Apple iOS vulnerabilities

3,941 known vulnerabilities affecting apple/iphone_os.

Total CVEs
3,941
CISA KEV
92
actively exploited
Public exploits
248
Exploited in wild
79
Severity breakdown
CRITICAL313HIGH1610MEDIUM1731LOW287

Vulnerabilities

Page 188 of 198
CVE-2011-3036MEDIUMCVSS 6.8fixed in 6.02012-03-05
CVE-2011-3036 [MEDIUM] CWE-704 CVE-2011-3036: Google Chrome before 17.0.963.65 does not properly perform a cast of an unspecified variable during Google Chrome before 17.0.963.65 does not properly perform a cast of an unspecified variable during handling of line boxes, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.
nvd
CVE-2011-3038MEDIUMCVSS 6.8fixed in 6.02012-03-05
CVE-2011-3038 [MEDIUM] CWE-416 CVE-2011-3038: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to multi-column handling.
nvd
CVE-2011-3044MEDIUMCVSS 6.8fixed in 6.02012-03-05
CVE-2011-3044 [MEDIUM] CWE-416 CVE-2011-3044: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG animation elements.
nvd
CVE-2011-3035MEDIUMCVSS 6.8fixed in 6.02012-03-05
CVE-2011-3035 [MEDIUM] CWE-416 CVE-2011-3035: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG use elements.
nvd
CVE-2011-3042MEDIUMCVSS 6.8fixed in 6.02012-03-05
CVE-2011-3042 [MEDIUM] CWE-416 CVE-2011-3042: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of table sections.
nvd
CVE-2011-3040MEDIUMCVSS 4.3fixed in 6.02012-03-05
CVE-2011-3040 [MEDIUM] CWE-125 CVE-2011-3040: Google Chrome before 17.0.963.65 does not properly handle text, which allows remote attackers to cau Google Chrome before 17.0.963.65 does not properly handle text, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted document.
nvd
CVE-2011-3034MEDIUMCVSS 6.8fixed in 6.02012-03-05
CVE-2011-3034 [MEDIUM] CWE-416 CVE-2011-3034: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving an SVG document.
nvd
CVE-2011-3037MEDIUMCVSS 6.8fixed in 6.02012-03-05
CVE-2011-3037 [MEDIUM] CWE-704 CVE-2011-3037: Google Chrome before 17.0.963.65 does not properly perform casts of unspecified variables during the Google Chrome before 17.0.963.65 does not properly perform casts of unspecified variables during the splitting of anonymous blocks, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.
nvd
CVE-2011-3021HIGHCVSS 7.5fixed in 6.02012-02-16
CVE-2011-3021 [HIGH] CWE-416 CVE-2011-3021: Use-after-free vulnerability in Google Chrome before 17.0.963.56 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 17.0.963.56 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to subframe loading.
nvd
CVE-2011-3026MEDIUMCVSS 6.8fixed in 6.02012-02-16
CVE-2011-3026 [MEDIUM] CWE-190 CVE-2011-3026: Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an integer truncation.
nvd
CVE-2011-3027MEDIUMCVSS 4.3fixed in 6.02012-02-16
CVE-2011-3027 [MEDIUM] CWE-704 CVE-2011-3027: Google Chrome before 17.0.963.56 does not properly perform a cast of an unspecified variable during Google Chrome before 17.0.963.56 does not properly perform a cast of an unspecified variable during handling of columns, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.
nvd
CVE-2011-3016MEDIUMCVSS 6.8fixed in 6.02012-02-16
CVE-2011-3016 [MEDIUM] CWE-416 CVE-2011-3016: Use-after-free vulnerability in Google Chrome before 17.0.963.56 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 17.0.963.56 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving counter nodes, related to a "read-after-free" issue.
nvd
CVE-2011-3966HIGHCVSS 7.5fixed in 6.02012-02-09
CVE-2011-3966 [HIGH] CWE-416 CVE-2011-3966: Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to error handling for Cascading Style Sheets (CSS) token-sequence data.
nvd
CVE-2011-3969MEDIUMCVSS 6.8fixed in 6.02012-02-09
CVE-2011-3969 [MEDIUM] CWE-416 CVE-2011-3969: Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to layout of SVG documents.
nvd
CVE-2011-3958MEDIUMCVSS 6.8fixed in 6.02012-02-09
CVE-2011-3958 [MEDIUM] CWE-416 CVE-2011-3958: Google Chrome before 17.0.963.46 does not properly perform casts of variables during handling of a c Google Chrome before 17.0.963.46 does not properly perform casts of variables during handling of a column span, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.
nvd
CVE-2011-3968MEDIUMCVSS 4.3fixed in 6.02012-02-09
CVE-2011-3968 [MEDIUM] CWE-416 CVE-2011-3968: Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving Cascading Style Sheets (CSS) token sequences.
nvd
CVE-2011-3971MEDIUMCVSS 6.8fixed in 6.02012-02-09
CVE-2011-3971 [MEDIUM] CWE-416 CVE-2011-3971: Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows user-assisted remote attacke Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to mousemove events.
nvd
CVE-2011-3924HIGHCVSS 7.5fixed in 6.02012-01-24
CVE-2011-3924 [HIGH] CWE-416 CVE-2011-3924: Use-after-free vulnerability in Google Chrome before 16.0.912.77 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 16.0.912.77 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to DOM selections.
nvd
CVE-2011-3926HIGHCVSS 7.5fixed in 6.02012-01-24
CVE-2011-3926 [HIGH] CWE-787 CVE-2011-3926: Heap-based buffer overflow in the tree builder in Google Chrome before 16.0.912.77 allows remote att Heap-based buffer overflow in the tree builder in Google Chrome before 16.0.912.77 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-3928HIGHCVSS 7.5fixed in 5.12012-01-24
CVE-2011-3928 [HIGH] CWE-416 CVE-2011-3928: Use-after-free vulnerability in Google Chrome before 16.0.912.77 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 16.0.912.77 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to DOM handling.
nvd