Apple Safari vulnerabilities
1,677 known vulnerabilities affecting apple/safari.
Total CVEs
1,677
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
52
Severity breakdown
CRITICAL211HIGH628MEDIUM815LOW22UNKNOWN1
Vulnerabilities
Page 33 of 84
CVE-2018-4392P3HIGHCVSS 8.8fixed in 12.0.12019-04-03
CVE-2018-4392 [HIGH] CWE-119 CVE-2018-4392: Multiple memory corruption issues were addressed with improved memory handling. This issue affected
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, tvOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.
nvdapple
CVE-2009-1725P3CRITICALCVSS 9.3≤ 4.0.1v2.0+25 more2009-07-09
CVE-2009-1725 [CRITICAL] CWE-189 CVE-2009-1725: WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPo
WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in KDE; QtWebKit (aka Qt toolkit); and possibly other products do not properly handle numeric character references, which allows remote attackers to execute arbitrary code or cause a denial of service (me
nvd
CVE-2018-4375P3HIGHCVSS 8.8fixed in 12.0.12019-04-03
CVE-2018-4375 [HIGH] CWE-119 CVE-2018-4375: Multiple memory corruption issues were addressed with improved memory handling. This issue affected
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.
nvdapple
CVE-2018-4376P3HIGHCVSS 8.8fixed in 12.0.12019-04-03
CVE-2018-4376 [HIGH] CWE-119 CVE-2018-4376: Multiple memory corruption issues were addressed with improved memory handling. This issue affected
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.
nvdapple
CVE-2010-1791P3CRITICALCVSS 9.3≤ 5.0v4.0+7 more2010-07-30
CVE-2010-1791 [CRITICAL] CWE-189 CVE-2010-1791: Integer signedness error in WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Wi
Integer signedness error in WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving a JavaScript array index.
nvd
CVE-2010-1788P3CRITICALCVSS 9.3≤ 5.0v4.0+7 more2010-07-30
CVE-2010-1788 [CRITICAL] CWE-119 CVE-2010-1788: WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on M
WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a use element in an SVG document.
nvd
CVE-2010-3803P3CRITICALCVSS 9.3≤ 5.0.2v5.0+51 more2010-11-22
CVE-2010-3803 [CRITICAL] CWE-189 CVE-2010-3803: Integer overflow in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, a
Integer overflow in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string.
nvd
CVE-2010-3116P3CRITICALCVSS 10.0fixed in 4.1.3≥ 5.0, < 5.0.32010-08-24
CVE-2010-3116 [CRITICAL] CWE-416 CVE-2010-3116: Multiple use-after-free vulnerabilities in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x be
Multiple use-after-free vulnerabilities in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to improper handling of MIME types by plug-ins.
nvd
CVE-2022-22637P3HIGHCVSS 8.8fixed in 15.4≥ unspecified, < 15.42022-09-23
CVE-2022-22637 [HIGH] CWE-346 CVE-2022-22637: A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. A malicious website may cause unexpected cross-origin behavior.
nvdapple
CVE-2010-1770P3CRITICALCVSS 9.3≤ 4.0.52010-06-11
CVE-2010-1770 [CRITICAL] CWE-94 CVE-2010-1770: WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Apple Safari before 4.1
WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Apple Safari before 4.1 on Mac OS X 10.4, and Google Chrome before 5.0.375.70 does not properly handle a transformation of a text node that has the IBM1147 character set, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption
nvd
CVE-2011-0215P3CRITICALCVSS 9.3≤ 5.0.5v1.0+54 more2011-07-21
CVE-2011-0215 [CRITICAL] CWE-20 CVE-2011-0215: ImageIO in Apple Safari before 5.0.6 on Windows does not properly address re-entrancy issues, which
ImageIO in Apple Safari before 5.0.6 on Windows does not properly address re-entrancy issues, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF file.
nvd
CVE-2010-3817P3CRITICALCVSS 9.3≤ 5.0.2v5.0+51 more2010-11-22
CVE-2010-3817 [CRITICAL] CVE-2010-3817: WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on M
WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly perform a cast of an unspecified variable during processing of Cascading Style Sheets (CSS) 3D transforms, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted w
nvd
CVE-2010-3809P3CRITICALCVSS 9.3≤ 5.0.2v5.0+51 more2010-11-22
CVE-2010-3809 [CRITICAL] CWE-94 CVE-2010-3809: WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on M
WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly perform a cast of an unspecified variable during processing of inline styling, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted web site.
nvd
CVE-2010-3819P3CRITICALCVSS 9.3≤ 5.0.2v5.0+51 more2010-11-22
CVE-2010-3819 [CRITICAL] CWE-94 CVE-2010-3819: WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on M
WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly perform a cast of an unspecified variable during processing of Cascading Style Sheets (CSS) boxes, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted we
nvd
CVE-2010-3826P3CRITICALCVSS 9.3≤ 5.0.2v5.0+51 more2010-11-22
CVE-2010-3826 [CRITICAL] CVE-2010-3826: WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on M
WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly perform a cast of an unspecified variable during processing of colors in an SVG document, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted web site.
nvd
CVE-2017-7022P3HIGHCVSS 7.8≤ 10.1.12017-07-20
CVE-2017-7022 [HIGH] CWE-119 CVE-2017-7022: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a craft
nvd
CVE-2017-7025P3HIGHCVSS 7.8≤ 10.1.12017-07-20
CVE-2017-7025 [HIGH] CWE-119 CVE-2017-7025: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a craft
nvd
CVE-2017-7023P3HIGHCVSS 7.8≤ 10.1.12017-07-20
CVE-2017-7023 [HIGH] CWE-119 CVE-2017-7023: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a craft
nvd
CVE-2017-7024P3HIGHCVSS 7.8≤ 10.1.12017-07-20
CVE-2017-7024 [HIGH] CWE-119 CVE-2017-7024: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a craft
nvd
CVE-2010-3821P3CRITICALCVSS 9.3≤ 5.0.2v5.0+51 more2010-11-22
CVE-2010-3821 [CRITICAL] CWE-119 CVE-2010-3821: WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on M
WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly handle the :first-letter pseudo-element in a Cascading Style Sheets (CSS) token sequence, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) vi
nvd