Apple Safari vulnerabilities
1,592 known vulnerabilities affecting apple/safari.
Total CVEs
1,592
CISA KEV
31
actively exploited
Public exploits
157
Exploited in wild
25
Severity breakdown
CRITICAL211HIGH603MEDIUM757LOW20UNKNOWN1
Vulnerabilities
Page 31 of 80
CVE-2018-4089HIGHCVSS 8.8PoCfixed in 11.0.32018-04-03
CVE-2018-4089 [HIGH] CWE-119 CVE-2018-4089: An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. Safari before 11.0.3 is affected. tvOS before 11.2.5 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a
nvdapple
CVE-2018-4101HIGHCVSS 8.8fixed in 11.12018-04-03
CVE-2018-4101 [HIGH] CWE-119 CVE-2018-4101: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (
nvdapple
CVE-2018-4096HIGHCVSS 8.8fixed in 11.0.32018-04-03
CVE-2018-4096 [HIGH] CWE-119 CVE-2018-4096: An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. Safari before 11.0.3 is affected. iCloud before 7.3 on Windows is affected. iTunes before 12.7.3 on Windows is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "WebKit" component. It allows
nvdapple
CVE-2018-4165HIGHCVSS 8.8fixed in 11.12018-04-03
CVE-2018-4165 [HIGH] CWE-119 CVE-2018-4165: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (
nvdapple
CVE-2018-4114HIGHCVSS 8.8fixed in 11.12018-04-03
CVE-2018-4114 [HIGH] CWE-119 CVE-2018-4114: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary cod
nvdapple
CVE-2018-4130HIGHCVSS 8.8fixed in 11.12018-04-03
CVE-2018-4130 [HIGH] CWE-119 CVE-2018-4130: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (
nvdapple
CVE-2018-4128HIGHCVSS 8.8fixed in 11.12018-04-03
CVE-2018-4128 [HIGH] CWE-119 CVE-2018-4128: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (
nvdapple
CVE-2017-2492MEDIUMCVSS 6.1fixed in 10.12018-04-03
CVE-2017-2492 [MEDIUM] CWE-79 CVE-2017-2492: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "JavaScriptCore" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that triggers prototype mishandling.
nvdapple
CVE-2018-4102MEDIUMCVSS 6.5fixed in 11.12018-04-03
CVE-2018-4102 [MEDIUM] CWE-20 CVE-2018-4102: An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involve
An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site.
nvdapple
CVE-2018-4116MEDIUMCVSS 6.5fixed in 11.12018-04-03
CVE-2018-4116 [MEDIUM] CWE-20 CVE-2018-4116: An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involve
An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site.
nvdapple
CVE-2018-4133MEDIUMCVSS 6.1fixed in 11.12018-04-03
CVE-2018-4133 [MEDIUM] CWE-79 CVE-2018-4133: An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involve
An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involves the "WebKit" component. A Safari cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvdapple
CVE-2018-4113MEDIUMCVSS 6.5fixed in 11.12018-04-03
CVE-2018-4113 [MEDIUM] CWE-617 CVE-2018-4113: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves a JavaScriptCore function in the "WebKit" component. It allows attackers
nvdapple
CVE-2017-7153MEDIUMCVSS 6.1fixed in 11.0.22018-04-03
CVE-2017-7153 [MEDIUM] CWE-601 CVE-2017-7153: An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2
An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to spoof user-interf
nvdapple
CVE-2017-2493MEDIUMCVSS 6.5fixed in 10.12018-04-03
CVE-2017-2493 [MEDIUM] CWE-200 CVE-2017-2493: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted elements on a web s
nvdapple
CVE-2018-4146MEDIUMCVSS 6.5fixed in 11.12018-04-03
CVE-2018-4146 [MEDIUM] CWE-119 CVE-2018-4146: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows attackers to cause a denial of service
nvdapple
CVE-2018-4117MEDIUMCVSS 6.5fixed in 11.12018-04-03
CVE-2018-4117 [MEDIUM] CWE-200 CVE-2018-4117: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is affected. The issue involves the fetch API in the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy an
nvdapple
CVE-2017-7830MEDIUMCVSS 6.5v11.0.32018-01-23
CVE-2017-7830 [MEDIUM] CVE-2017-7830: Safari 11.0.3
Apple Security Update: About the security content of Safari 11.0.3
Product: Safari
Version: 11.0.3
CVE: CVE-2017-7830
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2017-5753MEDIUMCVSS 5.6PoCv11.0.22018-01-08
CVE-2017-5753 [MEDIUM] CVE-2017-5753: Safari 11.0.2
Apple Security Update: About the security content of Safari 11.0.2
Product: Safari
Version: 11.0.2
CVE: CVE-2017-5753
Component: Safari 11.0.2
Description: Safari 11.0.2 includes security improvements to mitigate the effects of Spectre (CVE-2017-5753 and CVE-2017-5715).
apple
CVE-2017-5715MEDIUMCVSS 5.6PoCv11.0.22018-01-08
CVE-2017-5715 [MEDIUM] CVE-2017-5715: Safari 11.0.2
Apple Security Update: About the security content of Safari 11.0.2
Product: Safari
Version: 11.0.2
CVE: CVE-2017-5715
Component: Safari 11.0.2
Description: Safari 11.0.2 includes security improvements to mitigate the effects of Spectre (CVE-2017-5753 and CVE-2017-5715).
apple
CVE-2017-7160HIGHCVSS 8.8fixed in 11.0.22017-12-27
CVE-2017-7160 [HIGH] CWE-119 CVE-2017-7160: An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2
An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service
nvdapple