Apple Safari vulnerabilities
1,677 known vulnerabilities affecting apple/safari.
Total CVEs
1,677
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
52
Severity breakdown
CRITICAL211HIGH628MEDIUM815LOW22UNKNOWN1
Vulnerabilities
Page 69 of 84
CVE-2015-5828P4MEDIUMCVSS 4.3≤ 8.0.82015-10-09
CVE-2015-5828 [MEDIUM] CWE-20 CVE-2015-5828: The API in the WebKit Plug-ins component in Apple Safari before 9 does not provide notification of a
The API in the WebKit Plug-ins component in Apple Safari before 9 does not provide notification of an HTTP Redirection (aka 3xx) status code to a plugin, which allows remote attackers to bypass intended request restrictions via a crafted web site.
nvd
CVE-2011-2818P4MEDIUMCVSS 6.8fixed in 5.1.12011-08-03
CVE-2011-2818 [MEDIUM] CWE-416 CVE-2011-2818: Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to display box rendering.
nvd
CVE-2007-4431P4MEDIUMCVSS 6.8≤ 3.0.32007-08-20
CVE-2007-4431 [MEDIUM] CVE-2007-4431: Cross-domain vulnerability in Apple Safari for Windows 3.0.3 and earlier allows remote attackers to
Cross-domain vulnerability in Apple Safari for Windows 3.0.3 and earlier allows remote attackers to bypass the Same Origin Policy, with access from local zones to external domains, via a certain body.innerHTML property value, aka "classic JavaScript frame hijacking."
nvd
CVE-2009-2058P4MEDIUMCVSS 6.8≤ 3.2.22009-06-15
CVE-2009-2058 [MEDIUM] CWE-287 CVE-2009-2058: Apple Safari before 3.2.2 uses the HTTP Host header to determine the context of a document provided
Apple Safari before 3.2.2 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.
nvd
CVE-2016-1784P4MEDIUMCVSS 6.5fixed in 9.12016-03-24
CVE-2016-1784 [MEDIUM] CWE-400 CVE-2016-1784: The History implementation in WebKit in Apple iOS before 9.3, Safari before 9.1, and tvOS before 9.2
The History implementation in WebKit in Apple iOS before 9.3, Safari before 9.1, and tvOS before 9.2 allows remote attackers to cause a denial of service (resource consumption and application crash) via a crafted web site.
nvdapple
CVE-2017-2495P4MEDIUMCVSS 6.5≤ 10.12017-05-22
CVE-2017-2495 [MEDIUM] CWE-20 CVE-2017-2495: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "Safari" component. It allows remote attackers to cause a denial of service (application crash) via a crafted web site that improperly interacts with the history menu.
nvdapple
CVE-2018-4133P4MEDIUMCVSS 6.1fixed in 11.12018-04-03
CVE-2018-4133 [MEDIUM] CWE-79 CVE-2018-4133: An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involve
An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involves the "WebKit" component. A Safari cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvdapple
CVE-2006-1986P4HIGHCVSS 7.5v2.0v2.0.1+2 more2006-04-21
CVE-2006-1986 [HIGH] CVE-2006-1986: Apple Safari 2.0.3 allows remote attackers to cause a denial of service and possibly execute code vi
Apple Safari 2.0.3 allows remote attackers to cause a denial of service and possibly execute code via a large CELLSPACING attribute in a TABLE tag, which triggers an error in KWQListIteratorImpl::KWQListIteratorImpl.
nvd
CVE-2006-1987P4HIGHCVSS 7.5v2.0v2.0.1+2 more2006-04-21
CVE-2006-1987 [HIGH] CVE-2006-1987: Apple Safari 2.0.3 allows remote attackers to cause a denial of service and possibly execute code vi
Apple Safari 2.0.3 allows remote attackers to cause a denial of service and possibly execute code via an invalid FRAME tag, possibly due to (1) multiple SCROLLING attributes with no values, or (2) a SRC attribute with no value. NOTE: due to lack of diagnosis by the researcher, it is unclear which vector is responsible.
