Apple Safari vulnerabilities
1,677 known vulnerabilities affecting apple/safari.
Total CVEs
1,677
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
52
Severity breakdown
CRITICAL211HIGH628MEDIUM815LOW22UNKNOWN1
Vulnerabilities
Page 70 of 84
CVE-2018-4279P4MEDIUMCVSS 5.3fixed in 11.1.2vVersions prior to: Safari 11.1.22019-04-03
CVE-2018-4279 [MEDIUM] CWE-20 CVE-2018-4279: An inconsistent user interface issue was addressed with improved state management. This issue affect
An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to Safari 11.1.2.
nvdapple
CVE-2009-1718P4HIGHCVSS 7.1≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1718 [HIGH] CWE-200 CVE-2009-1718: WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to obtain sensitive informat
WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to obtain sensitive information via vectors involving drag events and the dragging of content over a crafted web page.
nvd
CVE-2026-28958P4MEDIUMCVSS 5.5fixed in 26.52026-05-11
CVE-2026-28958 [MEDIUM] CWE-200 CVE-2026-28958: This issue was addressed with improved data protection. This issue is fixed in Safari 26.5, iOS 18.7
This issue was addressed with improved data protection. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. An app may be able to access sensitive user data.
nvd
CVE-2012-0647P4MEDIUMCVSS 5.0≤ 5.1.3v1.0+71 more2012-03-12
CVE-2012-0647 [MEDIUM] CWE-200 CVE-2012-0647: WebKit in Apple Safari before 5.1.4 does not properly handle redirects in conjunction with HTTP auth
WebKit in Apple Safari before 5.1.4 does not properly handle redirects in conjunction with HTTP authentication, which might allow remote web servers to capture credentials by logging the Authorization HTTP header.
nvd
CVE-2010-1388P4MEDIUMCVSS 4.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1388 [MEDIUM] CWE-200 CVE-2010-1388: WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6, and before 4.1 on Mac OS X 10.4, do
WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6, and before 4.1 on Mac OS X 10.4, does not properly handle clipboard (1) drag and (2) paste operations for URLs, which allows user-assisted remote attackers to read arbitrary files via a crafted HTML document.
nvd
CVE-2009-1700P4MEDIUMCVSS 4.3≤ 3.2.2v2.0+22 more2009-06-10
CVE-2009-1700 [MEDIUM] CWE-200 CVE-2009-1700: The XSLT implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhon
The XSLT implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle redirects, which allows remote attackers to read XML content from arbitrary web pages via a crafted document.
nvd
CVE-2018-4232P4MEDIUMCVSS 4.3fixed in 11.1.12018-06-08
CVE-2018-4232 [MEDIUM] CVE-2018-4232: An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to overwrite cookies via a crafted web site.
nvdapple
CVE-2010-2249P4MEDIUMCVSS 6.5fixed in 5.0.42010-06-30
CVE-2010-2249 [MEDIUM] CWE-401 CVE-2010-2249: Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers t
Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.
nvd
CVE-2011-3037P4MEDIUMCVSS 6.8fixed in 6.02012-03-05
CVE-2011-3037 [MEDIUM] CWE-704 CVE-2011-3037: Google Chrome before 17.0.963.65 does not properly perform casts of unspecified variables during the
Google Chrome before 17.0.963.65 does not properly perform casts of unspecified variables during the splitting of anonymous blocks, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.
nvd
CVE-2011-3036P4MEDIUMCVSS 6.8fixed in 6.02012-03-05
CVE-2011-3036 [MEDIUM] CWE-704 CVE-2011-3036: Google Chrome before 17.0.963.65 does not properly perform a cast of an unspecified variable during
Google Chrome before 17.0.963.65 does not properly perform a cast of an unspecified variable during handling of line boxes, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.
