Apple Safari vulnerabilities
1,654 known vulnerabilities affecting apple/safari.
Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1
Vulnerabilities
Page 40 of 83
CVE-2012-3665P3CRITICALCVSS 9.3≤ 5.1.7v1.0+75 more2012-07-25
CVE-2012-3665 [CRITICAL] CWE-119 CVE-2012-3665: WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cau
WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.
nvd
CVE-2012-3667P3CRITICALCVSS 9.3≤ 5.1.7v1.0+75 more2012-07-25
CVE-2012-3667 [CRITICAL] CWE-119 CVE-2012-3667: WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cau
WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.
nvd
CVE-2012-3600P3CRITICALCVSS 9.3≤ 5.1.7v1.0+75 more2012-07-25
CVE-2012-3600 [CRITICAL] CVE-2012-3600: WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cau
WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.
nvd
CVE-2012-3636P3CRITICALCVSS 9.3≤ 5.1.7v1.0+75 more2012-07-25
CVE-2012-3636 [CRITICAL] CWE-119 CVE-2012-3636: WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cau
WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.
nvd
CVE-2012-3592P3CRITICALCVSS 9.3≤ 5.1.7v1.0+75 more2012-07-25
CVE-2012-3592 [CRITICAL] CVE-2012-3592: WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cau
WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.
nvd
CVE-2012-3599P3CRITICALCVSS 9.3≤ 5.1.7v1.0+75 more2012-07-25
CVE-2012-3599 [CRITICAL] CVE-2012-3599: WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cau
WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.
nvd
CVE-2011-0237P3CRITICALCVSS 9.3≤ 5.0.5v1.0+54 more2011-07-21
CVE-2011-0237 [CRITICAL] CWE-119 CVE-2011-0237: WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or c
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.
nvd
CVE-2011-0253P3CRITICALCVSS 9.3≤ 5.0.5v1.0+54 more2011-07-21
CVE-2011-0253 [CRITICAL] CWE-119 CVE-2011-0253: WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or c
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.
nvd
CVE-2011-0240P3CRITICALCVSS 9.3≤ 5.0.5v1.0+54 more2011-07-21
CVE-2011-0240 [CRITICAL] CWE-119 CVE-2011-0240: WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or c
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.
nvd
CVE-2011-0223P3CRITICALCVSS 9.3≤ 5.0.5v1.0+54 more2011-07-21
CVE-2011-0223 [CRITICAL] CWE-119 CVE-2011-0223: WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or c
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.
nvd
CVE-2019-8848P3HIGHCVSS 7.8fixed in 13.0.32020-10-27
CVE-2019-8848 [HIGH] CVE-2019-8848: This issue was addressed with improved checks. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iClo
This issue was addressed with improved checks. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iCloud for Windows 10.9, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, iOS 13.3 and iPadOS 13.3, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. An application may be able to gain elevated privileges.
nvd
CVE-2018-4474P3HIGHCVSS 7.5fixed in 12≥ unspecified, < 122020-10-27
CVE-2018-4474 [HIGH] CWE-400 CVE-2018-4474: A memory consumption issue was addressed with improved memory handling. This issue is fixed in iClou
A memory consumption issue was addressed with improved memory handling. This issue is fixed in iCloud for Windows 7.7, watchOS 5, Safari 12, iOS 12, iTunes 12.9 for Windows, tvOS 12. Unexpected interaction causes an ASSERT failure.
nvdapple
CVE-2009-1233P4MEDIUMCVSS 4.3PoCv3.2.2v42009-04-02
CVE-2009-1233 [MEDIUM] CWE-20 CVE-2009-1233: Apple Safari 3.2.2 and 4 Beta on Windows allows remote attackers to cause a denial of service (appli
Apple Safari 3.2.2 and 4 Beta on Windows allows remote attackers to cause a denial of service (application crash) via an XML document containing many nested A elements.
nvd
CVE-2018-4329P3HIGHCVSS 7.5fixed in 122019-04-03
CVE-2018-4329 [HIGH] CWE-19 CVE-2018-4329: Clearing a history item may not clear visits with redirect chains. The issue was addressed with impr
Clearing a history item may not clear visits with redirect chains. The issue was addressed with improved data deletion. This issue affected versions prior to iOS 12, Safari 12.
nvdapple
CVE-2025-43541P4MEDIUMCVSS 4.3fixed in 26.22025-12-17
CVE-2025-43541 [MEDIUM] CWE-843 CVE-2025-43541: A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 26.
A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple
CVE-2009-1701P3CRITICALCVSS 9.3≤ 3.2.2v2.0+22 more2009-06-10
CVE-2009-1701 [CRITICAL] CWE-399 CVE-2009-1701: Use-after-free vulnerability in the JavaScript DOM implementation in WebKit in Apple Safari before 4
Use-after-free vulnerability in the JavaScript DOM implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by destroying a document.body element that has an unspecified XML contai
nvd
CVE-2025-24209P3HIGHCVSS 7.0fixed in 18.42025-03-31
CVE-2025-24209 [HIGH] CWE-120 CVE-2025-24209: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 1
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, watchOS 11.4. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2009-1709P3CRITICALCVSS 9.3≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1709 [CRITICAL] CWE-399 CVE-2009-1709: Use-after-free vulnerability in the garbage-collection implementation in WebCore in WebKit in Apple
Use-after-free vulnerability in the garbage-collection implementation in WebCore in WebKit in Apple Safari before 4.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption and application crash) via an SVG animation element, related to SVG set objects, SVG marker elements, the targetElement attribute, and uns
nvd
CVE-2010-0053P3CRITICALCVSS 9.3≤ 4.0.4v4.0+4 more2010-03-15
CVE-2010-0053 [CRITICAL] CWE-399 CVE-2010-0053: Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execu
Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the run-in Cascading Style Sheets (CSS) display property.
nvd
CVE-2010-3823P3CRITICALCVSS 9.3≤ 5.0.2v5.0+51 more2010-11-22
CVE-2010-3823 [CRITICAL] CVE-2010-3823: Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 an
Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving Geolocation objects. NOTE: this might overlap CVE-2010-3415.
nvd