cbcvebase.

Apple Safari vulnerabilities

1,677 known vulnerabilities affecting apple/safari.

Total CVEs
1,677
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
52
Severity breakdown
CRITICAL211HIGH628MEDIUM815LOW22UNKNOWN1

Vulnerabilities

Page 60 of 84
CVE-2014-1340P4MEDIUMCVSS 6.8v7.0v7.0.1+14 more2014-07-01
CVE-2014-1340 [MEDIUM] CWE-119 CVE-2014-1340: WebKit, as used in Apple Safari before 6.1.5 and 7.x before 7.0.5, allows remote attackers to execut WebKit, as used in Apple Safari before 6.1.5 and 7.x before 7.0.5, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1.
nvd
CVE-2017-7830P4MEDIUMCVSS 6.5v11.0.32018-01-23
CVE-2017-7830 [MEDIUM] CVE-2017-7830: Safari 11.0.3 Apple Security Update: About the security content of Safari 11.0.3 Product: Safari Version: 11.0.3 CVE: CVE-2017-7830 Component: WebKit Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2014-1324P4MEDIUMCVSS 6.8≤ 6.1.3v6.0+12 more2014-05-22
CVE-2014-1324 [MEDIUM] CWE-119 CVE-2014-1324: WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execut WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-05-21-1.
nvd
CVE-2016-1858P4MEDIUMCVSS 6.5fixed in 9.1.12016-05-20
CVE-2016-1858 [MEDIUM] CWE-200 CVE-2016-1858: WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, improperly tr WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, improperly tracks taint attributes, which allows remote attackers to obtain sensitive information via a crafted web site.
nvdapple
CVE-2011-2805P4MEDIUMCVSS 6.8fixed in 5.1.12011-08-03
CVE-2011-2805 [MEDIUM] CWE-74 CVE-2011-2805: Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same Origin Policy and condu Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same Origin Policy and conduct script injection attacks via unspecified vectors.
nvd
CVE-2018-4273P4MEDIUMCVSS 6.5fixed in 11.1.22019-04-03
CVE-2018-4273 [MEDIUM] CWE-119 CVE-2018-4273: Multiple memory corruption issues were addressed with improved input validation. This issue affected Multiple memory corruption issues were addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvdapple
CVE-2017-7038P4MEDIUMCVSS 6.1fixed in 10.1.22017-07-20
CVE-2017-7038 [MEDIUM] CWE-79 CVE-2017-7038: A DOMParser XSS issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safar A DOMParser XSS issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component.
nvdapple
CVE-2018-4409P4MEDIUMCVSS 6.5fixed in 12.0.12019-04-03
CVE-2018-4409 [MEDIUM] CWE-400 CVE-2018-4409: A resource exhaustion issue was addressed with improved input validation. This issue affected versio A resource exhaustion issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1, tvOS 12.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.
nvdapple
CVE-2018-4271P4MEDIUMCVSS 6.5fixed in 11.1.22019-04-03
CVE-2018-4271 [MEDIUM] CWE-119 CVE-2018-4271: Multiple memory corruption issues were addressed with improved input validation. This issue affected Multiple memory corruption issues were addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvdapple
CVE-2010-1409P4MEDIUMCVSS 5.8≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1409 [MEDIUM] CVE-2010-1409: Incomplete blacklist vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10. Incomplete blacklist vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to trigger disclosure of data over IRC via vectors involving an IRC service port.
nvd
CVE-2022-0108P4MEDIUMCVSS 6.5v16.32023-02-13
CVE-2022-0108 [MEDIUM] CVE-2022-0108: Safari 16.3 Apple Security Update: About the security content of Safari 16.3 Product: Safari Version: 16.3 CVE: CVE-2022-0108 Component: CVE-2022-0108
apple
CVE-2012-0584P4MEDIUMCVSS 6.4≤ 5.1.2v1.0+69 more2012-03-12
CVE-2012-0584 [MEDIUM] CWE-20 CVE-2012-0584: The Internationalized Domain Name (IDN) feature in Apple Safari before 5.1.4 on Windows does not pro The Internationalized Domain Name (IDN) feature in Apple Safari before 5.1.4 on Windows does not properly restrict the characters in URLs, which allows remote attackers to spoof a domain name via unspecified homoglyphs.
nvd
CVE-2017-13789P4MEDIUMCVSS 6.5≤ 11.02017-11-13
CVE-2017-13789 [MEDIUM] CWE-20 CVE-2017-13789: An issue was discovered in certain Apple products. Safari before 11.0.1 is affected. The issue invol An issue was discovered in certain Apple products. Safari before 11.0.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site.
nvdapple
CVE-2017-13790P4MEDIUMCVSS 6.5≤ 11.02017-11-13
CVE-2017-13790 [MEDIUM] CWE-20 CVE-2017-13790: An issue was discovered in certain Apple products. Safari before 11.0.1 is affected. The issue invol An issue was discovered in certain Apple products. Safari before 11.0.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site.
nvdapple
CVE-2017-2511P4MEDIUMCVSS 6.5≤ 10.12017-05-22
CVE-2017-2511 [MEDIUM] CWE-20 CVE-2017-2511: An issue was discovered in certain Apple products. Safari before 10.1.1 is affected. The issue invol An issue was discovered in certain Apple products. Safari before 10.1.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site.
nvdapple
CVE-2019-8654P4MEDIUMCVSS 6.5fixed in 13.0.1≥ unspecified, < Safari 13.0.12019-12-18
CVE-2019-8654 [MEDIUM] CWE-20 CVE-2019-8654: An inconsistent user interface issue was addressed with improved state management. This issue is fix An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 13.0.1. Visiting a malicious website may lead to user interface spoofing.
nvdapple
CVE-2017-2475P4MEDIUMCVSS 6.1fixed in 10.12017-04-02
CVE-2017-2475 [MEDIUM] CWE-79 CVE-2017-2475: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via crafted use of frames on a web site.
nvdapple
CVE-2020-3841P4MEDIUMCVSS 6.5fixed in 13.0.5≥ unspecified, < Safari 13.0.52020-02-27
CVE-2020-3841 [MEDIUM] CWE-319 CVE-2020-3841: The issue was addressed with improved UI handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3 The issue was addressed with improved UI handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, Safari 13.0.5. A local user may unknowingly send a password unencrypted over the network.
nvd
CVE-2021-30890P4MEDIUMCVSS 6.1v15.12021-10-27
CVE-2021-30890 [MEDIUM] CVE-2021-30890: Safari 15.1 Apple Security Update: About the security content of Safari 15.1 Product: Safari Version: 15.1 CVE: CVE-2021-30890 Component: WebKit Impact: Processing maliciously crafted web content may lead to universal cross site scripting Description: A logic issue was addressed with improved state management.
apple
CVE-2020-3867P4MEDIUMCVSS 6.1fixed in 13.0.5≥ unspecified, < Safari 13.0.52020-02-27
CVE-2020-3867 [MEDIUM] CWE-79 CVE-2020-3867: A logic issue was addressed with improved state management. This issue is fixed in iOS 13.3.1 and iP A logic issue was addressed with improved state management. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd
Apple Safari vulnerabilities | cvebase