cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 91 of 207
CVE-2015-7105P3MEDIUMCVSS 6.8≤ 9.12015-12-11
CVE-2015-7105 [MEDIUM] CWE-119 CVE-2015-7105: CoreGraphics in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 a CoreGraphics in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file.
nvd
CVE-2018-4109P3HIGHCVSS 7.8fixed in 11.2.52018-04-03
CVE-2018-4109 [HIGH] CWE-119 CVE-2018-4109: An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2010-3832P3MEDIUMCVSS 6.8≤ 4.1v1.0.0+27 more2010-11-26
CVE-2010-3832 [MEDIUM] CWE-119 CVE-2010-3832: Heap-based buffer overflow in the GSM mobility management implementation in Telephony in Apple iOS b Heap-based buffer overflow in the GSM mobility management implementation in Telephony in Apple iOS before 4.2 on the iPhone and iPad allows remote attackers to execute arbitrary code on the baseband processor via a crafted Temporary Mobile Subscriber Identity (TMSI) field.
nvd
CVE-2021-1764P3HIGHCVSS 7.5fixed in 14.42021-04-02
CVE-2021-1764 [HIGH] CWE-416 CVE-2021-1764: A use after free issue was addressed with improved memory management. This issue is fixed in macOS B A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause a denial of service.
nvd
CVE-2024-54468P3HIGHCVSS 8.2fixed in 18.22025-01-27
CVE-2024-54468 [HIGH] CVE-2024-54468: The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadO The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, watchOS 11.2. An app may be able to break out of its sandbox.
nvd
CVE-2012-3607P3CRITICALCVSS 9.3≤ 6.0.2v6.0+1 more2012-09-13
CVE-2012-3607 [CRITICAL] CWE-119 CVE-2012-3607: WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or ca WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
nvd
CVE-2012-3606P3CRITICALCVSS 9.3≤ 6.0.2v6.0+1 more2012-09-13
CVE-2012-3606 [CRITICAL] CWE-119 CVE-2012-3606: WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or ca WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
nvd
CVE-2012-3687P3CRITICALCVSS 9.3≤ 6.0.2v6.0+1 more2012-09-13
CVE-2012-3687 [CRITICAL] CWE-119 CVE-2012-3687: WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or ca WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
nvd
CVE-2012-3621P3CRITICALCVSS 9.3≤ 6.0.2v6.0+1 more2012-09-13
CVE-2012-3621 [CRITICAL] CWE-119 CVE-2012-3621: WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or ca WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
nvd
CVE-2012-3701P3CRITICALCVSS 9.3≤ 6.0.2v6.0+1 more2012-09-13
CVE-2012-3701 [CRITICAL] CWE-119 CVE-2012-3701: WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or ca WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
nvd
CVE-2020-9958P3HIGHCVSS 7.8fixed in 14.02020-10-16
CVE-2020-9958 [HIGH] CWE-787 CVE-2020-9958: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 14.0 and iPadOS 14.0. An application may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2021-1813P3HIGHCVSS 7.8fixed in 14.52021-09-08
CVE-2021-1813 [HIGH] CWE-269 CVE-2021-1813: A validation issue was addressed with improved logic. This issue is fixed in Security Update 2021-00 A validation issue was addressed with improved logic. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A malicious application may be able to gain root privileges.
nvd
CVE-2019-8516P3HIGHCVSS 7.5fixed in 12.22019-12-18
CVE-2019-8516 [HIGH] CWE-20 CVE-2019-8516: A validation issue was addressed with improved logic. This issue is fixed in iOS 12.2, macOS Mojave A validation issue was addressed with improved logic. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. Processing a maliciously crafted string may lead to a denial of service.
nvd
CVE-2019-8573P3HIGHCVSS 7.5fixed in 12.32020-10-27
CVE-2019-8573 [HIGH] CWE-20 CVE-2019-8573: An input validation issue was addressed with improved input validation. This issue is fixed in macOS An input validation issue was addressed with improved input validation. This issue is fixed in macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, iOS 12.3, watchOS 5.2.1. A remote attacker may be able to cause a system denial of service.
nvd
CVE-2010-3257P3CRITICALCVSS 9.3fixed in 4.22010-09-07
CVE-2010-3257 [CRITICAL] CWE-416 CVE-2010-3257: Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving element focus.
nvd
CVE-2019-8637P3HIGHCVSS 7.8fixed in 12.32019-12-18
CVE-2019-8637 [HIGH] CWE-20 CVE-2019-8637: An input validation issue was addressed with improved input validation. This issue is fixed in iOS 1 An input validation issue was addressed with improved input validation. This issue is fixed in iOS 12.3, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to gain root privileges.
nvd
CVE-2020-3856P3HIGHCVSS 7.8fixed in 13.3.12020-02-27
CVE-2020-3856 [HIGH] CWE-20 CVE-2020-3856: A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 1 A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. Processing a maliciously crafted string may lead to heap corruption.
nvd
CVE-2020-3829P3HIGHCVSS 7.8fixed in 13.3.12020-02-27
CVE-2020-3829 [HIGH] CWE-125 CVE-2020-3829: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.3.1 An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to gain elevated privileges.
nvd
CVE-2017-2484P3HIGHCVSS 7.5≤ 10.2.12017-04-02
CVE-2017-2484 [HIGH] CVE-2017-2484: An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves t An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "Phone" component. It allows attackers to trigger telephone calls to arbitrary numbers via a third-party app.
nvd
CVE-2015-3684P3MEDIUMCVSS 6.8≤ 8.32015-07-03
CVE-2015-3684 [MEDIUM] CWE-119 CVE-2015-3684: The HTTPAuthentication implementation in CFNetwork in Apple iOS before 8.4 and OS X before 10.10.4 a The HTTPAuthentication implementation in CFNetwork in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted credentials in a URL.
nvd