nvd
CVE-2019-6228P4MEDIUMCVSS 6.1fixed in 12.0.3≥ unspecified, < Safari 12.0.32019-03-05
CVE-2019-6228 [MEDIUM] CWE-79 CVE-2019-6228: A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validatio
A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue is fixed in iOS 12.1.3, Safari 12.0.3. Processing maliciously crafted web content may lead to a cross site scripting attack.
nvdapple
CVE-2004-1122P4HIGHCVSS 7.5v1.2.32005-01-10
CVE-2004-1122 [HIGH] CVE-2004-1122: Safari 1.x to 1.2.4, and possibly other versions, allows inactive windows to launch dialog boxes, wh
Safari 1.x to 1.2.4, and possibly other versions, allows inactive windows to launch dialog boxes, which can allow remote attackers to spoof the dialog boxes from web sites in other windows, aka the "Dialog Box Spoofing Vulnerability," a different vulnerability than CVE-2004-1314.
nvd
CVE-2003-0370P4HIGHCVSS 7.5v1.02003-06-16
CVE-2003-0370 [HIGH] CVE-2003-0370: Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509
Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle attack.
nvd
CVE-2015-5827P4MEDIUMCVSS 5.0≤ 8.0.82015-09-18
CVE-2015-5827 [MEDIUM] CWE-200 CVE-2015-5827: WebKit in Apple iOS before 9 allows remote attackers to bypass the Same Origin Policy and obtain an
WebKit in Apple iOS before 9 allows remote attackers to bypass the Same Origin Policy and obtain an object reference via vectors involving a (1) custom event, (2) message event, or (3) pop state event.
nvd
CVE-2016-1786P4MEDIUMCVSS 5.4≤ 9.0.32016-03-24
CVE-2016-1786 [MEDIUM] CWE-200 CVE-2016-1786: The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles H
The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles HTTP responses with a 3xx (aka redirection) status code, which allows remote attackers to spoof the displayed URL, bypass the Same Origin Policy, and obtain sensitive cached information via a crafted web site.
nvdapple
CVE-2024-40780P4MEDIUMCVSS 5.5fixed in 17.62024-07-29
CVE-2024-40780 [MEDIUM] CWE-125 CVE-2024-40780: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 17.
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2015-1084P4MEDIUMCVSS 5.0≤ 6.2.3v7.0+14 more2015-03-18
CVE-2015-1084 [MEDIUM] CWE-17 CVE-2015-1084: The user interface in WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before
The user interface in WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, does not display URLs consistently, which makes it easier for remote attackers to conduct phishing attacks via a crafted URL.
nvd
CVE-2014-4363P4MEDIUMCVSS 5.0≥ 6.0, ≤ 6.1.5≥ 7.0, ≤ 7.0.52014-09-18
CVE-2014-4363 [MEDIUM] CWE-255 CVE-2014-4363: Safari in Apple iOS before 8 does not properly restrict the autofilling of passwords in forms, which
Safari in Apple iOS before 8 does not properly restrict the autofilling of passwords in forms, which allows remote attackers to obtain sensitive information via (1) an http web site, (2) an https web site with an unacceptable X.509 certificate, or (3) an IFRAME element.
nvd
CVE-2020-3852P4MEDIUMCVSS 5.3fixed in 13.0.5≥ unspecified, < 13.02020-10-27
CVE-2020-3852 [MEDIUM] CWE-863 CVE-2020-3852: A logic issue was addressed with improved validation. This issue is fixed in Safari 13.0.5. A URL sc
A logic issue was addressed with improved validation. This issue is fixed in Safari 13.0.5. A URL scheme may be incorrectly ignored when determining multimedia permission for a website.
nvd
CVE-2022-42824P4MEDIUMCVSS 5.5fixed in 16.12022-11-01
CVE-2022-42824 [MEDIUM] CVE-2022-42824: A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.1, macOS
A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may disclose sensitive user information.
nvdapple
CVE-2024-40779P4MEDIUMCVSS 5.5fixed in 17.62024-07-29
CVE-2024-40779 [MEDIUM] CWE-125 CVE-2024-40779: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 17.
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple