cbcvebase.

Apple iOS vulnerabilities

4,109 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,109
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL335HIGH1680MEDIUM1805LOW289

Vulnerabilities

Page 15 of 206
CVE-2017-2474P3HIGHCVSS 7.8PoC≤ 10.2.12017-04-02
CVE-2017-2474 [HIGH] CVE-2017-2474: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. An off-by-one error allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2016-7612P3HIGHCVSS 7.8PoC≤ 10.1.12017-02-20
CVE-2016-7612 [HIGH] CWE-119 CVE-2016-7612: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-6998P3HIGHCVSS 7.8PoC≤ 10.3.12017-05-22
CVE-2017-6998 [HIGH] CWE-119 CVE-2017-6998: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-6995P3HIGHCVSS 7.8PoC≤ 10.3.12017-05-22
CVE-2017-6995 [HIGH] CWE-119 CVE-2017-6995: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-6996P3HIGHCVSS 7.8PoC≤ 10.3.12017-05-22
CVE-2017-6996 [HIGH] CWE-119 CVE-2017-6996: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-6994P3HIGHCVSS 7.8PoC≤ 10.3.12017-05-22
CVE-2017-6994 [HIGH] CWE-119 CVE-2017-6994: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-6989P3HIGHCVSS 7.8PoC≤ 10.3.12017-05-22
CVE-2017-6989 [HIGH] CWE-119 CVE-2017-6989: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2016-4669P3HIGHCVSS 7.8PoCfixed in 10.12017-02-20
CVE-2016-4669 [HIGH] CWE-20 CVE-2016-4669: An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Kernel" component. It allows local users to execute arbitrary code in a privileged context or cause a denial of service (MIG code mishandling and system c
nvd
CVE-2017-2364P3MEDIUMCVSS 6.5PoC≤ 10.2.02017-02-20
CVE-2017-2364 [MEDIUM] CWE-200 CVE-2017-2364: An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0 An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
nvd
CVE-2016-1828P3HIGHCVSS 7.8PoCfixed in 9.3.22016-05-20
CVE-2016-1828 [HIGH] CVE-2016-1828: The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2 The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1827, CVE-2016-1829, and CVE-2016-1830.
nvd
CVE-2016-1827P3HIGHCVSS 7.8PoCfixed in 9.3.22016-05-20
CVE-2016-1827 [HIGH] CWE-119 CVE-2016-1827: The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2 The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1828, CVE-2016-1829, and CVE-2016-1830.
nvd
CVE-2019-8514P3HIGHCVSS 7.8PoCfixed in 12.22019-12-18
CVE-2019-8514 [HIGH] CVE-2019-8514: A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS M A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. An application may be able to gain elevated privileges.
nvd
CVE-2017-2367P3MEDIUMCVSS 6.5PoC≤ 10.2.12017-04-02
CVE-2017-2367 [MEDIUM] CVE-2017-2367: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
nvd
CVE-2017-2479P3MEDIUMCVSS 6.5PoCfixed in 10.32017-04-02
CVE-2017-2479 [MEDIUM] CWE-20 CVE-2017-2479: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affected. iTunes before 12.6 on Windows is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive inf
nvd
CVE-2017-2371P3MEDIUMCVSS 6.5PoCfixed in 10.2.12017-02-20
CVE-2017-2371 [MEDIUM] CWE-20 CVE-2017-2371: An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "WebKit" component, which allows remote attackers to launch popups via a crafted web site.
nvd
CVE-2017-7089P3MEDIUMCVSS 6.1PoC≤ 10.3.32017-10-23
CVE-2017-7089 [MEDIUM] CWE-79 CVE-2017-7089: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that is mishandled during parent-tab processing.
nvd
CVE-2013-2842P3HIGHCVSS 7.5PoC≤ 6.1.4v1.0.0+46 more2013-05-22
CVE-2013-2842 [HIGH] CWE-399 CVE-2013-2842: Use-after-free vulnerability in Google Chrome before 27.0.1453.93 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of widgets.
nvd
CVE-2016-1803P3HIGHCVSS 7.8PoCfixed in 9.3.22016-05-20
CVE-2016-1803 [HIGH] CWE-476 CVE-2016-1803: CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2. CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.
nvd
CVE-2016-1755P3HIGHCVSS 7.8PoCfixed in 9.32016-03-24
CVE-2016-1755 [HIGH] CVE-2016-1755: The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 all The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1754.
nvd
CVE-2016-1813P3HIGHCVSS 7.8PoCfixed in 9.3.22016-05-20
CVE-2016-1813 [HIGH] CWE-476 CVE-2016-1813: The IOAccelSharedUserClient2::page_off_resource method in Apple iOS before 9.3.2, OS X before 10.11. The IOAccelSharedUserClient2::page_off_resource method in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.
nvd
Apple iOS vulnerabilities | cvebase