Apple Safari vulnerabilities
1,654 known vulnerabilities affecting apple/safari.
Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1
Vulnerabilities
Page 32 of 83
CVE-2010-1782P3CRITICALCVSS 9.3≤ 5.0v4.0+7 more2010-07-30
CVE-2010-1782 [CRITICAL] CWE-119 CVE-2010-1782: WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on M
WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to the rendering of an inline element.
nvd
CVE-2010-3805P3CRITICALCVSS 9.3≤ 5.0.2v5.0+51 more2010-11-22
CVE-2010-3805 [CRITICAL] CVE-2010-3805: Integer underflow in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows,
Integer underflow in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving WebSockets. NOTE: this may overlap CVE-2010-3254.
nvd
CVE-2010-3803P3CRITICALCVSS 9.3≤ 5.0.2v5.0+51 more2010-11-22
CVE-2010-3803 [CRITICAL] CWE-189 CVE-2010-3803: Integer overflow in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, a
Integer overflow in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string.
nvd
CVE-2016-4591P3HIGHCVSS 7.5v9.1.22016-07-18
CVE-2016-4591 [HIGH] CVE-2016-4591: Safari 9.1.2
Apple Security Update: About the security content of Safari 9.1.2
Product: Safari
Version: 9.1.2
CVE: CVE-2016-4591
Component: WebKit
Impact: Visiting a maliciously crafted website may leak sensitive data
Description: A permissions issue existed in the handling of the location variable. This was addressed though additional ownership checks.
apple
CVE-2010-1770P3CRITICALCVSS 9.3≤ 4.0.52010-06-11
CVE-2010-1770 [CRITICAL] CWE-94 CVE-2010-1770: WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Apple Safari before 4.1
WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Apple Safari before 4.1 on Mac OS X 10.4, and Google Chrome before 5.0.375.70 does not properly handle a transformation of a text node that has the IBM1147 character set, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption
nvd
CVE-2010-3822P3CRITICALCVSS 9.3≤ 5.0.2v5.0+51 more2010-11-22
CVE-2010-3822 [CRITICAL] CWE-119 CVE-2010-3822: WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on M
WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, accesses an uninitialized pointer during processing of Cascading Style Sheets (CSS) counter styles, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted web site.
nvd
CVE-2010-3826P3CRITICALCVSS 9.3≤ 5.0.2v5.0+51 more2010-11-22
CVE-2010-3826 [CRITICAL] CVE-2010-3826: WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on M
WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly perform a cast of an unspecified variable during processing of colors in an SVG document, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted web site.
nvd
CVE-2018-4137P3HIGHCVSS 7.5fixed in 11.12018-04-03
CVE-2018-4137 [HIGH] CWE-200 CVE-2018-4137: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. The issue involves the "Safari Login AutoFill" component. It allows remote attackers to read autofilled data by leveraging lack of a user-confirmation requirement.
nvdapple
CVE-2020-9936P3HIGHCVSS 7.8fixed in 13.1.22020-10-16
CVE-2020-9936 [HIGH] CWE-787 CVE-2020-9936: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2007-4812P4MEDIUMCVSS 5.0PoCv3.0.32007-09-11
CVE-2007-4812 [MEDIUM] CWE-119 CVE-2007-4812: Buffer overflow in Apple Safari 3.0.3 522.15.5, and other versions before Beta Update 3.0.4, allows
Buffer overflow in Apple Safari 3.0.3 522.15.5, and other versions before Beta Update 3.0.4, allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact by setting document.location.hash to a long string. NOTE: the crash might actually occur in the alert method.
nvd
CVE-2026-64713P3HIGHCVSS 8.1fixed in 26.62026-07-27
CVE-2026-64713 [HIGH] CWE-203 CVE-2026-64713: This issue was addressed with improved checks. This issue is fixed in Safari 26.6, iOS 26.6 and iPad
This issue was addressed with improved checks. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Websites may know if the user has visited a given link.
nvd
CVE-2023-38572P3HIGHCVSS 7.5fixed in 16.6≥ unspecified, < 16.62023-07-27
CVE-2023-38572 [HIGH] CVE-2023-38572: The issue was addressed with improved checks. This issue is fixed in iOS 15.7.8 and iPadOS 15.7.8, i
The issue was addressed with improved checks. This issue is fixed in iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Ventura 13.5, Safari 16.6, watchOS 9.6. A website may be able to bypass Same Origin Policy.
nvdapple
CVE-2019-8562P3CRITICALCVSS 9.6fixed in 12.1≥ unspecified, < Safari 12.12019-12-18
CVE-2019-8562 [CRITICAL] CWE-787 CVE-2019-8562: A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.2, t
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12.9.4 for Windows. A sandboxed process may be able to circumvent sandbox restrictions.
nvdapple
CVE-2009-1687P3CRITICALCVSS 9.3≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1687 [CRITICAL] CWE-399 CVE-2009-1687: The JavaScript garbage collector in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1,
The JavaScript garbage collector in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle allocation failures, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document that
nvd
CVE-2010-1410P3CRITICALCVSS 9.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1410 [CRITICAL] CWE-119 CVE-2010-1410: WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac O
WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via an SVG document with nested use elements.
nvd
CVE-2012-5851P4MEDIUMCVSS 4.3PoCv5.1.72012-11-15
CVE-2012-5851 [MEDIUM] CWE-79 CVE-2012-5851: html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.
html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.7, does not consider all possible output contexts of reflected data, which makes it easier for remote attackers to bypass a cross-site scripting (XSS) protection mechanism via a crafted string, aka rdar problem 12019108.
nvd
CVE-2010-1793P3CRITICALCVSS 9.3≤ 5.0v4.0+7 more2010-07-30
CVE-2010-1793 [CRITICAL] CWE-399 CVE-2010-1793: Multiple use-after-free vulnerabilities in WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 thro
Multiple use-after-free vulnerabilities in WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a (1) font-face or (2) use element in an SVG document.
nvd
CVE-2010-1400P3CRITICALCVSS 9.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1400 [CRITICAL] CWE-399 CVE-2010-1400: Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and
Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving caption elements.
nvd
CVE-2010-1774P3CRITICALCVSS 9.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1774 [CRITICAL] CWE-119 CVE-2010-1774: WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac O
WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, accesses out-of-bounds memory during processing of HTML tables, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document.
nvd
CVE-2010-1419P3CRITICALCVSS 9.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1419 [CRITICAL] CWE-399 CVE-2010-1419: Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and
Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving a certain window close action that occurs during a drag-and-drop operation.
nvd