Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 176 of 207
CVE-2015-7116P4MEDIUMCVSS 4.3≤ 9.12016-01-10
CVE-2015-7116 [MEDIUM] CVE-2015-7116: libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to
libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted XML document, a different vulnerability than CVE-2015-7115.
nvd
CVE-2015-7115P4MEDIUMCVSS 4.3≤ 9.12016-01-10
CVE-2015-7115 [MEDIUM] CWE-119 CVE-2015-7115: libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to
libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted XML document, a different vulnerability than CVE-2015-7116.
nvd
CVE-2015-7043P4MEDIUMCVSS 4.3≤ 9.12015-12-11
CVE-2015-7043 [MEDIUM] CVE-2015-7043: The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 all
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to cause a denial of service via a crafted app, a different vulnerability than CVE-2015-7040, CVE-2015-7041, and CVE-2015-7042.
nvd
CVE-2015-7041P4MEDIUMCVSS 4.3≤ 9.12015-12-11
CVE-2015-7041 [MEDIUM] CVE-2015-7041: The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 all
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to cause a denial of service via a crafted app, a different vulnerability than CVE-2015-7040, CVE-2015-7042, and CVE-2015-7043.
nvd
CVE-2015-7042P4MEDIUMCVSS 4.3≤ 9.12015-12-11
CVE-2015-7042 [MEDIUM] CVE-2015-7042: The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 all
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to cause a denial of service via a crafted app, a different vulnerability than CVE-2015-7040, CVE-2015-7041, and CVE-2015-7043.
nvd
CVE-2015-7040P4MEDIUMCVSS 4.3≤ 9.12015-12-11
CVE-2015-7040 [MEDIUM] CVE-2015-7040: The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 all
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to cause a denial of service via a crafted app, a different vulnerability than CVE-2015-7041, CVE-2015-7042, and CVE-2015-7043.
nvd
CVE-2015-5825P4MEDIUMCVSS 4.3≤ 8.4.12015-09-18
CVE-2015-5825 [MEDIUM] CWE-200 CVE-2015-5825: WebKit in Apple iOS before 9 does not properly restrict the availability of Performance API times, w
WebKit in Apple iOS before 9 does not properly restrict the availability of Performance API times, which allows remote attackers to obtain sensitive information about the browser history, mouse movement, or network traffic via crafted JavaScript code.
nvd
CVE-2015-5782P4MEDIUMCVSS 4.3≤ 8.42015-08-17
CVE-2015-5782 [MEDIUM] CWE-200 CVE-2015-5782: ImageIO in Apple iOS before 8.4.1 and OS X before 10.10.5 does not properly initialize an unspecifie
ImageIO in Apple iOS before 8.4.1 and OS X before 10.10.5 does not properly initialize an unspecified data structure, which allows remote attackers to obtain sensitive information from process memory via a crafted TIFF image.
nvd
CVE-2015-5781P4MEDIUMCVSS 4.3≤ 8.42015-08-17
CVE-2015-5781 [MEDIUM] CWE-200 CVE-2015-5781: ImageIO in Apple iOS before 8.4.1 and OS X before 10.10.5 does not properly initialize an unspecifie
ImageIO in Apple iOS before 8.4.1 and OS X before 10.10.5 does not properly initialize an unspecified data structure, which allows remote attackers to obtain sensitive information from process memory via a crafted PNG image.
nvd
CVE-2022-32875P4MEDIUMCVSS 5.0fixed in 16.02022-11-01
CVE-2022-32875 [MEDIUM] CWE-200 CVE-2022-32875: A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, watchOS 9, macOS Monterey 12.6. An app may be able to read sensitive location information.
nvd
CVE-2024-27821P4MEDIUMCVSS 4.7fixed in 17.52024-05-14
CVE-2024-27821 [MEDIUM] CWE-22 CVE-2024-27821: A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iP
A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, watchOS 10.5. A shortcut may output sensitive user data without consent.
nvd
CVE-2016-1864P4MEDIUMCVSS 4.3≤ 9.2.12016-06-19
CVE-2016-1864 [MEDIUM] CWE-200 CVE-2016-1864: The XSS auditor in WebKit, as used in Apple iOS before 9.3 and Safari before 9.1, does not properly
The XSS auditor in WebKit, as used in Apple iOS before 9.3 and Safari before 9.1, does not properly handle redirects in block mode, which allows remote attackers to obtain sensitive information via a crafted URL.
nvd
CVE-2018-4092P4MEDIUMCVSS 4.7fixed in 11.2.52018-04-03
CVE-2018-4092 [MEDIUM] CWE-362 CVE-2018-4092: An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "Kernel" component. A race condition allows attackers to bypass intended memory-read restrictions via a crafted app.
nvd
CVE-2015-5826P4MEDIUMCVSS 4.3≤ 8.4.12015-09-18
CVE-2015-5826 [MEDIUM] CWE-284 CVE-2015-5826: WebKit in Apple iOS before 9 does not properly select the cases in which a Cascading Style Sheets (C
WebKit in Apple iOS before 9 does not properly select the cases in which a Cascading Style Sheets (CSS) document is required to have the text/css content type, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
nvd
CVE-2015-1156P4MEDIUMCVSS 4.3≤ 8.32015-05-08
CVE-2015-1156 [MEDIUM] CWE-264 CVE-2015-1156: The page-loading implementation in WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, a
The page-loading implementation in WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, does not properly handle the rel attribute in an A element, which allows remote attackers to bypass the Same Origin Policy for a link's target, and spoof the user interface, via a crafted web site.
nvd
CVE-2011-2877P4MEDIUMCVSS 6.8fixed in 5.12011-10-04
CVE-2011-2877 [MEDIUM] CVE-2011-2877: Google Chrome before 14.0.835.202 does not properly handle SVG text, which allows remote attackers t
Google Chrome before 14.0.835.202 does not properly handle SVG text, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale font."
nvd
CVE-2015-1091P4MEDIUMCVSS 4.3≤ 8.22015-04-10
CVE-2015-1091 [MEDIUM] CWE-200 CVE-2015-1091: The CFNetwork Session component in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not prope
The CFNetwork Session component in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not properly handle request headers during processing of redirects in HTTP responses, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
nvd
CVE-2014-4423P4MEDIUMCVSS 4.3≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4423 [MEDIUM] CWE-264 CVE-2014-4423: The Accounts subsystem in Apple iOS before 8 allows attackers to bypass a sandbox protection mechani
The Accounts subsystem in Apple iOS before 8 allows attackers to bypass a sandbox protection mechanism and obtain an active iCloud account's Apple ID and metadata via a crafted application.
nvd
CVE-2024-23235P4MEDIUMCVSS 4.7fixed in 16.7.6≥ 17.0, < 17.42024-03-08
CVE-2024-23235 [MEDIUM] CWE-362 CVE-2024-23235: A race condition was addressed with additional validation. This issue is fixed in iOS 16.7.6 and iPa
A race condition was addressed with additional validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. An app may be able to access user-sensitive data.
nvd
CVE-2015-5787P4MEDIUMCVSS 4.3≤ 8.42015-11-22
CVE-2015-5787 [MEDIUM] CWE-264 CVE-2015-5787: The kernel in Apple iOS before 8.4.1 does not properly restrict debugging features, which allows att
The kernel in Apple iOS before 8.4.1 does not properly restrict debugging features, which allows attackers to bypass background-execution limitations via a crafted app.
nvd