Apple Safari vulnerabilities
1,677 known vulnerabilities affecting apple/safari.
Total CVEs
1,677
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
52
Severity breakdown
CRITICAL211HIGH628MEDIUM815LOW22UNKNOWN1
Vulnerabilities
Page 16 of 84
CVE-2020-9800P3HIGHCVSS 8.8fixed in 13.1.1≥ unspecified, < Safari 13.1.12020-06-09
CVE-2020-9800 [HIGH] CWE-843 CVE-2020-9800: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 13.5
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8752P3HIGHCVSS 8.8fixed in 13.0.1≥ unspecified, < 13.02020-10-27
CVE-2019-8752 [HIGH] CWE-787 CVE-2019-8752: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in Safari 13.0.1, iOS 13.1 and iPadOS 13.1, iCloud for Windows 10.7, iCloud for Windows 7.14, tvOS 13, watchOS 6, iTunes 12.10.1 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2019-8773P3HIGHCVSS 8.8fixed in 13.0.1≥ unspecified, < 13.02020-10-27
CVE-2019-8773 [HIGH] CWE-787 CVE-2019-8773: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in Safari 13.0.1, iOS 13.1 and iPadOS 13.1, iCloud for Windows 10.7, iCloud for Windows 7.14, tvOS 13, watchOS 6, iTunes 12.10.1 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2022-3970P3HIGHCVSS 8.8fixed in 16.5.12022-11-13
CVE-2022-3970 [HIGH] CWE-189 CVE-2022-3970: A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function
A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 227500897dfb07fb7d27f
nvd
CVE-2022-22624P3HIGHCVSS 8.8fixed in 15.4≥ unspecified, < 15.42022-09-23
CVE-2022-22624 [HIGH] CWE-416 CVE-2022-22624: A use after free issue was addressed with improved memory management. This issue is fixed in macOS M
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.3, iOS 15.4 and iPadOS 15.4, tvOS 15.4, Safari 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2023-42950P3HIGHCVSS 8.8fixed in 17.2≥ unspecified, < 17.22024-03-28
CVE-2023-42950 [HIGH] CWE-416 CVE-2023-42950: A use after free issue was addressed with improved memory management. This issue is fixed in Safari
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2023-28198P3HIGHCVSS 8.8v16.42023-03-27
CVE-2023-28198 [HIGH] CVE-2023-28198: Safari 16.4
Apple Security Update: About the security content of Safari 16.4
Product: Safari
Version: 16.4
CVE: CVE-2023-28198
Component: WebKit
Impact: Processing web content may lead to arbitrary code execution
Description: A use-after-free issue was addressed with improved memory management.
apple
CVE-2022-26709P3HIGHCVSS 8.8fixed in 15.52022-11-01
CVE-2022-26709 [HIGH] CWE-416 CVE-2022-26709: A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15
A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4, Safari 15.5. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2023-23518P3HIGHCVSS 8.8fixed in 16.3≥ unspecified, < 16.32023-02-27
CVE-2023-23518 [HIGH] CWE-787 CVE-2023-23518: The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.3,
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.3, macOS Ventura 13.2, watchOS 9.3, macOS Big Sur 11.7.3, Safari 16.3, tvOS 16.3, iOS 16.3 and iPadOS 16.3. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2023-23517P3HIGHCVSS 8.8fixed in 16.3≥ unspecified, < 16.32023-02-27
CVE-2023-23517 [HIGH] CWE-119 CVE-2023-23517: The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.3,
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.3, macOS Ventura 13.2, watchOS 9.3, macOS Big Sur 11.7.3, Safari 16.3, tvOS 16.3, iOS 16.3 and iPadOS 16.3. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2022-42826P3HIGHCVSS 8.8fixed in 16.12023-02-27
CVE-2022-42826 [HIGH] CWE-416 CVE-2022-42826: A use after free issue was addressed with improved memory management. This issue is fixed in macOS V
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13, iOS 16.1 and iPadOS 16, Safari 16.1. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2023-42970P3HIGHCVSS 8.8fixed in 17.0≥ unspecified, < 172025-04-11
CVE-2023-42970 [HIGH] CWE-416 CVE-2023-42970: A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17, Safari 17. Processing web content may lead to arbitrary code execution.
nvdapple
CVE-2026-43731P3HIGHCVSS 8.8fixed in 26.5.22026-06-29
CVE-2026-43731 [HIGH] CWE-416 CVE-2026-43731: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.
nvd
CVE-2026-43794P3HIGHCVSS 8.8fixed in 26.6.12026-08-17
CVE-2026-43794 [HIGH] CWE-119 CVE-2026-43794: A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari
A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to memory corruption.
nvd
CVE-2020-9801P4MEDIUMCVSS 5.3PoCfixed in 13.1.1≥ unspecified, < Safari 13.1.12020-06-09
CVE-2020-9801 [MEDIUM] CVE-2020-9801: A logic issue was addressed with improved restrictions. This issue is fixed in Safari 13.1.1. A mali
A logic issue was addressed with improved restrictions. This issue is fixed in Safari 13.1.1. A malicious process may cause Safari to launch an application.
nvd
CVE-2018-4204P3HIGHCVSS 8.8fixed in 11.12018-06-08
CVE-2018-4204 [HIGH] CWE-119 CVE-2018-4204: An issue was discovered in certain Apple products. iOS before 11.4 is affected. iOS before 11.3.1 is
An issue was discovered in certain Apple products. iOS before 11.4 is affected. iOS before 11.3.1 is affected. Safari before 11.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code
nvdapple
CVE-2018-4199P3HIGHCVSS 8.8fixed in 11.1.12018-06-08
CVE-2018-4199 [HIGH] CWE-119 CVE-2018-4199: An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service
nvdapple
CVE-2011-0167P4MEDIUMCVSS 4.3PoC≤ 5.0.3v1.0+52 more2011-03-11
CVE-2011-0167 [MEDIUM] CWE-264 CVE-2011-0167: The windows functionality in WebKit in Apple Safari before 5.0.4 allows remote attackers to bypass t
The windows functionality in WebKit in Apple Safari before 5.0.4 allows remote attackers to bypass the Same Origin Policy, and force the upload of arbitrary local files from a client computer, via a crafted web site.
nvd
CVE-2017-2378P3HIGHCVSS 8.8≤ 10.0.32017-04-02
CVE-2017-2378 [HIGH] CWE-20 CVE-2017-2378: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves bookmark creation in the "WebKit" component. It allows remote attackers to execute arbitrary code or spoof a bookmark by leveraging mishandling of links during drag-and-drop actions.
nvdapple
CVE-2019-8544P3HIGHCVSS 8.8fixed in 12.1≥ unspecified, < Safari 12.12019-12-18
CVE-2019-8544 [HIGH] CWE-787 CVE-2019-8544: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple