cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 157 of 207
CVE-2018-4104P4MEDIUMCVSS 5.5fixed in 11.32018-04-03
CVE-2018-4104 [MEDIUM] CWE-200 CVE-2018-4104: An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvd
CVE-2021-30768P4MEDIUMCVSS 5.5fixed in 14.72021-09-08
CVE-2021-30768 [MEDIUM] CVE-2021-30768: A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-004 Catalina. A sandboxed process may be able to circumvent sandbox restrictions.
nvd
CVE-2020-9944P4MEDIUMCVSS 5.5fixed in 14.02020-12-08
CVE-2020-9944 [MEDIUM] CWE-125 CVE-2020-9944: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, tvOS 14.0, iOS 14.0 and iPadOS 14.0. An application may be able to read restricted memory.
nvd
CVE-2018-4413P4MEDIUMCVSS 5.5fixed in 12.12019-04-03
CVE-2018-4413 [MEDIUM] CWE-119 CVE-2018-4413: A memory initialization issue was addressed with improved memory handling. This issue affected versi A memory initialization issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1, macOS Mojave 10.14.1, tvOS 12.1, watchOS 5.1.
nvd
CVE-2021-30791P4MEDIUMCVSS 5.5fixed in 14.72021-09-08
CVE-2021-30791 [MEDIUM] CWE-125 CVE-2021-30791: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 14.7, An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 14.7, macOS Big Sur 11.5. Processing a maliciously crafted file may disclose user information.
nvd
CVE-2021-30723P4MEDIUMCVSS 5.5fixed in 14.62021-09-08
CVE-2021-30723 [MEDIUM] CVE-2021-30723: An information disclosure issue was addressed with improved state management. This issue is fixed in An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted USD file may disclose memory contents.
nvd
CVE-2016-4719P4MEDIUMCVSS 5.5≤ 9.3.52016-09-18
CVE-2016-4719 [MEDIUM] CWE-200 CVE-2016-4719: The GeoServices component in Apple iOS before 10 and watchOS before 3 does not properly restrict acc The GeoServices component in Apple iOS before 10 and watchOS before 3 does not properly restrict access to PlaceData information, which allows attackers to discover physical locations via a crafted application.
nvd
CVE-2021-30746P4MEDIUMCVSS 5.5fixed in 14.62021-09-08
CVE-2021-30746 [MEDIUM] CWE-125 CVE-2021-30746: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted USD file may disclose memory contents.
nvd
CVE-2021-30691P4MEDIUMCVSS 5.5fixed in 14.62021-09-08
CVE-2021-30691 [MEDIUM] CVE-2021-30691: An information disclosure issue was addressed with improved state management. This issue is fixed in An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted USD file may disclose memory contents.
nvd
CVE-2021-30694P4MEDIUMCVSS 5.5fixed in 14.62021-09-08
CVE-2021-30694 [MEDIUM] CVE-2021-30694: An information disclosure issue was addressed with improved state management. This issue is fixed in An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted USD file may disclose memory contents.
nvd
CVE-2021-30692P4MEDIUMCVSS 5.5fixed in 14.62021-09-08
CVE-2021-30692 [MEDIUM] CVE-2021-30692: An information disclosure issue was addressed with improved state management. This issue is fixed in An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted USD file may disclose memory contents.
nvd
CVE-2018-4399P4MEDIUMCVSS 5.5fixed in 12.02019-04-03
CVE-2018-4399 [MEDIUM] CWE-20 CVE-2018-4399: An access issue existed with privileged API calls. This issue was addressed with additional restrict An access issue existed with privileged API calls. This issue was addressed with additional restrictions. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
nvd
CVE-2019-8794P4MEDIUMCVSS 5.5fixed in 13.22019-12-18
CVE-2019-8794 [MEDIUM] CWE-20 CVE-2019-8794: A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.2 a A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to read restricted memory.
nvd
CVE-2021-30709P4MEDIUMCVSS 5.5fixed in 14.62021-09-08
CVE-2021-30709 [MEDIUM] CVE-2021-30709: This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.4, Security U This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted USD file may disclose memory contents.
nvd
CVE-2021-30946P4MEDIUMCVSS 5.5fixed in 15.22021-08-24
CVE-2021-30946 [MEDIUM] CVE-2021-30946: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.1, A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.1, watchOS 8.3, iOS 15.2 and iPadOS 15.2, macOS Big Sur 11.6.2. A malicious application may be able to bypass certain Privacy preferences.
nvd
CVE-2021-30685P4MEDIUMCVSS 5.5fixed in 14.62021-09-08
CVE-2021-30685 [MEDIUM] CVE-2021-30685: This issue was addressed with improved checks. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS This issue was addressed with improved checks. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. Parsing a maliciously crafted audio file may lead to disclosure of user information.
nvd
CVE-2020-9809P4MEDIUMCVSS 5.5fixed in 13.52020-06-09
CVE-2020-9809 [MEDIUM] CVE-2020-9809: An information disclosure issue was addressed with improved state management. This issue is fixed in An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A malicious application may be able to determine kernel memory layout.
nvd
CVE-2021-31007P4MEDIUMCVSS 5.5fixed in 15.12021-08-24
CVE-2021-31007 [MEDIUM] CWE-276 CVE-2021-31007: Description: A permissions issue was addressed with improved validation. This issue is fixed in iOS Description: A permissions issue was addressed with improved validation. This issue is fixed in iOS 15.1 and iPadOS 15.1, tvOS 15.1, macOS Big Sur 11.6.2, watchOS 8.1, macOS Monterey 12.1. A malicious application may be able to bypass Privacy preferences.
nvd
CVE-2021-30656P4MEDIUMCVSS 5.5fixed in 14.52021-09-08
CVE-2021-30656 [MEDIUM] CVE-2021-30656: An access issue was addressed with improved memory management. This issue is fixed in iOS 14.5 and i An access issue was addressed with improved memory management. This issue is fixed in iOS 14.5 and iPadOS 14.5. A malicious application may be able to determine kernel memory layout.
nvd
CVE-2014-1361P4MEDIUMCVSS 5.0≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1361 [MEDIUM] CWE-200 CVE-2014-1361: Secure Transport in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 does Secure Transport in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 does not ensure that a DTLS message is accepted only for a DTLS connection, which allows remote attackers to obtain potentially sensitive information from uninitialized process memory by providing a DTLS message within a TLS connection.
nvd
Apple iOS vulnerabilities | cvebase