Apple Safari vulnerabilities
1,677 known vulnerabilities affecting apple/safari.
Total CVEs
1,677
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
52
Severity breakdown
CRITICAL211HIGH628MEDIUM815LOW22UNKNOWN1
Vulnerabilities
Page 64 of 84
CVE-2011-3053P4MEDIUMCVSS 6.8fixed in 6.02012-03-22
CVE-2011-3053 [MEDIUM] CWE-416 CVE-2011-3053: Use-after-free vulnerability in Google Chrome before 17.0.963.83 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 17.0.963.83 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to block splitting.
nvd
CVE-2011-3042P4MEDIUMCVSS 6.8fixed in 6.02012-03-05
CVE-2011-3042 [MEDIUM] CWE-416 CVE-2011-3042: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of table sections.
nvd
CVE-2011-3039P4MEDIUMCVSS 6.8fixed in 6.02012-03-05
CVE-2011-3039 [MEDIUM] CWE-416 CVE-2011-3039: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to quote handling.
nvd
CVE-2011-3043P4MEDIUMCVSS 6.8fixed in 6.02012-03-05
CVE-2011-3043 [MEDIUM] CWE-416 CVE-2011-3043: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a flexbox (aka flexible box) in conjunction with the floating of elements.
nvd
CVE-2011-3044P4MEDIUMCVSS 6.8fixed in 6.02012-03-05
CVE-2011-3044 [MEDIUM] CWE-416 CVE-2011-3044: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG animation elements.
nvd
CVE-2011-3035P4MEDIUMCVSS 6.8fixed in 6.02012-03-05
CVE-2011-3035 [MEDIUM] CWE-416 CVE-2011-3035: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG use elements.
nvd
CVE-2011-3034P4MEDIUMCVSS 6.8fixed in 6.02012-03-05
CVE-2011-3034 [MEDIUM] CWE-416 CVE-2011-3034: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving an SVG document.
nvd
CVE-2016-4592P4MEDIUMCVSS 6.5v9.1.22016-07-18
CVE-2016-4592 [MEDIUM] CVE-2016-4592: Safari 9.1.2
Apple Security Update: About the security content of Safari 9.1.2
Product: Safari
Version: 9.1.2
CVE: CVE-2016-4592
Component: WebKit
Impact: Visiting a maliciously crafted webpage may lead to a system denial of service
Description: A memory consumption issue was addressed through improved memory handling.
apple
CVE-2020-3862P4MEDIUMCVSS 6.5fixed in 13.0.5≥ unspecified, < Safari 13.0.52020-02-27
CVE-2020-3862 [MEDIUM] CVE-2020-3862: A denial of service issue was addressed with improved memory handling. This issue is fixed in iOS 13
A denial of service issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. A malicious website may be able to cause a denial of service.
nvd
CVE-2018-4247P4MEDIUMCVSS 6.5fixed in 11.1.12018-06-08
CVE-2018-4247 [MEDIUM] CWE-20 CVE-2018-4247: An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. The issue involves the "Safari" component. It allows remote attackers to cause a denial of service (persistent Safari outage) via a crafted web site.
nvdapple
CVE-2018-4195P4MEDIUMCVSS 6.5fixed in 12vVersions prior to: Safari 122019-04-03
CVE-2018-4195 [MEDIUM] CWE-20 CVE-2018-4195: An inconsistent user interface issue was addressed with improved state management. This issue affect
An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to Safari 12.
nvdapple
CVE-2021-30744P4MEDIUMCVSS 6.1fixed in 14.1.12021-09-08
CVE-2021-30744 [MEDIUM] CWE-79 CVE-2021-30744: Description: A cross-origin issue with iframe elements was addressed with improved tracking of secur
Description: A cross-origin issue with iframe elements was addressed with improved tracking of security origins. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
CVE-2021-30689P4MEDIUMCVSS 6.1fixed in 14.1.12021-09-08
CVE-2021-30689 [MEDIUM] CWE-79 CVE-2021-30689: A logic issue was addressed with improved state management. This issue is fixed in tvOS 14.6, iOS 14
A logic issue was addressed with improved state management. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
CVE-2019-8551P4MEDIUMCVSS 6.1fixed in 12.1≥ unspecified, < Safari 12.12019-12-18
CVE-2019-8551 [MEDIUM] CWE-79 CVE-2019-8551: A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, tvOS 12.2, Sa
A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
CVE-2010-3813P4MEDIUMCVSS 5.8≤ 5.0.2v5.0+51 more2010-11-22
CVE-2010-3813 [MEDIUM] CWE-264 CVE-2010-3813: The WebCore::HTMLLinkElement::process function in WebCore/html/HTMLLinkElement.cpp in WebKit, as use
The WebCore::HTMLLinkElement::process function in WebCore/html/HTMLLinkElement.cpp in WebKit, as used in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4; webkitgtk before 1.2.6; and possibly other products does not verify whether DNS prefetching is enabled when processing an HTML LINK element, whi
nvd
CVE-2019-6229P4MEDIUMCVSS 6.1fixed in 12.0.3≥ unspecified, < Safari 12.0.32019-03-05
CVE-2019-6229 [MEDIUM] CWE-79 CVE-2019-6229: A logic issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, tvOS 12.1.2
A logic issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
CVE-2017-2492P4MEDIUMCVSS 6.1fixed in 10.12018-04-03
CVE-2017-2492 [MEDIUM] CWE-79 CVE-2017-2492: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "JavaScriptCore" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that triggers prototype mishandling.
nvdapple
CVE-2024-40817P4MEDIUMCVSS 6.1fixed in 17.62024-07-29
CVE-2024-40817 [MEDIUM] CWE-1021 CVE-2024-40817: The issue was addressed with improved UI handling. This issue is fixed in Safari 17.6, macOS Montere
The issue was addressed with improved UI handling. This issue is fixed in Safari 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. Visiting a website that frames malicious content may lead to UI spoofing.
nvdapple
CVE-2025-43229P4MEDIUMCVSS 6.1fixed in 18.62025-07-30
CVE-2025-43229 [MEDIUM] CWE-79 CVE-2025-43229: This issue was addressed through improved state management. This issue is fixed in Safari 18.6, macO
This issue was addressed through improved state management. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
CVE-2007-3185P4HIGHCVSS 7.8v3.0.12007-06-12
CVE-2007-3185 [HIGH] CWE-399 CVE-2007-3185: Apple Safari Beta 3.0.1 for Windows public beta allows remote attackers to cause a denial of service
Apple Safari Beta 3.0.1 for Windows public beta allows remote attackers to cause a denial of service (crash) via unspecified DHTML manipulations that trigger memory corruption, as demonstrated using Hamachi.
nvd