cbcvebase.

Apple Safari vulnerabilities

1,654 known vulnerabilities affecting apple/safari.

Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1

Vulnerabilities

Page 67 of 83
CVE-2011-1440P4MEDIUMCVSS 6.8fixed in 5.1.12011-05-03
CVE-2011-1440 [MEDIUM] CWE-416 CVE-2011-1440: Use-after-free vulnerability in Google Chrome before 11.0.696.57 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 11.0.696.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the ruby element and Cascading Style Sheets (CSS) token sequences.
nvd
CVE-2011-2792P4MEDIUMCVSS 6.8fixed in 5.1.12011-08-03
CVE-2011-2792 [MEDIUM] CWE-416 CVE-2011-2792: Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to float removal.
nvd
CVE-2011-2857P4MEDIUMCVSS 6.8fixed in 5.1.42011-09-19
CVE-2011-2857 [MEDIUM] CWE-416 CVE-2011-2857: Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the focus controller.
nvd
CVE-2011-3969P4MEDIUMCVSS 6.8fixed in 6.02012-02-09
CVE-2011-3969 [MEDIUM] CWE-416 CVE-2011-3969: Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to layout of SVG documents.
nvd
CVE-2016-1771P4MEDIUMCVSS 6.5≤ 9.0.32016-03-24
CVE-2016-1771 [MEDIUM] CWE-19 CVE-2016-1771: The Downloads feature in Apple Safari before 9.1 mishandles file expansion, which allows remote atta The Downloads feature in Apple Safari before 9.1 mishandles file expansion, which allows remote attackers to cause a denial of service via a crafted web site.
nvdapple
CVE-2016-4651P4MEDIUMCVSS 6.1≤ 9.1.12016-07-22
CVE-2016-4651 [MEDIUM] CWE-79 CVE-2016-4651: Cross-site scripting (XSS) vulnerability in the WebKit JavaScript bindings in Apple iOS before 9.3.3 Cross-site scripting (XSS) vulnerability in the WebKit JavaScript bindings in Apple iOS before 9.3.3 and Safari before 9.1.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTTP/0.9 response, related to a "cross-protocol cross-site scripting (XPXSS)" vulnerability.
nvdapple
CVE-2016-4585P4MEDIUMCVSS 6.1v9.1.22016-07-18
CVE-2016-4585 [MEDIUM] CVE-2016-4585: Safari 9.1.2 Apple Security Update: About the security content of Safari 9.1.2 Product: Safari Version: 9.1.2 CVE: CVE-2016-4585 Component: WebKit Page Loading Impact: A malicious website may exfiltrate data cross-origin Description: A cross-site scripting issue existed in Safari URL redirection. This issue was addressed through improved URL validation on redirection.
apple
CVE-2009-1694P4MEDIUMCVSS 5.8≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1694 [MEDIUM] CVE-2009-1694: WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 thr WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle redirects, which allows remote attackers to read images from arbitrary web sites via vectors involving a CANVAS element and redirection, related to a "cross-site image capture issue."
nvd
CVE-2018-4133P4MEDIUMCVSS 6.1fixed in 11.12018-04-03
CVE-2018-4133 [MEDIUM] CWE-79 CVE-2018-4133: An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involve An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involves the "WebKit" component. A Safari cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvdapple
CVE-2019-8764P4MEDIUMCVSS 6.1v13.0.12019-09-24
CVE-2019-8764 [MEDIUM] CVE-2019-8764: Safari 13.0.1 Apple Security Update: About the security content of Safari 13.0.1 Product: Safari Version: 13.0.1 CVE: CVE-2019-8764 Component: WebKit Impact: Processing maliciously crafted web content may lead to universal cross site scripting Description: A logic issue was addressed with improved state management.
apple
CVE-2017-7109P4MEDIUMCVSS 6.1≤ 10.1.22017-10-23
CVE-2017-7109 [MEDIUM] CWE-79 CVE-2017-7109: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. A cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web
nvdapple
CVE-2017-7059P4MEDIUMCVSS 6.1fixed in 10.1.22017-07-20
CVE-2017-7059 [MEDIUM] CWE-79 CVE-2017-7059: A DOMParser XSS issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safar A DOMParser XSS issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component.
nvdapple
CVE-2022-32891P4MEDIUMCVSS 6.1fixed in 16.0≥ unspecified, < 162023-02-27
CVE-2022-32891 [MEDIUM] CWE-1021 CVE-2022-32891: The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchO The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchOS 9, iOS 16. Visiting a website that frames malicious content may lead to UI spoofing.
nvdapple
CVE-2021-30682P4MEDIUMCVSS 5.5fixed in 14.1.12021-09-08
CVE-2021-30682 [MEDIUM] CVE-2021-30682: A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 a A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. A malicious application may be able to leak sensitive user information.
nvdapple
CVE-2015-3752P4MEDIUMCVSS 5.0≥ 6.0, < 6.2.8≥ 7.0, < 7.1.8+1 more2015-08-16
CVE-2015-3752 [MEDIUM] CWE-200 CVE-2015-3752: The Content Security Policy implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, The Content Security Policy implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly restrict cookie transmission for report requests, which allows remote attackers to obtain sensitive information via vectors involving (1) a cross-origin request or
nvd
CVE-2004-1314P4HIGHCVSS 7.5v1.0v1.1+5 more2005-01-10
CVE-2004-1314 [HIGH] CVE-2004-1314: Safari 1.x allows remote attackers to spoof arbitrary web sites by injecting content from one window Safari 1.x allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability, a different vulnerability than CVE-2004-1122.
nvd
CVE-2016-4590P4MEDIUMCVSS 5.4≤ 9.1.12016-07-22
CVE-2016-4590 [MEDIUM] CWE-20 CVE-2016-4590: WebKit in Apple iOS before 9.3.3 and Safari before 9.1.2 mishandles about: URLs, which allows remote WebKit in Apple iOS before 9.3.3 and Safari before 9.1.2 mishandles about: URLs, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
nvdapple
CVE-2021-30836P4MEDIUMCVSS 5.5fixed in 15.0.02021-10-28
CVE-2021-30836 [MEDIUM] CWE-125 CVE-2021-30836: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.8 An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted audio file may disclose restricted memory.
nvdapple
CVE-2023-40417P4MEDIUMCVSS 5.4fixed in 17.0≥ unspecified, < 172023-09-27
CVE-2023-40417 [MEDIUM] CVE-2023-40417: A window management issue was addressed with improved state management. This issue is fixed in Safar A window management issue was addressed with improved state management. This issue is fixed in Safari 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. Visiting a website that frames malicious content may lead to UI spoofing.
nvdapple
CVE-2011-0160P4MEDIUMCVSS 5.0≤ 5.0.3v1.0+52 more2011-03-11
CVE-2011-0160 [MEDIUM] CWE-20 CVE-2011-0160: WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle redirects WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle redirects in conjunction with HTTP Basic Authentication, which might allow remote web servers to capture credentials by logging the Authorization HTTP header.
nvd
Apple Safari vulnerabilities | cvebase