cbcvebase.

Apple Safari vulnerabilities

1,654 known vulnerabilities affecting apple/safari.

Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1

Vulnerabilities

Page 63 of 83
CVE-2007-3185P4HIGHCVSS 7.8v3.0.12007-06-12
CVE-2007-3185 [HIGH] CWE-399 CVE-2007-3185: Apple Safari Beta 3.0.1 for Windows public beta allows remote attackers to cause a denial of service Apple Safari Beta 3.0.1 for Windows public beta allows remote attackers to cause a denial of service (crash) via unspecified DHTML manipulations that trigger memory corruption, as demonstrated using Hamachi.
nvd
CVE-2021-30720P4MEDIUMCVSS 5.4fixed in 14.1.12021-09-08
CVE-2021-30720 [MEDIUM] CWE-287 CVE-2021-30720: A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 a A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. A malicious website may be able to access restricted ports on arbitrary servers.
nvdapple
CVE-2011-1296P4HIGHCVSS 7.5fixed in 5.0.62011-03-25
CVE-2011-1296 [HIGH] CWE-20 CVE-2011-1296: Google Chrome before 10.0.648.204 does not properly handle SVG text, which allows remote attackers t Google Chrome before 10.0.648.204 does not properly handle SVG text, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-1115P4HIGHCVSS 7.5fixed in 5.0.62011-03-01
CVE-2011-1115 [HIGH] CVE-2011-1115: Google Chrome before 9.0.597.107 does not properly render tables, which allows remote attackers to c Google Chrome before 9.0.597.107 does not properly render tables, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-1451P4HIGHCVSS 7.5fixed in 5.0.62011-05-03
CVE-2011-1451 [HIGH] CWE-20 CVE-2011-1451: Google Chrome before 11.0.696.57 does not properly handle DOM id maps, which allows remote attackers Google Chrome before 11.0.696.57 does not properly handle DOM id maps, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "dangling pointers."
nvd
CVE-2011-1295P4HIGHCVSS 7.5fixed in 5.0.62011-03-25
CVE-2011-1295 [HIGH] CWE-20 CVE-2011-1295: WebKit, as used in Google Chrome before 10.0.648.204 and Apple Safari before 5.0.6, does not properl WebKit, as used in Google Chrome before 10.0.648.204 and Apple Safari before 5.0.6, does not properly handle node parentage, which allows remote attackers to cause a denial of service (DOM tree corruption), conduct cross-site scripting (XSS) attacks, or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2020-9860P4MEDIUMCVSS 5.4fixed in 13.0.5≥ unspecified, < 13.02020-10-27
CVE-2020-9860 [MEDIUM] CVE-2020-9860: A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in Safari 13.0.5. Processing a maliciously crafted URL may lead to arbitrary javascript code execution.
nvd
CVE-2026-20643P4MEDIUMCVSS 5.4fixed in 26.42026-03-17
CVE-2026-20643 [MEDIUM] CWE-20 CVE-2026-20643: A cross-origin issue in the Navigation API was addressed with improved input validation. This issue A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS, iPadOS, and macOS, Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may bypass Same Origin Policy.
nvd
CVE-2012-1521P4MEDIUMCVSS 6.8fixed in 6.02012-05-01
CVE-2012-1521 [MEDIUM] CWE-416 CVE-2012-1521: Use-after-free vulnerability in the XML parser in Google Chrome before 18.0.1025.168 allows remote a Use-after-free vulnerability in the XML parser in Google Chrome before 18.0.1025.168 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-3078P4MEDIUMCVSS 6.8fixed in 6.02012-05-01
CVE-2011-3078 [MEDIUM] CWE-416 CVE-2011-3078: Use-after-free vulnerability in Google Chrome before 18.0.1025.168 allows remote attackers to cause Use-after-free vulnerability in Google Chrome before 18.0.1025.168 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the floating of elements, a different vulnerability than CVE-2011-3081.
nvd
CVE-2011-3075P4MEDIUMCVSS 6.8fixed in 6.02012-04-05
CVE-2011-3075 [MEDIUM] CWE-416 CVE-2011-3075: Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to style-application commands.
nvd
CVE-2011-3038P4MEDIUMCVSS 6.8fixed in 6.02012-03-05
CVE-2011-3038 [MEDIUM] CWE-416 CVE-2011-3038: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to multi-column handling.
nvd
CVE-2011-3076P4MEDIUMCVSS 6.8fixed in 6.02012-04-05
CVE-2011-3076 [MEDIUM] CWE-416 CVE-2011-3076: Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to focus handling.
nvd
CVE-2011-3069P4MEDIUMCVSS 6.8fixed in 6.02012-04-05
CVE-2011-3069 [MEDIUM] CWE-416 CVE-2011-3069: Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome bef Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to line boxes.
nvd
CVE-2011-3074P4MEDIUMCVSS 6.8fixed in 6.02012-04-05
CVE-2011-3074 [MEDIUM] CWE-416 CVE-2011-3074: Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of media.
nvd
CVE-2011-3073P4MEDIUMCVSS 6.8fixed in 6.02012-04-05
CVE-2011-3073 [MEDIUM] CWE-416 CVE-2011-3073: Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of SVG resources.
nvd
CVE-2011-3068P4MEDIUMCVSS 6.8fixed in 6.02012-04-05
CVE-2011-3068 [MEDIUM] CWE-416 CVE-2011-3068: Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome bef Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to run-in boxes.
nvd
CVE-2011-3053P4MEDIUMCVSS 6.8fixed in 6.02012-03-22
CVE-2011-3053 [MEDIUM] CWE-416 CVE-2011-3053: Use-after-free vulnerability in Google Chrome before 17.0.963.83 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 17.0.963.83 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to block splitting.
nvd
CVE-2011-3042P4MEDIUMCVSS 6.8fixed in 6.02012-03-05
CVE-2011-3042 [MEDIUM] CWE-416 CVE-2011-3042: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of table sections.
nvd
CVE-2011-3039P4MEDIUMCVSS 6.8fixed in 6.02012-03-05
CVE-2011-3039 [MEDIUM] CWE-416 CVE-2011-3039: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to quote handling.
nvd
Apple Safari vulnerabilities | cvebase