Apple Safari vulnerabilities
1,654 known vulnerabilities affecting apple/safari.
Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1
Vulnerabilities
Page 36 of 83
CVE-2010-1771P3CRITICALCVSS 9.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1771 [CRITICAL] CWE-399 CVE-2010-1771: Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and
Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving fonts.
nvd
CVE-2010-1786P3CRITICALCVSS 9.3≤ 5.0v4.0+7 more2010-07-30
CVE-2010-1786 [CRITICAL] CWE-399 CVE-2010-1786: Use-after-free vulnerability in WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 an
Use-after-free vulnerability in WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a foreignObject element in an SVG document.
nvd
CVE-2010-1780P3CRITICALCVSS 9.3≤ 5.0v4.0+7 more2010-07-30
CVE-2010-1780 [CRITICAL] CWE-399 CVE-2010-1780: Use-after-free vulnerability in WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 an
Use-after-free vulnerability in WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to element focus.
nvd
CVE-2010-0054P3CRITICALCVSS 9.3≤ 4.0.4v4.0+4 more2010-03-15
CVE-2010-0054 [CRITICAL] CWE-399 CVE-2010-0054: Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execu
Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving HTML IMG elements.
nvd
CVE-2010-3824P3CRITICALCVSS 9.3≤ 5.0.2v5.0+51 more2010-11-22
CVE-2010-3824 [CRITICAL] CWE-399 CVE-2010-3824: Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 an
Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving SVG use elements.
nvd
CVE-2010-3811P3CRITICALCVSS 9.3≤ 5.0.2v5.0+51 more2010-11-22
CVE-2010-3811 [CRITICAL] CWE-399 CVE-2010-3811: Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 an
Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving element attributes.
nvd
CVE-2010-3816P3CRITICALCVSS 9.3≤ 5.0.2v5.0+51 more2010-11-22
CVE-2010-3816 [CRITICAL] CWE-399 CVE-2010-3816: Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 an
Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving scrollbars.
nvd
CVE-2010-3818P3CRITICALCVSS 9.3≤ 5.0.2v5.0+51 more2010-11-22
CVE-2010-3818 [CRITICAL] CWE-399 CVE-2010-3818: Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 an
Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving inline text boxes.
nvd
CVE-2010-1385P3CRITICALCVSS 9.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1385 [CRITICAL] CWE-399 CVE-2010-1385: Use-after-free vulnerability in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, a
Use-after-free vulnerability in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.
nvd
CVE-2018-4311P3HIGHCVSS 8.1fixed in 122019-04-03
CVE-2018-4311 [HIGH] CWE-200 CVE-2018-4311: The issue was addressed by removing origin information. This issue affected versions prior to iOS 12
The issue was addressed by removing origin information. This issue affected versions prior to iOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
nvdapple
CVE-2017-2389P3HIGHCVSS 8.1≤ 10.0.32017-04-02
CVE-2017-2389 [HIGH] CVE-2017-2389: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof an HTTP authentication sheet or cause a denial of service via a crafted web site.
nvdapple
CVE-2010-3820P3CRITICALCVSS 9.3≤ 5.0.2v5.0+51 more2010-11-22
CVE-2010-3820 [CRITICAL] CWE-399 CVE-2010-3820: WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on M
WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, accesses uninitialized memory during processing of editable elements, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted web site.
nvd
CVE-2011-1797P3CRITICALCVSS 9.3≤ 5.0.5v1.0+54 more2011-07-21
CVE-2011-1797 [CRITICAL] CWE-119 CVE-2011-1797: WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or c
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.
nvd
CVE-2016-4733P3HIGHCVSS 7.8fixed in 10.02016-09-25
CVE-2016-4733 [HIGH] CVE-2016-4733: WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execu
WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4611, CVE-2016-4730, CVE-2016-4734, and CVE-2016-4735.
nvdapple
CVE-2011-0235P3CRITICALCVSS 9.3≤ 5.0.5v1.0+54 more2011-07-21
CVE-2011-0235 [CRITICAL] CWE-119 CVE-2011-0235: WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or c
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.
nvd
CVE-2011-0233P3CRITICALCVSS 9.3≤ 5.0.5v1.0+54 more2011-07-21
CVE-2011-0233 [CRITICAL] CWE-119 CVE-2011-0233: WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or c
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.
nvd
CVE-2011-1288P3CRITICALCVSS 9.3≤ 5.0.5v1.0+54 more2011-07-21
CVE-2011-1288 [CRITICAL] CWE-119 CVE-2011-1288: WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or c
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.
nvd
CVE-2011-0255P3CRITICALCVSS 9.3≤ 5.0.5v1.0+54 more2011-07-21
CVE-2011-0255 [CRITICAL] CWE-119 CVE-2011-0255: WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or c
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.
nvd
CVE-2011-0218P3CRITICALCVSS 9.3≤ 5.0.5v1.0+54 more2011-07-21
CVE-2011-0218 [CRITICAL] CWE-119 CVE-2011-0218: WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or c
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.
nvd
CVE-2011-0238P3CRITICALCVSS 9.3≤ 5.0.5v1.0+54 more2011-07-21
CVE-2011-0238 [CRITICAL] CWE-119 CVE-2011-0238: WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or c
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.
nvd