cbcvebase.

Apple Safari vulnerabilities

1,654 known vulnerabilities affecting apple/safari.

Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1

Vulnerabilities

Page 42 of 83
CVE-2009-3384P3CRITICALCVSS 9.3≤ 4.0.3v0.8+58 more2009-11-13
CVE-2009-3384 [CRITICAL] CVE-2009-3384: Multiple unspecified vulnerabilities in WebKit in Apple Safari before 4.0.4 on Windows allow remote Multiple unspecified vulnerabilities in WebKit in Apple Safari before 4.0.4 on Windows allow remote FTP servers to execute arbitrary code, cause a denial of service (application crash), or obtain sensitive information via a crafted directory listing in a reply.
nvd
CVE-2017-2499P3HIGHCVSS 7.8fixed in 10.1.12017-05-22
CVE-2017-2499 [HIGH] CWE-119 CVE-2017-2499: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. The issue involves the "WebKit Web Inspector" component. It allows attackers to execute arbitrary unsigned code or cause a denial of service (memory corruption) via a crafted app.
nvdapple
CVE-2018-4274P3HIGHCVSS 7.5fixed in 11.1.22019-04-03
CVE-2018-4274 [HIGH] CWE-20 CVE-2018-4274: A spoofing issue existed in the handling of URLs. This issue was addressed with improved input valid A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, Safari 11.1.2.
nvdapple
CVE-2024-54551P3HIGHCVSS 7.5fixed in 17.62025-03-21
CVE-2024-54551 [HIGH] CWE-119 CVE-2024-54551: The issue was addressed with improved memory handling. This issue is fixed in Safari 17.6, iOS 17.6 The issue was addressed with improved memory handling. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing web content may lead to a denial-of-service.
nvdapple
CVE-2020-9903P3HIGHCVSS 7.5fixed in 13.1.2≥ unspecified, < Safari 13.1.22020-10-16
CVE-2020-9903 [HIGH] CWE-346 CVE-2020-9903: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.6 and iPadOS 1 A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.6 and iPadOS 13.6, Safari 13.1.2. A malicious attacker may cause Safari to suggest a password for the wrong domain.
nvdapple
CVE-2008-2307P3CRITICALCVSS 9.3≤ 3.1.1v3.0+5 more2008-06-23
CVE-2008-2307 [CRITICAL] CWE-399 CVE-2008-2307: Unspecified vulnerability in WebKit in Apple Safari before 3.1.2, as distributed in Mac OS X before Unspecified vulnerability in WebKit in Apple Safari before 3.1.2, as distributed in Mac OS X before 10.5.4, and standalone for Windows and Mac OS X 10.4, allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors involving JavaScript arrays that trigger memory corruption.
nvd
CVE-2021-30823P3MEDIUMCVSS 6.5fixed in 15.0.0≥ unspecified, < 152021-10-28
CVE-2021-30823 [MEDIUM] CVE-2021-30823: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.0.1 A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.0.1, iOS 14.8 and iPadOS 14.8, tvOS 15, Safari 15, watchOS 8. An attacker in a privileged network position may be able to bypass HSTS.
nvdapple
CVE-2026-20665P3MEDIUMCVSS 6.5fixed in 26.42026-03-25
CVE-2026-20665 [MEDIUM] CWE-693 CVE-2026-20665: This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
nvd
CVE-2014-4466P3HIGHCVSS 7.5≤ 6.2.0v7.0+8 more2014-12-10
CVE-2014-4466 [HIGH] CWE-399 CVE-2014-4466: WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-12-2-1.
nvd
CVE-2008-1026P3MEDIUMCVSS 6.8v3v3.12008-04-17
CVE-2008-1026 [MEDIUM] CWE-119 CVE-2008-1026: Integer overflow in the PCRE regular expression compiler (JavaScriptCore/pcre/pcre_compile.cpp) in A Integer overflow in the PCRE regular expression compiler (JavaScriptCore/pcre/pcre_compile.cpp) in Apple WebKit, as used in Safari before 3.1.1, allows remote attackers to execute arbitrary code via a regular expression with large, nested repetition counts, which triggers a heap-based buffer overflow.
