cbcvebase.

Apple Safari vulnerabilities

1,654 known vulnerabilities affecting apple/safari.

Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1

Vulnerabilities

Page 74 of 83
CVE-2017-2385P4MEDIUMCVSS 5.5≤ 10.0.32017-04-02
CVE-2017-2385 [MEDIUM] CWE-200 CVE-2017-2385: An issue was discovered in certain Apple products. Safari before 10.1 is affected. The issue involve An issue was discovered in certain Apple products. Safari before 10.1 is affected. The issue involves the "Safari Login AutoFill" component. It allows local users to obtain access to locked keychain items via unspecified vectors.
nvdapple
CVE-2015-1128P4MEDIUMCVSS 5.0≤ 6.2.4v7.0+16 more2015-04-10
CVE-2015-1128 [MEDIUM] CWE-200 CVE-2015-1128: The private-browsing implementation in Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8 The private-browsing implementation in Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 allows attackers to obtain sensitive browsing-history information via vectors involving push-notification requests.
nvd
CVE-2012-3693P4MEDIUMCVSS 5.0≤ 5.1.7v1.0+75 more2012-07-25
CVE-2012-3693 [MEDIUM] CVE-2012-3693: Incomplete blacklist vulnerability in WebKit in Apple Safari before 6.0 allows remote attackers to s Incomplete blacklist vulnerability in WebKit in Apple Safari before 6.0 allows remote attackers to spoof domain names in URLs, and possibly conduct phishing attacks, by leveraging the availability of IDN support and Unicode fonts to construct unspecified homoglyphs.
nvd
CVE-2011-0214P4MEDIUMCVSS 5.0≤ 5.0.5v1.0+54 more2011-07-21
CVE-2011-0214 [MEDIUM] CWE-310 CVE-2011-0214: CFNetwork in Apple Safari before 5.0.6 on Windows does not properly handle an untrusted attribute of CFNetwork in Apple Safari before 5.0.6 on Windows does not properly handle an untrusted attribute of a system root certificate, which allows remote web servers to bypass intended SSL restrictions via a certificate signed by a blacklisted certification authority.
nvd
CVE-2015-3729P4MEDIUMCVSS 4.3≥ 6.0, < 6.2.8≥ 7.0, < 7.1.8+1 more2015-08-16
CVE-2015-3729 [MEDIUM] CWE-254 CVE-2015-3729: Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and o Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not indicate what web site originated an input prompt, which allows remote attackers to conduct spoofing attacks via a crafted site.
nvd
CVE-2015-5788P4MEDIUMCVSS 4.3≤ 8.0.82015-09-18
CVE-2015-5788 [MEDIUM] CWE-200 CVE-2015-5788: The WebKit Canvas implementation in Apple iOS before 9 allows remote attackers to bypass the Same Or The WebKit Canvas implementation in Apple iOS before 9 allows remote attackers to bypass the Same Origin Policy and obtain sensitive image information via vectors involving a CANVAS element.
nvd
CVE-2007-4692P4MEDIUMCVSS 4.3≤ 3.0.3v3.0+1 more2007-11-15
CVE-2007-4692 [MEDIUM] CWE-287 CVE-2007-4692: The tabbed browsing feature in Apple Safari 3 before Beta Update 3.0.4 on Windows, and Mac OS X 10.4 The tabbed browsing feature in Apple Safari 3 before Beta Update 3.0.4 on Windows, and Mac OS X 10.4 through 10.4.10, allows remote attackers to spoof HTTP authentication for other sites and possibly conduct phishing attacks by causing an authentication sheet to be displayed for a tab that is not active, which makes it appear as if it is associated wi
nvd
CVE-2015-5825P4MEDIUMCVSS 4.3≤ 8.0.82015-09-18
CVE-2015-5825 [MEDIUM] CWE-200 CVE-2015-5825: WebKit in Apple iOS before 9 does not properly restrict the availability of Performance API times, w WebKit in Apple iOS before 9 does not properly restrict the availability of Performance API times, which allows remote attackers to obtain sensitive information about the browser history, mouse movement, or network traffic via crafted JavaScript code.
nvd
