cbcvebase.

Apple Safari vulnerabilities

1,654 known vulnerabilities affecting apple/safari.

Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1

Vulnerabilities

Page 66 of 83
CVE-2009-2199P4MEDIUMCVSS 5.8≤ 4.0.2v2.0+26 more2009-08-12
CVE-2009-2199 [MEDIUM] CVE-2009-2199: Incomplete blacklist vulnerability in WebKit in Apple Safari before 4.0.3, as used on iPhone OS befo Incomplete blacklist vulnerability in WebKit in Apple Safari before 4.0.3, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to spoof domain names in URLs, and possibly conduct phishing attacks, via unspecified homoglyphs.
nvd
CVE-2018-4309P4MEDIUMCVSS 6.1fixed in 122019-04-03
CVE-2018-4309 [MEDIUM] CWE-79 CVE-2018-4309: A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validatio A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
nvdapple
CVE-2018-4345P4MEDIUMCVSS 6.1fixed in 122019-04-03
CVE-2018-4345 [MEDIUM] CWE-79 CVE-2018-4345: A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validatio A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
nvdapple
CVE-2018-4377P4MEDIUMCVSS 6.1fixed in 12.0.12019-04-03
CVE-2018-4377 [MEDIUM] CWE-79 CVE-2018-4377: A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validatio A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue affected versions prior to iOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.
nvdapple
CVE-2019-8674P4MEDIUMCVSS 6.1fixed in 13≥ unspecified, < Safari 132019-12-18
CVE-2019-8674 [MEDIUM] CWE-79 CVE-2019-8674: A logic issue was addressed with improved state management. This issue is fixed in iOS 13, Safari 13 A logic issue was addressed with improved state management. This issue is fixed in iOS 13, Safari 13. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
CVE-2019-6204P4MEDIUMCVSS 6.1fixed in 12.1≥ unspecified, < Safari 12.12019-12-18
CVE-2019-6204 [MEDIUM] CWE-79 CVE-2019-6204: A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, Safari 12.1. A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, Safari 12.1. Enabling the Safari Reader feature on a maliciously crafted webpage may lead to universal cross site scripting.
nvdapple
CVE-2019-8505P4MEDIUMCVSS 6.1fixed in 12.1≥ unspecified, < Safari 12.12019-12-18
CVE-2019-8505 [MEDIUM] CWE-79 CVE-2019-8505: A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, Safari 12.1. A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, Safari 12.1. Enabling the Safari Reader feature on a maliciously crafted webpage may lead to universal cross site scripting.
nvdapple
CVE-2025-24208P4MEDIUMCVSS 6.1fixed in 18.42025-03-31
CVE-2025-24208 [MEDIUM] CWE-79 CVE-2025-24208: A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 18.4, A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4. Loading a malicious iframe may lead to a cross-site scripting attack.
nvdapple
CVE-2017-7142P4MEDIUMCVSS 5.3≤ 10.1.22017-10-23
CVE-2017-7142 [MEDIUM] CWE-200 CVE-2017-7142: An issue was discovered in certain Apple products. Safari before 11 is affected. The issue involves An issue was discovered in certain Apple products. Safari before 11 is affected. The issue involves the "WebKit Storage" component. It allows attackers to bypass the Safari Private Browsing protection mechanism, and consequently obtain sensitive information about visited web sites.
nvdapple
CVE-2014-4465P4MEDIUMCVSS 5.0≤ 6.2.0v7.1.0+1 more2014-12-10
CVE-2014-4465 [MEDIUM] CWE-20 CVE-2014-4465: WebKit in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1 allows remote attackers WebKit in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1 allows remote attackers to bypass the Same Origin Policy via crafted Cascading Style Sheets (CSS) token sequences within an SVG file in the SRC attribute of an IMG element.
nvd
CVE-2024-44246P4MEDIUMCVSS 5.3fixed in 18.22024-12-12
CVE-2024-44246 [MEDIUM] CWE-125 CVE-2024-44246: The issue was addressed with improved routing of Safari-originated requests. This issue is fixed in The issue was addressed with improved routing of Safari-originated requests. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2. On a device with Private Relay enabled, adding a website to the Safari Reading List may reveal the originating IP address to the website.
nvd
CVE-2014-1346P4MEDIUMCVSS 5.0≤ 6.1.3v6.0+12 more2014-05-22
CVE-2014-1346 [MEDIUM] CWE-20 CVE-2014-1346: WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, does not properly interpret Unico WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, does not properly interpret Unicode encoding, which allows remote attackers to spoof a postMessage origin, and bypass intended restrictions on sending a message to a connected frame or window, via crafted characters in a URL.
nvd
CVE-2007-3718P4HIGHCVSS 7.5v3.02007-07-12
CVE-2007-3718 [HIGH] CVE-2007-3718: Multiple unspecified vulnerabilities in the SVG parsing engine in Apple Safari 3 Beta for Windows ha Multiple unspecified vulnerabilities in the SVG parsing engine in Apple Safari 3 Beta for Windows have unspecified remote attack vectors and impact. NOTE: this issue contains no actionable information, but it was released by a reliable researcher.
nvd
CVE-2021-30930P4MEDIUMCVSS 5.3v152021-09-20
CVE-2021-30930 [MEDIUM] CVE-2021-30930: Safari 15 Apple Security Update: About the security content of Safari 15 Product: Safari Version: 15 CVE: CVE-2021-30930 Component: WebRTC Impact: An attacker may be able to track users through their IP address Description: A logic issue was addressed with improved state management.
apple
CVE-2026-43704P4MEDIUMCVSS 5.3fixed in 26.5.22026-06-29
CVE-2026-43704 [MEDIUM] CWE-416 CVE-2026-43704: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious web extension may be able to cause an unexpected process crash.
nvd
CVE-2024-44212P4MEDIUMCVSS 5.3fixed in 18.12024-12-12
CVE-2024-44212 [MEDIUM] CWE-346 CVE-2024-44212: A cookie management issue was addressed with improved state management. This issue is fixed in Safar A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Cookies belonging to one origin may be sent to another origin.
nvd
CVE-2026-20676P4MEDIUMCVSS 5.3fixed in 26.32026-02-11
CVE-2026-20676 [MEDIUM] CWE-400 CVE-2026-20676: This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. A website may be able to track users through Safari web extensions.
nvdapple
CVE-2011-3060P4MEDIUMCVSS 6.8fixed in 6.02012-03-30
CVE-2011-3060 [MEDIUM] CWE-125 CVE-2011-3060: Google Chrome before 18.0.1025.142 does not properly handle text fragments, which allows remote atta Google Chrome before 18.0.1025.142 does not properly handle text fragments, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2011-3059P4MEDIUMCVSS 6.8fixed in 6.02012-03-30
CVE-2011-3059 [MEDIUM] CWE-125 CVE-2011-3059: Google Chrome before 18.0.1025.142 does not properly handle SVG text elements, which allows remote a Google Chrome before 18.0.1025.142 does not properly handle SVG text elements, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2011-2854P4MEDIUMCVSS 6.8fixed in 5.1.42011-09-19
CVE-2011-2854 [MEDIUM] CWE-416 CVE-2011-2854: Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to "ruby / table style handing."
nvd
Apple Safari vulnerabilities | cvebase