cbcvebase.

Apple Safari vulnerabilities

1,654 known vulnerabilities affecting apple/safari.

Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1

Vulnerabilities

Page 25 of 83
CVE-2017-7096P3HIGHCVSS 8.8≤ 10.1.22017-10-23
CVE-2017-7096 [HIGH] CWE-119 CVE-2017-7096: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory c
nvdapple
CVE-2017-7107P3HIGHCVSS 8.8≤ 10.1.22017-10-23
CVE-2017-7107 [HIGH] CWE-119 CVE-2017-7107: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory c
nvdapple
CVE-2017-7019P3HIGHCVSS 8.8fixed in 10.1.22017-07-20
CVE-2017-7019 [HIGH] CWE-119 CVE-2017-7019: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit Page Loading" component. It allows remote attackers to execute arbitrary code or cause
nvdapple
CVE-2017-7081P3HIGHCVSS 8.8≤ 10.1.22017-10-23
CVE-2017-7081 [HIGH] CWE-119 CVE-2017-7081: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory c
nvdapple
CVE-2017-7091P3HIGHCVSS 8.8≤ 10.1.22017-10-23
CVE-2017-7091 [HIGH] CWE-119 CVE-2017-7091: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory c
nvdapple
CVE-2017-7104P3HIGHCVSS 8.8≤ 10.1.22017-10-23
CVE-2017-7104 [HIGH] CWE-119 CVE-2017-7104: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory c
nvdapple
CVE-2017-7100P3HIGHCVSS 8.8≤ 10.1.22017-10-23
CVE-2017-7100 [HIGH] CWE-119 CVE-2017-7100: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory c
nvdapple
CVE-2017-7093P3HIGHCVSS 8.8≤ 10.1.22017-10-23
CVE-2017-7093 [HIGH] CWE-119 CVE-2017-7093: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory c
nvdapple
CVE-2017-7094P3HIGHCVSS 8.8≤ 10.1.22017-10-23
CVE-2017-7094 [HIGH] CWE-119 CVE-2017-7094: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory c
nvdapple
CVE-2017-7098P3HIGHCVSS 8.8≤ 10.1.22017-10-23
CVE-2017-7098 [HIGH] CWE-119 CVE-2017-7098: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory c
nvdapple
CVE-2017-7087P3HIGHCVSS 8.8≤ 10.1.22017-10-23
CVE-2017-7087 [HIGH] CWE-119 CVE-2017-7087: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory c
nvdapple
CVE-2017-7020P3HIGHCVSS 8.8fixed in 10.1.22017-07-20
CVE-2017-7020 [HIGH] CWE-119 CVE-2017-7020: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of s
nvdapple
CVE-2017-7052P3HIGHCVSS 8.8fixed in 10.1.22017-07-20
CVE-2017-7052 [HIGH] CWE-119 CVE-2017-7052: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of s
nvdapple
CVE-2016-7578P3HIGHCVSS 8.8fixed in 10.0.12017-02-20
CVE-2016-7578 [HIGH] CWE-119 CVE-2016-7578: An issue was discovered in certain Apple products. iOS before 10.1 is affected. Safari before 10.0.1 An issue was discovered in certain Apple products. iOS before 10.1 is affected. Safari before 10.0.1 is affected. iCloud before 6.0.1 is affected. iTunes before 12.5.2 is affected. tvOS before 10.0.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruptio
nvdapple
CVE-2009-0945P3CRITICALCVSS 9.3≤ 3.2.2v0.8+44 more2009-05-13
CVE-2009-0945 [CRITICAL] CWE-94 CVE-2009-0945: Array index error in the insertItemBefore method in WebKit, as used in Apple Safari before 3.2.3 and Array index error in the insertItemBefore method in WebKit, as used in Apple Safari before 3.2.3 and 4 Public Beta, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome Stable before 1.0.154.65, and possibly other products allows remote attackers to execute arbitrary code via a document with a SVGPathList data struct
nvd
CVE-2010-1398P3CRITICALCVSS 9.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1398 [CRITICAL] CWE-119 CVE-2010-1398: WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac O WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly perform ordered list insertions, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document, related to the insertion of an uns
nvd
CVE-2008-3623P3CRITICALCVSS 9.3≤ 3.1.2v0.8+32 more2008-11-17
CVE-2008-3623 [CRITICAL] CWE-119 CVE-2008-3623: Heap-based buffer overflow in CoreGraphics in Apple Safari before 3.2 on Windows, in iPhone OS 1.0 t Heap-based buffer overflow in CoreGraphics in Apple Safari before 3.2 on Windows, in iPhone OS 1.0 through 2.2.1, and in iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted image, related to improper handling of color spaces.
nvd
CVE-2026-20660P3HIGHCVSS 7.5fixed in 26.32026-02-11
CVE-2026-20660 [HIGH] CWE-22 CVE-2026-20660: A path handling issue was addressed with improved logic. This issue is fixed in Safari 26.3, iOS 18. A path handling issue was addressed with improved logic. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.5, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. A remote user may be able to write arbitrary files.
nvdapple
CVE-2025-24167P3CRITICALCVSS 9.8fixed in 18.42025-03-31
CVE-2025-24167 [CRITICAL] CVE-2025-24167: This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, watchOS 11.4. A download's origin may be incorrectly associated.
nvdapple
CVE-2016-1857P3HIGHCVSS 8.8fixed in 9.1.12016-05-20
CVE-2016-1857 [HIGH] CVE-2016-1857: WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1854, CVE-2016-1855, and CVE-2016-1856.
nvdapple
Apple Safari vulnerabilities | cvebase