cbcvebase.

Apple Safari vulnerabilities

1,654 known vulnerabilities affecting apple/safari.

Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1

Vulnerabilities

Page 61 of 83
CVE-2024-40785P4MEDIUMCVSS 6.1fixed in 17.62024-07-29
CVE-2024-40785 [MEDIUM] CWE-79 CVE-2024-40785: This issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 16.7.9 and iP This issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to a cross site scripting attack.
nvdapple
CVE-2024-40857P4MEDIUMCVSS 6.1fixed in 18.0fixed in 182024-09-17
CVE-2024-40857 [MEDIUM] CWE-79 CVE-2024-40857: This issue was addressed through improved state management. This issue is fixed in Safari 18, iOS 18 This issue was addressed through improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
CVE-2011-0983P4HIGHCVSS 7.5fixed in 5.0.62011-02-10
CVE-2011-0983 [HIGH] CWE-20 CVE-2011-0983: Google Chrome before 9.0.597.94 does not properly handle anonymous blocks, which allows remote attac Google Chrome before 9.0.597.94 does not properly handle anonymous blocks, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-0981P4HIGHCVSS 7.5fixed in 5.0.62011-02-10
CVE-2011-0981 [HIGH] CWE-20 CVE-2011-0981: Google Chrome before 9.0.597.94 does not properly perform event handling for animations, which allow Google Chrome before 9.0.597.94 does not properly perform event handling for animations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2015-3801P4MEDIUMCVSS 5.0≤ 8.0.82015-09-18
CVE-2015-3801 [MEDIUM] CWE-264 CVE-2015-3801: The document.cookie API implementation in the CFNetwork Cookies subsystem in WebKit in Apple iOS bef The document.cookie API implementation in the CFNetwork Cookies subsystem in WebKit in Apple iOS before 9 allows remote attackers to bypass an intended single-cookie restriction via unspecified vectors.
nvd
CVE-2020-9916P4MEDIUMCVSS 5.3fixed in 13.1.2≥ unspecified, < Safari 13.1.22020-10-16
CVE-2020-9916 [MEDIUM] CVE-2020-9916: A URL Unicode encoding issue was addressed with improved state management. This issue is fixed in iO A URL Unicode encoding issue was addressed with improved state management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A malicious attacker may be able to conceal the destination of a URL.
nvdapple
CVE-2011-1203P4HIGHCVSS 7.5fixed in 5.0.62011-03-11
CVE-2011-1203 [HIGH] CVE-2011-1203: Google Chrome before 10.0.648.127 does not properly handle SVG cursors, which allows remote attacker Google Chrome before 10.0.648.127 does not properly handle SVG cursors, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-1109P4HIGHCVSS 7.5fixed in 5.0.62011-03-01
CVE-2011-1109 [HIGH] CWE-20 CVE-2011-1109: Google Chrome before 9.0.597.107 does not properly process nodes in Cascading Style Sheets (CSS) sty Google Chrome before 9.0.597.107 does not properly process nodes in Cascading Style Sheets (CSS) stylesheets, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2010-1391P4MEDIUMCVSS 4.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1391 [MEDIUM] CWE-22 CVE-2010-1391: Multiple directory traversal vulnerabilities in the (a) Local Storage and (b) Web SQL database imple Multiple directory traversal vulnerabilities in the (a) Local Storage and (b) Web SQL database implementations in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allow remote attackers to create arbitrary database files via vectors involving a (1) %2f and .. (dot dot) or (2) %5c and .. (dot
nvd
CVE-2024-27834P4MEDIUMCVSS 5.5fixed in 17.52024-05-14
CVE-2024-27834 [MEDIUM] CWE-277 CVE-2024-27834: The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPa The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, watchOS 10.5. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
nvdapple
CVE-2025-31254P4MEDIUMCVSS 5.4fixed in 26.0fixed in 262025-09-15
CVE-2025-31254 [MEDIUM] CWE-863 CVE-2025-31254: This issue was addressed with improved URL validation. This issue is fixed in Safari 26, iOS 26 and This issue was addressed with improved URL validation. This issue is fixed in Safari 26, iOS 26 and iPadOS 26. Processing maliciously crafted web content may lead to unexpected URL redirection.
nvdapple
CVE-2014-1387P4MEDIUMCVSS 6.8≤ 6.1.5v6.0+16 more2014-08-14
CVE-2014-1387 [MEDIUM] CWE-119 CVE-2014-1387: WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execut WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in HT6367.
nvd
CVE-2014-1388P4MEDIUMCVSS 6.8v7.0v7.0.1+16 more2014-08-14
CVE-2014-1388 [MEDIUM] CWE-119 CVE-2014-1388: WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execut WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in HT6367.
nvd
CVE-2014-1389P4MEDIUMCVSS 6.8≤ 6.1.5v6.0+16 more2014-08-14
CVE-2014-1389 [MEDIUM] CWE-119 CVE-2014-1389: WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execut WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in HT6367.
nvd
CVE-2014-1384P4MEDIUMCVSS 6.8≤ 6.1.5v6.0+16 more2014-08-14
CVE-2014-1384 [MEDIUM] CWE-119 CVE-2014-1384: WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execut WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in HT6367.
nvd
CVE-2014-1385P4MEDIUMCVSS 6.8≤ 6.1.5v6.0+16 more2014-08-14
CVE-2014-1385 [MEDIUM] CWE-119 CVE-2014-1385: WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execut WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in HT6367.
nvd
CVE-2014-1745P4HIGHCVSS 7.1v16.42023-03-27
CVE-2014-1745 [HIGH] CVE-2014-1745: Safari 16.4 Apple Security Update: About the security content of Safari 16.4 Product: Safari Version: 16.4 CVE: CVE-2014-1745 Component: WebKit Impact: Processing a file may lead to a denial-of-service or potentially disclose memory contents Description: The issue was addressed with improved checks.
apple
CVE-2014-1386P4MEDIUMCVSS 6.8v7.0v7.0.1+16 more2014-08-14
CVE-2014-1386 [MEDIUM] CWE-119 CVE-2014-1386: WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execut WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in HT6367.
nvd
CVE-2014-1390P4MEDIUMCVSS 6.8v7.0v7.0.1+16 more2014-08-14
CVE-2014-1390 [MEDIUM] CWE-119 CVE-2014-1390: WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execut WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in HT6367.
nvd
CVE-2013-1041P4MEDIUMCVSS 6.8≤ 6.0.52013-09-19
CVE-2013-1041 [MEDIUM] CWE-119 CVE-2013-1041: WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.
nvd
Apple Safari vulnerabilities | cvebase