Apple Safari vulnerabilities
1,592 known vulnerabilities affecting apple/safari.
Total CVEs
1,592
CISA KEV
31
actively exploited
Public exploits
157
Exploited in wild
25
Severity breakdown
CRITICAL211HIGH603MEDIUM757LOW20UNKNOWN1
Vulnerabilities
Page 44 of 80
CVE-2016-1785MEDIUMCVSS 6.5≤ 9.0.32016-03-24
CVE-2016-1785 [MEDIUM] CWE-200 CVE-2016-1785: The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles c
The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles character encoding during access to cached data, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
nvdapple
CVE-2016-1786MEDIUMCVSS 5.4≤ 9.0.32016-03-24
CVE-2016-1786 [MEDIUM] CWE-200 CVE-2016-1786: The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles H
The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles HTTP responses with a 3xx (aka redirection) status code, which allows remote attackers to spoof the displayed URL, bypass the Same Origin Policy, and obtain sensitive cached information via a crafted web site.
nvdapple
CVE-2016-1772MEDIUMCVSS 4.3≤ 9.0.32016-03-24
CVE-2016-1772 [MEDIUM] CWE-200 CVE-2016-1772: The Top Sites feature in Apple Safari before 9.1 mishandles cookie storage, which makes it easier fo
The Top Sites feature in Apple Safari before 9.1 mishandles cookie storage, which makes it easier for remote web servers to track users via unspecified vectors.
nvdapple
CVE-2016-1779MEDIUMCVSS 6.5≤ 9.0.32016-03-24
CVE-2016-1779 [MEDIUM] CWE-200 CVE-2016-1779: WebKit in Apple iOS before 9.3 and Safari before 9.1 allows remote attackers to bypass the Same Orig
WebKit in Apple iOS before 9.3 and Safari before 9.1 allows remote attackers to bypass the Same Origin Policy and obtain physical-location data via a crafted geolocation request.
nvdapple
CVE-2009-2197MEDIUMCVSS 4.3≤ 9.0.32016-03-24
CVE-2009-2197 [MEDIUM] CWE-19 CVE-2009-2197: Apple Safari before 9.1 allows remote attackers to spoof the user interface via a web page that plac
Apple Safari before 9.1 allows remote attackers to spoof the user interface via a web page that places text in a crafted context, leading to unintended use of that text within a Safari dialog.
nvdapple
CVE-2016-1771MEDIUMCVSS 6.5≤ 9.0.32016-03-24
CVE-2016-1771 [MEDIUM] CWE-19 CVE-2016-1771: The Downloads feature in Apple Safari before 9.1 mishandles file expansion, which allows remote atta
The Downloads feature in Apple Safari before 9.1 mishandles file expansion, which allows remote attackers to cause a denial of service via a crafted web site.
nvdapple
CVE-2016-1781MEDIUMCVSS 4.3≤ 9.0.32016-03-24
CVE-2016-1781 [MEDIUM] CWE-19 CVE-2016-1781: WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles attachment URLs, which makes it easi
WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles attachment URLs, which makes it easier for remote web servers to track users via unspecified vectors.
nvdapple
CVE-2016-1725HIGHCVSS 8.8≤ 9.0.22016-02-01
CVE-2016-1725 [HIGH] CVE-2016-1725: WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3, allows remote attackers to execut
WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1723 and CVE-2016-1726.
nvdapple
CVE-2016-1723HIGHCVSS 8.8≤ 9.0.22016-02-01
CVE-2016-1723 [HIGH] CWE-119 CVE-2016-1723: WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3, allows remote attackers to execut
WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1725 and CVE-2016-1726.
nvdapple
CVE-2016-1726HIGHCVSS 8.8≤ 9.0.22016-02-01
CVE-2016-1726 [HIGH] CVE-2016-1726: WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3, allows remote attackers to execut
WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1723 and CVE-2016-1725.
