cbcvebase.

Apple Safari vulnerabilities

1,654 known vulnerabilities affecting apple/safari.

Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH622MEDIUM790LOW20UNKNOWN11

Vulnerabilities

Page 15 of 83
CVE-2023-42866P3HIGHCVSS 8.8fixed in 16.6≥ unspecified, < 16.62024-01-10
CVE-2023-42866 [HIGH] CVE-2023-42866: The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.5, iO The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, tvOS 16.6, Safari 16.6, watchOS 9.6. Processing web content may lead to arbitrary code execution.
nvdapple
CVE-2007-3284P4HIGHCVSS 7.8PoCv3.0.12007-06-19
CVE-2007-3284 [HIGH] CVE-2007-3284: corefoundation.dll in Apple Safari 3.0.1 (552.12.2) for Windows allows remote attackers to cause a d corefoundation.dll in Apple Safari 3.0.1 (552.12.2) for Windows allows remote attackers to cause a denial of service (crash) via certain forms that trigger errors related to History, possibly involving multiple form fields with the same name.
nvd
CVE-2017-7092P3HIGHCVSS 8.8≤ 10.1.22017-10-23
CVE-2017-7092 [HIGH] CWE-119 CVE-2017-7092: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory c
nvdapple
CVE-2007-0342P4HIGHCVSS 7.5PoCv2.0.4_419.32007-01-18
CVE-2007-0342 [HIGH] CVE-2007-0342: WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null deref WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and application crash) via a TD element with a large number in the ROWSPAN attribute, as demonstrated by a crash of OmniWeb 5.5.3 on Mac OS X 10.4.8, a different vulnerability than CVE-2006-2019.
nvd
CVE-2024-54534P3CRITICALCVSS 9.8fixed in 18.22024-12-12
CVE-2024-54534 [CRITICAL] CWE-787 CVE-2024-54534: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.6, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to memory corruption.
nvd
CVE-2017-2415P3HIGHCVSS 8.8v10.12017-03-27
CVE-2017-2415 [HIGH] CVE-2017-2415: Safari 10.1 Apple Security Update: About the security content of Safari 10.1 Product: Safari Version: 10.1 CVE: CVE-2017-2415 Component: WebKit Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: A type confusion issue was addressed through improved memory handling.
apple
CVE-2011-0167P4MEDIUMCVSS 4.3PoC≤ 5.0.3v1.0+52 more2011-03-11
CVE-2011-0167 [MEDIUM] CWE-264 CVE-2011-0167: The windows functionality in WebKit in Apple Safari before 5.0.4 allows remote attackers to bypass t The windows functionality in WebKit in Apple Safari before 5.0.4 allows remote attackers to bypass the Same Origin Policy, and force the upload of arbitrary local files from a client computer, via a crafted web site.
nvd
CVE-2020-9893P3HIGHCVSS 8.8fixed in 13.1.2≥ unspecified, < Safari 13.1.22020-10-16
CVE-2020-9893 [HIGH] CWE-416 CVE-2020-9893: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13. A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
nvdapple
CVE-2020-9951P3HIGHCVSS 8.8fixed in 14.0≥ unspecified, < Safari 14.02020-10-16
CVE-2020-9951 [HIGH] CWE-416 CVE-2020-9951: A use after free issue was addressed with improved memory management. This issue is fixed in Safari A use after free issue was addressed with improved memory management. This issue is fixed in Safari 14.0. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2020-9983P3HIGHCVSS 8.8fixed in 14.0≥ unspecified, < Safari 14.02020-10-16
CVE-2020-9983 [HIGH] CWE-787 CVE-2020-9983: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Saf An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Safari 14.0. Processing maliciously crafted web content may lead to code execution.
nvd
CVE-2019-7285P3HIGHCVSS 8.8fixed in 12.1≥ unspecified, < Safari 12.12019-12-18
CVE-2019-7285 [HIGH] CWE-416 CVE-2019-7285: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12. A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2019-6227P3HIGHCVSS 8.8fixed in 12.0.3≥ unspecified, < Safari 12.0.32019-03-05
CVE-2019-6227 [HIGH] CWE-787 CVE-2019-6227: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12 A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, watchOS 5.1.3, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2020-3865P3HIGHCVSS 8.8fixed in 13.0.5≥ unspecified, < Safari 13.0.52020-02-27
CVE-2020-3865 [HIGH] CWE-787 CVE-2020-3865: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2021-30797P3HIGHCVSS 8.8fixed in 14.1.22021-09-08
CVE-2021-30797 [HIGH] CVE-2021-30797: This issue was addressed with improved checks. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS This issue was addressed with improved checks. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. Processing maliciously crafted web content may lead to code execution.
nvdapple
CVE-2019-8583P3HIGHCVSS 8.8fixed in 12.1.1≥ unspecified, < Safari 12.1.12019-12-18
CVE-2019-8583 [HIGH] CWE-787 CVE-2019-8583: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2019-6234P3HIGHCVSS 8.8fixed in 12.0.3≥ unspecified, < Safari 12.0.32019-03-05
CVE-2019-6234 [HIGH] CWE-787 CVE-2019-6234: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12 A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2019-8686P3HIGHCVSS 8.8fixed in 12.1.2≥ unspecified, < Safari 12.1.22019-12-18
CVE-2019-8686 [HIGH] CWE-416 CVE-2019-8686: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2019-8687P3HIGHCVSS 8.8fixed in 12.1.2≥ unspecified, < Safari 12.1.22019-12-18
CVE-2019-8687 [HIGH] CWE-787 CVE-2019-8687: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2019-8666P3HIGHCVSS 8.8fixed in 12.1.2≥ unspecified, < Safari 12.1.22019-12-18
CVE-2019-8666 [HIGH] CWE-787 CVE-2019-8666: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2019-8681P3HIGHCVSS 8.8fixed in 12.1.2≥ unspecified, < Safari 12.1.22019-12-18
CVE-2019-8681 [HIGH] CWE-416 CVE-2019-8681: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
Apple Safari vulnerabilities | cvebase