cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 185 of 207
CVE-2013-3955P4MEDIUMCVSS 6.2v5.0v5.0.1+8 more2013-06-05
CVE-2013-3955 [MEDIUM] CWE-20 CVE-2013-3955: The get_xattrinfo function in the XNU kernel in Apple iOS 5.x and 6.x through 6.1.3 on iPad devices The get_xattrinfo function in the XNU kernel in Apple iOS 5.x and 6.x through 6.1.3 on iPad devices does not properly validate the header of an AppleDouble file, which might allow local users to cause a denial of service (memory corruption) or have unspecified other impact via an invalid file on an msdosfs filesystem.
nvd
CVE-2010-4012P4MEDIUMCVSS 6.2v4.0v4.12010-12-08
CVE-2010-4012 [MEDIUM] CWE-362 CVE-2010-4012: Race condition in Apple iOS 4.0 through 4.1 for iPhone 3G and later allows physically proximate atta Race condition in Apple iOS 4.0 through 4.1 for iPhone 3G and later allows physically proximate attackers to bypass the passcode lock by making a call from the Emergency Call screen, then quickly pressing the Sleep/Wake button.
nvd
CVE-2014-4373P4MEDIUMCVSS 5.5≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4373 [MEDIUM] CVE-2014-4373: The IntelAccelerator driver in the IOAcceleratorFamily subsystem in Apple iOS before 8 and Apple TV The IntelAccelerator driver in the IOAcceleratorFamily subsystem in Apple iOS before 8 and Apple TV before 7 allows attackers to cause a denial of service (NULL pointer dereference and device restart) via a crafted application.
nvd
CVE-2017-2368P4MEDIUMCVSS 5.5≤ 10.2.02017-02-20
CVE-2017-2368 [MEDIUM] CWE-20 CVE-2017-2368: An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "Contacts" component. It allows remote attackers to cause a denial of service (application crash) via a crafted contact card.
nvd
CVE-2018-4400P4MEDIUMCVSS 5.5fixed in 12.12019-04-03
CVE-2018-4400 [MEDIUM] CWE-20 CVE-2018-4400: A validation issue was addressed with improved logic. This issue affected versions prior to iOS 12.1 A validation issue was addressed with improved logic. This issue affected versions prior to iOS 12.1, macOS Mojave 10.14.1, watchOS 5.1.
nvd
CVE-2019-8538P4MEDIUMCVSS 5.5fixed in 12.22020-10-27
CVE-2019-8538 [MEDIUM] CVE-2019-8538: A denial of service issue was addressed with improved validation. This issue is fixed in watchOS 5.2 A denial of service issue was addressed with improved validation. This issue is fixed in watchOS 5.2, macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, iOS 12.2. Processing a maliciously crafted vcf file may lead to a denial of service.
nvd
CVE-2017-7097P4MEDIUMCVSS 5.5≤ 10.3.32017-10-23
CVE-2017-7097 [MEDIUM] CWE-119 CVE-2017-7097: An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Mail MessageUI" component. It allows attackers to cause a denial of service (memory corruption) via a crafted image.
nvd
CVE-2018-4365P4MEDIUMCVSS 5.5fixed in 12.12019-04-03
CVE-2018-4365 [MEDIUM] CWE-125 CVE-2018-4365: An out-of-bounds read was addressed with improved bounds checking. This issue affected versions prio An out-of-bounds read was addressed with improved bounds checking. This issue affected versions prior to iOS 12.1.
nvd
CVE-2022-32827P4MEDIUMCVSS 5.5fixed in 16.02022-11-01
CVE-2022-32827 [MEDIUM] CWE-787 CVE-2022-32827: A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 1 A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 16, macOS Ventura 13. An app may be able to cause a denial-of-service.
nvd
CVE-2016-1865P4MEDIUMCVSS 5.5fixed in 9.3.32016-07-22
CVE-2016-1865 [MEDIUM] CWE-476 CVE-2016-1865: The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2 The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to cause a denial of service (NULL pointer dereference) via unspecified vectors.
