cbcvebase.

Apple Safari vulnerabilities

1,654 known vulnerabilities affecting apple/safari.

Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH622MEDIUM790LOW20UNKNOWN11

Vulnerabilities

Page 3 of 83
CVE-2022-46691P1HIGHCVSS 8.8Exploitedfixed in 16.22022-12-15
CVE-2022-46691 [HIGH] CWE-787 CVE-2022-46691: A memory consumption issue was addressed with improved memory handling. This issue is fixed in Safar A memory consumption issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2022-46700P1HIGHCVSS 8.8Exploitedfixed in 16.22022-12-15
CVE-2022-46700 [HIGH] CWE-787 CVE-2022-46700: A memory corruption issue was addressed with improved input validation. This issue is fixed in Safar A memory corruption issue was addressed with improved input validation. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2022-46692P1MEDIUMCVSS 5.5Exploitedfixed in 16.22022-12-15
CVE-2022-46692 [MEDIUM] CWE-345 CVE-2022-46692: A logic issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS A logic issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, iOS 15.7.2 and iPadOS 15.7.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may bypass Same Origin Policy.
nvdapple
CVE-2020-9910P1HIGHCVSS 8.8Exploitedfixed in 13.1.2≥ unspecified, < Safari 13.1.22020-10-16
CVE-2020-9910 [HIGH] CVE-2020-9910: Multiple issues were addressed with improved logic. This issue is fixed in iOS 13.6 and iPadOS 13.6, Multiple issues were addressed with improved logic. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
nvdapple
CVE-2023-23496P1HIGHCVSS 8.8Exploitedfixed in 16.3≥ unspecified, < 16.32023-02-27
CVE-2023-23496 [HIGH] CWE-94 CVE-2023-23496: The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.2, watchOS 9.3 The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.2, watchOS 9.3, iOS 15.7.2 and iPadOS 15.7.2, Safari 16.3, tvOS 16.3, iOS 16.3 and iPadOS 16.3. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2022-42852P1MEDIUMCVSS 6.5Exploitedfixed in 16.22022-12-15
CVE-2022-42852 [MEDIUM] CWE-200 CVE-2022-42852: The issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2 The issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may result in the disclosure of process memory.
nvdapple
CVE-2023-32402P1MEDIUMCVSS 6.5Exploitedfixed in 16.5≥ unspecified, < 16.52023-06-23
CVE-2023-32402 [MEDIUM] CWE-125 CVE-2023-32402: An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9 An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing web content may disclose sensitive information.
nvdapple
CVE-2019-8771P1MEDIUMCVSS 6.1Exploitedfixed in 13.0.1≥ unspecified, < 13.02020-10-27
CVE-2019-8771 [MEDIUM] CWE-1021 CVE-2019-8771: This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 13. This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 13.0.1, iOS 13. Maliciously crafted web content may violate iframe sandboxing policy.
nvdapple
CVE-2022-46705P1MEDIUMCVSS 4.3Exploitedfixed in 16.22023-02-27
CVE-2022-46705 [MEDIUM] CVE-2022-46705: A spoofing issue existed in the handling of URLs. This issue was addressed with improved input valid A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, Safari 16.2. Visiting a malicious website may lead to address bar spoofing.
nvdapple
CVE-2025-24113P1MEDIUMCVSS 4.3Exploitedfixed in 18.3fixed in 18.42025-01-27
CVE-2025-24113 [MEDIUM] CVE-2025-24113: The issue was addressed with improved UI. This issue is fixed in Safari 18.3, Safari 18.4, iOS 18.3 The issue was addressed with improved UI. This issue is fixed in Safari 18.3, Safari 18.4, iOS 18.3 and iPadOS 18.3, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sequoia 15.4, visionOS 2.3, visionOS 2.4, watchOS 11.4. Visiting a malicious website may lead to user interface spoofing.
nvdapple
CVE-2023-32423P2MEDIUMCVSS 6.5Exploitedfixed in 16.5≥ unspecified, < 16.52023-06-23
CVE-2023-32423 [MEDIUM] CWE-120 CVE-2023-32423: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in watchOS A buffer overflow issue was addressed with improved memory handling. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing web content may disclose sensitive information.
nvdapple
CVE-2020-9850P1CRITICALCVSS 9.8PoCfixed in 13.1.1≥ unspecified, < Safari 13.1.12020-06-09
CVE-2020-9850 [CRITICAL] CVE-2020-9850: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 1 A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. A remote attacker may be able to cause arbitrary code execution.
nvd
CVE-2017-5753P2MEDIUMCVSS 5.6PoCv11.0.22018-01-08
CVE-2017-5753 [MEDIUM] CVE-2017-5753: Safari 11.0.2 Apple Security Update: About the security content of Safari 11.0.2 Product: Safari Version: 11.0.2 CVE: CVE-2017-5753 Component: Safari 11.0.2 Description: Safari 11.0.2 includes security improvements to mitigate the effects of Spectre (CVE-2017-5753 and CVE-2017-5715).
apple
CVE-2010-1205P2CRITICALCVSS 9.8PoCfixed in 5.0.42010-06-30
CVE-2010-1205 [CRITICAL] CWE-120 CVE-2010-1205: Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.
nvd
CVE-2018-4162P2HIGHCVSS 8.8PoCfixed in 11.12018-04-03
CVE-2018-4162 [HIGH] CWE-119 CVE-2018-4162: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary cod
nvdapple
CVE-2018-4416P2HIGHCVSS 8.8PoCfixed in 12.0.12019-04-03
CVE-2018-4416 [HIGH] CWE-119 CVE-2018-4416: Multiple memory corruption issues were addressed with improved memory handling. This issue affected Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, tvOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.
nvdapple
CVE-2017-5715P2MEDIUMCVSS 5.6PoCv11.0.22018-01-08
CVE-2017-5715 [MEDIUM] CVE-2017-5715: Safari 11.0.2 Apple Security Update: About the security content of Safari 11.0.2 Product: Safari Version: 11.0.2 CVE: CVE-2017-5715 Component: Safari 11.0.2 Description: Safari 11.0.2 includes security improvements to mitigate the effects of Spectre (CVE-2017-5753 and CVE-2017-5715).
apple
CVE-2014-1303P2CRITICALCVSS 10.0PoCv7.0.22014-03-26
CVE-2014-1303 [CRITICAL] CWE-119 CVE-2014-1303: Heap-based buffer overflow in Apple Safari 7.0.2 allows remote attackers to execute arbitrary code a Heap-based buffer overflow in Apple Safari 7.0.2 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism via unspecified vectors, as demonstrated by Liang Chen during a Pwn2Own competition at CanSecWest 2014.
nvd
CVE-2011-1774P2HIGHCVSS 8.8PoC≤ 5.0.5v1.0+54 more2011-07-21
CVE-2011-1774 [HIGH] CVE-2011-1774: WebKit in Apple Safari before 5.0.6 has improper libxslt security settings, which allows remote atta WebKit in Apple Safari before 5.0.6 has improper libxslt security settings, which allows remote attackers to create arbitrary files, and consequently execute arbitrary code, via a crafted web site. NOTE: this may overlap CVE-2011-1425.
nvd
CVE-2019-8689P2HIGHCVSS 8.8PoCfixed in 12.1.2≥ unspecified, < Safari 12.1.22019-12-18
CVE-2019-8689 [HIGH] CWE-787 CVE-2019-8689: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
Apple Safari vulnerabilities | cvebase