Apple Safari vulnerabilities

1,592 known vulnerabilities affecting apple/safari.

Total CVEs
1,592
CISA KEV
31
actively exploited
Public exploits
157
Exploited in wild
25
Severity breakdown
CRITICAL211HIGH603MEDIUM757LOW20UNKNOWN1

Vulnerabilities

Page 37 of 80
CVE-2017-2521HIGHCVSS 8.8PoCv10.1.12017-05-15
CVE-2017-2521 [HIGH] CVE-2017-2521: Safari 10.1.1 Apple Security Update: About the security content of Safari 10.1.1 Product: Safari Version: 10.1.1 CVE: CVE-2017-2521 Component: WebKit Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2011-3438HIGHCVSS 8.8v5.0.62017-04-24
CVE-2011-3438 [HIGH] CWE-119 CVE-2011-3438: WebKit, as used in Safari 5.0.6, allows remote attackers to cause a denial of service (process crash WebKit, as used in Safari 5.0.6, allows remote attackers to cause a denial of service (process crash) or arbitrary code execution.
nvd
CVE-2017-5949CRITICALCVSS 9.8v222017-04-03
CVE-2017-5949 [CRITICAL] CWE-787 CVE-2017-5949: JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 22, allows remote atta JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 22, allows remote attackers to cause a denial of service (heap-based out-of-bounds write and application crash) or possibly have unspecified other impact via crafted JavaScript code that triggers access to red-zone memory locations, related to jit/ThunkGenerators.cpp, llin
nvd
CVE-2016-10226HIGHCVSS 7.5v182017-04-03
CVE-2016-10226 [HIGH] CWE-125 CVE-2016-10226: JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 18, allows remote atta JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 18, allows remote attackers to cause a denial of service (bitfield out-of-bounds read and application crash) via crafted JavaScript code that is mishandled in the operatorString function, related to assembler/MacroAssemblerARM64.h, assembler/MacroAssemblerX86Common.h, and wa
nvd
CVE-2016-10222HIGHCVSS 7.5v182017-04-03
CVE-2016-10222 [HIGH] CWE-20 CVE-2016-10222: runtime/JSONObject.cpp in JavaScriptCore in WebKit, as distributed in Safari Technology Preview Rele runtime/JSONObject.cpp in JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 18, allows remote attackers to cause a denial of service (segmentation violation and application crash) via crafted JavaScript code that triggers a "type confusion" in the JSON.stringify function.
nvd
CVE-2017-2444HIGHCVSS 8.8≤ 10.0.32017-04-02
CVE-2017-2444 [HIGH] CWE-119 CVE-2017-2444: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "CoreGraphics" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a cr
nvdapple
CVE-2017-2466HIGHCVSS 8.8PoC≤ 10.0.32017-04-02
CVE-2017-2466 [HIGH] CWE-119 CVE-2017-2466: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
nvdapple
CVE-2017-2455HIGHCVSS 8.8PoC≤ 10.0.32017-04-02
CVE-2017-2455 [HIGH] CWE-119 CVE-2017-2455: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
nvdapple
CVE-2017-2377HIGHCVSS 7.5≤ 10.0.32017-04-02
CVE-2017-2377 [HIGH] CWE-119 CVE-2017-2377: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit Web Inspector" component. It allows attackers to cause a denial of service (memory corruption and application crash) by leveraging a window-close action during a debugger-pause state.
nvdapple
CVE-2017-2470HIGHCVSS 8.8PoC≤ 10.0.32017-04-02
CVE-2017-2470 [HIGH] CWE-119 CVE-2017-2470: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
nvdapple
CVE-2017-2457HIGHCVSS 8.8PoC≤ 10.0.32017-04-02
CVE-2017-2457 [HIGH] CWE-119 CVE-2017-2457: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
nvdapple
CVE-2017-2396HIGHCVSS 8.8≤ 10.0.32017-04-02
CVE-2017-2396 [HIGH] CWE-119 CVE-2017-2396: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
nvdapple
CVE-2017-2389HIGHCVSS 8.1≤ 10.0.32017-04-02
CVE-2017-2389 [HIGH] CVE-2017-2389: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof an HTTP authentication sheet or cause a denial of service via a crafted web site.
nvdapple
CVE-2017-2378HIGHCVSS 8.8≤ 10.0.32017-04-02
CVE-2017-2378 [HIGH] CWE-20 CVE-2017-2378: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves bookmark creation in the "WebKit" component. It allows remote attackers to execute arbitrary code or spoof a bookmark by leveraging mishandling of links during drag-and-drop actions.
nvdapple
CVE-2017-2468HIGHCVSS 8.8PoC≤ 10.0.32017-04-02
CVE-2017-2468 [HIGH] CWE-119 CVE-2017-2468: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
nvdapple
CVE-2017-2433HIGHCVSS 8.8≤ 10.0.32017-04-02
CVE-2017-2433 [HIGH] CWE-119 CVE-2017-2433: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
nvdapple
CVE-2017-2447HIGHCVSS 8.1PoC≤ 10.0.32017-04-02
CVE-2017-2447 [HIGH] CWE-119 CVE-2017-2447: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted web site.
nvdapple
CVE-2017-2392HIGHCVSS 7.8≤ 10.0.32017-04-02
CVE-2017-2392 [HIGH] CWE-119 CVE-2017-2392: An issue was discovered in certain Apple products. Safari before 10.1 is affected. The issue involve An issue was discovered in certain Apple products. Safari before 10.1 is affected. The issue involves the "WebKit" component. It allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted app.
nvdapple
CVE-2017-2464HIGHCVSS 8.8PoC≤ 10.0.32017-04-02
CVE-2017-2464 [HIGH] CWE-119 CVE-2017-2464: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
nvdapple
CVE-2017-2394HIGHCVSS 8.8≤ 10.0.32017-04-02
CVE-2017-2394 [HIGH] CWE-119 CVE-2017-2394: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
nvdapple