cbcvebase.

Apple Safari vulnerabilities

1,654 known vulnerabilities affecting apple/safari.

Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1

Vulnerabilities

Page 70 of 83
CVE-2010-2249P4MEDIUMCVSS 6.5fixed in 5.0.42010-06-30
CVE-2010-2249 [MEDIUM] CWE-401 CVE-2010-2249: Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers t Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.
nvd
CVE-2011-3037P4MEDIUMCVSS 6.8fixed in 6.02012-03-05
CVE-2011-3037 [MEDIUM] CWE-704 CVE-2011-3037: Google Chrome before 17.0.963.65 does not properly perform casts of unspecified variables during the Google Chrome before 17.0.963.65 does not properly perform casts of unspecified variables during the splitting of anonymous blocks, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.
nvd
CVE-2008-3281P4MEDIUMCVSS 6.5fixed in 4.02008-08-27
CVE-2008-3281 [MEDIUM] CWE-776 CVE-2008-3281: libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribut libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
nvd
CVE-2011-3036P4MEDIUMCVSS 6.8fixed in 6.02012-03-05
CVE-2011-3036 [MEDIUM] CWE-704 CVE-2011-3036: Google Chrome before 17.0.963.65 does not properly perform a cast of an unspecified variable during Google Chrome before 17.0.963.65 does not properly perform a cast of an unspecified variable during handling of line boxes, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.
nvd
CVE-2011-3897P4MEDIUMCVSS 6.8fixed in 5.1.42011-11-11
CVE-2011-3897 [MEDIUM] CWE-416 CVE-2011-3897: Use-after-free vulnerability in Google Chrome before 15.0.874.120 allows user-assisted remote attack Use-after-free vulnerability in Google Chrome before 15.0.874.120 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to editing.
nvd
CVE-2011-3971P4MEDIUMCVSS 6.8fixed in 6.02012-02-09
CVE-2011-3971 [MEDIUM] CWE-416 CVE-2011-3971: Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows user-assisted remote attacke Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to mousemove events.
nvd
CVE-2012-3713P4MEDIUMCVSS 4.3≤ 6.0v1.0+76 more2012-09-20
CVE-2012-3713 [MEDIUM] CWE-264 CVE-2012-3713: Apple Safari before 6.0.1 does not properly handle the Quarantine attribute of HTML documents, which Apple Safari before 6.0.1 does not properly handle the Quarantine attribute of HTML documents, which allows user-assisted remote attackers to read arbitrary files by leveraging the presence of a downloaded document.
nvd
CVE-2009-2027P4HIGHCVSS 7.2≤ 3.2.3v3.0+10 more2009-06-10
CVE-2009-2027 [HIGH] CWE-264 CVE-2009-2027: The Installer in Apple Safari before 4.0 on Windows allows local users to gain privileges by checkin The Installer in Apple Safari before 4.0 on Windows allows local users to gain privileges by checking a box that specifies an immediate launch of the application after installation, related to an unspecified compression method.
nvd
CVE-2011-0244P4MEDIUMCVSS 4.3≤ 5.0.5v1.0+54 more2011-07-21
CVE-2011-0244 [MEDIUM] CWE-200 CVE-2011-0244: WebKit in Apple Safari before 5.0.6 allows user-assisted remote attackers to read arbitrary files vi WebKit in Apple Safari before 5.0.6 allows user-assisted remote attackers to read arbitrary files via vectors related to improper canonicalization of URLs within RSS feeds.
nvd
CVE-2012-0679P4MEDIUMCVSS 4.3≤ 5.1.7v1.0+75 more2012-07-25
CVE-2012-0679 [MEDIUM] CWE-264 CVE-2012-0679: Apple Safari before 6.0 allows remote attackers to read arbitrary files via a feed:// URL. Apple Safari before 6.0 allows remote attackers to read arbitrary files via a feed:// URL.
nvd
CVE-2009-2066P4MEDIUMCVSS 6.8≤ 3.2.1v0.8+52 more2009-06-15
CVE-2009-2066 [MEDIUM] CWE-287 CVE-2009-2066: Apple Safari detects http content in https web pages only when the top-level frame uses https, which Apple Safari detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying an http page to include an https iframe that references a script file on an http site, related to "HTTP-Intended-but-HTTPS-Loadable (HPIHSL) pa
nvd
CVE-2009-2062P4MEDIUMCVSS 6.8≤ 3.2.1v0.8+52 more2009-06-15
CVE-2009-2062 [MEDIUM] CWE-287 CVE-2009-2062: Apple Safari before 3.2.2 processes a 3xx HTTP CONNECT response before a successful SSL handshake, w Apple Safari before 3.2.2 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying this CONNECT response to specify a 302 redirect to an arbitrary https web site.
nvd
CVE-2025-43434P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43434 [MEDIUM] CWE-416 CVE-2025-43434: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple
CVE-2025-43438P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43438 [MEDIUM] CWE-416 CVE-2025-43438: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple
CVE-2011-0166P4MEDIUMCVSS 5.8≤ 5.0.3v1.0+52 more2011-03-11
CVE-2011-0166 [MEDIUM] CWE-264 CVE-2011-0166: The HTML5 drag and drop functionality in WebKit in Apple Safari before 5.0.4 allows user-assisted re The HTML5 drag and drop functionality in WebKit in Apple Safari before 5.0.4 allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via vectors related to the dragging of content. NOTE: this might overlap CVE-2011-0778.
nvd
CVE-2006-1987P4HIGHCVSS 7.5v2.0v2.0.1+2 more2006-04-21
CVE-2006-1987 [HIGH] CVE-2006-1987: Apple Safari 2.0.3 allows remote attackers to cause a denial of service and possibly execute code vi Apple Safari 2.0.3 allows remote attackers to cause a denial of service and possibly execute code via an invalid FRAME tag, possibly due to (1) multiple SCROLLING attributes with no values, or (2) a SRC attribute with no value. NOTE: due to lack of diagnosis by the researcher, it is unclear which vector is responsible.
nvd
CVE-2016-4618P4MEDIUMCVSS 6.1v9.1.32016-09-25
CVE-2016-4618 [MEDIUM] CWE-79 CVE-2016-4618: Cross-site scripting (XSS) vulnerability in Safari Reader in Apple iOS before 10 and Safari before 1 Cross-site scripting (XSS) vulnerability in Safari Reader in Apple iOS before 10 and Safari before 10 allows remote attackers to inject arbitrary web script or HTML via a crafted web site, aka "Universal XSS (UXSS)."
nvdapple
CVE-2025-43211P4MEDIUMCVSS 6.2fixed in 18.62025-07-30
CVE-2025-43211 [MEDIUM] CWE-770 CVE-2025-43211: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing web content may lead to a denial-of-service.
nvdapple
CVE-2012-3689P4MEDIUMCVSS 5.8≤ 5.1.7v1.0+75 more2012-07-25
CVE-2012-3689 [MEDIUM] CWE-20 CVE-2012-3689: WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-a WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-assisted remote attackers to bypass the Same Origin Policy via a crafted web site.
nvd
CVE-2012-3691P4MEDIUMCVSS 5.8≤ 5.1.7v1.0+75 more2012-07-25
CVE-2012-3691 [MEDIUM] CWE-20 CVE-2012-3691: WebKit in Apple Safari before 6.0 does not properly handle Cascading Style Sheets (CSS) property val WebKit in Apple Safari before 6.0 does not properly handle Cascading Style Sheets (CSS) property values, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
nvd
Apple Safari vulnerabilities | cvebase