cbcvebase.

Apple Safari vulnerabilities

1,654 known vulnerabilities affecting apple/safari.

Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1

Vulnerabilities

Page 62 of 83
CVE-2013-1047P4MEDIUMCVSS 6.8≤ 6.0.52013-09-19
CVE-2013-1047 [MEDIUM] CWE-119 CVE-2013-1047: WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.
nvd
CVE-2013-1039P4MEDIUMCVSS 6.8≤ 6.0.52013-09-19
CVE-2013-1039 [MEDIUM] CWE-119 CVE-2013-1039: WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.
nvd
CVE-2013-1037P4MEDIUMCVSS 6.8≤ 6.0.52013-09-19
CVE-2013-1037 [MEDIUM] CWE-119 CVE-2013-1037: WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.
nvd
CVE-2013-1040P4MEDIUMCVSS 6.8≤ 6.0.52013-09-19
CVE-2013-1040 [MEDIUM] CWE-119 CVE-2013-1040: WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.
nvd
CVE-2013-1038P4MEDIUMCVSS 6.8≤ 6.0.52013-09-19
CVE-2013-1038 [MEDIUM] CWE-119 CVE-2013-1038: WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.
nvd
CVE-2011-3071P4MEDIUMCVSS 6.8fixed in 6.02012-04-05
CVE-2011-3071 [MEDIUM] CWE-416 CVE-2011-3071: Use-after-free vulnerability in the HTMLMediaElement implementation in Google Chrome before 18.0.102 Use-after-free vulnerability in the HTMLMediaElement implementation in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2018-4146P4MEDIUMCVSS 6.5fixed in 11.12018-04-03
CVE-2018-4146 [MEDIUM] CWE-119 CVE-2018-4146: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows attackers to cause a denial of service
nvdapple
CVE-2018-4374P4MEDIUMCVSS 6.1fixed in 12.0.12019-04-03
CVE-2018-4374 [MEDIUM] CWE-79 CVE-2018-4374: A logic issue was addressed with improved validation. This issue affected versions prior to iOS 12.1 A logic issue was addressed with improved validation. This issue affected versions prior to iOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.
nvdapple
CVE-2018-4362P4MEDIUMCVSS 6.5fixed in 11.1.22019-04-03
CVE-2018-4362 [MEDIUM] CWE-20 CVE-2018-4362: An inconsistent user interface issue was addressed with improved state management. This issue affect An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to Safari 11.1.2, iOS 12.
nvdapple
CVE-2023-42956P4MEDIUMCVSS 6.5fixed in 17.2≥ unspecified, < 17.22024-03-28
CVE-2023-42956 [MEDIUM] CVE-2023-42956: The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, iOS 17.2 The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2. Processing web content may lead to a denial-of-service.
nvdapple
CVE-2018-4260P4MEDIUMCVSS 6.5fixed in 11.1.22019-04-03
CVE-2018-4260 [MEDIUM] CWE-20 CVE-2018-4260: An inconsistent user interface issue was addressed with improved state management. This issue affect An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to iOS 11.4.1, Safari 11.1.2.
nvdapple
CVE-2024-54658P4MEDIUMCVSS 6.5fixed in 17.42025-02-10
CVE-2024-54658 [MEDIUM] CWE-400 CVE-2024-54658: The issue was addressed with improved memory handling. This issue is fixed in Safari 17.4, iOS 17.4 The issue was addressed with improved memory handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing web content may lead to a denial-of-service.
nvdapple
CVE-2007-3514P4HIGHCVSS 8.5v3.0.22007-07-03
CVE-2007-3514 [HIGH] CVE-2007-3514: Cross-domain vulnerability in Apple Safari for Windows 3.0.2 allows remote attackers to bypass the S Cross-domain vulnerability in Apple Safari for Windows 3.0.2 allows remote attackers to bypass the Same Origin Policy and access restricted information from other domains via JavaScript that overwrites the document variable and statically sets the document.domain attribute to a file:// location, a different vector than CVE-2007-3482.
nvd
CVE-2019-8813P4MEDIUMCVSS 6.1fixed in 13.0.3≥ unspecified, < Safari 13.0.32019-12-18
CVE-2019-8813 [MEDIUM] CWE-79 CVE-2019-8813: A logic issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPad A logic issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
CVE-2019-8719P4MEDIUMCVSS 6.1v132019-09-19
CVE-2019-8719 [MEDIUM] CVE-2019-8719: Safari 13 Apple Security Update: About the security content of Safari 13 Product: Safari Version: 13 CVE: CVE-2019-8719 Component: WebKit Impact: Processing maliciously crafted web content may lead to universal cross site scripting Description: A logic issue was addressed with improved state management.
apple
CVE-2019-8625P4MEDIUMCVSS 6.1v132019-09-19
CVE-2019-8625 [MEDIUM] CVE-2019-8625: Safari 13 Apple Security Update: About the security content of Safari 13 Product: Safari Version: 13 CVE: CVE-2019-8625 Component: WebKit Impact: Processing maliciously crafted web content may lead to universal cross site scripting Description: A logic issue was addressed with improved state management.
apple
CVE-2022-42799P4MEDIUMCVSS 6.1fixed in 16.12022-11-01
CVE-2022-42799 [MEDIUM] CWE-1021 CVE-2022-42799: The issue was addressed with improved UI handling. This issue is fixed in tvOS 16.1, macOS Ventura 1 The issue was addressed with improved UI handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Visiting a malicious website may lead to user interface spoofing.
nvdapple
CVE-2011-0219P4MEDIUMCVSS 5.8≤ 5.0.5v1.0+54 more2011-07-21
CVE-2011-0219 [MEDIUM] CWE-264 CVE-2011-0219: Apple Safari before 5.0.6 allows remote attackers to bypass the Same Origin Policy, and modify the r Apple Safari before 5.0.6 allows remote attackers to bypass the Same Origin Policy, and modify the rendering of text from arbitrary web sites, via a Java applet that loads fonts.
nvd
CVE-2019-8762P4MEDIUMCVSS 6.1fixed in 13.0.1≥ unspecified, < 13.02020-10-27
CVE-2019-8762 [MEDIUM] CWE-79 CVE-2019-8762: A validation issue was addressed with improved logic. This issue is fixed in Safari 13.0.1, iOS 13.1 A validation issue was addressed with improved logic. This issue is fixed in Safari 13.0.1, iOS 13.1 and iPadOS 13.1, iCloud for Windows 10.7, tvOS 13, iCloud for Windows 7.14, iTunes 12.10.1 for Windows. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
CVE-2023-32445P4MEDIUMCVSS 6.1fixed in 16.6≥ unspecified, < 16.62023-07-28
CVE-2023-32445 [MEDIUM] CWE-79 CVE-2023-32445: This issue was addressed with improved checks. This issue is fixed in Safari 16.6, watchOS 9.6, iOS This issue was addressed with improved checks. This issue is fixed in Safari 16.6, watchOS 9.6, iOS 15.7.8 and iPadOS 15.7.8, tvOS 16.6, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. Processing a document may lead to a cross site scripting attack.
nvdapple
Apple Safari vulnerabilities | cvebase