cbcvebase.

Apple Safari vulnerabilities

1,654 known vulnerabilities affecting apple/safari.

Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1

Vulnerabilities

Page 56 of 83
CVE-2011-2819P4MEDIUMCVSS 6.8fixed in 5.1.12011-08-03
CVE-2011-2819 [MEDIUM] CVE-2011-2819: Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same Origin Policy via vecto Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same Origin Policy via vectors related to handling of the base URI.
nvd
CVE-2011-3231P4MEDIUMCVSS 6.8≤ 5.1v1.0+69 more2011-10-14
CVE-2011-3231 [MEDIUM] CWE-94 CVE-2011-3231: The SSL implementation in Apple Safari before 5.1.1 on Mac OS X before 10.7 accesses uninitialized m The SSL implementation in Apple Safari before 5.1.1 on Mac OS X before 10.7 accesses uninitialized memory during the processing of X.509 certificates, which allows remote web servers to execute arbitrary code via a crafted certificate.
nvd
CVE-2011-3056P4MEDIUMCVSS 6.8fixed in 5.1.72012-03-22
CVE-2011-3056 [MEDIUM] CWE-346 CVE-2011-3056: Google Chrome before 17.0.963.83 allows remote attackers to bypass the Same Origin Policy via vector Google Chrome before 17.0.963.83 allows remote attackers to bypass the Same Origin Policy via vectors involving a "magic iframe."
nvd
CVE-2018-4273P4MEDIUMCVSS 6.5fixed in 11.1.22019-04-03
CVE-2018-4273 [MEDIUM] CWE-119 CVE-2018-4273: Multiple memory corruption issues were addressed with improved input validation. This issue affected Multiple memory corruption issues were addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvdapple
CVE-2018-4270P4MEDIUMCVSS 6.5fixed in 11.1.22019-04-03
CVE-2018-4270 [MEDIUM] CWE-119 CVE-2018-4270: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvdapple
CVE-2018-4439P4MEDIUMCVSS 6.5fixed in 12.0.22019-04-03
CVE-2018-4439 [MEDIUM] CWE-20 CVE-2018-4439: A logic issue was addressed with improved validation. This issue affected versions prior to iOS 12.1 A logic issue was addressed with improved validation. This issue affected versions prior to iOS 12.1.1, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.
nvdapple
CVE-2016-4758P4MEDIUMCVSS 6.5≤ 9.1.32016-09-25
CVE-2016-4758 [MEDIUM] CWE-200 CVE-2016-4758: WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not proper WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not properly restrict access to the location variable, which allows remote attackers to obtain sensitive information via a crafted web site.
nvdapple
CVE-2016-1785P4MEDIUMCVSS 6.5≤ 9.0.32016-03-24
CVE-2016-1785 [MEDIUM] CWE-200 CVE-2016-1785: The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles c The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles character encoding during access to cached data, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
nvdapple
CVE-2017-7085P4MEDIUMCVSS 6.5≤ 10.1.22017-10-23
CVE-2017-7085 [MEDIUM] CWE-20 CVE-2017-7085: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar.
nvdapple
CVE-2017-2359P4MEDIUMCVSS 6.5≤ 10.0.22017-02-20
CVE-2017-2359 [MEDIUM] CVE-2017-2359: An issue was discovered in certain Apple products. Safari before 10.0.3 is affected. The issue invol An issue was discovered in certain Apple products. Safari before 10.0.3 is affected. The issue involves the "Safari" component, which allows remote attackers to spoof the address bar via a crafted web site.
nvdapple
CVE-2018-4116P4MEDIUMCVSS 6.5fixed in 11.12018-04-03
CVE-2018-4116 [MEDIUM] CWE-20 CVE-2018-4116: An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involve An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site.
nvdapple
CVE-2017-7011P4MEDIUMCVSS 6.5≤ 10.1.12017-07-20
CVE-2017-7011 [MEDIUM] CWE-20 CVE-2017-7011: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to spoof the address bar via a crafted web site that uses FRAME elements.
nvdapple
CVE-2018-4102P4MEDIUMCVSS 6.5fixed in 11.12018-04-03
CVE-2018-4102 [MEDIUM] CWE-20 CVE-2018-4102: An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involve An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site.
nvdapple
CVE-2018-4444P4MEDIUMCVSS 6.5fixed in 12.0.2≥ unspecified, < 12.02020-10-27
CVE-2018-4444 [MEDIUM] CVE-2018-4444: A logic issue was addressed with improved state management. This issue is fixed in Safari 12.0.2, iO A logic issue was addressed with improved state management. This issue is fixed in Safari 12.0.2, iOS 12.1.1, tvOS 12.1.1, iTunes 12.9.2 for Windows. Processing maliciously crafted web content may disclose sensitive user information.
nvdapple
CVE-2016-4613P4MEDIUMCVSS 6.5≤ 10.0.02017-02-20
CVE-2016-4613 [MEDIUM] CWE-200 CVE-2016-4613: An issue was discovered in certain Apple products. Safari before 10.0.1 is affected. iCloud before 6 An issue was discovered in certain Apple products. Safari before 10.0.1 is affected. iCloud before 6.0.1 is affected. iTunes before 12.5.2 is affected. tvOS before 10.0.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive information via a crafted web site.
nvdapple
CVE-2024-40866P4MEDIUMCVSS 6.5fixed in 18.0fixed in 182024-09-17
CVE-2024-40866 [MEDIUM] CVE-2024-40866: The issue was addressed with improved UI. This issue is fixed in Safari 18, macOS Sequoia 15. Visiti The issue was addressed with improved UI. This issue is fixed in Safari 18, macOS Sequoia 15. Visiting a malicious website may lead to address bar spoofing.
nvdapple
CVE-2024-23271P4MEDIUMCVSS 6.5fixed in 17.32024-04-24
CVE-2024-23271 [MEDIUM] CWE-284 CVE-2024-23271: A logic issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 17.3 and i A logic issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. A malicious website may cause unexpected cross-origin behavior.
nvdapple
CVE-2025-24192P4MEDIUMCVSS 6.5fixed in 18.42025-03-31
CVE-2025-24192 [MEDIUM] CVE-2025-24192: A script imports issue was addressed with improved isolation. This issue is fixed in Safari 18.4, iO A script imports issue was addressed with improved isolation. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4. Visiting a website may leak sensitive data.
nvdapple
CVE-2022-32784P4MEDIUMCVSS 6.5fixed in 15.6≥ unspecified, < 15.62023-02-27
CVE-2022-32784 [MEDIUM] CWE-200 CVE-2022-32784: The issue was addressed with improved UI handling. This issue is fixed in Safari 15.6, iOS 15.6 and The issue was addressed with improved UI handling. This issue is fixed in Safari 15.6, iOS 15.6 and iPadOS 15.6. Visiting a maliciously crafted website may leak sensitive data.
nvdapple
CVE-2025-24188P4MEDIUMCVSS 6.5fixed in 18.62025-07-30
CVE-2025-24188 [MEDIUM] CWE-703 CVE-2025-24188: A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple
Apple Safari vulnerabilities | cvebase