nvd
CVE-2015-5780P4CRITICALCVSS 10.0≤ 8.0.82015-10-09
CVE-2015-5780 [CRITICAL] CWE-20 CVE-2015-5780: The Safari Extensions implementation in Apple Safari before 9 does not require user confirmation bef The Safari Extensions implementation in Apple Safari before 9 does not require user confirmation before replacing an installed extension, which has unspecified impact and attack vectors.
nvd
CVE-2017-2377P3HIGHCVSS 7.5≤ 10.0.32017-04-02
CVE-2017-2377 [HIGH] CWE-119 CVE-2017-2377: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit Web Inspector" component. It allows attackers to cause a denial of service (memory corruption and application crash) by leveraging a window-close action during a debugger-pause state.
nvdapple
CVE-2011-3926P3HIGHCVSS 7.5fixed in 6.02012-01-24
CVE-2011-3926 [HIGH] CWE-787 CVE-2011-3926: Heap-based buffer overflow in the tree builder in Google Chrome before 16.0.912.77 allows remote att Heap-based buffer overflow in the tree builder in Google Chrome before 16.0.912.77 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2005-3018P4MEDIUMCVSS 5.0PoCv1.0v1.1+7 more2005-09-21
CVE-2005-3018 [MEDIUM] CVE-2005-3018: Apple Safari allows remote attackers to cause a denial of service (application crash) via a crafted Apple Safari allows remote attackers to cause a denial of service (application crash) via a crafted data:// URL.
nvd
CVE-2021-30888P3HIGHCVSS 7.4v15.12021-10-27
CVE-2021-30888 [HIGH] CVE-2021-30888: Safari 15.1 Apple Security Update: About the security content of Safari 15.1 Product: Safari Version: 15.1 CVE: CVE-2021-30888 Component: WebKit Impact: A malicious website using Content Security Policy reports may be able to leak information via redirect behavior Description: An information leakage issue was addressed.
apple
CVE-2018-4186P3HIGHCVSS 7.5fixed in 11.12019-01-11
CVE-2018-4186 [HIGH] CWE-200 CVE-2018-4186: In Safari before 11.1, an information leakage issue existed in the handling of downloads in Safari P In Safari before 11.1, an information leakage issue existed in the handling of downloads in Safari Private Browsing. This issue was addressed with additional validation.
nvdapple
CVE-2010-1131P4MEDIUMCVSS 4.3PoCv4.0.52010-03-27
CVE-2010-1131 [MEDIUM] CVE-2010-1131: JavaScriptCore.dll, as used in Apple Safari 4.0.5 on Windows XP SP3, allows remote attackers to caus JavaScriptCore.dll, as used in Apple Safari 4.0.5 on Windows XP SP3, allows remote attackers to cause a denial of service (application crash) via an HTML document composed of many successive occurrences of the substring.
nvd
CVE-2018-4117P3MEDIUMCVSS 6.5fixed in 11.12018-04-03
CVE-2018-4117 [MEDIUM] CWE-200 CVE-2018-4117: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is affected. The issue involves the fetch API in the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy an
nvdapple
CVE-2008-0298P4MEDIUMCVSS 4.3PoCv2.0v2.0.1+3 more2008-01-16
CVE-2008-0298 [MEDIUM] CWE-20 CVE-2008-0298: KHTML WebKit as used in Apple Safari 2.x allows remote attackers to cause a denial of service (brows KHTML WebKit as used in Apple Safari 2.x allows remote attackers to cause a denial of service (browser crash) via a crafted web page, possibly involving a STYLE attribute of a DIV element.
nvd
CVE-2026-43725P3HIGHCVSS 7.1fixed in 26.5.22026-06-29
CVE-2026-43725 [HIGH] CWE-20 CVE-2026-43725: The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26 The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to process restricted web content outside the sandbox.
nvd
Apple Safari vulnerabilities | cvebase