cbcvebase.

Apple Safari vulnerabilities

1,654 known vulnerabilities affecting apple/safari.

Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1

Vulnerabilities

Page 69 of 83
CVE-2009-2196P4MEDIUMCVSS 5.0v4.0v4.0.1+1 more2009-08-12
CVE-2009-2196 [MEDIUM] CVE-2009-2196: Unspecified vulnerability in Apple Safari 4 before 4.0.3 allows remote web servers to place an arbit Unspecified vulnerability in Apple Safari 4 before 4.0.3 allows remote web servers to place an arbitrary web site in the Top Sites view, and possibly conduct phishing attacks, via unknown vectors.
nvd
CVE-2009-1693P4MEDIUMCVSS 5.8≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1693 [MEDIUM] CVE-2009-1693: WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 thr WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to read images from arbitrary web sites via a CANVAS element with an SVG image, related to a "cross-site image capture issue."
nvd
CVE-2017-2495P4MEDIUMCVSS 6.5≤ 10.12017-05-22
CVE-2017-2495 [MEDIUM] CWE-20 CVE-2017-2495: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "Safari" component. It allows remote attackers to cause a denial of service (application crash) via a crafted web site that improperly interacts with the history menu.
nvdapple
CVE-2006-1986P4HIGHCVSS 7.5v2.0v2.0.1+2 more2006-04-21
CVE-2006-1986 [HIGH] CVE-2006-1986: Apple Safari 2.0.3 allows remote attackers to cause a denial of service and possibly execute code vi Apple Safari 2.0.3 allows remote attackers to cause a denial of service and possibly execute code via a large CELLSPACING attribute in a TABLE tag, which triggers an error in KWQListIteratorImpl::KWQListIteratorImpl.
nvd
CVE-2019-6228P4MEDIUMCVSS 6.1fixed in 12.0.3≥ unspecified, < Safari 12.0.32019-03-05
CVE-2019-6228 [MEDIUM] CWE-79 CVE-2019-6228: A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validatio A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue is fixed in iOS 12.1.3, Safari 12.0.3. Processing maliciously crafted web content may lead to a cross site scripting attack.
nvdapple
CVE-2004-1122P4HIGHCVSS 7.5v1.2.32005-01-10
CVE-2004-1122 [HIGH] CVE-2004-1122: Safari 1.x to 1.2.4, and possibly other versions, allows inactive windows to launch dialog boxes, wh Safari 1.x to 1.2.4, and possibly other versions, allows inactive windows to launch dialog boxes, which can allow remote attackers to spoof the dialog boxes from web sites in other windows, aka the "Dialog Box Spoofing Vulnerability," a different vulnerability than CVE-2004-1314.
nvd
CVE-2003-0370P4HIGHCVSS 7.5v1.02003-06-16
CVE-2003-0370 [HIGH] CVE-2003-0370: Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle attack.
nvd
CVE-2015-5827P4MEDIUMCVSS 5.0≤ 8.0.82015-09-18
CVE-2015-5827 [MEDIUM] CWE-200 CVE-2015-5827: WebKit in Apple iOS before 9 allows remote attackers to bypass the Same Origin Policy and obtain an WebKit in Apple iOS before 9 allows remote attackers to bypass the Same Origin Policy and obtain an object reference via vectors involving a (1) custom event, (2) message event, or (3) pop state event.
nvd
CVE-2016-1786P4MEDIUMCVSS 5.4≤ 9.0.32016-03-24
CVE-2016-1786 [MEDIUM] CWE-200 CVE-2016-1786: The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles H The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles HTTP responses with a 3xx (aka redirection) status code, which allows remote attackers to spoof the displayed URL, bypass the Same Origin Policy, and obtain sensitive cached information via a crafted web site.
nvdapple
CVE-2024-40780P4MEDIUMCVSS 5.5fixed in 17.62024-07-29
CVE-2024-40780 [MEDIUM] CWE-125 CVE-2024-40780: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 17. An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2015-1084P4MEDIUMCVSS 5.0≤ 6.2.3v7.0+14 more2015-03-18
CVE-2015-1084 [MEDIUM] CWE-17 CVE-2015-1084: The user interface in WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before The user interface in WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, does not display URLs consistently, which makes it easier for remote attackers to conduct phishing attacks via a crafted URL.
nvd
CVE-2014-4363P4MEDIUMCVSS 5.0≥ 6.0, ≤ 6.1.5≥ 7.0, ≤ 7.0.52014-09-18
CVE-2014-4363 [MEDIUM] CWE-255 CVE-2014-4363: Safari in Apple iOS before 8 does not properly restrict the autofilling of passwords in forms, which Safari in Apple iOS before 8 does not properly restrict the autofilling of passwords in forms, which allows remote attackers to obtain sensitive information via (1) an http web site, (2) an https web site with an unacceptable X.509 certificate, or (3) an IFRAME element.
nvd
CVE-2020-3852P4MEDIUMCVSS 5.3fixed in 13.0.5≥ unspecified, < 13.02020-10-27
CVE-2020-3852 [MEDIUM] CWE-863 CVE-2020-3852: A logic issue was addressed with improved validation. This issue is fixed in Safari 13.0.5. A URL sc A logic issue was addressed with improved validation. This issue is fixed in Safari 13.0.5. A URL scheme may be incorrectly ignored when determining multimedia permission for a website.
nvd
CVE-2024-40779P4MEDIUMCVSS 5.5fixed in 17.62024-07-29
CVE-2024-40779 [MEDIUM] CWE-125 CVE-2024-40779: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 17. An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2022-42824P4MEDIUMCVSS 5.5fixed in 16.12022-11-01
CVE-2022-42824 [MEDIUM] CVE-2022-42824: A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.1, macOS A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may disclose sensitive user information.
nvdapple
CVE-2009-1718P4HIGHCVSS 7.1≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1718 [HIGH] CWE-200 CVE-2009-1718: WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to obtain sensitive informat WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to obtain sensitive information via vectors involving drag events and the dragging of content over a crafted web page.
nvd
CVE-2026-28958P4MEDIUMCVSS 5.5fixed in 26.52026-05-11
CVE-2026-28958 [MEDIUM] CWE-200 CVE-2026-28958: This issue was addressed with improved data protection. This issue is fixed in Safari 26.5, iOS 26.5 This issue was addressed with improved data protection. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. An app may be able to access sensitive user data.
nvd
CVE-2010-1388P4MEDIUMCVSS 4.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1388 [MEDIUM] CWE-200 CVE-2010-1388: WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6, and before 4.1 on Mac OS X 10.4, do WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6, and before 4.1 on Mac OS X 10.4, does not properly handle clipboard (1) drag and (2) paste operations for URLs, which allows user-assisted remote attackers to read arbitrary files via a crafted HTML document.
nvd
CVE-2009-1700P4MEDIUMCVSS 4.3≤ 3.2.2v2.0+22 more2009-06-10
CVE-2009-1700 [MEDIUM] CWE-200 CVE-2009-1700: The XSLT implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhon The XSLT implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle redirects, which allows remote attackers to read XML content from arbitrary web pages via a crafted document.
nvd
CVE-2018-4232P4MEDIUMCVSS 4.3fixed in 11.1.12018-06-08
CVE-2018-4232 [MEDIUM] CVE-2018-4232: An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to overwrite cookies via a crafted web site.
nvdapple
Apple Safari vulnerabilities | cvebase