cbcvebase.

Apple Safari vulnerabilities

1,677 known vulnerabilities affecting apple/safari.

Total CVEs
1,677
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
52
Severity breakdown
CRITICAL211HIGH628MEDIUM815LOW22UNKNOWN1

Vulnerabilities

Page 63 of 84
CVE-2019-8719P4MEDIUMCVSS 6.1v132019-09-19
CVE-2019-8719 [MEDIUM] CVE-2019-8719: Safari 13 Apple Security Update: About the security content of Safari 13 Product: Safari Version: 13 CVE: CVE-2019-8719 Component: WebKit Impact: Processing maliciously crafted web content may lead to universal cross site scripting Description: A logic issue was addressed with improved state management.
apple
CVE-2019-8625P4MEDIUMCVSS 6.1v132019-09-19
CVE-2019-8625 [MEDIUM] CVE-2019-8625: Safari 13 Apple Security Update: About the security content of Safari 13 Product: Safari Version: 13 CVE: CVE-2019-8625 Component: WebKit Impact: Processing maliciously crafted web content may lead to universal cross site scripting Description: A logic issue was addressed with improved state management.
apple
CVE-2020-3902P4MEDIUMCVSS 6.1fixed in 13.1≥ unspecified, < Safari 13.12020-04-01
CVE-2020-3902 [MEDIUM] CWE-79 CVE-2020-3902: An input validation issue was addressed with improved input validation. This issue is fixed in iOS 1 An input validation issue was addressed with improved input validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Processing maliciously crafted web content may lead to a cross site scripting attack.
nvd
CVE-2019-8762P4MEDIUMCVSS 6.1fixed in 13.0.1≥ unspecified, < 13.02020-10-27
CVE-2019-8762 [MEDIUM] CWE-79 CVE-2019-8762: A validation issue was addressed with improved logic. This issue is fixed in Safari 13.0.1, iOS 13.1 A validation issue was addressed with improved logic. This issue is fixed in Safari 13.0.1, iOS 13.1 and iPadOS 13.1, iCloud for Windows 10.7, tvOS 13, iCloud for Windows 7.14, iTunes 12.10.1 for Windows. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
CVE-2023-32445P4MEDIUMCVSS 6.1fixed in 16.6≥ unspecified, < 16.62023-07-28
CVE-2023-32445 [MEDIUM] CWE-79 CVE-2023-32445: This issue was addressed with improved checks. This issue is fixed in Safari 16.6, watchOS 9.6, iOS This issue was addressed with improved checks. This issue is fixed in Safari 16.6, watchOS 9.6, iOS 15.7.8 and iPadOS 15.7.8, tvOS 16.6, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. Processing a document may lead to a cross site scripting attack.
nvdapple
CVE-2024-40857P4MEDIUMCVSS 6.1fixed in 18.0fixed in 182024-09-17
CVE-2024-40857 [MEDIUM] CWE-79 CVE-2024-40857: This issue was addressed through improved state management. This issue is fixed in Safari 18, iOS 18 This issue was addressed through improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
CVE-2021-30720P4MEDIUMCVSS 5.4fixed in 14.1.12021-09-08
CVE-2021-30720 [MEDIUM] CWE-287 CVE-2021-30720: A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 a A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. A malicious website may be able to access restricted ports on arbitrary servers.
nvdapple
CVE-2011-1115P4HIGHCVSS 7.5fixed in 5.0.62011-03-01
CVE-2011-1115 [HIGH] CVE-2011-1115: Google Chrome before 9.0.597.107 does not properly render tables, which allows remote attackers to c Google Chrome before 9.0.597.107 does not properly render tables, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-1451P4HIGHCVSS 7.5fixed in 5.0.62011-05-03
CVE-2011-1451 [HIGH] CWE-20 CVE-2011-1451: Google Chrome before 11.0.696.57 does not properly handle DOM id maps, which allows remote attackers Google Chrome before 11.0.696.57 does not properly handle DOM id maps, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "dangling pointers."
nvd
CVE-2011-1295P4HIGHCVSS 7.5fixed in 5.0.62011-03-25
CVE-2011-1295 [HIGH] CWE-20 CVE-2011-1295: WebKit, as used in Google Chrome before 10.0.648.204 and Apple Safari before 5.0.6, does not properl WebKit, as used in Google Chrome before 10.0.648.204 and Apple Safari before 5.0.6, does not properly handle node parentage, which allows remote attackers to cause a denial of service (DOM tree corruption), conduct cross-site scripting (XSS) attacks, or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2020-9860P4MEDIUMCVSS 5.4fixed in 13.0.5≥ unspecified, < 13.02020-10-27
CVE-2020-9860 [MEDIUM] CVE-2020-9860: A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in Safari 13.0.5. Processing a maliciously crafted URL may lead to arbitrary javascript code execution.
nvd
CVE-2026-20643P4MEDIUMCVSS 5.4fixed in 26.42026-03-17
CVE-2026-20643 [MEDIUM] CWE-20 CVE-2026-20643: A cross-origin issue in the Navigation API was addressed with improved input validation. This issue A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS, iPadOS, and macOS, Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may bypass Same Origin Policy.
nvd
CVE-2026-65341P4MEDIUMCVSS 5.4fixed in 26.6.12026-08-17
CVE-2026-65341 [MEDIUM] CWE-119 CVE-2026-65341: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18. The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to memory corruption.
nvd
CVE-2020-9894P4MEDIUMCVSS 4.3fixed in 13.1.2≥ unspecified, < Safari 13.1.22020-10-16
CVE-2020-9894 [MEDIUM] CWE-125 CVE-2020-9894: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.6 An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
nvdapple
CVE-2011-3071P4MEDIUMCVSS 6.8fixed in 6.02012-04-05
CVE-2011-3071 [MEDIUM] CWE-416 CVE-2011-3071: Use-after-free vulnerability in the HTMLMediaElement implementation in Google Chrome before 18.0.102 Use-after-free vulnerability in the HTMLMediaElement implementation in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-3075P4MEDIUMCVSS 6.8fixed in 6.02012-04-05
CVE-2011-3075 [MEDIUM] CWE-416 CVE-2011-3075: Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to style-application commands.
nvd
CVE-2011-3038P4MEDIUMCVSS 6.8fixed in 6.02012-03-05
CVE-2011-3038 [MEDIUM] CWE-416 CVE-2011-3038: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to multi-column handling.
nvd
CVE-2011-3069P4MEDIUMCVSS 6.8fixed in 6.02012-04-05
CVE-2011-3069 [MEDIUM] CWE-416 CVE-2011-3069: Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome bef Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to line boxes.
nvd
CVE-2011-3074P4MEDIUMCVSS 6.8fixed in 6.02012-04-05
CVE-2011-3074 [MEDIUM] CWE-416 CVE-2011-3074: Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of media.
nvd
CVE-2011-3073P4MEDIUMCVSS 6.8fixed in 6.02012-04-05
CVE-2011-3073 [MEDIUM] CWE-416 CVE-2011-3073: Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of SVG resources.
nvd
Apple Safari vulnerabilities | cvebase