cbcvebase.

Apple Safari vulnerabilities

1,654 known vulnerabilities affecting apple/safari.

Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1

Vulnerabilities

Page 57 of 83
CVE-2026-43663P4MEDIUMCVSS 6.5fixed in 26.5.22026-06-29
CVE-2026-43663 [MEDIUM] CWE-119 CVE-2026-43663: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26. The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-39872P4MEDIUMCVSS 6.5fixed in 26.5.22026-06-29
CVE-2026-39872 [MEDIUM] CWE-119 CVE-2026-39872: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26. The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2009-1703P4HIGHCVSS 7.1≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1703 [HIGH] CWE-200 CVE-2009-1703: WebKit in Apple Safari before 4.0 does not prevent references to file: URLs within (1) audio and (2) WebKit in Apple Safari before 4.0 does not prevent references to file: URLs within (1) audio and (2) video elements, which allows remote attackers to determine the existence of arbitrary files via a crafted HTML document.
nvd
CVE-2011-1121P4HIGHCVSS 7.5fixed in 5.0.62011-03-01
CVE-2011-1121 [HIGH] CWE-190 CVE-2011-1121: Integer overflow in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of se Integer overflow in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a TEXTAREA element.
nvd
CVE-2011-1188P4HIGHCVSS 7.5fixed in 5.0.62011-03-11
CVE-2011-1188 [HIGH] CVE-2011-1188: Google Chrome before 10.0.648.127 does not properly handle counter nodes, which allows remote attack Google Chrome before 10.0.648.127 does not properly handle counter nodes, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-2827P4HIGHCVSS 7.5fixed in 5.1.12011-08-29
CVE-2011-2827 [HIGH] CWE-416 CVE-2011-2827: Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to text searching.
nvd
CVE-2007-2398P4HIGHCVSS 7.1v3.0.12007-06-21
CVE-2007-2398 [HIGH] CVE-2007-2398: Apple Safari 3.0.1 beta (522.12.12) on Windows allows remote attackers to modify the window title an Apple Safari 3.0.1 beta (522.12.12) on Windows allows remote attackers to modify the window title and address bar while filling the main window with arbitrary content by setting the location bar and using setTimeout() to create an event that modifies the window content, which could facilitate phishing attacks.
nvd
CVE-2009-1713P4HIGHCVSS 7.1≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1713 [HIGH] CWE-200 CVE-2009-1713: The XSLT functionality in WebKit in Apple Safari before 4.0 does not properly implement the document The XSLT functionality in WebKit in Apple Safari before 4.0 does not properly implement the document function, which allows remote attackers to read (1) arbitrary local files and (2) files from different security zones via unspecified vectors.
nvd
CVE-2014-4474P4MEDIUMCVSS 6.8≤ 6.2.0v7.0+8 more2014-12-10
CVE-2014-4474 [MEDIUM] CWE-399 CVE-2014-4474: WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-12-2-1.
nvd
CVE-2014-4473P4MEDIUMCVSS 6.8≤ 6.2.0v7.0+8 more2014-12-10
CVE-2014-4473 [MEDIUM] CWE-399 CVE-2014-4473: WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-12-2-1.
nvd
CVE-2014-4471P4MEDIUMCVSS 6.8≤ 6.2.0v7.0+8 more2014-12-10
CVE-2014-4471 [MEDIUM] CWE-399 CVE-2014-4471: WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-12-2-1.
nvd
CVE-2014-4470P4MEDIUMCVSS 6.8≤ 6.2.0v7.0+8 more2014-12-10
CVE-2014-4470 [MEDIUM] CWE-399 CVE-2014-4470: WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-12-2-1.
nvd
CVE-2014-4475P4MEDIUMCVSS 6.8≤ 6.2.0v7.0+8 more2014-12-10
CVE-2014-4475 [MEDIUM] CWE-399 CVE-2014-4475: WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-12-2-1.
nvd
CVE-2014-4469P4MEDIUMCVSS 6.8≤ 6.2.0v7.0+8 more2014-12-10
CVE-2014-4469 [MEDIUM] CWE-399 CVE-2014-4469: WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-12-2-1.
nvd
CVE-2014-4472P4MEDIUMCVSS 6.8≤ 6.2.0v7.0+8 more2014-12-10
CVE-2014-4472 [MEDIUM] CWE-399 CVE-2014-4472: WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-12-2-1.
nvd
CVE-2014-4468P4MEDIUMCVSS 6.8≤ 6.2.0v7.0+8 more2014-12-10
CVE-2014-4468 [MEDIUM] CWE-399 CVE-2014-4468: WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-12-2-1.
nvd
CVE-2014-1343P4MEDIUMCVSS 6.8≤ 6.1.3v6.0+12 more2014-05-22
CVE-2014-1343 [MEDIUM] CWE-119 CVE-2014-1343: WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execut WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-05-21-1.
nvd
CVE-2014-1313P4MEDIUMCVSS 6.8≤ 6.1.2v6.0+10 more2014-04-02
CVE-2014-1313 [MEDIUM] CWE-119 CVE-2014-1313: WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execut WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-04-01-1.
nvd
CVE-2014-1341P4MEDIUMCVSS 6.8≤ 6.1.3v6.0+12 more2014-05-22
CVE-2014-1341 [MEDIUM] CWE-119 CVE-2014-1341: WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execut WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-05-21-1.
nvd
CVE-2014-1323P4MEDIUMCVSS 6.8≤ 6.1.3v6.0+12 more2014-05-22
CVE-2014-1323 [MEDIUM] CWE-119 CVE-2014-1323: WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execut WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-05-21-1.
nvd
Apple Safari vulnerabilities | cvebase