nvd
CVE-2025-24091P4MEDIUMCVSS 5.5≤ 18.32025-04-30
CVE-2025-24091 [MEDIUM] CWE-290 CVE-2025-24091: An app could impersonate system notifications. Sensitive notifications now require restricted entitl An app could impersonate system notifications. Sensitive notifications now require restricted entitlements. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.3. An app may be able to cause a denial-of-service.
nvd
CVE-2023-32385P4MEDIUMCVSS 5.5fixed in 16.52023-06-23
CVE-2023-32385 [MEDIUM] CWE-770 CVE-2023-32385: A denial-of-service issue was addressed with improved memory handling. This issue is fixed in iOS 16 A denial-of-service issue was addressed with improved memory handling. This issue is fixed in iOS 16.5 and iPadOS 16.5, macOS Ventura 13.4. Opening a PDF file may lead to unexpected app termination.
nvd
CVE-2015-5862P4MEDIUMCVSS 4.3≤ 8.4.12015-09-18
CVE-2015-5862 [MEDIUM] CWE-119 CVE-2015-5862: The Audio component in Apple iOS before 9 allows remote attackers to cause a denial of service (memo The Audio component in Apple iOS before 9 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted audio file.
nvd
CVE-2007-3755P4MEDIUMCVSS 4.3v1.0.1v1.0.22007-09-27
CVE-2007-3755 [MEDIUM] CWE-20 CVE-2007-3755: Mail in Apple iPhone 1.1.1 allows remote user-assisted attackers to force the iPhone user to make ca Mail in Apple iPhone 1.1.1 allows remote user-assisted attackers to force the iPhone user to make calls to arbitrary telephone numbers via a "tel:" link, which does not prompt the user before dialing the number.
nvd
CVE-2011-3243P4MEDIUMCVSS 4.3v3.0v3.1+17 more2011-10-14
CVE-2011-3243 [MEDIUM] CWE-79 CVE-2011-3243: Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5 and Safari before Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5 and Safari before 5.1.1, allows remote attackers to inject arbitrary web script or HTML via vectors involving inactive DOM windows.
nvd
CVE-2015-5856P4MEDIUMCVSS 4.3≤ 8.4.12015-09-18
CVE-2015-5856 [MEDIUM] CWE-254 CVE-2015-5856: The Application Store component in Apple iOS before 9 allows remote attackers to cause a denial of s The Application Store component in Apple iOS before 9 allows remote attackers to cause a denial of service to an enterprise-signed app via a crafted ITMS URL.
nvd
CVE-2009-0960P4MEDIUMCVSS 4.3v1.0.0v1.0.1+15 more2009-06-19
CVE-2009-0960 [MEDIUM] CVE-2009-0960: The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2 The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 does not provide an option to disable remote image loading in HTML email, which allows remote attackers to determine the device address and when an e-mail is read via an HTML email containing an image URL.
nvd
CVE-2011-3426P4MEDIUMCVSS 4.3v3.0v3.1+17 more2011-10-14
CVE-2011-3426 [MEDIUM] CWE-79 CVE-2011-3426: Cross-site scripting (XSS) vulnerability in Safari in Apple iOS before 5 allows remote web servers t Cross-site scripting (XSS) vulnerability in Safari in Apple iOS before 5 allows remote web servers to inject arbitrary web script or HTML via a file accompanied by a "Content-Disposition: attachment" HTTP header.
nvd
CVE-2013-5129P4MEDIUMCVSS 4.3≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-5129 [MEDIUM] CWE-79 CVE-2013-5129: Multiple cross-site scripting (XSS) vulnerabilities in WebKit in Apple iOS before 7 allow user-assis Multiple cross-site scripting (XSS) vulnerabilities in WebKit in Apple iOS before 7 allow user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving a (1) drag-and-drop or (2) copy-and-paste operation.
nvd
CVE-2013-5131P4MEDIUMCVSS 4.3≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-5131 [MEDIUM] CWE-79 CVE-2013-5131: Cross-site scripting (XSS) vulnerability in WebKit in Apple iOS before 7 allows remote attackers to Cross-site scripting (XSS) vulnerability in WebKit in Apple iOS before 7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
Apple iOS vulnerabilities | cvebase