cbcvebase.

Apple Safari vulnerabilities

1,654 known vulnerabilities affecting apple/safari.

Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1

Vulnerabilities

Page 72 of 83
CVE-2025-43441P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43441 [MEDIUM] CWE-119 CVE-2025-43441: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7. The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2009-2420P4MEDIUMCVSS 5.8v3.2.32009-07-09
CVE-2009-2420 [MEDIUM] CVE-2009-2420: Apple Safari 3.2.3 does not properly implement the file: protocol handler, which allows remote attac Apple Safari 3.2.3 does not properly implement the file: protocol handler, which allows remote attackers to read arbitrary files or cause a denial of service (launch of multiple Windows Explorer instances) via vectors involving an unspecified HTML tag, possibly a related issue to CVE-2009-1703.
nvd
CVE-2010-1413P4MEDIUMCVSS 5.0≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1413 [MEDIUM] CWE-310 CVE-2010-1413: WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac O WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, sends NTLM credentials in cleartext in unspecified circumstances, which allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2023-42883P4MEDIUMCVSS 5.5fixed in 17.2≥ unspecified, < 17.22023-12-12
CVE-2023-42883 [MEDIUM] CVE-2023-42883: The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Son The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, watchOS 10.2, tvOS 17.2, iOS 16.7.3 and iPadOS 16.7.3. Processing an image may lead to a denial-of-service.
nvdapple
CVE-2011-1190P4MEDIUMCVSS 5.0fixed in 5.0.62011-03-11
CVE-2011-1190 [MEDIUM] CWE-200 CVE-2011-1190: The Web Workers implementation in Google Chrome before 10.0.648.127 allows remote attackers to bypas The Web Workers implementation in Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, related to an "error message leak."
nvd
CVE-2020-7463P4MEDIUMCVSS 5.5fixed in 14.12021-03-26
CVE-2020-7463 [MEDIUM] CWE-416 CVE-2020-7463: In FreeBSD 12.1-STABLE before r364644, 11.4-STABLE before r364651, 12.1-RELEASE before p9, 11.4-RELE In FreeBSD 12.1-STABLE before r364644, 11.4-STABLE before r364651, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 11.3-RELEASE before p13, improper handling in the kernel causes a use-after-free bug by sending large user messages from multiple threads on the same SCTP socket. The use-after-free situation may result in unintended kernel behaviour
nvd
CVE-2004-0720P4HIGHCVSS 7.5v1.2.22004-07-27
CVE-2004-0720 [HIGH] CVE-2004-0720: Safari 1.2.2 does not properly prevent a frame in one domain from injecting content into a frame tha Safari 1.2.2 does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.
nvd
CVE-2015-1112P4MEDIUMCVSS 5.0≤ 6.2.4v7.0+16 more2015-04-10
CVE-2015-1112 [MEDIUM] CWE-200 CVE-2015-1112: Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, as used on iOS before 8.3 and oth Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, as used on iOS before 8.3 and other platforms, does not properly delete browsing-history data from the history.plist file, which allows attackers to obtain sensitive information by reading this file.
nvd
CVE-2023-42872P4MEDIUMCVSS 5.5fixed in 17.02024-01-10
CVE-2023-42872 [MEDIUM] CVE-2023-42872: The issue was addressed with additional permissions checks. This issue is fixed in macOS Sonoma 14, The issue was addressed with additional permissions checks. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. An app may be able to access sensitive user data.
nvd
CVE-2026-64718P4MEDIUMCVSS 5.5fixed in 26.62026-07-27
CVE-2026-64718 [MEDIUM] CWE-416 CVE-2026-64718: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2010-1384P4MEDIUMCVSS 4.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1384 [MEDIUM] CWE-200 CVE-2010-1384: Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not provide a warning about a (1) http or (2) https URL that contains a username and password, which makes it easier for remote attackers to conduct phishing attacks via a crafted URL.
nvd
CVE-2008-4216P4MEDIUMCVSS 4.3≤ 3.1.2v0.8+32 more2008-11-17
CVE-2008-4216 [MEDIUM] CWE-200 CVE-2008-4216: The plug-in interface in WebKit in Apple Safari before 3.2 does not prevent plug-ins from accessing The plug-in interface in WebKit in Apple Safari before 3.2 does not prevent plug-ins from accessing local URLs, which allows remote attackers to obtain sensitive information via vectors that "launch local files."
nvd
CVE-2015-3755P4MEDIUMCVSS 4.3≥ 6.0, < 6.2.8≥ 7.0, < 7.1.8+1 more2015-08-16
CVE-2015-3755 [MEDIUM] CWE-254 CVE-2015-3755: WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8 WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, allows remote attackers to spoof the user interface via a malformed URL.
nvd
CVE-2015-3754P4MEDIUMCVSS 4.3≥ 6.0, < 6.2.8≥ 7.0, < 7.1.8+1 more2015-08-16
CVE-2015-3754 [MEDIUM] CWE-200 CVE-2015-3754: The private-browsing implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8. The private-browsing implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8 does not prevent caching of HTTP authentication credentials, which makes it easier for remote attackers to track users via a crafted web site.
nvd
CVE-2015-5767P4MEDIUMCVSS 4.3≤ 8.0.82015-09-18
CVE-2015-5767 [MEDIUM] CVE-2015-5767: The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspeci The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspecified vectors, a different vulnerability than CVE-2015-5764 and CVE-2015-5765.
nvd
CVE-2015-5765P4MEDIUMCVSS 4.3≤ 8.0.82015-09-18
CVE-2015-5765 [MEDIUM] CVE-2015-5765: The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspeci The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspecified vectors, a different vulnerability than CVE-2015-5764 and CVE-2015-5767.
nvd
CVE-2011-2855P4MEDIUMCVSS 6.8fixed in 5.1.42011-09-19
CVE-2011-2855 [MEDIUM] CWE-74 CVE-2011-2855: Google Chrome before 14.0.835.163 does not properly handle Cascading Style Sheets (CSS) token sequen Google Chrome before 14.0.835.163 does not properly handle Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale node."
nvd
CVE-2016-7592P4MEDIUMCVSS 4.3≤ 10.0.12017-02-20
CVE-2016-7592 [MEDIUM] CWE-200 CVE-2016-7592: An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component, which allows remote attackers to obtain sensitive information via crafted JavaScript prompts on a web site.
nvdapple
CVE-2014-1345P4MEDIUMCVSS 4.3≤ 6.1.4v6.0+14 more2014-07-01
CVE-2014-1345 [MEDIUM] CVE-2014-1345: WebKit in Apple iOS before 7.1.2 and Apple Safari before 6.1.5 and 7.x before 7.0.5 does not properl WebKit in Apple iOS before 7.1.2 and Apple Safari before 6.1.5 and 7.x before 7.0.5 does not properly encode domain names in URLs, which allows remote attackers to spoof the address bar via a crafted web site.
nvd
CVE-2009-2416P4MEDIUMCVSS 6.5fixed in 4.0.42009-08-11
CVE-2009-2416 [MEDIUM] CWE-416 CVE-2009-2416: Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and l Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.
nvd
Apple Safari vulnerabilities | cvebase