cbcvebase.

Apple Safari vulnerabilities

1,613 known vulnerabilities affecting apple/safari.

Total CVEs
1,613
CISA KEV
31
actively exploited
Public exploits
157
Exploited in wild
25
Severity breakdown
CRITICAL211HIGH615MEDIUM766LOW20UNKNOWN1

Vulnerabilities

Page 14 of 81
CVE-2022-46698MEDIUMCVSS 6.5fixed in 16.22022-12-15
CVE-2022-46698 [MEDIUM] CWE-693 CVE-2022-46698: A logic issue was addressed with improved checks. This issue is fixed in Safari 16.2, tvOS 16.2, iCl A logic issue was addressed with improved checks. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may disclose sensitive user information.
nvdapple
CVE-2022-3970HIGHCVSS 8.8fixed in 16.5.12022-11-13
CVE-2022-3970 [HIGH] CWE-189 CVE-2022-3970: A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 227500897dfb07fb7d27f
nvd
CVE-2022-42823HIGHCVSS 8.8fixed in 16.12022-11-01
CVE-2022-42823 [HIGH] CWE-843 CVE-2022-42823: A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1 A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2022-32892HIGHCVSS 8.6fixed in 16.02022-11-01
CVE-2022-32892 [HIGH] CVE-2022-32892: An access issue was addressed with improvements to the sandbox. This issue is fixed in Safari 16, iO An access issue was addressed with improvements to the sandbox. This issue is fixed in Safari 16, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Ventura 13. A sandboxed process may be able to circumvent sandbox restrictions.
nvdapple
CVE-2022-32922HIGHCVSS 8.8fixed in 16.12022-11-01
CVE-2022-32922 [HIGH] CWE-416 CVE-2022-32922: A use after free issue was addressed with improved memory management. This issue is fixed in Safari A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2022-26717HIGHCVSS 8.8fixed in 15.52022-11-01
CVE-2022-26717 [HIGH] CWE-416 CVE-2022-26717: A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15 A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, Safari 15.5, iTunes 12.12.4 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2022-26716HIGHCVSS 8.8fixed in 15.52022-11-01
CVE-2022-26716 [HIGH] CWE-787 CVE-2022-26716: A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4, Safari 15.5. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2022-26709HIGHCVSS 8.8fixed in 15.52022-11-01
CVE-2022-26709 [HIGH] CWE-416 CVE-2022-26709: A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15 A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4, Safari 15.5. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2022-26719HIGHCVSS 8.8fixed in 15.52022-11-01
CVE-2022-26719 [HIGH] CWE-787 CVE-2022-26719: A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4, Safari 15.5. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2022-42799MEDIUMCVSS 6.1fixed in 16.12022-11-01
CVE-2022-42799 [MEDIUM] CWE-1021 CVE-2022-42799: The issue was addressed with improved UI handling. This issue is fixed in tvOS 16.1, macOS Ventura 1 The issue was addressed with improved UI handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Visiting a malicious website may lead to user interface spoofing.
nvdapple
CVE-2022-42824MEDIUMCVSS 5.5fixed in 16.12022-11-01
CVE-2022-42824 [MEDIUM] CVE-2022-42824: A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.1, macOS A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may disclose sensitive user information.
nvdapple
CVE-2022-32923MEDIUMCVSS 6.5fixed in 16.12022-11-01
CVE-2022-32923 [MEDIUM] CWE-79 CVE-2022-32923: A correctness issue in the JIT was addressed with improved checks. This issue is fixed in tvOS 16.1, A correctness issue in the JIT was addressed with improved checks. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may disclose internal states of the app.
nvdapple
CVE-2022-22629HIGHCVSS 8.8fixed in 15.4≥ unspecified, < 15.42022-09-23
CVE-2022-22629 [HIGH] CWE-787 CVE-2022-22629: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Mo A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iTunes 12.12.3 for Windows, iOS 15.4 and iPadOS 15.4, tvOS 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2022-22628HIGHCVSS 8.8fixed in 15.4≥ unspecified, < 15.42022-09-23
CVE-2022-22628 [HIGH] CWE-416 CVE-2022-22628: A use after free issue was addressed with improved memory management. This issue is fixed in macOS M A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2022-22637HIGHCVSS 8.8fixed in 15.4≥ unspecified, < 15.42022-09-23
CVE-2022-22637 [HIGH] CWE-346 CVE-2022-22637: A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12 A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. A malicious website may cause unexpected cross-origin behavior.
nvdapple
CVE-2022-22624HIGHCVSS 8.8fixed in 15.4≥ unspecified, < 15.42022-09-23
CVE-2022-22624 [HIGH] CWE-416 CVE-2022-22624: A use after free issue was addressed with improved memory management. This issue is fixed in macOS M A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.3, iOS 15.4 and iPadOS 15.4, tvOS 15.4, Safari 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2022-22610HIGHCVSS 8.8fixed in 15.4≥ unspecified, < 15.42022-09-23
CVE-2022-22610 [HIGH] CWE-787 CVE-2022-22610: A memory corruption issue was addressed with improved state management. This issue is fixed in macOS A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. Processing maliciously crafted web content may lead to code execution.
nvdapple
CVE-2022-26700HIGHCVSS 8.8fixed in 15.52022-09-23
CVE-2022-26700 [HIGH] CWE-787 CVE-2022-26700: A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, Safari 15.5. Processing maliciously crafted web content may lead to code execution.
nvdapple
CVE-2022-32863CRITICALCVSS 9.8fixed in 15.62022-09-20
CVE-2022-32863 [CRITICAL] CWE-787 CVE-2022-32863: A memory corruption issue was addressed with improved state management. This issue is fixed in Safar A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 15.6, macOS Monterey 12.5. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2022-32912HIGHCVSS 8.8fixed in 16.0≥ unspecified, < 162022-09-20
CVE-2022-32912 [HIGH] CWE-125 CVE-2022-32912: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 16, An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple