cbcvebase.

Apple Safari vulnerabilities

1,677 known vulnerabilities affecting apple/safari.

Total CVEs
1,677
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
52
Severity breakdown
CRITICAL211HIGH628MEDIUM815LOW22UNKNOWN1

Vulnerabilities

Page 26 of 84
CVE-2020-9783P3HIGHCVSS 8.8fixed in 13.1≥ unspecified, < Safari 13.12020-04-01
CVE-2020-9783 [HIGH] CWE-416 CVE-2020-9783: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13. A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Processing maliciously crafted web content may lead to code execution.
nvd
CVE-2009-0945P3CRITICALCVSS 9.3≤ 3.2.2v0.8+44 more2009-05-13
CVE-2009-0945 [CRITICAL] CWE-94 CVE-2009-0945: Array index error in the insertItemBefore method in WebKit, as used in Apple Safari before 3.2.3 and Array index error in the insertItemBefore method in WebKit, as used in Apple Safari before 3.2.3 and 4 Public Beta, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome Stable before 1.0.154.65, and possibly other products allows remote attackers to execute arbitrary code via a document with a SVGPathList data struct
nvd
CVE-2010-1398P3CRITICALCVSS 9.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1398 [CRITICAL] CWE-119 CVE-2010-1398: WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac O WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly perform ordered list insertions, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document, related to the insertion of an uns
nvd
CVE-2008-3623P3CRITICALCVSS 9.3≤ 3.1.2v0.8+32 more2008-11-17
CVE-2008-3623 [CRITICAL] CWE-119 CVE-2008-3623: Heap-based buffer overflow in CoreGraphics in Apple Safari before 3.2 on Windows, in iPhone OS 1.0 t Heap-based buffer overflow in CoreGraphics in Apple Safari before 3.2 on Windows, in iPhone OS 1.0 through 2.2.1, and in iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted image, related to improper handling of color spaces.
nvd
CVE-2026-20660P3HIGHCVSS 7.5fixed in 26.32026-02-11
CVE-2026-20660 [HIGH] CWE-22 CVE-2026-20660: A path handling issue was addressed with improved logic. This issue is fixed in Safari 26.3, iOS 18. A path handling issue was addressed with improved logic. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.5, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. A remote user may be able to write arbitrary files.
nvdapple
CVE-2025-24167P3CRITICALCVSS 9.8fixed in 18.42025-03-31
CVE-2025-24167 [CRITICAL] CVE-2025-24167: This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, watchOS 11.4. A download's origin may be incorrectly associated.
nvdapple
CVE-2016-4737P3HIGHCVSS 8.8fixed in 10.02016-09-25
CVE-2016-4737 [HIGH] CWE-119 CVE-2016-4737: WebKit in Apple iOS before 10, Safari before 10, tvOS before 10, and watchOS before 3 allows remote WebKit in Apple iOS before 10, Safari before 10, tvOS before 10, and watchOS before 3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
nvdapple
CVE-2016-4735P3HIGHCVSS 8.8fixed in 10.02016-09-25
CVE-2016-4735 [HIGH] CVE-2016-4735: WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execu WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4611, CVE-2016-4730, CVE-2016-4733, and CVE-2016-4734.
nvdapple
CVE-2016-4730P3HIGHCVSS 8.8fixed in 10.02016-09-25
CVE-2016-4730 [HIGH] CVE-2016-4730: WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execu WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4611, CVE-2016-4733, CVE-2016-4734, and CVE-2016-4735.
nvdapple
CVE-2016-1724P3HIGHCVSS 8.8fixed in 9.0.32016-02-01
CVE-2016-1724 [HIGH] CWE-119 CVE-2016-1724: WebKit, as used in Apple iOS before 9.2.1, Safari before 9.0.3, and tvOS before 9.1.1, allows remote WebKit, as used in Apple iOS before 9.2.1, Safari before 9.0.3, and tvOS before 9.1.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1727.
nvdapple
CVE-2016-4624P3HIGHCVSS 8.8fixed in 9.1.22016-07-22
CVE-2016-4624 [HIGH] CVE-2016-4624: WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4589, CVE-2016-4622, and CVE-2016-4623.
nvdapple
CVE-2016-4623P3HIGHCVSS 8.8fixed in 9.1.22016-07-22
CVE-2016-4623 [HIGH] CVE-2016-4623: WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4589, CVE-2016-4622, and CVE-2016-4624.
nvdapple
CVE-2016-4589P3HIGHCVSS 8.8v9.1.22016-07-18
CVE-2016-4589 [HIGH] CVE-2016-4589: Safari 9.1.2 Apple Security Update: About the security content of Safari 9.1.2 Product: Safari Version: 9.1.2 CVE: CVE-2016-4589 Component: WebKit Impact: Visiting a maliciously crafted website may lead to arbitrary code execution Description: Multiple memory corruption issues were addressed through improved memory handling.
apple
CVE-2016-1856P3HIGHCVSS 8.8fixed in 9.1.12016-05-20
CVE-2016-1856 [HIGH] CVE-2016-1856: WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1854, CVE-2016-1855, and CVE-2016-1857.
nvdapple
CVE-2016-1854P3HIGHCVSS 8.8fixed in 9.1.12016-05-20
CVE-2016-1854 [HIGH] CWE-119 CVE-2016-1854: WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1855, CVE-2016-1856, and CVE-2016-1857.
nvdapple
CVE-2009-1684P4MEDIUMCVSS 4.3PoC≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1684 [MEDIUM] CWE-79 CVE-2009-1684: Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via an event handler that triggers script execution in the context of the next loaded document.
nvd
CVE-2016-4586P3HIGHCVSS 8.8fixed in 9.1.22016-07-22
CVE-2016-4586 [HIGH] CWE-119 CVE-2016-4586: WebKit in Apple Safari before 9.1.2 and tvOS before 9.2.2 allows remote attackers to execute arbitra WebKit in Apple Safari before 9.1.2 and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
nvdapple
CVE-2016-4762P3HIGHCVSS 8.8≤ 9.1.32016-09-25
CVE-2016-4762 [HIGH] CWE-119 CVE-2016-4762: WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, iCloud before 6.0 on Windows, and Sa WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, iCloud before 6.0 on Windows, and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
nvdapple
CVE-2018-4361P3HIGHCVSS 8.8fixed in 122019-04-03
CVE-2018-4361 [HIGH] CVE-2018-4361: A memory consumption issue was addressed with improved memory handling. This issue affected versions A memory consumption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
nvdapple
CVE-2016-4765P3HIGHCVSS 8.8fixed in 10.02016-09-25
CVE-2016-4765 [HIGH] CVE-2016-4765: WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4759, CVE-2016-4766, CVE-2016-4767, and CVE-2016-4768.
nvdapple
Apple Safari vulnerabilities | cvebase