Apple Safari vulnerabilities
1,654 known vulnerabilities affecting apple/safari.
Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1
Vulnerabilities
Page 42 of 83
CVE-2009-3384P3CRITICALCVSS 9.3≤ 4.0.3v0.8+58 more2009-11-13
CVE-2009-3384 [CRITICAL] CVE-2009-3384: Multiple unspecified vulnerabilities in WebKit in Apple Safari before 4.0.4 on Windows allow remote
Multiple unspecified vulnerabilities in WebKit in Apple Safari before 4.0.4 on Windows allow remote FTP servers to execute arbitrary code, cause a denial of service (application crash), or obtain sensitive information via a crafted directory listing in a reply.
nvd
CVE-2017-2499P3HIGHCVSS 7.8fixed in 10.1.12017-05-22
CVE-2017-2499 [HIGH] CWE-119 CVE-2017-2499: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. The issue involves the "WebKit Web Inspector" component. It allows attackers to execute arbitrary unsigned code or cause a denial of service (memory corruption) via a crafted app.
nvdapple
CVE-2018-4274P3HIGHCVSS 7.5fixed in 11.1.22019-04-03
CVE-2018-4274 [HIGH] CWE-20 CVE-2018-4274: A spoofing issue existed in the handling of URLs. This issue was addressed with improved input valid
A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, Safari 11.1.2.
nvdapple
CVE-2024-54551P3HIGHCVSS 7.5fixed in 17.62025-03-21
CVE-2024-54551 [HIGH] CWE-119 CVE-2024-54551: The issue was addressed with improved memory handling. This issue is fixed in Safari 17.6, iOS 17.6
The issue was addressed with improved memory handling. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing web content may lead to a denial-of-service.
nvdapple
CVE-2020-9903P3HIGHCVSS 7.5fixed in 13.1.2≥ unspecified, < Safari 13.1.22020-10-16
CVE-2020-9903 [HIGH] CWE-346 CVE-2020-9903: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.6 and iPadOS 1
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.6 and iPadOS 13.6, Safari 13.1.2. A malicious attacker may cause Safari to suggest a password for the wrong domain.
nvdapple
CVE-2008-2307P3CRITICALCVSS 9.3≤ 3.1.1v3.0+5 more2008-06-23
CVE-2008-2307 [CRITICAL] CWE-399 CVE-2008-2307: Unspecified vulnerability in WebKit in Apple Safari before 3.1.2, as distributed in Mac OS X before
Unspecified vulnerability in WebKit in Apple Safari before 3.1.2, as distributed in Mac OS X before 10.5.4, and standalone for Windows and Mac OS X 10.4, allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors involving JavaScript arrays that trigger memory corruption.
nvd
CVE-2021-30823P3MEDIUMCVSS 6.5fixed in 15.0.0≥ unspecified, < 152021-10-28
CVE-2021-30823 [MEDIUM] CVE-2021-30823: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.0.1
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.0.1, iOS 14.8 and iPadOS 14.8, tvOS 15, Safari 15, watchOS 8. An attacker in a privileged network position may be able to bypass HSTS.
nvdapple
CVE-2026-20665P3MEDIUMCVSS 6.5fixed in 26.42026-03-25
CVE-2026-20665 [MEDIUM] CWE-693 CVE-2026-20665: This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS
This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
nvd
CVE-2014-4466P3HIGHCVSS 7.5≤ 6.2.0v7.0+8 more2014-12-10
CVE-2014-4466 [HIGH] CWE-399 CVE-2014-4466: WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote
WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-12-2-1.
nvd
CVE-2008-1026P3MEDIUMCVSS 6.8v3v3.12008-04-17
CVE-2008-1026 [MEDIUM] CWE-119 CVE-2008-1026: Integer overflow in the PCRE regular expression compiler (JavaScriptCore/pcre/pcre_compile.cpp) in A
Integer overflow in the PCRE regular expression compiler (JavaScriptCore/pcre/pcre_compile.cpp) in Apple WebKit, as used in Safari before 3.1.1, allows remote attackers to execute arbitrary code via a regular expression with large, nested repetition counts, which triggers a heap-based buffer overflow.
