Apple Safari vulnerabilities
1,592 known vulnerabilities affecting apple/safari.
Total CVEs
1,592
CISA KEV
31
actively exploited
Public exploits
157
Exploited in wild
25
Severity breakdown
CRITICAL211HIGH603MEDIUM757LOW20UNKNOWN1
Vulnerabilities
Page 42 of 80
CVE-2016-4737HIGHCVSS 8.8fixed in 10.02016-09-25
CVE-2016-4737 [HIGH] CWE-119 CVE-2016-4737: WebKit in Apple iOS before 10, Safari before 10, tvOS before 10, and watchOS before 3 allows remote
WebKit in Apple iOS before 10, Safari before 10, tvOS before 10, and watchOS before 3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
nvdapple
CVE-2016-4730HIGHCVSS 8.8fixed in 10.02016-09-25
CVE-2016-4730 [HIGH] CVE-2016-4730: WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execu
WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4611, CVE-2016-4733, CVE-2016-4734, and CVE-2016-4735.
nvdapple
CVE-2016-4768HIGHCVSS 8.8fixed in 10.02016-09-25
CVE-2016-4768 [HIGH] CVE-2016-4768: WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10
WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4759, CVE-2016-4765, CVE-2016-4766, and CVE-2016-4767.
nvdapple
CVE-2016-4759HIGHCVSS 8.8fixed in 10.02016-09-25
CVE-2016-4759 [HIGH] CWE-119 CVE-2016-4759: WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10
WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4765, CVE-2016-4766, CVE-2016-4767, and CVE-2016-4768.
nvdapple
CVE-2016-4611HIGHCVSS 8.8fixed in 10.02016-09-25
CVE-2016-4611 [HIGH] CWE-119 CVE-2016-4611: WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execu
WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4730, CVE-2016-4733, CVE-2016-4734, and CVE-2016-4735.
nvdapple
CVE-2016-4767HIGHCVSS 8.8fixed in 10.02016-09-25
CVE-2016-4767 [HIGH] CVE-2016-4767: WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10
WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4759, CVE-2016-4765, CVE-2016-4766, and CVE-2016-4768.
nvdapple
CVE-2016-4729HIGHCVSS 8.8≤ 9.1.32016-09-25
CVE-2016-4729 [HIGH] CWE-119 CVE-2016-4729: WebKit in Apple iOS before 10 and Safari before 10 allows remote attackers to execute arbitrary code
WebKit in Apple iOS before 10 and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4731.
nvdapple
CVE-2016-4728HIGHCVSS 8.8fixed in 10.02016-09-25
CVE-2016-4728 [HIGH] CWE-20 CVE-2016-4728: WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10
WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 mishandles error prototypes, which allows remote attackers to execute arbitrary code via a crafted web site.
nvdapple
CVE-2016-4733HIGHCVSS 7.8fixed in 10.02016-09-25
CVE-2016-4733 [HIGH] CVE-2016-4733: WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execu
WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4611, CVE-2016-4730, CVE-2016-4734, and CVE-2016-4735.
nvdapple
CVE-2016-4760MEDIUMCVSS 6.5≤ 9.1.32016-09-25
CVE-2016-4760 [MEDIUM] CWE-284 CVE-2016-4760: WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote a
WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to conduct DNS rebinding attacks against non-HTTP Safari sessions by leveraging HTTP/0.9 support.
nvdapple
CVE-2016-4758MEDIUMCVSS 6.5≤ 9.1.32016-09-25
CVE-2016-4758 [MEDIUM] CWE-200 CVE-2016-4758: WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not proper
WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not properly restrict access to the location variable, which allows remote attackers to obtain sensitive information via a crafted web site.
nvdapple
CVE-2016-4763MEDIUMCVSS 6.8≤ 9.1.32016-09-25
CVE-2016-4763 [MEDIUM] CWE-310 CVE-2016-4763: WKWebView in WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 do
WKWebView in WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not properly verify X.509 certificates from HTTPS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
nvdapple
CVE-2016-4618MEDIUMCVSS 6.1v9.1.32016-09-25
CVE-2016-4618 [MEDIUM] CWE-79 CVE-2016-4618: Cross-site scripting (XSS) vulnerability in Safari Reader in Apple iOS before 10 and Safari before 1
Cross-site scripting (XSS) vulnerability in Safari Reader in Apple iOS before 10 and Safari before 10 allows remote attackers to inject arbitrary web script or HTML via a crafted web site, aka "Universal XSS (UXSS)."
nvdapple
CVE-2016-4751LOWCVSS 3.5≤ 9.1.32016-09-25
CVE-2016-4751 [LOW] CWE-254 CVE-2016-4751: The Safari Tabs component in Apple Safari before 10 allows remote attackers to spoof the address bar
The Safari Tabs component in Apple Safari before 10 allows remote attackers to spoof the address bar of a tab via a crafted web site.
nvdapple
CVE-2016-4657HIGHCVSS 8.8KEVPoCv9.1.32016-09-01
CVE-2016-4657 [HIGH] CVE-2016-4657: Safari 9.1.3
Apple Security Update: About the security content of Safari 9.1.3
Product: Safari
Version: 9.1.3
CVE: CVE-2016-4657
Component: WebKit
Impact: Visiting a maliciously crafted website may lead to arbitrary code execution
Description: A memory corruption issue was addressed through improved memory handling.
apple
CVE-2016-4586HIGHCVSS 8.8fixed in 9.1.22016-07-22
CVE-2016-4586 [HIGH] CWE-119 CVE-2016-4586: WebKit in Apple Safari before 9.1.2 and tvOS before 9.2.2 allows remote attackers to execute arbitra
WebKit in Apple Safari before 9.1.2 and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
nvdapple
CVE-2016-4624HIGHCVSS 8.8fixed in 9.1.22016-07-22
CVE-2016-4624 [HIGH] CVE-2016-4624: WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers
WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4589, CVE-2016-4622, and CVE-2016-4623.
nvdapple
CVE-2016-4584HIGHCVSS 8.8fixed in 9.1.22016-07-22
CVE-2016-4584 [HIGH] CWE-119 CVE-2016-4584: The WebKit Page Loading implementation in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS befo
The WebKit Page Loading implementation in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
nvdapple
CVE-2016-4622HIGHCVSS 8.8fixed in 9.1.22016-07-22
CVE-2016-4622 [HIGH] CVE-2016-4622: WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers
WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4589, CVE-2016-4623, and CVE-2016-4624.
nvdapple
CVE-2016-4623HIGHCVSS 8.8fixed in 9.1.22016-07-22
CVE-2016-4623 [HIGH] CVE-2016-4623: WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers
WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4589, CVE-2016-4622, and CVE-2016-4624.
nvdapple