CVE-2016-1864P4MEDIUMCVSS 4.3≤ 9.0.32016-06-19
CVE-2016-1864 [MEDIUM] CWE-200 CVE-2016-1864: The XSS auditor in WebKit, as used in Apple iOS before 9.3 and Safari before 9.1, does not properly The XSS auditor in WebKit, as used in Apple iOS before 9.3 and Safari before 9.1, does not properly handle redirects in block mode, which allows remote attackers to obtain sensitive information via a crafted URL.
nvdapple
CVE-2017-2500P4MEDIUMCVSS 4.7≤ 10.12017-05-22
CVE-2017-2500 [MEDIUM] CWE-20 CVE-2017-2500: An issue was discovered in certain Apple products. Safari before 10.1.1 is affected. The issue invol An issue was discovered in certain Apple products. Safari before 10.1.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site.
nvdapple
CVE-2015-5826P4MEDIUMCVSS 4.3≤ 8.0.82015-09-18
CVE-2015-5826 [MEDIUM] CWE-284 CVE-2015-5826: WebKit in Apple iOS before 9 does not properly select the cases in which a Cascading Style Sheets (C WebKit in Apple iOS before 9 does not properly select the cases in which a Cascading Style Sheets (CSS) document is required to have the text/css content type, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
nvd
CVE-2015-1156P4MEDIUMCVSS 4.3≤ 6.2.5v7.0+18 more2015-05-08
CVE-2015-1156 [MEDIUM] CWE-264 CVE-2015-1156: The page-loading implementation in WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, a The page-loading implementation in WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, does not properly handle the rel attribute in an A element, which allows remote attackers to bypass the Same Origin Policy for a link's target, and spoof the user interface, via a crafted web site.
nvd
CVE-2011-2877P4MEDIUMCVSS 6.8fixed in 5.1.42011-10-04
CVE-2011-2877 [MEDIUM] CVE-2011-2877: Google Chrome before 14.0.835.202 does not properly handle SVG text, which allows remote attackers t Google Chrome before 14.0.835.202 does not properly handle SVG text, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale font."
nvd
CVE-2024-40776P4MEDIUMCVSS 4.3fixed in 17.62024-07-29
CVE-2024-40776 [MEDIUM] CWE-416 CVE-2024-40776: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2024-44244P4MEDIUMCVSS 4.3fixed in 18.12024-10-28
CVE-2024-44244 [MEDIUM] CWE-787 CVE-2024-44244: A memory corruption issue was addressed with improved input validation. This issue is fixed in Safar A memory corruption issue was addressed with improved input validation. This issue is fixed in Safari 18.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2025-31206P4MEDIUMCVSS 4.3fixed in 18.52025-05-12
CVE-2025-31206 [MEDIUM] CWE-843 CVE-2025-31206: A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 18. A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple
CVE-2012-3696P4MEDIUMCVSS 4.3≤ 5.1.7v1.0+75 more2012-07-25
CVE-2012-3696 [MEDIUM] CWE-20 CVE-2012-3696: CRLF injection vulnerability in WebKit in Apple Safari before 6.0 allows remote attackers to inject CRLF injection vulnerability in WebKit in Apple Safari before 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP request splitting attacks via a crafted web site that leverages improper WebSockets URI handling.
nvd
CVE-2012-3690P4MEDIUMCVSS 4.3≤ 5.1.7v1.0+75 more2012-07-25
CVE-2012-3690 [MEDIUM] CWE-264 CVE-2012-3690: WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-a WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-assisted remote attackers to read arbitrary files via a crafted web site.
nvd
CVE-2025-30427P4MEDIUMCVSS 4.3fixed in 18.42025-03-31
CVE-2025-30427 [MEDIUM] CWE-416 CVE-2025-30427: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple
CVE-2025-24216P4MEDIUMCVSS 4.3fixed in 18.42025-03-31
CVE-2025-24216 [MEDIUM] CWE-119 CVE-2025-24216: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple
Apple Safari vulnerabilities | cvebase