cbcvebase.

Apple Safari vulnerabilities

1,654 known vulnerabilities affecting apple/safari.

Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1

Vulnerabilities

Page 60 of 83
CVE-2017-7038P4MEDIUMCVSS 6.1fixed in 10.1.22017-07-20
CVE-2017-7038 [MEDIUM] CWE-79 CVE-2017-7038: A DOMParser XSS issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safar A DOMParser XSS issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component.
nvdapple
CVE-2018-4409P4MEDIUMCVSS 6.5fixed in 12.0.12019-04-03
CVE-2018-4409 [MEDIUM] CWE-400 CVE-2018-4409: A resource exhaustion issue was addressed with improved input validation. This issue affected versio A resource exhaustion issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1, tvOS 12.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.
nvdapple
CVE-2018-4271P4MEDIUMCVSS 6.5fixed in 11.1.22019-04-03
CVE-2018-4271 [MEDIUM] CWE-119 CVE-2018-4271: Multiple memory corruption issues were addressed with improved input validation. This issue affected Multiple memory corruption issues were addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvdapple
CVE-2010-1409P4MEDIUMCVSS 5.8≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1409 [MEDIUM] CVE-2010-1409: Incomplete blacklist vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10. Incomplete blacklist vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to trigger disclosure of data over IRC via vectors involving an IRC service port.
nvd
CVE-2022-0108P4MEDIUMCVSS 6.5v16.32023-02-13
CVE-2022-0108 [MEDIUM] CVE-2022-0108: Safari 16.3 Apple Security Update: About the security content of Safari 16.3 Product: Safari Version: 16.3 CVE: CVE-2022-0108 Component: CVE-2022-0108
apple
CVE-2012-0584P4MEDIUMCVSS 6.4≤ 5.1.2v1.0+69 more2012-03-12
CVE-2012-0584 [MEDIUM] CWE-20 CVE-2012-0584: The Internationalized Domain Name (IDN) feature in Apple Safari before 5.1.4 on Windows does not pro The Internationalized Domain Name (IDN) feature in Apple Safari before 5.1.4 on Windows does not properly restrict the characters in URLs, which allows remote attackers to spoof a domain name via unspecified homoglyphs.
nvd
CVE-2017-13789P4MEDIUMCVSS 6.5≤ 11.02017-11-13
CVE-2017-13789 [MEDIUM] CWE-20 CVE-2017-13789: An issue was discovered in certain Apple products. Safari before 11.0.1 is affected. The issue invol An issue was discovered in certain Apple products. Safari before 11.0.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site.
nvdapple
CVE-2017-13790P4MEDIUMCVSS 6.5≤ 11.02017-11-13
CVE-2017-13790 [MEDIUM] CWE-20 CVE-2017-13790: An issue was discovered in certain Apple products. Safari before 11.0.1 is affected. The issue invol An issue was discovered in certain Apple products. Safari before 11.0.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site.
nvdapple
CVE-2017-2511P4MEDIUMCVSS 6.5≤ 10.12017-05-22
CVE-2017-2511 [MEDIUM] CWE-20 CVE-2017-2511: An issue was discovered in certain Apple products. Safari before 10.1.1 is affected. The issue invol An issue was discovered in certain Apple products. Safari before 10.1.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site.
nvdapple
CVE-2019-8654P4MEDIUMCVSS 6.5fixed in 13.0.1≥ unspecified, < Safari 13.0.12019-12-18
CVE-2019-8654 [MEDIUM] CWE-20 CVE-2019-8654: An inconsistent user interface issue was addressed with improved state management. This issue is fix An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 13.0.1. Visiting a malicious website may lead to user interface spoofing.
nvdapple
CVE-2017-2475P4MEDIUMCVSS 6.1fixed in 10.12017-04-02
CVE-2017-2475 [MEDIUM] CWE-79 CVE-2017-2475: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via crafted use of frames on a web site.
nvdapple
CVE-2020-3841P4MEDIUMCVSS 6.5fixed in 13.0.5≥ unspecified, < Safari 13.0.52020-02-27
CVE-2020-3841 [MEDIUM] CWE-319 CVE-2020-3841: The issue was addressed with improved UI handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3 The issue was addressed with improved UI handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, Safari 13.0.5. A local user may unknowingly send a password unencrypted over the network.
nvd
CVE-2020-3867P4MEDIUMCVSS 6.1fixed in 13.0.5≥ unspecified, < Safari 13.0.52020-02-27
CVE-2020-3867 [MEDIUM] CWE-79 CVE-2020-3867: A logic issue was addressed with improved state management. This issue is fixed in iOS 13.3.1 and iP A logic issue was addressed with improved state management. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd
CVE-2021-1825P4MEDIUMCVSS 6.1fixed in 14.1≥ unspecified, < 14.12021-09-08
CVE-2021-1825 [MEDIUM] CWE-79 CVE-2021-1825: An input validation issue was addressed with improved input validation. This issue is fixed in iTune An input validation issue was addressed with improved input validation. This issue is fixed in iTunes 12.11.3 for Windows, iCloud for Windows 12.3, macOS Big Sur 11.3, Safari 14.1, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing maliciously crafted web content may lead to a cross site scripting attack.
nvd
CVE-2021-30890P4MEDIUMCVSS 6.1v15.12021-10-27
CVE-2021-30890 [MEDIUM] CVE-2021-30890: Safari 15.1 Apple Security Update: About the security content of Safari 15.1 Product: Safari Version: 15.1 CVE: CVE-2021-30890 Component: WebKit Impact: Processing maliciously crafted web content may lead to universal cross site scripting Description: A logic issue was addressed with improved state management.
apple
CVE-2026-43804P4MEDIUMCVSS 6.5fixed in 26.62026-07-27
CVE-2026-43804 [MEDIUM] CWE-400 CVE-2026-43804: This issue was addressed through improved state management. This issue is fixed in Safari 26.6, iOS This issue was addressed through improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6. Visiting a website may lead to an app denial-of-service.
nvd
CVE-2018-4266P4MEDIUMCVSS 5.9fixed in 11.1.22019-04-03
CVE-2018-4266 [MEDIUM] CWE-362 CVE-2018-4266: A race condition was addressed with additional validation. This issue affected versions prior toiVer A race condition was addressed with additional validation. This issue affected versions prior toiVersions prior to: OS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvdapple
CVE-2019-8658P4MEDIUMCVSS 6.1fixed in 12.1.2≥ unspecified, < Safari 12.1.22019-12-18
CVE-2019-8658 [MEDIUM] CWE-79 CVE-2019-8658: A logic issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS M A logic issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
CVE-2017-2549P4MEDIUMCVSS 6.1≤ 10.12017-05-22
CVE-2017-2549 [MEDIUM] CWE-79 CVE-2017-2549: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with frame loading.
nvdapple
CVE-2020-9925P4MEDIUMCVSS 6.1fixed in 13.1.2≥ unspecified, < Safari 13.1.22020-10-16
CVE-2020-9925 [MEDIUM] CWE-79 CVE-2020-9925: A logic issue was addressed with improved state management. This issue is fixed in iOS 13.6 and iPad A logic issue was addressed with improved state management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
Apple Safari vulnerabilities | cvebase