cbcvebase.

Apple Safari vulnerabilities

1,654 known vulnerabilities affecting apple/safari.

Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1

Vulnerabilities

Page 41 of 83
CVE-2009-1705P3CRITICALCVSS 9.3≤ 3.2.3v3.0+10 more2009-06-10
CVE-2009-1705 [CRITICAL] CWE-189 CVE-2009-1705: CoreGraphics in Apple Safari before 4.0 on Windows does not properly use arithmetic during automatic CoreGraphics in Apple Safari before 4.0 on Windows does not properly use arithmetic during automatic hinting of TrueType fonts, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted font data.
nvd
CVE-2021-23841P3MEDIUMCVSS 5.9fixed in 14.1.12021-02-16
CVE-2021-23841 [MEDIUM] CWE-476 CVE-2021-23841: The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while parsing the issuer field (which might occur if the issuer field is maliciously constructed). This ma
nvdapple
CVE-2011-3845P3HIGHCVSS 7.6v5.1.22012-03-08
CVE-2011-3845 [HIGH] CWE-399 CVE-2011-3845: Use-after-free vulnerability in Apple Safari 5.1.2, when a plug-in with a blocking function is insta Use-after-free vulnerability in Apple Safari 5.1.2, when a plug-in with a blocking function is installed, allows user-assisted remote attackers to execute arbitrary code via a crafted web page that is accessed during user interaction with the plug-in, leading to improper coordination between an API call and the plug-in unloading functionality, as demons
nvd
CVE-2014-4459P3MEDIUMCVSS 6.8≥ 6.0, < 6.2.1≥ 7.0, < 7.1.1+1 more2014-11-18
CVE-2014-4459 [MEDIUM] CVE-2014-4459: Use-after-free vulnerability in WebKit, as used in Apple OS X before 10.10.1, allows remote attacker Use-after-free vulnerability in WebKit, as used in Apple OS X before 10.10.1, allows remote attackers to execute arbitrary code via crafted page objects in an HTML document.
nvd
CVE-2010-0047P3HIGHCVSS 8.8≤ 4.0.4v4.0+4 more2010-03-15
CVE-2010-0047 [HIGH] CWE-399 CVE-2010-0047: Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execu Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to "HTML object element fallback content."
nvd
CVE-2005-2594P4MEDIUMCVSS 5.0PoCv1.32005-08-17
CVE-2005-2594 [MEDIUM] CVE-2005-2594: Apple Safari 1.3 (132) on Mac OS X 1.3.9 allows remote attackers to cause a denial of service (crash Apple Safari 1.3 (132) on Mac OS X 1.3.9 allows remote attackers to cause a denial of service (crash) via certain Javascript, possibly involving a function that defines a handler for itself within the function body.
nvd
CVE-2010-3257P3CRITICALCVSS 9.3fixed in 4.1.3≥ 5.0, < 5.0.32010-09-07
CVE-2010-3257 [CRITICAL] CWE-416 CVE-2010-3257: Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving element focus.
nvd
CVE-2017-5949P3CRITICALCVSS 9.8v222017-04-03
CVE-2017-5949 [CRITICAL] CWE-787 CVE-2017-5949: JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 22, allows remote atta JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 22, allows remote attackers to cause a denial of service (heap-based out-of-bounds write and application crash) or possibly have unspecified other impact via crafted JavaScript code that triggers access to red-zone memory locations, related to jit/ThunkGenerators.cpp, llin
nvd
CVE-2010-4494P3HIGHCVSS 7.5fixed in 5.0.42010-12-07
CVE-2010-4494 [HIGH] CWE-415 CVE-2010-4494: Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.5 Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
nvd
CVE-2012-3615P3CRITICALCVSS 9.3≤ 5.1.7v1.0+75 more2012-07-25
CVE-2012-3615 [CRITICAL] CVE-2012-3615: WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cau WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.
nvd
CVE-2012-3683P3CRITICALCVSS 9.3≤ 5.1.7v1.0+75 more2012-07-25
CVE-2012-3683 [CRITICAL] CWE-119 CVE-2012-3683: WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cau WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.
nvd
CVE-2012-3666P3CRITICALCVSS 9.3≤ 5.1.7v1.0+75 more2012-07-25
CVE-2012-3666 [CRITICAL] CWE-119 CVE-2012-3666: WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cau WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.
nvd
CVE-2012-3637P3CRITICALCVSS 9.3≤ 5.1.7v1.0+75 more2012-07-25
CVE-2012-3637 [CRITICAL] CVE-2012-3637: WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cau WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.
nvd
CVE-2012-3630P3CRITICALCVSS 9.3≤ 5.1.7v1.0+75 more2012-07-25
CVE-2012-3630 [CRITICAL] CVE-2012-3630: WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cau WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.
nvd
CVE-2025-31184P3HIGHCVSS 7.8fixed in 18.42025-03-31
CVE-2025-31184 [HIGH] CWE-281 CVE-2025-31184: This issue was addressed with improved permissions checking. This issue is fixed in Safari 18.4, iOS This issue was addressed with improved permissions checking. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4. An app may gain unauthorized access to Local Network.
nvdapple
CVE-2012-3590P3HIGHCVSS 8.8≤ 5.1.7v1.0+75 more2012-07-25
CVE-2012-3590 [HIGH] CVE-2012-3590: WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cau WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.
nvd
CVE-2010-1806P3CRITICALCVSS 9.3v4.0v4.0.0b+8 more2010-09-10
CVE-2010-1806 [CRITICAL] CWE-399 CVE-2010-1806: Use-after-free vulnerability in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2 allows remote att Use-after-free vulnerability in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via run-in styling in an element, related to object pointers.
nvd
CVE-2010-1750P3CRITICALCVSS 9.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1750 [CRITICAL] CWE-399 CVE-2010-1750: Use-after-free vulnerability in Apple Safari before 5.0 on Windows allows remote attackers to execut Use-after-free vulnerability in Apple Safari before 5.0 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to improper window management.
nvd
CVE-2021-30698P3HIGHCVSS 7.5fixed in 14.1.12021-09-08
CVE-2021-30698 [HIGH] CWE-476 CVE-2021-30698: A null pointer dereference was addressed with improved input validation. This issue is fixed in macO A null pointer dereference was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.4, Safari 14.1.1, iOS 14.6 and iPadOS 14.6. A remote attacker may be able to cause a denial of service.
nvdapple
CVE-2017-2392P3HIGHCVSS 7.8≤ 10.0.32017-04-02
CVE-2017-2392 [HIGH] CWE-119 CVE-2017-2392: An issue was discovered in certain Apple products. Safari before 10.1 is affected. The issue involve An issue was discovered in certain Apple products. Safari before 10.1 is affected. The issue involves the "WebKit" component. It allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted app.
nvdapple