nvd
CVE-2011-3897P4MEDIUMCVSS 6.8fixed in 5.1.42011-11-11
CVE-2011-3897 [MEDIUM] CWE-416 CVE-2011-3897: Use-after-free vulnerability in Google Chrome before 15.0.874.120 allows user-assisted remote attack
Use-after-free vulnerability in Google Chrome before 15.0.874.120 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to editing.
nvd
CVE-2011-3971P4MEDIUMCVSS 6.8fixed in 6.02012-02-09
CVE-2011-3971 [MEDIUM] CWE-416 CVE-2011-3971: Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows user-assisted remote attacke
Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to mousemove events.
nvd
CVE-2012-3713P4MEDIUMCVSS 4.3≤ 6.0v1.0+76 more2012-09-20
CVE-2012-3713 [MEDIUM] CWE-264 CVE-2012-3713: Apple Safari before 6.0.1 does not properly handle the Quarantine attribute of HTML documents, which
Apple Safari before 6.0.1 does not properly handle the Quarantine attribute of HTML documents, which allows user-assisted remote attackers to read arbitrary files by leveraging the presence of a downloaded document.
nvd
CVE-2009-2027P4HIGHCVSS 7.2≤ 3.2.3v3.0+10 more2009-06-10
CVE-2009-2027 [HIGH] CWE-264 CVE-2009-2027: The Installer in Apple Safari before 4.0 on Windows allows local users to gain privileges by checkin
The Installer in Apple Safari before 4.0 on Windows allows local users to gain privileges by checking a box that specifies an immediate launch of the application after installation, related to an unspecified compression method.
nvd
CVE-2011-0244P4MEDIUMCVSS 4.3≤ 5.0.5v1.0+54 more2011-07-21
CVE-2011-0244 [MEDIUM] CWE-200 CVE-2011-0244: WebKit in Apple Safari before 5.0.6 allows user-assisted remote attackers to read arbitrary files vi
WebKit in Apple Safari before 5.0.6 allows user-assisted remote attackers to read arbitrary files via vectors related to improper canonicalization of URLs within RSS feeds.
nvd
CVE-2012-0679P4MEDIUMCVSS 4.3≤ 5.1.7v1.0+75 more2012-07-25
CVE-2012-0679 [MEDIUM] CWE-264 CVE-2012-0679: Apple Safari before 6.0 allows remote attackers to read arbitrary files via a feed:// URL.
Apple Safari before 6.0 allows remote attackers to read arbitrary files via a feed:// URL.
nvd
CVE-2025-43429P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43429 [MEDIUM] CWE-119 CVE-2025-43429: A buffer overflow was addressed with improved bounds checking. This issue is fixed in Safari 26.1, i
A buffer overflow was addressed with improved bounds checking. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2009-2066P4MEDIUMCVSS 6.8≤ 3.2.1v0.8+52 more2009-06-15
CVE-2009-2066 [MEDIUM] CWE-287 CVE-2009-2066: Apple Safari detects http content in https web pages only when the top-level frame uses https, which
Apple Safari detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying an http page to include an https iframe that references a script file on an http site, related to "HTTP-Intended-but-HTTPS-Loadable (HPIHSL) pa
nvd
CVE-2009-2062P4MEDIUMCVSS 6.8≤ 3.2.1v0.8+52 more2009-06-15
CVE-2009-2062 [MEDIUM] CWE-287 CVE-2009-2062: Apple Safari before 3.2.2 processes a 3xx HTTP CONNECT response before a successful SSL handshake, w
Apple Safari before 3.2.2 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying this CONNECT response to specify a 302 redirect to an arbitrary https web site.
nvd
CVE-2009-2196P4MEDIUMCVSS 5.0v4.0v4.0.1+1 more2009-08-12
CVE-2009-2196 [MEDIUM] CVE-2009-2196: Unspecified vulnerability in Apple Safari 4 before 4.0.3 allows remote web servers to place an arbit
Unspecified vulnerability in Apple Safari 4 before 4.0.3 allows remote web servers to place an arbitrary web site in the Top Sites view, and possibly conduct phishing attacks, via unknown vectors.
nvd