cbcvebase.

Apple Safari vulnerabilities

1,677 known vulnerabilities affecting apple/safari.

Total CVEs
1,677
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
52
Severity breakdown
CRITICAL211HIGH628MEDIUM815LOW22UNKNOWN1

Vulnerabilities

Page 71 of 84
CVE-2011-0166P4MEDIUMCVSS 5.8≤ 5.0.3v1.0+52 more2011-03-11
CVE-2011-0166 [MEDIUM] CWE-264 CVE-2011-0166: The HTML5 drag and drop functionality in WebKit in Apple Safari before 5.0.4 allows user-assisted re The HTML5 drag and drop functionality in WebKit in Apple Safari before 5.0.4 allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via vectors related to the dragging of content. NOTE: this might overlap CVE-2011-0778.
nvd
CVE-2016-4618P4MEDIUMCVSS 6.1v9.1.32016-09-25
CVE-2016-4618 [MEDIUM] CWE-79 CVE-2016-4618: Cross-site scripting (XSS) vulnerability in Safari Reader in Apple iOS before 10 and Safari before 1 Cross-site scripting (XSS) vulnerability in Safari Reader in Apple iOS before 10 and Safari before 10 allows remote attackers to inject arbitrary web script or HTML via a crafted web site, aka "Universal XSS (UXSS)."
nvdapple
CVE-2025-43211P4MEDIUMCVSS 6.2fixed in 18.62025-07-30
CVE-2025-43211 [MEDIUM] CWE-770 CVE-2025-43211: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing web content may lead to a denial-of-service.
nvdapple
CVE-2012-3689P4MEDIUMCVSS 5.8≤ 5.1.7v1.0+75 more2012-07-25
CVE-2012-3689 [MEDIUM] CWE-20 CVE-2012-3689: WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-a WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-assisted remote attackers to bypass the Same Origin Policy via a crafted web site.
nvd
CVE-2012-3691P4MEDIUMCVSS 5.8≤ 5.1.7v1.0+75 more2012-07-25
CVE-2012-3691 [MEDIUM] CWE-20 CVE-2012-3691: WebKit in Apple Safari before 6.0 does not properly handle Cascading Style Sheets (CSS) property val WebKit in Apple Safari before 6.0 does not properly handle Cascading Style Sheets (CSS) property values, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
nvd
CVE-2009-2841P4MEDIUMCVSS 5.0≤ 4.0.3v0.8+58 more2009-11-13
CVE-2009-2841 [MEDIUM] CVE-2009-2841: The HTMLMediaElement::loadResource function in html/HTMLMediaElement.cpp in WebCore in WebKit before The HTMLMediaElement::loadResource function in html/HTMLMediaElement.cpp in WebCore in WebKit before r49480, as used in Apple Safari before 4.0.4 on Mac OS X, does not perform the expected callbacks for HTML 5 media elements that have external URLs for media resources, which allows remote attackers to trigger sub-resource requests to arbitrary web sites via a
nvd
CVE-2021-30861P4MEDIUMCVSS 5.5fixed in 15.0.02021-08-24
CVE-2021-30861 [MEDIUM] CVE-2021-30861: A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12 A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1. A malicious application may bypass Gatekeeper checks.
nvdapple
CVE-2010-1421P4MEDIUMCVSS 4.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1421 [MEDIUM] CVE-2010-1421: The execCommand JavaScript function in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10 The execCommand JavaScript function in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly restrict remote execution of clipboard commands, which allows remote attackers to modify the clipboard via a crafted HTML document.
nvd
CVE-2012-0676P4MEDIUMCVSS 5.0≤ 5.1.6v1.0+74 more2012-05-11
CVE-2012-0676 [MEDIUM] CWE-20 CVE-2012-0676: WebKit in Apple Safari before 5.1.7 does not properly track state information during the processing WebKit in Apple Safari before 5.1.7 does not properly track state information during the processing of form input, which allows remote attackers to fill in form fields on the pages of arbitrary web sites via unspecified vectors.
nvd
CVE-2019-8725P4MEDIUMCVSS 5.3fixed in 13.0.1≥ unspecified, < Safari 13.0.12019-12-18
CVE-2019-8725 [MEDIUM] CVE-2019-8725: The issue was addressed with improved handling of service worker lifetime. This issue is fixed in Sa The issue was addressed with improved handling of service worker lifetime. This issue is fixed in Safari 13.0.1. Service workers may leak private browsing history.
nvdapple
CVE-2026-20608P4MEDIUMCVSS 5.5fixed in 26.32026-02-11
CVE-2026-20608 [MEDIUM] CWE-770 CVE-2026-20608: This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2023-27932P4MEDIUMCVSS 5.5fixed in 16.4≥ unspecified, < 16.42023-05-08
CVE-2023-27932 [MEDIUM] CWE-346 CVE-2023-27932: This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, tvOS 16.4, watchOS 9.4. Processing maliciously crafted web content may bypass Same Origin Policy.
nvdapple
CVE-2011-3887P4MEDIUMCVSS 5.0fixed in 5.1.42011-10-25
CVE-2011-3887 [MEDIUM] CWE-565 CVE-2011-3887: Google Chrome before 15.0.874.102 does not properly handle javascript: URLs, which allows remote att Google Chrome before 15.0.874.102 does not properly handle javascript: URLs, which allows remote attackers to bypass intended access restrictions and read cookies via unspecified vectors.
nvd
CVE-2010-1408P4MEDIUMCVSS 4.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1408 [MEDIUM] CVE-2010-1408: WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac O WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to bypass intended restrictions on outbound connections to "non-default TCP ports" via a crafted port number, related to an "integer truncation issue." NOTE: this may overlap CVE-2010-1099.
nvd
CVE-2015-5764P4MEDIUMCVSS 4.3≤ 8.0.82015-09-18
CVE-2015-5764 [MEDIUM] CWE-20 CVE-2015-5764: The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspeci The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspecified vectors, a different vulnerability than CVE-2015-5765 and CVE-2015-5767.
nvd
CVE-2025-31257P4MEDIUMCVSS 4.7fixed in 18.52025-05-12
CVE-2025-31257 [MEDIUM] CWE-119 CVE-2025-31257: This issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 This issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple
CVE-2016-7650P4MEDIUMCVSS 4.7≤ 10.0.12017-02-20
CVE-2016-7650 [MEDIUM] CWE-79 CVE-2016-7650: An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. The issue involves the "Safari Reader" component, which allows remote attackers to conduct UXSS attacks via a crafted web site.
nvdapple
CVE-2008-3281P4MEDIUMCVSS 6.5fixed in 4.02008-08-27
CVE-2008-3281 [MEDIUM] CWE-776 CVE-2008-3281: libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribut libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
nvd
CVE-2015-5820P4MEDIUMCVSS 4.3≤ 8.0.82015-09-18
CVE-2015-5820 [MEDIUM] CWE-20 CVE-2015-5820: WebKit in Apple iOS before 9 allows remote attackers to trigger a dialing action via a crafted (1) t WebKit in Apple iOS before 9 allows remote attackers to trigger a dialing action via a crafted (1) tel://, (2) facetime://, or (3) facetime-audio:// URL.
nvd
CVE-2011-2855P4MEDIUMCVSS 6.8fixed in 5.1.42011-09-19
CVE-2011-2855 [MEDIUM] CWE-74 CVE-2011-2855: Google Chrome before 14.0.835.163 does not properly handle Cascading Style Sheets (CSS) token sequen Google Chrome before 14.0.835.163 does not properly handle Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale node."
nvd
Apple Safari vulnerabilities | cvebase