Apple Safari vulnerabilities
1,677 known vulnerabilities affecting apple/safari.
Total CVEs
1,677
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
52
Severity breakdown
CRITICAL211HIGH628MEDIUM815LOW22UNKNOWN1
Vulnerabilities
Page 61 of 84
CVE-2021-1825P4MEDIUMCVSS 6.1fixed in 14.1≥ unspecified, < 14.12021-09-08
CVE-2021-1825 [MEDIUM] CWE-79 CVE-2021-1825: An input validation issue was addressed with improved input validation. This issue is fixed in iTune
An input validation issue was addressed with improved input validation. This issue is fixed in iTunes 12.11.3 for Windows, iCloud for Windows 12.3, macOS Big Sur 11.3, Safari 14.1, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing maliciously crafted web content may lead to a cross site scripting attack.
nvd
CVE-2018-4266P4MEDIUMCVSS 5.9fixed in 11.1.22019-04-03
CVE-2018-4266 [MEDIUM] CWE-362 CVE-2018-4266: A race condition was addressed with additional validation. This issue affected versions prior toiVer
A race condition was addressed with additional validation. This issue affected versions prior toiVersions prior to: OS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvdapple
CVE-2020-9925P4MEDIUMCVSS 6.1fixed in 13.1.2≥ unspecified, < Safari 13.1.22020-10-16
CVE-2020-9925 [MEDIUM] CWE-79 CVE-2020-9925: A logic issue was addressed with improved state management. This issue is fixed in iOS 13.6 and iPad
A logic issue was addressed with improved state management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
CVE-2019-8658P4MEDIUMCVSS 6.1fixed in 12.1.2≥ unspecified, < Safari 12.1.22019-12-18
CVE-2019-8658 [MEDIUM] CWE-79 CVE-2019-8658: A logic issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS M
A logic issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
CVE-2017-2549P4MEDIUMCVSS 6.1≤ 10.12017-05-22
CVE-2017-2549 [MEDIUM] CWE-79 CVE-2017-2549: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with frame loading.
nvdapple
CVE-2011-0219P4MEDIUMCVSS 5.8≤ 5.0.5v1.0+54 more2011-07-21
CVE-2011-0219 [MEDIUM] CWE-264 CVE-2011-0219: Apple Safari before 5.0.6 allows remote attackers to bypass the Same Origin Policy, and modify the r
Apple Safari before 5.0.6 allows remote attackers to bypass the Same Origin Policy, and modify the rendering of text from arbitrary web sites, via a Java applet that loads fonts.
nvd
CVE-2011-0983P4HIGHCVSS 7.5fixed in 5.0.62011-02-10
CVE-2011-0983 [HIGH] CWE-20 CVE-2011-0983: Google Chrome before 9.0.597.94 does not properly handle anonymous blocks, which allows remote attac
Google Chrome before 9.0.597.94 does not properly handle anonymous blocks, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-0981P4HIGHCVSS 7.5fixed in 5.0.62011-02-10
CVE-2011-0981 [HIGH] CWE-20 CVE-2011-0981: Google Chrome before 9.0.597.94 does not properly perform event handling for animations, which allow
Google Chrome before 9.0.597.94 does not properly perform event handling for animations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-1296P4HIGHCVSS 7.5fixed in 5.0.62011-03-25
CVE-2011-1296 [HIGH] CWE-20 CVE-2011-1296: Google Chrome before 10.0.648.204 does not properly handle SVG text, which allows remote attackers t
Google Chrome before 10.0.648.204 does not properly handle SVG text, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2015-3801P4MEDIUMCVSS 5.0≤ 8.0.82015-09-18
CVE-2015-3801 [MEDIUM] CWE-264 CVE-2015-3801: The document.cookie API implementation in the CFNetwork Cookies subsystem in WebKit in Apple iOS bef
The document.cookie API implementation in the CFNetwork Cookies subsystem in WebKit in Apple iOS before 9 allows remote attackers to bypass an intended single-cookie restriction via unspecified vectors.
nvd
CVE-2020-9916P4MEDIUMCVSS 5.3fixed in 13.1.2≥ unspecified, < Safari 13.1.22020-10-16
CVE-2020-9916 [MEDIUM] CVE-2020-9916: A URL Unicode encoding issue was addressed with improved state management. This issue is fixed in iO
A URL Unicode encoding issue was addressed with improved state management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A malicious attacker may be able to conceal the destination of a URL.
nvdapple
CVE-2011-1203P4HIGHCVSS 7.5fixed in 5.0.62011-03-11
CVE-2011-1203 [HIGH] CVE-2011-1203: Google Chrome before 10.0.648.127 does not properly handle SVG cursors, which allows remote attacker
Google Chrome before 10.0.648.127 does not properly handle SVG cursors, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-1109P4HIGHCVSS 7.5fixed in 5.0.62011-03-01
CVE-2011-1109 [HIGH] CWE-20 CVE-2011-1109: Google Chrome before 9.0.597.107 does not properly process nodes in Cascading Style Sheets (CSS) sty
Google Chrome before 9.0.597.107 does not properly process nodes in Cascading Style Sheets (CSS) stylesheets, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2010-1391P4MEDIUMCVSS 4.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1391 [MEDIUM] CWE-22 CVE-2010-1391: Multiple directory traversal vulnerabilities in the (a) Local Storage and (b) Web SQL database imple
Multiple directory traversal vulnerabilities in the (a) Local Storage and (b) Web SQL database implementations in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allow remote attackers to create arbitrary database files via vectors involving a (1) %2f and .. (dot dot) or (2) %5c and .. (dot
nvd
CVE-2024-27834P4MEDIUMCVSS 5.5fixed in 17.52024-05-14
CVE-2024-27834 [MEDIUM] CWE-277 CVE-2024-27834: The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPa
The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, watchOS 10.5. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
nvdapple
CVE-2025-31254P4MEDIUMCVSS 5.4fixed in 26.0fixed in 262025-09-15
CVE-2025-31254 [MEDIUM] CWE-863 CVE-2025-31254: This issue was addressed with improved URL validation. This issue is fixed in Safari 26, iOS 26 and
This issue was addressed with improved URL validation. This issue is fixed in Safari 26, iOS 26 and iPadOS 26. Processing maliciously crafted web content may lead to unexpected URL redirection.
nvdapple
CVE-2014-1387P4MEDIUMCVSS 6.8≤ 6.1.5v6.0+16 more2014-08-14
CVE-2014-1387 [MEDIUM] CWE-119 CVE-2014-1387: WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execut
WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in HT6367.
nvd
CVE-2014-1388P4MEDIUMCVSS 6.8v7.0v7.0.1+16 more2014-08-14
CVE-2014-1388 [MEDIUM] CWE-119 CVE-2014-1388: WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execut
WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in HT6367.
nvd
CVE-2014-1389P4MEDIUMCVSS 6.8≤ 6.1.5v6.0+16 more2014-08-14
CVE-2014-1389 [MEDIUM] CWE-119 CVE-2014-1389: WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execut
WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in HT6367.
nvd
CVE-2014-1384P4MEDIUMCVSS 6.8≤ 6.1.5v6.0+16 more2014-08-14
CVE-2014-1384 [MEDIUM] CWE-119 CVE-2014-1384: WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execut
WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in HT6367.
nvd