Apple Safari vulnerabilities
1,654 known vulnerabilities affecting apple/safari.
Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1
Vulnerabilities
Page 65 of 83
CVE-2011-1117P4HIGHCVSS 7.5fixed in 5.0.62011-03-01
CVE-2011-1117 [HIGH] CVE-2011-1117: Google Chrome before 9.0.597.107 does not properly handle XHTML documents, which allows remote attac
Google Chrome before 9.0.597.107 does not properly handle XHTML documents, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale nodes."
nvd
CVE-2011-1114P4HIGHCVSS 7.5fixed in 5.0.62011-03-01
CVE-2011-1114 [HIGH] CVE-2011-1114: Google Chrome before 9.0.597.107 does not properly handle tables, which allows remote attackers to c
Google Chrome before 9.0.597.107 does not properly handle tables, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale node."
nvd
CVE-2017-7006P4MEDIUMCVSS 5.3fixed in 10.1.22017-07-20
CVE-2017-7006 [MEDIUM] CWE-203 CVE-2017-7006: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct a timing side-channel attack to bypass the Same Origin Policy and obtain sensitive information via a crafted web site that u
nvdapple
CVE-2024-40794P4MEDIUMCVSS 5.3fixed in 17.62024-07-29
CVE-2024-40794 [MEDIUM] CWE-287 CVE-2024-40794: This issue was addressed through improved state management. This issue is fixed in Safari 17.6, iOS
This issue was addressed through improved state management. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. Private Browsing tabs may be accessed without authentication.
nvdapple
CVE-2024-44296P4MEDIUMCVSS 5.4fixed in 18.12024-10-28
CVE-2024-44296 [MEDIUM] CVE-2024-44296: The issue was addressed with improved checks. This issue is fixed in Safari 18.1, iOS 17.7.1 and iPa
The issue was addressed with improved checks. This issue is fixed in Safari 18.1, iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
nvd
CVE-2009-2200P4HIGHCVSS 7.1≤ 4.0.2v0.8+58 more2009-08-12
CVE-2009-2200 [HIGH] CWE-200 CVE-2009-2200: WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage att
WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote attackers to launch arbitrary file: URLs and obtain sensitive information via a crafted HTML document.
nvd
CVE-2024-44202P4MEDIUMCVSS 5.3fixed in 182024-09-17
CVE-2024-44202 [MEDIUM] CWE-287 CVE-2024-44202: An authentication issue was addressed with improved state management. This issue is fixed in Safari
An authentication issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18. Private Browsing tabs may be accessed without authentication.
nvdapple
CVE-2020-9894P4MEDIUMCVSS 4.3fixed in 13.1.2≥ unspecified, < Safari 13.1.22020-10-16
CVE-2020-9894 [MEDIUM] CWE-125 CVE-2020-9894: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.6
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
nvdapple
CVE-2011-3050P4MEDIUMCVSS 6.8fixed in 6.02012-03-22
CVE-2011-3050 [MEDIUM] CWE-416 CVE-2011-3050: Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome bef
Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 17.0.963.83 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the :first-letter pseudo-element.
nvd
CVE-2011-3032P4MEDIUMCVSS 6.8fixed in 6.02012-03-05
CVE-2011-3032 [MEDIUM] CWE-416 CVE-2011-3032: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of SVG values.
nvd
CVE-2016-4743P4HIGHCVSS 7.1≤ 10.0.12017-02-20
CVE-2016-4743 [HIGH] CWE-119 CVE-2016-4743: An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive information from process memory or cause a denial of service (memory corruption and ap
nvdapple
CVE-2011-3041P4MEDIUMCVSS 6.8fixed in 6.02012-03-05
CVE-2011-3041 [MEDIUM] CWE-416 CVE-2011-3041: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of class attributes.
nvd
CVE-2011-3044P4MEDIUMCVSS 6.8fixed in 6.02012-03-05
CVE-2011-3044 [MEDIUM] CWE-416 CVE-2011-3044: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG animation elements.
nvd
CVE-2011-3035P4MEDIUMCVSS 6.8fixed in 6.02012-03-05
CVE-2011-3035 [MEDIUM] CWE-416 CVE-2011-3035: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG use elements.
nvd
CVE-2011-1449P4MEDIUMCVSS 6.8fixed in 5.0.62011-05-03
CVE-2011-1449 [MEDIUM] CWE-416 CVE-2011-1449: Use-after-free vulnerability in the WebSockets implementation in Google Chrome before 11.0.696.57 al
Use-after-free vulnerability in the WebSockets implementation in Google Chrome before 11.0.696.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-2790P4MEDIUMCVSS 6.8fixed in 5.1.12011-08-03
CVE-2011-2790 [MEDIUM] CWE-416 CVE-2011-2790: Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving floating styles.
nvd
CVE-2011-3016P4MEDIUMCVSS 6.8fixed in 6.02012-02-16
CVE-2011-3016 [MEDIUM] CWE-416 CVE-2011-3016: Use-after-free vulnerability in Google Chrome before 17.0.963.56 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 17.0.963.56 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving counter nodes, related to a "read-after-free" issue.
nvd
CVE-2011-2788P4MEDIUMCVSS 6.8fixed in 5.1.12011-08-03
CVE-2011-2788 [MEDIUM] CWE-120 CVE-2011-2788: Buffer overflow in the inspector serialization functionality in Google Chrome before 13.0.782.107 al
Buffer overflow in the inspector serialization functionality in Google Chrome before 13.0.782.107 allows user-assisted remote attackers to have an unspecified impact via unknown vectors.
nvd
CVE-2007-2408P4MEDIUMCVSS 6.8v3.0.1v3.0.22007-08-03
CVE-2007-2408 [MEDIUM] CWE-20 CVE-2007-2408: WebKit in Apple Safari 3 Beta before Update 3.0.3 does not properly recognize an unchecked "Enable J
WebKit in Apple Safari 3 Beta before Update 3.0.3 does not properly recognize an unchecked "Enable Java" setting, which allows remote attackers to execute Java applets via a crafted web page.
nvd
CVE-2017-7060P4MEDIUMCVSS 6.5fixed in 10.1.22017-07-20
CVE-2017-7060 [MEDIUM] CWE-20 CVE-2017-7060: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. The issue involves the "Safari Printing" component. It allows remote attackers to cause a denial of service (excessive print dialogs) via a crafted web site.
nvdapple