cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 99 of 207
CVE-2019-8542P3HIGHCVSS 7.8fixed in 12.22019-12-18
CVE-2019-8542 [HIGH] CWE-120 CVE-2019-8542: A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.2, macO A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. A malicious application may be able to elevate privileges.
nvd
CVE-2019-6221P3HIGHCVSS 7.8fixed in 12.1.32019-03-05
CVE-2019-6221 [HIGH] CWE-125 CVE-2019-6221: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3 An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, iTunes 12.9.3 for Windows. A malicious application may be able to elevate privileges.
nvd
CVE-2016-7576P3HIGHCVSS 7.8fixed in 9.3.32019-01-11
CVE-2016-7576 [HIGH] CWE-119 CVE-2016-7576: In iOS before 9.3.3, a memory corruption issue existed in the kernel. This issue was addressed throu In iOS before 9.3.3, a memory corruption issue existed in the kernel. This issue was addressed through improved memory handling.
nvd
CVE-2018-4326P3HIGHCVSS 7.8fixed in 12.02019-04-03
CVE-2018-4326 [HIGH] CWE-119 CVE-2018-4326: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14.
nvd
CVE-2020-9827P3HIGHCVSS 7.5fixed in 13.52020-06-09
CVE-2020-9827 [HIGH] CVE-2020-9827: A denial of service issue was addressed with improved input validation. This issue is fixed in iOS 1 A denial of service issue was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A remote attacker may be able to cause a denial of service.
nvd
CVE-2020-9917P3HIGHCVSS 7.5fixed in 13.62020-10-16
CVE-2020-9917 [HIGH] CVE-2020-9917: This issue was addressed with improved checks. This issue is fixed in iOS 13.6 and iPadOS 13.6. A re This issue was addressed with improved checks. This issue is fixed in iOS 13.6 and iPadOS 13.6. A remote attacker may be able to cause a denial of service.
nvd
CVE-2015-3686P3MEDIUMCVSS 6.8≤ 8.32015-07-03
CVE-2015-3686 [MEDIUM] CVE-2015-3686: CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrar CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted text file, a different vulnerability than CVE-2015-3685, CVE-2015-3687, CVE-2015-3688, and CVE-2015-3689.
nvd
CVE-2015-3687P3MEDIUMCVSS 6.8≤ 8.32015-07-03
CVE-2015-3687 [MEDIUM] CVE-2015-3687: CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrar CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted text file, a different vulnerability than CVE-2015-3685, CVE-2015-3686, CVE-2015-3688, and CVE-2015-3689.
nvd
CVE-2015-3688P3MEDIUMCVSS 6.8≤ 8.32015-07-03
CVE-2015-3688 [MEDIUM] CVE-2015-3688: CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrar CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted text file, a different vulnerability than CVE-2015-3685, CVE-2015-3686, CVE-2015-3687, and CVE-2015-3689.
nvd
CVE-2021-30888P3HIGHCVSS 7.4fixed in 14.8.1v15.02021-08-24
CVE-2021-30888 [HIGH] CWE-601 CVE-2021-30888: An information leakage issue was addressed. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS M An information leakage issue was addressed. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, iOS 14.8.1 and iPadOS 14.8.1, tvOS 15.1, watchOS 8.1. A malicious website using Content Security Policy reports may be able to leak information via redirect behavior .
nvd
CVE-2015-7074P3MEDIUMCVSS 6.8≤ 9.12015-12-11
CVE-2015-7074 [MEDIUM] CWE-119 CVE-2015-7074: CoreMedia Playback in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote a CoreMedia Playback in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed media file.
nvd
CVE-2015-5939P3MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-5939 [MEDIUM] CVE-2015-5939: ImageIO in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attacke ImageIO in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted metadata in an image, a different vulnerability than CVE-2015-5935, CVE-2015-5936, and CVE-2015-5937.
nvd
CVE-2015-5937P3MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-5937 [MEDIUM] CVE-2015-5937: ImageIO in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attacke ImageIO in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted metadata in an image, a different vulnerability than CVE-2015-5935, CVE-2015-5936, and CVE-2015-5939.
nvd
CVE-2015-5936P3MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-5936 [MEDIUM] CVE-2015-5936: ImageIO in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attacke ImageIO in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted metadata in an image, a different vulnerability than CVE-2015-5935, CVE-2015-5937, and CVE-2015-5939.
nvd
CVE-2015-5935P3MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-5935 [MEDIUM] CWE-119 CVE-2015-5935: ImageIO in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attacke ImageIO in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted metadata in an image, a different vulnerability than CVE-2015-5936, CVE-2015-5937, and CVE-2015-5939.
nvd
CVE-2015-1093P3MEDIUMCVSS 6.8fixed in 8.32015-04-10
CVE-2015-1093 [MEDIUM] CVE-2015-1093: FontParser in Apple iOS before 8.3 and Apple OS X before 10.10.3 allows remote attackers to execute FontParser in Apple iOS before 8.3 and Apple OS X before 10.10.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file.
nvd
CVE-2015-7008P3MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-7008 [MEDIUM] CVE-2015-7008: FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitr FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7009, CVE-2015-7010, and CVE-2015-7018.
nvd
CVE-2015-7018P3MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-7018 [MEDIUM] CVE-2015-7018: FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitr FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7008, CVE-2015-7009, and CVE-2015-7010.
nvd
CVE-2015-7009P3MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-7009 [MEDIUM] CVE-2015-7009: FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitr FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7008, CVE-2015-7010, and CVE-2015-7018.
nvd
CVE-2015-6991P3MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-6991 [MEDIUM] CVE-2015-6991: FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitr FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6993, CVE-2015-7008, CVE-2015-7009, CVE-2015-7010, and CVE-2015-7018.
nvd
Apple iOS vulnerabilities | cvebase