Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 207 of 207
CVE-2014-4352P4LOWCVSS 2.1≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4352 [LOW] CWE-310 CVE-2014-4352: Address Book in Apple iOS before 8 relies on the hardware UID for its encryption key, which makes it
Address Book in Apple iOS before 8 relies on the hardware UID for its encryption key, which makes it easier for physically proximate attackers to obtain sensitive information by obtaining this UID.
nvd
CVE-2008-4230P4LOWCVSS 1.9v1.0v1.0.1+11 more2008-11-25
CVE-2008-4230 [LOW] CWE-200 CVE-2008-4230: The Passcode Lock feature in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 throug
The Passcode Lock feature in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 displays SMS messages when the emergency-call screen is visible, which allows physically proximate attackers to obtain sensitive information by reading these messages. NOTE: this might be a duplicate of CVE-2008-4593.
nvd
CVE-2012-3734P4LOWCVSS 1.9≤ 5.1.1v1.0.0+38 more2012-09-20
CVE-2012-3734 [LOW] CWE-310 CVE-2012-3734: Office Viewer in Apple iOS before 6 writes cleartext document data to a temporary file, which might
Office Viewer in Apple iOS before 6 writes cleartext document data to a temporary file, which might allow local users to bypass a document's intended (1) Data Protection level or (2) encryption state by reading the temporary content.
nvd
CVE-2021-30956P4LOWCVSS 2.4fixed in 15.22021-08-24
CVE-2021-30956 [LOW] CVE-2021-30956: A lock screen issue allowed access to contacts on a locked device. This issue was addressed with imp
A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. This issue is fixed in iOS 15.2 and iPadOS 15.2. An attacker with physical access to a device may be able to see private contact information.
nvd
CVE-2018-4387P4LOWCVSS 2.4fixed in 12.12019-04-03
CVE-2018-4387 [LOW] CWE-200 CVE-2018-4387: A lock screen issue allowed access to photos via Reply With Message on a locked device. This issue w
A lock screen issue allowed access to photos via Reply With Message on a locked device. This issue was addressed with improved state management. This issue affected versions prior to iOS 12.1.
nvd
CVE-2020-3828P4LOWCVSS 2.4fixed in 13.3.12020-02-27
CVE-2020-3828 [LOW] CVE-2020-3828: A lock screen issue allowed access to contacts on a locked device. This issue was addressed with imp
A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1. A person with physical access to an iOS device may be able to access contacts from the lock screen.
nvd
CVE-2019-8775P4LOWCVSS 2.4fixed in 13.12019-12-18
CVE-2019-8775 [LOW] CVE-2019-8775: The issue was addressed by restricting options offered on a locked device. This issue is fixed in iO
The issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 13.1 and iPadOS 13.1. A person with physical access to an iOS device may be able to access contacts from the lock screen.
nvd
CVE-2020-3891P4LOWCVSS 2.4fixed in 13.42020-04-01
CVE-2020-3891 [LOW] CVE-2020-3891: A logic issue was addressed with improved state management. This issue is fixed in iOS 13.4 and iPad
A logic issue was addressed with improved state management. This issue is fixed in iOS 13.4 and iPadOS 13.4, watchOS 6.2. A person with physical access to a locked iOS device may be able to respond to messages even when replies are disabled.
nvd
CVE-2018-4430P4LOWCVSS 2.4fixed in 12.1.12019-04-03
CVE-2018-4430 [LOW] CWE-200 CVE-2018-4430: A lock screen issue allowed access to contacts on a locked device. This issue was addressed with imp
A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. This issue affected versions prior to iOS 12.1.1.
nvd
CVE-2020-9848P4LOWCVSS 2.4fixed in 13.52020-06-09
CVE-2020-9848 [LOW] CVE-2020-9848: An authorization issue was addressed with improved state management. This issue is fixed in iOS 13.5
An authorization issue was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5. A person with physical access to an iOS device may be able to view notification contents from the lockscreen.
nvd
CVE-2020-9959P4LOWCVSS 2.4fixed in 14.02020-10-16
CVE-2020-9959 [LOW] CWE-667 CVE-2020-9959: A lock screen issue allowed access to messages on a locked device. This issue was addressed with imp
A lock screen issue allowed access to messages on a locked device. This issue was addressed with improved state management. This issue is fixed in iOS 14.0 and iPadOS 14.0. A person with physical access to an iOS device may be able to view notification contents from the lockscreen.
nvd
CVE-2009-2207P4LOWCVSS 2.1v3.0v3.0.12009-09-10
CVE-2009-2207 [LOW] CWE-264 CVE-2009-2207: The MobileMail component in Apple iPhone OS 3.0 and 3.0.1, and iPhone OS 3.0 for iPod touch, lists d
The MobileMail component in Apple iPhone OS 3.0 and 3.0.1, and iPhone OS 3.0 for iPod touch, lists deleted e-mail messages in Spotlight search results, which might allow local users to obtain sensitive information by reading these messages.
nvd
CVE-2018-4325P4LOWCVSS 2.4fixed in 12.02019-04-03
CVE-2018-4325 [LOW] CWE-200 CVE-2018-4325: A logic issue was addressed with improved restrictions. This issue affected versions prior to iOS 12
A logic issue was addressed with improved restrictions. This issue affected versions prior to iOS 12.
nvd
CVE-2011-3431P4LOWCVSS 2.1v3.0v3.1+17 more2011-10-14
CVE-2011-3431 [LOW] CWE-200 CVE-2011-3431: The Home screen component in Apple iOS before 5 does not properly support a certain application-swit
The Home screen component in Apple iOS before 5 does not properly support a certain application-switching gesture, which might allow physically proximate attackers to obtain sensitive state information by watching the device's screen.
nvd
← Previous207 / 207