nvdapple
CVE-2016-1724HIGHCVSS 8.8fixed in 9.0.32016-02-01
CVE-2016-1724 [HIGH] CWE-119 CVE-2016-1724: WebKit, as used in Apple iOS before 9.2.1, Safari before 9.0.3, and tvOS before 9.1.1, allows remote
WebKit, as used in Apple iOS before 9.2.1, Safari before 9.0.3, and tvOS before 9.1.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1727.
nvdapple
CVE-2016-1727HIGHCVSS 8.8fixed in 9.0.32016-02-01
CVE-2016-1727 [HIGH] CVE-2016-1727: WebKit, as used in Apple iOS before 9.2.1, Safari before 9.0.3, and tvOS before 9.1.1, allows remote
WebKit, as used in Apple iOS before 9.2.1, Safari before 9.0.3, and tvOS before 9.1.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1724.
nvdapple
CVE-2016-1728MEDIUMCVSS 4.3≤ 9.0.22016-02-01
CVE-2016-1728 [MEDIUM] CWE-200 CVE-2016-1728: The Cascading Style Sheets (CSS) implementation in Apple iOS before 9.2.1 and Safari before 9.0.3 mi
The Cascading Style Sheets (CSS) implementation in Apple iOS before 9.2.1 and Safari before 9.0.3 mishandles the "a:visited button" selector during height processing, which makes it easier for remote attackers to obtain sensitive browser-history information via a crafted web site.
nvdapple
CVE-2015-7104MEDIUMCVSS 6.8≤ 9.0.12015-12-11
CVE-2015-7104 [MEDIUM] CWE-119 CVE-2015-7104: WebKit in Apple Safari before 9.0.2 and tvOS before 9.1 allows remote attackers to execute arbitrary
WebKit in Apple Safari before 9.0.2 and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
nvdapple
CVE-2015-7093MEDIUMCVSS 4.3≤ 9.0.12015-12-11
CVE-2015-7093 [MEDIUM] CWE-20 CVE-2015-7093: Safari in Apple iOS before 9.2 allows remote attackers to spoof a URL in the user interface via a cr
Safari in Apple iOS before 9.2 allows remote attackers to spoof a URL in the user interface via a crafted web site.
nvd
CVE-2015-7096MEDIUMCVSS 6.8≤ 9.0.12015-12-11
CVE-2015-7096 [MEDIUM] CVE-2015-7096: WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to
WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-7048, CVE-2015-7095, CVE-2015-7097, CVE-2015-7098, CVE-2015-7099, CVE-2015-7100, CVE-2015-7101, CVE-2015
nvdapple
CVE-2015-7097MEDIUMCVSS 6.8≤ 9.0.12015-12-11
CVE-2015-7097 [MEDIUM] CVE-2015-7097: WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to
WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-7048, CVE-2015-7095, CVE-2015-7096, CVE-2015-7098, CVE-2015-7099, CVE-2015-7100, CVE-2015-7101, CVE-2015
nvdapple
CVE-2015-7099MEDIUMCVSS 6.8≤ 9.0.12015-12-11
CVE-2015-7099 [MEDIUM] CVE-2015-7099: WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to
WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-7048, CVE-2015-7095, CVE-2015-7096, CVE-2015-7097, CVE-2015-7098, CVE-2015-7100, CVE-2015-7101, CVE-2015
nvdapple
CVE-2015-7098MEDIUMCVSS 6.8≤ 9.0.12015-12-11
CVE-2015-7098 [MEDIUM] CVE-2015-7098: WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to
WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-7048, CVE-2015-7095, CVE-2015-7096, CVE-2015-7097, CVE-2015-7099, CVE-2015-7100, CVE-2015-7101, CVE-2015
nvdapple
CVE-2015-7102MEDIUMCVSS 6.8≤ 9.0.12015-12-11
CVE-2015-7102 [MEDIUM] CVE-2015-7102: WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to
WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-7048, CVE-2015-7095, CVE-2015-7096, CVE-2015-7097, CVE-2015-7098, CVE-2015-7099, CVE-2015-7100, CVE-2015
nvdapple