cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 151 of 207
CVE-2019-8850P4MEDIUMCVSS 5.5fixed in 13.12020-10-27
CVE-2019-8850 [MEDIUM] CWE-125 CVE-2019-8850: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Cat An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15, iOS 13.1 and iPadOS 13.1, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, watchOS 6. Processing a maliciously crafted audio file may disclose restricted memory.
nvd
CVE-2021-30706P4MEDIUMCVSS 5.5fixed in 14.62021-09-08
CVE-2021-30706 [MEDIUM] CWE-125 CVE-2021-30706: Processing a maliciously crafted image may lead to disclosure of user information. This issue is fix Processing a maliciously crafted image may lead to disclosure of user information. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. This issue was addressed with improved checks.
nvd
CVE-2021-30819P4MEDIUMCVSS 5.5fixed in 15.02021-10-19
CVE-2021-30819 [MEDIUM] CWE-125 CVE-2021-30819: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 15 an An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 15 and iPadOS 15. Processing a maliciously crafted USD file may disclose memory contents.
nvd
CVE-2019-6207P4MEDIUMCVSS 5.5fixed in 12.22019-12-18
CVE-2019-6207 [MEDIUM] CWE-125 CVE-2019-6207: An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to determine kernel memory layout.
nvd
CVE-2024-27810P4MEDIUMCVSS 5.5fixed in 17.52024-05-14
CVE-2024-27810 [MEDIUM] CWE-22 CVE-2024-27810: A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iP A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, watchOS 10.5. An app may be able to read sensitive location information.
nvd
CVE-2024-40780P4MEDIUMCVSS 5.5fixed in 16.7.9≥ 17.0, < 17.62024-07-29
CVE-2024-40780 [MEDIUM] CWE-125 CVE-2024-40780: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 17. An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2015-1084P4MEDIUMCVSS 5.0≤ 8.22015-03-18
CVE-2015-1084 [MEDIUM] CWE-17 CVE-2015-1084: The user interface in WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before The user interface in WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, does not display URLs consistently, which makes it easier for remote attackers to conduct phishing attacks via a crafted URL.
nvd
CVE-2024-27789P4MEDIUMCVSS 5.5fixed in 16.7.82024-05-14
CVE-2024-27789 [MEDIUM] CWE-922 CVE-2024-27789: A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7. A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, macOS Monterey 12.7.5, macOS Sonoma 14.4, macOS Ventura 13.6.7. An app may be able to access user-sensitive data.
nvd
CVE-2014-4363P4MEDIUMCVSS 5.0≥ 7.0, ≤ 7.1.22014-09-18
CVE-2014-4363 [MEDIUM] CWE-255 CVE-2014-4363: Safari in Apple iOS before 8 does not properly restrict the autofilling of passwords in forms, which Safari in Apple iOS before 8 does not properly restrict the autofilling of passwords in forms, which allows remote attackers to obtain sensitive information via (1) an http web site, (2) an https web site with an unacceptable X.509 certificate, or (3) an IFRAME element.
nvd
CVE-2013-3950P4MEDIUMCVSS 5.0v5.1v5.1.1+6 more2013-06-05
CVE-2013-3950 [MEDIUM] CWE-119 CVE-2013-3950: Stack-based buffer overflow in the openSharedCacheFile function in dyld.cpp in dyld in Apple iOS 5.1 Stack-based buffer overflow in the openSharedCacheFile function in dyld.cpp in dyld in Apple iOS 5.1.x and 6.x through 6.1.3 makes it easier for attackers to conduct untethering attacks via a long string in the DYLD_SHARED_CACHE_DIR environment variable.
nvd
CVE-2022-32841P4MEDIUMCVSS 5.5fixed in 15.62022-09-23
CVE-2022-32841 [MEDIUM] CWE-125 CVE-2022-32841: The issue was addressed with improved memory handling. This issue is fixed in watchOS 8.7, tvOS 15.6 The issue was addressed with improved memory handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. Processing a maliciously crafted image may result in disclosure of process memory.
nvd
CVE-2024-44131P4MEDIUMCVSS 5.5fixed in 18.02024-09-17
CVE-2024-44131 [MEDIUM] CWE-59 CVE-2024-44131: This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18 and iPa This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to access sensitive user data.
nvd
CVE-2024-40836P4MEDIUMCVSS 5.5fixed in 16.7.9≥ 17.0, < 17.62024-07-29
CVE-2024-40836 [MEDIUM] CWE-200 CVE-2024-40836: A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7. A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, watchOS 10.6. A shortcut may be able to use sensitive data with certain actions without prompting the user.
nvd
CVE-2023-40429P4MEDIUMCVSS 5.5fixed in 17.02023-09-27
CVE-2023-40429 [MEDIUM] CVE-2023-40429: A permissions issue was addressed with improved validation. This issue is fixed in tvOS 17, iOS 17 a A permissions issue was addressed with improved validation. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. An app may be able to access sensitive user data.
nvd
CVE-2018-4356P4MEDIUMCVSS 5.3fixed in 12.02019-04-03
CVE-2018-4356 [MEDIUM] CVE-2018-4356: A permissions issue existed. This issue was addressed with improved permission validation. This issu A permissions issue existed. This issue was addressed with improved permission validation. This issue affected versions prior to iOS 12.
nvd
CVE-2018-4224P4MEDIUMCVSS 5.5fixed in 11.42018-06-08
CVE-2018-4224 [MEDIUM] CWE-200 CVE-2018-4224: An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "Security" component. It allows local users to bypass intended re
nvd
CVE-2025-31191P4MEDIUMCVSS 5.5fixed in 18.42025-03-31
CVE-2025-31191 [MEDIUM] CWE-200 CVE-2025-31191: This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPad This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, watchOS 11.4. An app may be able to access sensitive user data.
nvd
CVE-2014-4491P4MEDIUMCVSS 5.0≤ 8.1.22015-01-30
CVE-2014-4491 [MEDIUM] CWE-200 CVE-2014-4491: The extension APIs in the kernel in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV The extension APIs in the kernel in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 do not prevent the presence of addresses within an OSBundleMachOHeaders key in a response, which makes it easier for attackers to bypass the ASLR protection mechanism via a crafted app.
nvd
CVE-2023-42823P4MEDIUMCVSS 5.5fixed in 16.7.2v17.02024-02-21
CVE-2023-42823 [MEDIUM] CWE-922 CVE-2023-42823: The issue was resolved by sanitizing logging This issue is fixed in watchOS 10.1, macOS Sonoma 14.1, The issue was resolved by sanitizing logging This issue is fixed in watchOS 10.1, macOS Sonoma 14.1, tvOS 17.1, macOS Monterey 12.7.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, macOS Ventura 13.6.1. An app may be able to access user-sensitive data.
nvd
CVE-2021-1815P4MEDIUMCVSS 5.5fixed in 14.52021-09-08
CVE-2021-1815 [MEDIUM] CWE-22 CVE-2021-1815: A parsing issue in the handling of directory paths was addressed with improved path validation. This A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A local user may be able to modify protected parts of the file system.
nvd
Apple iOS vulnerabilities | cvebase