cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 85 of 207
CVE-2012-3632P3CRITICALCVSS 9.3≤ 6.0.2v6.0+1 more2012-09-13
CVE-2012-3632 [CRITICAL] CWE-119 CVE-2012-3632: WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or ca WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
nvd
CVE-2017-2407P3HIGHCVSS 7.8≤ 10.2.12017-04-02
CVE-2017-2407 [HIGH] CWE-119 CVE-2017-2407: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "FontParser" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a cr
nvd
CVE-2017-2435P3HIGHCVSS 7.8≤ 10.2.12017-04-02
CVE-2017-2435 [HIGH] CWE-119 CVE-2017-2435: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "CoreText" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a craf
nvd
CVE-2017-2406P3HIGHCVSS 7.8≤ 10.2.12017-04-02
CVE-2017-2406 [HIGH] CWE-119 CVE-2017-2406: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "FontParser" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a cr
nvd
CVE-2015-5903P3CRITICALCVSS 10.0≤ 8.4.12015-09-18
CVE-2015-5903 [CRITICAL] CVE-2015-5903: The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5868 and CVE-2015-5896.
nvd
CVE-2017-2487P3HIGHCVSS 7.8≤ 10.2.12017-04-02
CVE-2017-2487 [HIGH] CWE-119 CVE-2017-2487: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "FontParser" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a cr
nvd
CVE-2014-4388P3HIGHCVSS 7.8≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4388 [HIGH] CWE-20 CVE-2014-4388: IOKit in Apple iOS before 8 and Apple TV before 7 does not properly validate IODataQueue object meta IOKit in Apple iOS before 8 and Apple TV before 7 does not properly validate IODataQueue object metadata, which allows attackers to execute arbitrary code in a privileged context via an application that provides crafted values in unspecified metadata fields, a different vulnerability than CVE-2014-4418.
nvd
CVE-2014-4418P3HIGHCVSS 7.8≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4418 [HIGH] CVE-2014-4418: IOKit in Apple iOS before 8 and Apple TV before 7 does not properly validate IODataQueue object meta IOKit in Apple iOS before 8 and Apple TV before 7 does not properly validate IODataQueue object metadata, which allows attackers to execute arbitrary code in a privileged context via an application that provides crafted values in unspecified metadata fields, a different vulnerability than CVE-2014-4388.
nvd
CVE-2016-1824P3HIGHCVSS 7.8fixed in 9.3.22016-05-20
CVE-2016-1824 [HIGH] CVE-2016-1824: IOHIDFamily in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2. IOHIDFamily in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1823.
nvd
CVE-2016-1750P3HIGHCVSS 7.8fixed in 9.32016-03-24
CVE-2016-1750 [HIGH] CWE-416 CVE-2016-1750: Use-after-free vulnerability in the kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before Use-after-free vulnerability in the kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2017-2434P3CRITICALCVSS 9.8≤ 10.2.12017-04-02
CVE-2017-2434 [CRITICAL] CWE-20 CVE-2017-2434: An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves t An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "HomeKit" component. It allows attackers to have an unspecified impact by leveraging the presence of Home Control on Control Center.
nvd
CVE-2017-2401P3HIGHCVSS 7.8≤ 10.2.12017-04-02
CVE-2017-2401 [HIGH] CWE-119 CVE-2017-2401: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app
nvd
CVE-2017-7009P3HIGHCVSS 7.8≤ 10.3.22017-07-20
CVE-2017-7009 [HIGH] CWE-119 CVE-2017-7009: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "IOUSBFamily" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a
nvd
CVE-2017-7026P3HIGHCVSS 7.8≤ 10.3.22017-07-20
CVE-2017-7026 [HIGH] CWE-119 CVE-2017-7026: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a craft
nvd
CVE-2017-7027P3HIGHCVSS 7.8≤ 10.3.22017-07-20
CVE-2017-7027 [HIGH] CWE-119 CVE-2017-7027: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a craft
nvd
CVE-2019-8593P3HIGHCVSS 7.8fixed in 12.32019-12-18
CVE-2019-8593 [HIGH] CWE-787 CVE-2019-8593: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12 A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.3, tvOS 12.3, watchOS 5.2.1. An application may be able to execute arbitrary code with system privileges.
nvd
CVE-2016-4698P3HIGHCVSS 7.8≤ 9.3.52016-09-25
CVE-2016-4698 [HIGH] CWE-20 CVE-2016-4698: AppleMobileFileIntegrity in Apple iOS before 10 and OS X before 10.12 mishandles process entitlement AppleMobileFileIntegrity in Apple iOS before 10 and OS X before 10.12 mishandles process entitlement and Team ID values in the task port inheritance policy, which allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2017-7162P3HIGHCVSS 7.8fixed in 11.22017-12-27
CVE-2017-7162 [HIGH] CWE-119 CVE-2017-7162: An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "IOKit" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2017-7069P3HIGHCVSS 7.8≤ 10.3.22017-07-20
CVE-2017-7069 [HIGH] CWE-119 CVE-2017-7069: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a craft
nvd
CVE-2015-7053P3MEDIUMCVSS 6.8≤ 9.12015-12-11
CVE-2015-7053 [MEDIUM] CWE-119 CVE-2015-7053: ImageIO in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows ImageIO in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted image.
nvd
Apple iOS vulnerabilities | cvebase