nvd
CVE-2015-5780P4CRITICALCVSS 10.0≤ 8.0.82015-10-09
CVE-2015-5780 [CRITICAL] CWE-20 CVE-2015-5780: The Safari Extensions implementation in Apple Safari before 9 does not require user confirmation bef
The Safari Extensions implementation in Apple Safari before 9 does not require user confirmation before replacing an installed extension, which has unspecified impact and attack vectors.
nvd
CVE-2017-2377P3HIGHCVSS 7.5≤ 10.0.32017-04-02
CVE-2017-2377 [HIGH] CWE-119 CVE-2017-2377: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit Web Inspector" component. It allows attackers to cause a denial of service (memory corruption and application crash) by leveraging a window-close action during a debugger-pause state.
nvdapple
CVE-2011-3926P3HIGHCVSS 7.5fixed in 6.02012-01-24
CVE-2011-3926 [HIGH] CWE-787 CVE-2011-3926: Heap-based buffer overflow in the tree builder in Google Chrome before 16.0.912.77 allows remote att
Heap-based buffer overflow in the tree builder in Google Chrome before 16.0.912.77 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2005-3018P4MEDIUMCVSS 5.0PoCv1.0v1.1+7 more2005-09-21
CVE-2005-3018 [MEDIUM] CVE-2005-3018: Apple Safari allows remote attackers to cause a denial of service (application crash) via a crafted
Apple Safari allows remote attackers to cause a denial of service (application crash) via a crafted data:// URL.
nvd
CVE-2021-30888P3HIGHCVSS 7.4v15.12021-10-27
CVE-2021-30888 [HIGH] CVE-2021-30888: Safari 15.1
Apple Security Update: About the security content of Safari 15.1
Product: Safari
Version: 15.1
CVE: CVE-2021-30888
Component: WebKit
Impact: A malicious website using Content Security Policy reports may be able to leak information via redirect behavior
Description: An information leakage issue was addressed.
apple
CVE-2018-4186P3HIGHCVSS 7.5fixed in 11.12019-01-11
CVE-2018-4186 [HIGH] CWE-200 CVE-2018-4186: In Safari before 11.1, an information leakage issue existed in the handling of downloads in Safari P
In Safari before 11.1, an information leakage issue existed in the handling of downloads in Safari Private Browsing. This issue was addressed with additional validation.
nvdapple
CVE-2010-1131P4MEDIUMCVSS 4.3PoCv4.0.52010-03-27
CVE-2010-1131 [MEDIUM] CVE-2010-1131: JavaScriptCore.dll, as used in Apple Safari 4.0.5 on Windows XP SP3, allows remote attackers to caus
JavaScriptCore.dll, as used in Apple Safari 4.0.5 on Windows XP SP3, allows remote attackers to cause a denial of service (application crash) via an HTML document composed of many successive occurrences of the substring.
nvd
CVE-2018-4117P3MEDIUMCVSS 6.5fixed in 11.12018-04-03
CVE-2018-4117 [MEDIUM] CWE-200 CVE-2018-4117: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is affected. The issue involves the fetch API in the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy an
nvdapple
CVE-2008-0298P4MEDIUMCVSS 4.3PoCv2.0v2.0.1+3 more2008-01-16
CVE-2008-0298 [MEDIUM] CWE-20 CVE-2008-0298: KHTML WebKit as used in Apple Safari 2.x allows remote attackers to cause a denial of service (brows
KHTML WebKit as used in Apple Safari 2.x allows remote attackers to cause a denial of service (browser crash) via a crafted web page, possibly involving a STYLE attribute of a DIV element.
nvd
CVE-2026-43725P3HIGHCVSS 7.1fixed in 26.5.22026-06-29
CVE-2026-43725 [HIGH] CWE-20 CVE-2026-43725: The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26
The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to process restricted web content outside the sandbox.
nvd