cbcvebase.

Apple Safari vulnerabilities

1,677 known vulnerabilities affecting apple/safari.

Total CVEs
1,677
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
52
Severity breakdown
CRITICAL211HIGH628MEDIUM815LOW22UNKNOWN1

Vulnerabilities

Page 56 of 84
CVE-2015-7013P4MEDIUMCVSS 6.8v9.0.1
CVE-2015-7013 [MEDIUM] CVE-2015-7013: Safari 9.0.1 Apple Security Update: About the security content of Safari 9.0.1 Product: Safari Version: 9.0.1 CVE: CVE-2015-7013 Component: CVE-2015-5931
apple
CVE-2015-7011P4MEDIUMCVSS 6.8≤ 9.02015-10-23
CVE-2015-7011 [MEDIUM] CWE-119 CVE-2015-7011: WebKit, as used in Apple Safari before 9.0.1 and iTunes before 12.3.1, allows remote attackers to ex WebKit, as used in Apple Safari before 9.0.1 and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-3 and APPLE-SA-2015-10-21-5.
nvdapple
CVE-2009-3455P4HIGHCVSS 7.5≤ 4.0.2v0.8+38 more2009-09-29
CVE-2009-3455 [HIGH] CVE-2009-3455: Apple Safari, possibly before 4.0.3, on Mac OS X does not properly handle a '\0' character in a doma Apple Safari, possibly before 4.0.3, on Mac OS X does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
nvd
CVE-2014-1269P4MEDIUMCVSS 6.8≤ 6.1.1v6.0+8 more2014-02-27
CVE-2014-1269 [MEDIUM] CVE-2014-1269: WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execut WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1268 and CVE-2014-1270.
nvd
CVE-2014-1270P4MEDIUMCVSS 6.8≤ 6.1.1v6.0+8 more2014-02-27
CVE-2014-1270 [MEDIUM] CVE-2014-1270: WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execut WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1268 and CVE-2014-1269.
nvd
CVE-2015-1075P4MEDIUMCVSS 6.8≤ 6.2.3v7.0+14 more2015-03-18
CVE-2015-1075 [MEDIUM] CWE-399 CVE-2015-1075: WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.
nvd
CVE-2014-1268P4MEDIUMCVSS 6.8≤ 6.1.1v6.0+8 more2014-02-27
CVE-2014-1268 [MEDIUM] CWE-119 CVE-2014-1268: WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execut WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1269 and CVE-2014-1270.
nvd
CVE-2011-2819P4MEDIUMCVSS 6.8fixed in 5.1.12011-08-03
CVE-2011-2819 [MEDIUM] CVE-2011-2819: Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same Origin Policy via vecto Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same Origin Policy via vectors related to handling of the base URI.
nvd
CVE-2011-3231P4MEDIUMCVSS 6.8≤ 5.1v1.0+69 more2011-10-14
CVE-2011-3231 [MEDIUM] CWE-94 CVE-2011-3231: The SSL implementation in Apple Safari before 5.1.1 on Mac OS X before 10.7 accesses uninitialized m The SSL implementation in Apple Safari before 5.1.1 on Mac OS X before 10.7 accesses uninitialized memory during the processing of X.509 certificates, which allows remote web servers to execute arbitrary code via a crafted certificate.
nvd
CVE-2011-3056P4MEDIUMCVSS 6.8fixed in 5.1.72012-03-22
CVE-2011-3056 [MEDIUM] CWE-346 CVE-2011-3056: Google Chrome before 17.0.963.83 allows remote attackers to bypass the Same Origin Policy via vector Google Chrome before 17.0.963.83 allows remote attackers to bypass the Same Origin Policy via vectors involving a "magic iframe."
nvd
CVE-2018-4270P4MEDIUMCVSS 6.5fixed in 11.1.22019-04-03
CVE-2018-4270 [MEDIUM] CWE-119 CVE-2018-4270: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvdapple
CVE-2018-4439P4MEDIUMCVSS 6.5fixed in 12.0.22019-04-03
CVE-2018-4439 [MEDIUM] CWE-20 CVE-2018-4439: A logic issue was addressed with improved validation. This issue affected versions prior to iOS 12.1 A logic issue was addressed with improved validation. This issue affected versions prior to iOS 12.1.1, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.
nvdapple
CVE-2016-4758P4MEDIUMCVSS 6.5≤ 9.1.32016-09-25
CVE-2016-4758 [MEDIUM] CWE-200 CVE-2016-4758: WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not proper WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not properly restrict access to the location variable, which allows remote attackers to obtain sensitive information via a crafted web site.
nvdapple
CVE-2016-1785P4MEDIUMCVSS 6.5≤ 9.0.32016-03-24
CVE-2016-1785 [MEDIUM] CWE-200 CVE-2016-1785: The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles c The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles character encoding during access to cached data, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
nvdapple
CVE-2017-7085P4MEDIUMCVSS 6.5≤ 10.1.22017-10-23
CVE-2017-7085 [MEDIUM] CWE-20 CVE-2017-7085: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar.
nvdapple
CVE-2017-2359P4MEDIUMCVSS 6.5≤ 10.0.22017-02-20
CVE-2017-2359 [MEDIUM] CVE-2017-2359: An issue was discovered in certain Apple products. Safari before 10.0.3 is affected. The issue invol An issue was discovered in certain Apple products. Safari before 10.0.3 is affected. The issue involves the "Safari" component, which allows remote attackers to spoof the address bar via a crafted web site.
nvdapple
CVE-2017-7011P4MEDIUMCVSS 6.5≤ 10.1.12017-07-20
CVE-2017-7011 [MEDIUM] CWE-20 CVE-2017-7011: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to spoof the address bar via a crafted web site that uses FRAME elements.
nvdapple
CVE-2018-4102P4MEDIUMCVSS 6.5fixed in 11.12018-04-03
CVE-2018-4102 [MEDIUM] CWE-20 CVE-2018-4102: An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involve An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site.
nvdapple
CVE-2018-4444P4MEDIUMCVSS 6.5fixed in 12.0.2≥ unspecified, < 12.02020-10-27
CVE-2018-4444 [MEDIUM] CVE-2018-4444: A logic issue was addressed with improved state management. This issue is fixed in Safari 12.0.2, iO A logic issue was addressed with improved state management. This issue is fixed in Safari 12.0.2, iOS 12.1.1, tvOS 12.1.1, iTunes 12.9.2 for Windows. Processing maliciously crafted web content may disclose sensitive user information.
nvdapple
CVE-2016-4613P4MEDIUMCVSS 6.5≤ 10.0.02017-02-20
CVE-2016-4613 [MEDIUM] CWE-200 CVE-2016-4613: An issue was discovered in certain Apple products. Safari before 10.0.1 is affected. iCloud before 6 An issue was discovered in certain Apple products. Safari before 10.0.1 is affected. iCloud before 6.0.1 is affected. iTunes before 12.5.2 is affected. tvOS before 10.0.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive information via a crafted web site.
nvdapple
Apple Safari vulnerabilities | cvebase