cbcvebase.

Apple Safari vulnerabilities

1,677 known vulnerabilities affecting apple/safari.

Total CVEs
1,677
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
52
Severity breakdown
CRITICAL211HIGH628MEDIUM815LOW22UNKNOWN1

Vulnerabilities

Page 68 of 84
CVE-2021-30682P4MEDIUMCVSS 5.5fixed in 14.1.12021-09-08
CVE-2021-30682 [MEDIUM] CVE-2021-30682: A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 a A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. A malicious application may be able to leak sensitive user information.
nvdapple
CVE-2015-3752P4MEDIUMCVSS 5.0≥ 6.0, < 6.2.8≥ 7.0, < 7.1.8+1 more2015-08-16
CVE-2015-3752 [MEDIUM] CWE-200 CVE-2015-3752: The Content Security Policy implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, The Content Security Policy implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly restrict cookie transmission for report requests, which allows remote attackers to obtain sensitive information via vectors involving (1) a cross-origin request or
nvd
CVE-2004-1314P4HIGHCVSS 7.5v1.0v1.1+5 more2005-01-10
CVE-2004-1314 [HIGH] CVE-2004-1314: Safari 1.x allows remote attackers to spoof arbitrary web sites by injecting content from one window Safari 1.x allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability, a different vulnerability than CVE-2004-1122.
nvd
CVE-2021-30836P4MEDIUMCVSS 5.5fixed in 15.0.02021-10-28
CVE-2021-30836 [MEDIUM] CWE-125 CVE-2021-30836: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.8 An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted audio file may disclose restricted memory.
nvdapple
CVE-2023-40417P4MEDIUMCVSS 5.4fixed in 17.0≥ unspecified, < 172023-09-27
CVE-2023-40417 [MEDIUM] CVE-2023-40417: A window management issue was addressed with improved state management. This issue is fixed in Safar A window management issue was addressed with improved state management. This issue is fixed in Safari 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. Visiting a website that frames malicious content may lead to UI spoofing.
nvdapple
CVE-2011-0160P4MEDIUMCVSS 5.0≤ 5.0.3v1.0+52 more2011-03-11
CVE-2011-0160 [MEDIUM] CWE-20 CVE-2011-0160: WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle redirects WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle redirects in conjunction with HTTP Basic Authentication, which might allow remote web servers to capture credentials by logging the Authorization HTTP header.
nvd
CVE-2023-32370P4MEDIUMCVSS 5.3v16.42023-03-27
CVE-2023-32370 [MEDIUM] CVE-2023-32370: Safari 16.4 Apple Security Update: About the security content of Safari 16.4 Product: Safari Version: 16.4 CVE: CVE-2023-32370 Component: WebKit Impact: Content Security Policy to block domains with wildcards may fail Description: A logic issue was addressed with improved validation.
apple
CVE-2025-46282P4MEDIUMCVSS 5.5fixed in 26.22025-12-17
CVE-2025-46282 [MEDIUM] CWE-284 CVE-2025-46282: The issue was addressed with additional permissions checks. This issue is fixed in Safari 26.2, macO The issue was addressed with additional permissions checks. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. An app may be able to access sensitive user data.
nvdapple
CVE-2024-44229P4MEDIUMCVSS 5.3fixed in 18.12024-10-28
CVE-2024-44229 [MEDIUM] CVE-2024-44229: An information leakage was addressed with additional validation. This issue is fixed in Safari 18.1, An information leakage was addressed with additional validation. This issue is fixed in Safari 18.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, visionOS 2.1. Private browsing may leak some browsing history.
nvd
CVE-2022-32833P4MEDIUMCVSS 5.3fixed in 16.02022-12-15
CVE-2022-32833 [MEDIUM] CWE-922 CVE-2022-32833: An issue existed with the file paths used to store website data. The issue was resolved by improving An issue existed with the file paths used to store website data. The issue was resolved by improving how website data is stored. This issue is fixed in iOS 16. An unauthorized user may be able to access browsing history.
nvdapple
CVE-2022-32861P4MEDIUMCVSS 5.3fixed in 15.62022-09-20
CVE-2022-32861 [MEDIUM] CVE-2022-32861: A logic issue was addressed with improved state management. This issue is fixed in Safari 15.6, macO A logic issue was addressed with improved state management. This issue is fixed in Safari 15.6, macOS Monterey 12.5. A user may be tracked through their IP address.
nvdapple
CVE-2010-1422P4MEDIUMCVSS 4.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1422 [MEDIUM] CVE-2010-1422: WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac O WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly handle changes to keyboard focus that occur during processing of key press events, which allows remote attackers to force arbitrary key presses via a crafted HTML document.
nvd
CVE-2007-3743P4MEDIUMCVSS 6.8≤ 3.0.22007-08-03
CVE-2007-3743 [MEDIUM] CWE-119 CVE-2007-3743: Stack-based buffer overflow in bookmark handling in Apple Safari 3 Beta before Update 3.0.3 on Windo Stack-based buffer overflow in bookmark handling in Apple Safari 3 Beta before Update 3.0.3 on Windows allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a bookmark with a long title.
nvd
CVE-2007-4671P4MEDIUMCVSS 6.8≤ 3.0.32007-09-27
CVE-2007-4671 [MEDIUM] CWE-20 CVE-2007-4671: Unspecified vulnerability in Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Unspecified vulnerability in Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows remote attackers to "alter or access" HTTPS content via an HTTP session with a crafted web page that causes Javascript to be applied to HTTPS pages from the same domain.
nvd
CVE-2011-3059P4MEDIUMCVSS 6.8fixed in 6.02012-03-30
CVE-2011-3059 [MEDIUM] CWE-125 CVE-2011-3059: Google Chrome before 18.0.1025.142 does not properly handle SVG text elements, which allows remote a Google Chrome before 18.0.1025.142 does not properly handle SVG text elements, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2011-2799P4MEDIUMCVSS 6.8fixed in 5.1.12011-08-03
CVE-2011-2799 [MEDIUM] CWE-416 CVE-2011-2799: Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to HTML range handling.
nvd
CVE-2011-2797P4MEDIUMCVSS 6.8fixed in 5.1.12011-08-03
CVE-2011-2797 [MEDIUM] CWE-416 CVE-2011-2797: Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to resource caching.
nvd
CVE-2011-2847P4MEDIUMCVSS 6.8fixed in 5.1.42011-09-19
CVE-2011-2847 [MEDIUM] CWE-416 CVE-2011-2847: Use-after-free vulnerability in the document loader in Google Chrome before 14.0.835.163 allows remo Use-after-free vulnerability in the document loader in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.
nvd
CVE-2009-2816P4MEDIUMCVSS 6.8fixed in 4.0.42009-11-13
CVE-2009-2816 [MEDIUM] CWE-352 CVE-2009-2816: The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4.0.4 and Google Chrome before 3.0.195.33, includes certain custom HTTP headers in the OPTIONS request during cross-origin operations with preflight, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a
nvd
CVE-2011-2846P4MEDIUMCVSS 6.8fixed in 5.1.42011-09-19
CVE-2011-2846 [MEDIUM] CWE-416 CVE-2011-2846: Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to unload event handling.
nvd
Apple Safari vulnerabilities | cvebase