Apple Safari vulnerabilities
1,654 known vulnerabilities affecting apple/safari.
Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1
Vulnerabilities
Page 64 of 83
CVE-2011-3043P4MEDIUMCVSS 6.8fixed in 6.02012-03-05
CVE-2011-3043 [MEDIUM] CWE-416 CVE-2011-3043: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a flexbox (aka flexible box) in conjunction with the floating of elements.
nvd
CVE-2011-3034P4MEDIUMCVSS 6.8fixed in 6.02012-03-05
CVE-2011-3034 [MEDIUM] CWE-416 CVE-2011-3034: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving an SVG document.
nvd
CVE-2016-4592P4MEDIUMCVSS 6.5v9.1.22016-07-18
CVE-2016-4592 [MEDIUM] CVE-2016-4592: Safari 9.1.2
Apple Security Update: About the security content of Safari 9.1.2
Product: Safari
Version: 9.1.2
CVE: CVE-2016-4592
Component: WebKit
Impact: Visiting a maliciously crafted webpage may lead to a system denial of service
Description: A memory consumption issue was addressed through improved memory handling.
apple
CVE-2020-3862P4MEDIUMCVSS 6.5fixed in 13.0.5≥ unspecified, < Safari 13.0.52020-02-27
CVE-2020-3862 [MEDIUM] CVE-2020-3862: A denial of service issue was addressed with improved memory handling. This issue is fixed in iOS 13
A denial of service issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. A malicious website may be able to cause a denial of service.
nvd
CVE-2018-4247P4MEDIUMCVSS 6.5fixed in 11.1.12018-06-08
CVE-2018-4247 [MEDIUM] CWE-20 CVE-2018-4247: An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. The issue involves the "Safari" component. It allows remote attackers to cause a denial of service (persistent Safari outage) via a crafted web site.
nvdapple
CVE-2018-4195P4MEDIUMCVSS 6.5fixed in 12vVersions prior to: Safari 122019-04-03
CVE-2018-4195 [MEDIUM] CWE-20 CVE-2018-4195: An inconsistent user interface issue was addressed with improved state management. This issue affect
An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to Safari 12.
nvdapple
CVE-2025-43240P4MEDIUMCVSS 6.2fixed in 18.62025-07-30
CVE-2025-43240 [MEDIUM] CWE-703 CVE-2025-43240: A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia
A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. A download's origin may be incorrectly associated.
nvdapple
CVE-2020-3902P4MEDIUMCVSS 6.1fixed in 13.1≥ unspecified, < Safari 13.12020-04-01
CVE-2020-3902 [MEDIUM] CWE-79 CVE-2020-3902: An input validation issue was addressed with improved input validation. This issue is fixed in iOS 1
An input validation issue was addressed with improved input validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Processing maliciously crafted web content may lead to a cross site scripting attack.
nvd
CVE-2021-30689P4MEDIUMCVSS 6.1fixed in 14.1.12021-09-08
CVE-2021-30689 [MEDIUM] CWE-79 CVE-2021-30689: A logic issue was addressed with improved state management. This issue is fixed in tvOS 14.6, iOS 14
A logic issue was addressed with improved state management. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
CVE-2019-8551P4MEDIUMCVSS 6.1fixed in 12.1≥ unspecified, < Safari 12.12019-12-18
CVE-2019-8551 [MEDIUM] CWE-79 CVE-2019-8551: A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, tvOS 12.2, Sa
A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
CVE-2010-3813P4MEDIUMCVSS 5.8≤ 5.0.2v5.0+51 more2010-11-22
CVE-2010-3813 [MEDIUM] CWE-264 CVE-2010-3813: The WebCore::HTMLLinkElement::process function in WebCore/html/HTMLLinkElement.cpp in WebKit, as use
The WebCore::HTMLLinkElement::process function in WebCore/html/HTMLLinkElement.cpp in WebKit, as used in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4; webkitgtk before 1.2.6; and possibly other products does not verify whether DNS prefetching is enabled when processing an HTML LINK element, whi
nvd
CVE-2019-6229P4MEDIUMCVSS 6.1fixed in 12.0.3≥ unspecified, < Safari 12.0.32019-03-05
CVE-2019-6229 [MEDIUM] CWE-79 CVE-2019-6229: A logic issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, tvOS 12.1.2
A logic issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
CVE-2017-2492P4MEDIUMCVSS 6.1fixed in 10.12018-04-03
CVE-2017-2492 [MEDIUM] CWE-79 CVE-2017-2492: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "JavaScriptCore" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that triggers prototype mishandling.
nvdapple
CVE-2021-30744P4MEDIUMCVSS 6.1fixed in 14.1.12021-09-08
CVE-2021-30744 [MEDIUM] CWE-79 CVE-2021-30744: Description: A cross-origin issue with iframe elements was addressed with improved tracking of secur
Description: A cross-origin issue with iframe elements was addressed with improved tracking of security origins. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
CVE-2024-40817P4MEDIUMCVSS 6.1fixed in 17.62024-07-29
CVE-2024-40817 [MEDIUM] CWE-1021 CVE-2024-40817: The issue was addressed with improved UI handling. This issue is fixed in Safari 17.6, macOS Montere
The issue was addressed with improved UI handling. This issue is fixed in Safari 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. Visiting a website that frames malicious content may lead to UI spoofing.
nvdapple
CVE-2025-43229P4MEDIUMCVSS 6.1fixed in 18.62025-07-30
CVE-2025-43229 [MEDIUM] CWE-79 CVE-2025-43229: This issue was addressed through improved state management. This issue is fixed in Safari 18.6, macO
This issue was addressed through improved state management. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
CVE-2015-3751P4MEDIUMCVSS 5.0≥ 6.0, < 6.2.8≥ 7.0, < 7.1.8+1 more2015-08-16
CVE-2015-3751 [MEDIUM] CWE-254 CVE-2015-3751: WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8
WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, allows remote attackers to bypass a Content Security Policy protection mechanism by using a video control in conjunction with an IMG element within an OBJECT element.
nvd
CVE-2015-3753P4MEDIUMCVSS 5.0≥ 6.0, < 6.2.8≥ 7.0, < 7.1.8+1 more2015-08-16
CVE-2015-3753 [MEDIUM] CWE-200 CVE-2015-3753: WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8
WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly perform taint checking for CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive image data by leveraging a redirect to a data:image resource.
nvd
CVE-2008-1024P4MEDIUMCVSS 6.8v3v3.12008-04-17
CVE-2008-1024 [MEDIUM] CWE-399 CVE-2008-1024: Apple Safari before 3.1.1, when running on Windows XP or Vista, allows remote attackers to cause a d
Apple Safari before 3.1.1, when running on Windows XP or Vista, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a file download with a crafted file name, which triggers memory corruption.
nvd
CVE-2014-4452P4MEDIUMCVSS 5.4≥ 6.0, < 6.2.1≥ 7.0, < 7.1.1+1 more2014-11-18
CVE-2014-4452 [MEDIUM] CWE-399 CVE-2014-4452: WebKit, as used in Apple iOS before 8.1.1 and Apple TV before 7.0.2, allows remote attackers to exec
WebKit, as used in Apple iOS before 8.1.1 and Apple TV before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-4462.
nvd