cbcvebase.

Apple Safari vulnerabilities

1,677 known vulnerabilities affecting apple/safari.

Total CVEs
1,677
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
52
Severity breakdown
CRITICAL211HIGH628MEDIUM815LOW22UNKNOWN1

Vulnerabilities

Page 35 of 84
CVE-2006-2019P4MEDIUMCVSS 5.0PoCv1.3.1v2.0.32006-04-25
CVE-2006-2019 [MEDIUM] CVE-2006-2019: Apple Mac OS X Safari 2.0.3, 1.3.1, and possibly other versions allows remote attackers to cause a d Apple Mac OS X Safari 2.0.3, 1.3.1, and possibly other versions allows remote attackers to cause a denial of service (CPU consumption and crash) via a TD element with a large number in the rowspan attribute.
nvd
CVE-2017-2376P3HIGHCVSS 7.5≤ 10.0.32017-04-02
CVE-2017-2376 [HIGH] CVE-2017-2376: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar by leveraging text input during the loading of a page.
nvdapple
CVE-2010-0048P3HIGHCVSS 8.8≤ 4.0.4v4.0+3 more2010-03-15
CVE-2010-0048 [HIGH] CWE-399 CVE-2010-0048: Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execu Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted XML document.
nvd
CVE-2016-7613P3HIGHCVSS 7.8≤ 10.0.02017-02-20
CVE-2016-7613 [HIGH] CWE-264 CVE-2016-7613: An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context via a crafted app that leverages object-lifetime mishandling dur
nvd
CVE-2016-4676P3HIGHCVSS 7.5fixed in 10.0.1vbefore 10.0.12020-02-03
CVE-2016-4676 [HIGH] CWE-200 CVE-2016-4676: A Cross-origin vulnerability exists in WebKit in Apple Safari before 10.0.1 when processing location A Cross-origin vulnerability exists in WebKit in Apple Safari before 10.0.1 when processing location attributes, which could let a remote malicious user obtain sensitive information.
nvd
CVE-2026-64713P3HIGHCVSS 8.1fixed in 26.62026-07-27
CVE-2026-64713 [HIGH] CWE-203 CVE-2026-64713: This issue was addressed with improved checks. This issue is fixed in Safari 26.6, iOS 26.6 and iPad This issue was addressed with improved checks. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Websites may know if the user has visited a given link.
nvd
CVE-2025-43480P3HIGHCVSS 8.1fixed in 26.12025-11-04
CVE-2025-43480 [HIGH] CWE-942 CVE-2025-43480: The issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 26.1 and iPadO The issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious website may exfiltrate data cross-origin.
nvdapple
CVE-2018-4277P3HIGHCVSS 7.5fixed in 11.1.12019-01-11
CVE-2018-4277 [HIGH] CWE-20 CVE-2018-4277: In iOS before 11.4.1, watchOS before 4.3.2, tvOS before 11.4.1, Safari before 11.1.1, macOS High Sie In iOS before 11.4.1, watchOS before 4.3.2, tvOS before 11.4.1, Safari before 11.1.1, macOS High Sierra before 10.13.6, a spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation.
nvdapple
CVE-2020-9911P3HIGHCVSS 7.5fixed in 13.1.2≥ unspecified, < Safari 13.1.22020-10-16
CVE-2020-9911 [HIGH] CVE-2020-9911: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.6 and iPadOS 1 A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.6 and iPadOS 13.6, Safari 13.1.2. An issue in Safari Reader mode may allow a remote attacker to bypass the Same Origin Policy.
nvdapple
CVE-2025-7424P3HIGHCVSS 7.5v18.62025-07-30
CVE-2025-7424 [HIGH] CVE-2025-7424: Safari 18.6 Apple Security Update: About the security content of Safari 18.6 Product: Safari Version: 18.6 CVE: CVE-2025-7424 Component: Safari 18.6 Impact: Processing a file may lead to memory corruption Description: This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org.
apple
CVE-2010-1401P3CRITICALCVSS 9.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1401 [CRITICAL] CWE-399 CVE-2010-1401: Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in WebKit in Apple S Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving the :first-letter pseudo-element.
nvd
CVE-2025-24213P3HIGHCVSS 7.8fixed in 18.4fixed in 18.52025-03-31
CVE-2025-24213 [HIGH] CWE-843 CVE-2025-24213: This issue was addressed with improved handling of floats. This issue is fixed in Safari 18.5, iOS 1 This issue was addressed with improved handling of floats. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. A type confusion issue could lead to memory corruption.
nvdapple
CVE-2020-3864P3HIGHCVSS 7.8fixed in 13.0.5≥ unspecified, < 13.02020-10-27
CVE-2020-3864 [HIGH] CWE-346 CVE-2020-3864: A logic issue was addressed with improved validation. This issue is fixed in iCloud for Windows 7.17 A logic issue was addressed with improved validation. This issue is fixed in iCloud for Windows 7.17, iTunes 12.10.4 for Windows, iCloud for Windows 10.9.2, tvOS 13.3.1, Safari 13.0.5, iOS 13.3.1 and iPadOS 13.3.1. A DOM object context may not have had a unique security origin.
nvd
CVE-2017-17821P3CRITICALCVSS 9.8v462017-12-21
CVE-2017-17821 [CRITICAL] CWE-119 CVE-2017-17821: WTF/wtf/FastBitVector.h in WebKit, as distributed in Safari Technology Preview Release 46, allows re WTF/wtf/FastBitVector.h in WebKit, as distributed in Safari Technology Preview Release 46, allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact because it calls the FastBitVectorWordOwner::resizeSlow function (in WTF/wtf/FastBitVector.cpp) for a purpose other than initializing a bitvector
nvd
CVE-2009-1704P3CRITICALCVSS 9.3≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1704 [CRITICAL] CWE-94 CVE-2009-1704: CFNetwork in Apple Safari before 4.0 misinterprets downloaded image files as local HTML documents in CFNetwork in Apple Safari before 4.0 misinterprets downloaded image files as local HTML documents in unspecified circumstances, which allows remote attackers to execute arbitrary JavaScript code by placing it in an image file.
nvd
CVE-2026-28962P3HIGHCVSS 7.5fixed in 26.52026-05-11
CVE-2026-28962 [HIGH] CWE-200 CVE-2026-28962: This issue was addressed with improved access restrictions. This issue is fixed in Safari 26.5, iOS This issue was addressed with improved access restrictions. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. Processing maliciously crafted web content may disclose sensitive user information.
nvd
CVE-2009-0321P4MEDIUMCVSS 4.3PoCv3.2.12009-01-28
CVE-2009-0321 [MEDIUM] CWE-59 CVE-2009-0321: Apple Safari 3.2.1 (aka AppVer 3.525.27.1) on Windows allows remote attackers to cause a denial of s Apple Safari 3.2.1 (aka AppVer 3.525.27.1) on Windows allows remote attackers to cause a denial of service (infinite loop or access violation) via a link to an http URI in which the authority (aka hostname) portion is either a (1) . (dot) or (2) .. (dot dot) sequence.
nvd
CVE-2010-1758P3CRITICALCVSS 9.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1758 [CRITICAL] CWE-399 CVE-2010-1758: Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving DOM Range objects.
nvd
CVE-2010-1761P3CRITICALCVSS 9.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1761 [CRITICAL] CWE-399 CVE-2010-1761: Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving HTML document subtrees.
nvd
CVE-2010-1405P3CRITICALCVSS 9.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1405 [CRITICAL] CWE-399 CVE-2010-1405: Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an HTML element that has custom vertical positioning.
nvd
Apple Safari vulnerabilities | cvebase