cbcvebase.

Apple Safari vulnerabilities

1,654 known vulnerabilities affecting apple/safari.

Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1

Vulnerabilities

Page 68 of 83
CVE-2024-44229P4MEDIUMCVSS 5.3fixed in 18.12024-10-28
CVE-2024-44229 [MEDIUM] CVE-2024-44229: An information leakage was addressed with additional validation. This issue is fixed in Safari 18.1, An information leakage was addressed with additional validation. This issue is fixed in Safari 18.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, visionOS 2.1. Private browsing may leak some browsing history.
nvd
CVE-2025-46282P4MEDIUMCVSS 5.5fixed in 26.22025-12-17
CVE-2025-46282 [MEDIUM] CWE-284 CVE-2025-46282: The issue was addressed with additional permissions checks. This issue is fixed in Safari 26.2, macO The issue was addressed with additional permissions checks. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. An app may be able to access sensitive user data.
nvdapple
CVE-2023-32370P4MEDIUMCVSS 5.3v16.42023-03-27
CVE-2023-32370 [MEDIUM] CVE-2023-32370: Safari 16.4 Apple Security Update: About the security content of Safari 16.4 Product: Safari Version: 16.4 CVE: CVE-2023-32370 Component: WebKit Impact: Content Security Policy to block domains with wildcards may fail Description: A logic issue was addressed with improved validation.
apple
CVE-2022-32833P4MEDIUMCVSS 5.3fixed in 16.02022-12-15
CVE-2022-32833 [MEDIUM] CWE-922 CVE-2022-32833: An issue existed with the file paths used to store website data. The issue was resolved by improving An issue existed with the file paths used to store website data. The issue was resolved by improving how website data is stored. This issue is fixed in iOS 16. An unauthorized user may be able to access browsing history.
nvdapple
CVE-2022-32861P4MEDIUMCVSS 5.3fixed in 15.62022-09-20
CVE-2022-32861 [MEDIUM] CVE-2022-32861: A logic issue was addressed with improved state management. This issue is fixed in Safari 15.6, macO A logic issue was addressed with improved state management. This issue is fixed in Safari 15.6, macOS Monterey 12.5. A user may be tracked through their IP address.
nvdapple
CVE-2010-1422P4MEDIUMCVSS 4.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1422 [MEDIUM] CVE-2010-1422: WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac O WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly handle changes to keyboard focus that occur during processing of key press events, which allows remote attackers to force arbitrary key presses via a crafted HTML document.
nvd
CVE-2007-3743P4MEDIUMCVSS 6.8≤ 3.0.22007-08-03
CVE-2007-3743 [MEDIUM] CWE-119 CVE-2007-3743: Stack-based buffer overflow in bookmark handling in Apple Safari 3 Beta before Update 3.0.3 on Windo Stack-based buffer overflow in bookmark handling in Apple Safari 3 Beta before Update 3.0.3 on Windows allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a bookmark with a long title.
nvd
CVE-2007-4671P4MEDIUMCVSS 6.8≤ 3.0.32007-09-27
CVE-2007-4671 [MEDIUM] CWE-20 CVE-2007-4671: Unspecified vulnerability in Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Unspecified vulnerability in Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows remote attackers to "alter or access" HTTPS content via an HTTP session with a crafted web page that causes Javascript to be applied to HTTPS pages from the same domain.
nvd
CVE-2011-2799P4MEDIUMCVSS 6.8fixed in 5.1.12011-08-03
CVE-2011-2799 [MEDIUM] CWE-416 CVE-2011-2799: Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to HTML range handling.
nvd
CVE-2011-2797P4MEDIUMCVSS 6.8fixed in 5.1.12011-08-03
CVE-2011-2797 [MEDIUM] CWE-416 CVE-2011-2797: Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to resource caching.
nvd
CVE-2011-2351P4MEDIUMCVSS 6.8fixed in 5.1.12011-06-29
CVE-2011-2351 [MEDIUM] CWE-416 CVE-2011-2351: Use-after-free vulnerability in Google Chrome before 12.0.742.112 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 12.0.742.112 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG use elements.
nvd
CVE-2011-2847P4MEDIUMCVSS 6.8fixed in 5.1.42011-09-19
CVE-2011-2847 [MEDIUM] CWE-416 CVE-2011-2847: Use-after-free vulnerability in the document loader in Google Chrome before 14.0.835.163 allows remo Use-after-free vulnerability in the document loader in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.
nvd
CVE-2009-2816P4MEDIUMCVSS 6.8fixed in 4.0.42009-11-13
CVE-2009-2816 [MEDIUM] CWE-352 CVE-2009-2816: The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4.0.4 and Google Chrome before 3.0.195.33, includes certain custom HTTP headers in the OPTIONS request during cross-origin operations with preflight, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a
nvd
CVE-2011-2846P4MEDIUMCVSS 6.8fixed in 5.1.42011-09-19
CVE-2011-2846 [MEDIUM] CWE-416 CVE-2011-2846: Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to unload event handling.
nvd
CVE-2015-5828P4MEDIUMCVSS 4.3≤ 8.0.82015-10-09
CVE-2015-5828 [MEDIUM] CWE-20 CVE-2015-5828: The API in the WebKit Plug-ins component in Apple Safari before 9 does not provide notification of a The API in the WebKit Plug-ins component in Apple Safari before 9 does not provide notification of an HTTP Redirection (aka 3xx) status code to a plugin, which allows remote attackers to bypass intended request restrictions via a crafted web site.
nvd
CVE-2011-2818P4MEDIUMCVSS 6.8fixed in 5.1.12011-08-03
CVE-2011-2818 [MEDIUM] CWE-416 CVE-2011-2818: Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to display box rendering.
nvd
CVE-2007-4431P4MEDIUMCVSS 6.8≤ 3.0.32007-08-20
CVE-2007-4431 [MEDIUM] CVE-2007-4431: Cross-domain vulnerability in Apple Safari for Windows 3.0.3 and earlier allows remote attackers to Cross-domain vulnerability in Apple Safari for Windows 3.0.3 and earlier allows remote attackers to bypass the Same Origin Policy, with access from local zones to external domains, via a certain body.innerHTML property value, aka "classic JavaScript frame hijacking."
nvd
CVE-2025-43429P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43429 [MEDIUM] CWE-119 CVE-2025-43429: A buffer overflow was addressed with improved bounds checking. This issue is fixed in Safari 26.1, i A buffer overflow was addressed with improved bounds checking. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2009-2058P4MEDIUMCVSS 6.8≤ 3.2.22009-06-15
CVE-2009-2058 [MEDIUM] CWE-287 CVE-2009-2058: Apple Safari before 3.2.2 uses the HTTP Host header to determine the context of a document provided Apple Safari before 3.2.2 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.
nvd
CVE-2016-1784P4MEDIUMCVSS 6.5fixed in 9.12016-03-24
CVE-2016-1784 [MEDIUM] CWE-400 CVE-2016-1784: The History implementation in WebKit in Apple iOS before 9.3, Safari before 9.1, and tvOS before 9.2 The History implementation in WebKit in Apple iOS before 9.3, Safari before 9.1, and tvOS before 9.2 allows remote attackers to cause a denial of service (resource consumption and application crash) via a crafted web site.
nvdapple
Apple Safari vulnerabilities | cvebase