017-07-20
CVE-2017-7006 [MEDIUM] CWE-203 CVE-2017-7006: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct a timing side-channel attack to bypass the Same Origin Policy and obtain sensitive information via a crafted web site that u
nvd
CVE-2015-5766P4MEDIUMCVSS 5.0≤ 8.42015-08-17
CVE-2015-5766 [MEDIUM] CWE-22 CVE-2015-5766: Directory traversal vulnerability in Air Traffic in Apple iOS before 8.4.1 allows attackers to acces Directory traversal vulnerability in Air Traffic in Apple iOS before 8.4.1 allows attackers to access arbitrary filesystem locations via vectors related to asset handling.
nvd
CVE-2024-40794P4MEDIUMCVSS 5.3fixed in 17.62024-07-29
CVE-2024-40794 [MEDIUM] CWE-287 CVE-2024-40794: This issue was addressed through improved state management. This issue is fixed in Safari 17.6, iOS This issue was addressed through improved state management. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. Private Browsing tabs may be accessed without authentication.
nvd
CVE-2015-5841P4MEDIUMCVSS 5.0≤ 8.4.12015-09-18
CVE-2015-5841 [MEDIUM] CWE-74 CVE-2015-5841: The CFNetwork Proxies component in Apple iOS before 9 does not properly handle a Set-Cookie header w The CFNetwork Proxies component in Apple iOS before 9 does not properly handle a Set-Cookie header within a response to an HTTP CONNECT request, which allows remote proxy servers to conduct cookie-injection attacks via a crafted response.
nvd
CVE-2024-44296P4MEDIUMCVSS 5.4fixed in 17.7.1≥ 18.0, < 18.12024-10-28
CVE-2024-44296 [MEDIUM] CVE-2024-44296: The issue was addressed with improved checks. This issue is fixed in Safari 18.1, iOS 17.7.1 and iPa The issue was addressed with improved checks. This issue is fixed in Safari 18.1, iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
nvd
CVE-2020-10002P4MEDIUMCVSS 5.5fixed in 14.22020-12-08
CVE-2020-10002 [MEDIUM] CVE-2020-10002: A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11. A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, tvOS 14.2, iTunes 12.11 for Windows. A local user may be able to read arbitrary files.
nvd
CVE-2015-5912P4MEDIUMCVSS 5.0≤ 8.4.12015-09-18
CVE-2015-5912 [MEDIUM] CWE-17 CVE-2015-5912: The CFNetwork FTPProtocol component in Apple iOS before 9 allows remote FTP proxy servers to trigger The CFNetwork FTPProtocol component in Apple iOS before 9 allows remote FTP proxy servers to trigger TCP connection attempts to intranet hosts via crafted responses.
nvd
CVE-2023-41968P4MEDIUMCVSS 5.5fixed in 17.02023-09-27
CVE-2023-41968 [MEDIUM] CWE-59 CVE-2023-41968: This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to read arbitrary files.
nvd
CVE-2019-8798P4MEDIUMCVSS 5.5fixed in 13.22019-12-18
CVE-2019-8798 [MEDIUM] CWE-787 CVE-2019-8798: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13 A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with system privileges.
nvd
CVE-2021-1769P4MEDIUMCVSS 5.5fixed in 14.42021-04-02
CVE-2021-1769 [MEDIUM] CVE-2021-1769: A logic issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.2, Sec A logic issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
nvd
CVE-2015-5746P4MEDIUMCVSS 5.0≤ 8.42015-08-17
CVE-2015-5746 [MEDIUM] CWE-284 CVE-2015-5746: AppleFileConduit in Apple iOS before 8.4.1 allows attackers to bypass intended restrictions on files AppleFileConduit in Apple iOS before 8.4.1 allows attackers to bypass intended restrictions on filesystem access via an afc command that leverages symlink mishandling.
nvd
CVE-2025-43444P4MEDIUMCVSS 5.3fixed in 26.12025-11-04
CVE-2025-43444 [MEDIUM] CWE-276 CVE-2025-43444: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.2 an A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. An app may be able to fingerprint the user.
nvd
Apple iOS vulnerabilities | cvebase