cbcvebase.

Apple Safari vulnerabilities

1,677 known vulnerabilities affecting apple/safari.

Total CVEs
1,677
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
52
Severity breakdown
CRITICAL211HIGH628MEDIUM815LOW22UNKNOWN1

Vulnerabilities

Page 67 of 84
CVE-2026-43704P4MEDIUMCVSS 5.3fixed in 26.5.22026-06-29
CVE-2026-43704 [MEDIUM] CWE-416 CVE-2026-43704: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious web extension may be able to cause an unexpected process crash.
nvd
CVE-2024-44212P4MEDIUMCVSS 5.3fixed in 18.12024-12-12
CVE-2024-44212 [MEDIUM] CWE-346 CVE-2024-44212: A cookie management issue was addressed with improved state management. This issue is fixed in Safar A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Cookies belonging to one origin may be sent to another origin.
nvd
CVE-2026-20676P4MEDIUMCVSS 5.3fixed in 26.32026-02-11
CVE-2026-20676 [MEDIUM] CWE-400 CVE-2026-20676: This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. A website may be able to track users through Safari web extensions.
nvdapple
CVE-2011-3060P4MEDIUMCVSS 6.8fixed in 6.02012-03-30
CVE-2011-3060 [MEDIUM] CWE-125 CVE-2011-3060: Google Chrome before 18.0.1025.142 does not properly handle text fragments, which allows remote atta Google Chrome before 18.0.1025.142 does not properly handle text fragments, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2011-2854P4MEDIUMCVSS 6.8fixed in 5.1.42011-09-19
CVE-2011-2854 [MEDIUM] CWE-416 CVE-2011-2854: Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to "ruby / table style handing."
nvd
CVE-2011-1440P4MEDIUMCVSS 6.8fixed in 5.1.12011-05-03
CVE-2011-1440 [MEDIUM] CWE-416 CVE-2011-1440: Use-after-free vulnerability in Google Chrome before 11.0.696.57 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 11.0.696.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the ruby element and Cascading Style Sheets (CSS) token sequences.
nvd
CVE-2011-2351P4MEDIUMCVSS 6.8fixed in 5.1.12011-06-29
CVE-2011-2351 [MEDIUM] CWE-416 CVE-2011-2351: Use-after-free vulnerability in Google Chrome before 12.0.742.112 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 12.0.742.112 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG use elements.
nvd
CVE-2011-2792P4MEDIUMCVSS 6.8fixed in 5.1.12011-08-03
CVE-2011-2792 [MEDIUM] CWE-416 CVE-2011-2792: Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to float removal.
nvd
CVE-2011-2857P4MEDIUMCVSS 6.8fixed in 5.1.42011-09-19
CVE-2011-2857 [MEDIUM] CWE-416 CVE-2011-2857: Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the focus controller.
nvd
CVE-2011-3969P4MEDIUMCVSS 6.8fixed in 6.02012-02-09
CVE-2011-3969 [MEDIUM] CWE-416 CVE-2011-3969: Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to layout of SVG documents.
nvd
CVE-2007-2408P4MEDIUMCVSS 6.8v3.0.1v3.0.22007-08-03
CVE-2007-2408 [MEDIUM] CWE-20 CVE-2007-2408: WebKit in Apple Safari 3 Beta before Update 3.0.3 does not properly recognize an unchecked "Enable J WebKit in Apple Safari 3 Beta before Update 3.0.3 does not properly recognize an unchecked "Enable Java" setting, which allows remote attackers to execute Java applets via a crafted web page.
nvd
CVE-2016-1771P4MEDIUMCVSS 6.5≤ 9.0.32016-03-24
CVE-2016-1771 [MEDIUM] CWE-19 CVE-2016-1771: The Downloads feature in Apple Safari before 9.1 mishandles file expansion, which allows remote atta The Downloads feature in Apple Safari before 9.1 mishandles file expansion, which allows remote attackers to cause a denial of service via a crafted web site.
nvdapple
CVE-2016-4651P4MEDIUMCVSS 6.1≤ 9.1.12016-07-22
CVE-2016-4651 [MEDIUM] CWE-79 CVE-2016-4651: Cross-site scripting (XSS) vulnerability in the WebKit JavaScript bindings in Apple iOS before 9.3.3 Cross-site scripting (XSS) vulnerability in the WebKit JavaScript bindings in Apple iOS before 9.3.3 and Safari before 9.1.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTTP/0.9 response, related to a "cross-protocol cross-site scripting (XPXSS)" vulnerability.
nvdapple
CVE-2009-1693P4MEDIUMCVSS 5.8≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1693 [MEDIUM] CVE-2009-1693: WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 thr WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to read images from arbitrary web sites via a CANVAS element with an SVG image, related to a "cross-site image capture issue."
nvd
CVE-2016-4585P4MEDIUMCVSS 6.1v9.1.22016-07-18
CVE-2016-4585 [MEDIUM] CVE-2016-4585: Safari 9.1.2 Apple Security Update: About the security content of Safari 9.1.2 Product: Safari Version: 9.1.2 CVE: CVE-2016-4585 Component: WebKit Page Loading Impact: A malicious website may exfiltrate data cross-origin Description: A cross-site scripting issue existed in Safari URL redirection. This issue was addressed through improved URL validation on redirection.
apple
CVE-2009-1694P4MEDIUMCVSS 5.8≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1694 [MEDIUM] CVE-2009-1694: WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 thr WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle redirects, which allows remote attackers to read images from arbitrary web sites via vectors involving a CANVAS element and redirection, related to a "cross-site image capture issue."
nvd
CVE-2019-8764P4MEDIUMCVSS 6.1v13.0.12019-09-24
CVE-2019-8764 [MEDIUM] CVE-2019-8764: Safari 13.0.1 Apple Security Update: About the security content of Safari 13.0.1 Product: Safari Version: 13.0.1 CVE: CVE-2019-8764 Component: WebKit Impact: Processing maliciously crafted web content may lead to universal cross site scripting Description: A logic issue was addressed with improved state management.
apple
CVE-2017-7109P4MEDIUMCVSS 6.1≤ 10.1.22017-10-23
CVE-2017-7109 [MEDIUM] CWE-79 CVE-2017-7109: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. A cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web
nvdapple
CVE-2017-7059P4MEDIUMCVSS 6.1fixed in 10.1.22017-07-20
CVE-2017-7059 [MEDIUM] CWE-79 CVE-2017-7059: A DOMParser XSS issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safar A DOMParser XSS issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component.
nvdapple
CVE-2022-32891P4MEDIUMCVSS 6.1fixed in 16.0≥ unspecified, < 162023-02-27
CVE-2022-32891 [MEDIUM] CWE-1021 CVE-2022-32891: The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchO The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchOS 9, iOS 16. Visiting a website that frames malicious content may lead to UI spoofing.
nvdapple
Apple Safari vulnerabilities | cvebase