cbcvebase.

Apple Safari vulnerabilities

1,654 known vulnerabilities affecting apple/safari.

Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1

Vulnerabilities

Page 75 of 83
CVE-2025-43368P4MEDIUMCVSS 4.3fixed in 26.0fixed in 262025-09-15
CVE-2025-43368 [MEDIUM] CWE-416 CVE-2025-43368: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple
CVE-2025-43425P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43425 [MEDIUM] CWE-119 CVE-2025-43425: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 26.1 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2025-43427P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43427 [MEDIUM] CWE-20 CVE-2025-43427: This issue was addressed through improved state management. This issue is fixed in Safari 26.1, iOS This issue was addressed through improved state management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2026-28901P4MEDIUMCVSS 4.3fixed in 26.52026-05-11
CVE-2026-28901 [MEDIUM] CWE-119 CVE-2026-28901: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2011-3908P4MEDIUMCVSS 5.0fixed in 5.1.42011-12-13
CVE-2011-3908 [MEDIUM] CWE-125 CVE-2011-3908: Google Chrome before 16.0.912.63 does not properly parse SVG documents, which allows remote attacker Google Chrome before 16.0.912.63 does not properly parse SVG documents, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2024-44185P4MEDIUMCVSS 5.5fixed in 17.62024-10-24
CVE-2024-44185 [MEDIUM] CVE-2024-44185: The issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 17.6 and iPadO The issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2011-3242P4MEDIUMCVSS 5.0≤ 5.1v1.0+69 more2011-10-14
CVE-2011-3242 [MEDIUM] CWE-200 CVE-2011-3242: The Private Browsing feature in Apple Safari before 5.1.1 on Mac OS X does not properly recognize th The Private Browsing feature in Apple Safari before 5.1.1 on Mac OS X does not properly recognize the Always value of the Block Cookies setting, which makes it easier for remote web servers to track users via a cookie.
nvd
CVE-2008-1999P4MEDIUMCVSS 5.0v3.1.12008-04-28
CVE-2008-1999 [MEDIUM] CVE-2008-1999: Apple Safari 3.1.1 allows remote attackers to spoof the address bar by placing many "invisible" char Apple Safari 3.1.1 allows remote attackers to spoof the address bar by placing many "invisible" characters in the userinfo subcomponent of the authority component of the URL (aka the user field), as demonstrated by %E3%80%80 sequences.
nvd
CVE-2011-4692P4MEDIUMCVSS 5.0≤ 5.1.12011-12-07
CVE-2011-4692 [MEDIUM] CWE-264 CVE-2011-4692: WebKit, as used in Apple Safari 5.1.1 and earlier and Google Chrome 15 and earlier, does not prevent WebKit, as used in Apple Safari 5.1.1 and earlier and Google Chrome 15 and earlier, does not prevent capture of data about the time required for image loading, which makes it easier for remote attackers to determine whether an image exists in the browser cache via crafted JavaScript code, as demonstrated by visipisi.
nvd
CVE-2010-1390P4MEDIUMCVSS 4.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1390 [MEDIUM] CWE-79 CVE-2010-1390: Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 throu Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via vectors related to improper UTF-7 canonicalization, and lack of termination of a quoted string in an HTML document.
nvd
CVE-2010-3810P4MEDIUMCVSS 4.3≤ 5.0.2v5.0+51 more2010-11-22
CVE-2010-3810 [MEDIUM] CVE-2010-3810: WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on M WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly handle the History object, which allows remote attackers to spoof the location bar's URL or add URLs to the history via a cross-origin attack.
nvd
CVE-2010-1406P4MEDIUMCVSS 4.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1406 [MEDIUM] CVE-2010-1406: WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac O WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, sends an https URL in the Referer header of an http request in certain circumstances involving https to http redirection, which allows remote HTTP servers to obtain potentially sensitive information via standard HTTP logging, a related issue to CVE-20
nvd
CVE-2010-1393P4MEDIUMCVSS 4.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1393 [MEDIUM] CWE-200 CVE-2010-1393: The Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 5.0 on Mac OS X 10. The Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to discover sensitive URLs via an HREF attribute associated with a redirecting URL.
nvd
CVE-2012-3715P4MEDIUMCVSS 4.3≤ 6.0v1.0+76 more2012-09-20
CVE-2012-3715 [MEDIUM] CWE-310 CVE-2012-3715: Apple Safari before 6.0.1 makes http requests for https URIs in certain circumstances involving a pa Apple Safari before 6.0.1 makes http requests for https URIs in certain circumstances involving a paste into the address bar, which allows user-assisted remote attackers to obtain sensitive information by sniffing the network.
nvd
CVE-2010-1778P4MEDIUMCVSS 4.3≤ 5.0v4.0+7 more2010-07-30
CVE-2010-1778 [MEDIUM] CWE-79 CVE-2010-1778: Cross-site scripting (XSS) vulnerability in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 Cross-site scripting (XSS) vulnerability in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via an RSS feed.
nvd
CVE-2016-1728P4MEDIUMCVSS 4.3≤ 9.0.22016-02-01
CVE-2016-1728 [MEDIUM] CWE-200 CVE-2016-1728: The Cascading Style Sheets (CSS) implementation in Apple iOS before 9.2.1 and Safari before 9.0.3 mi The Cascading Style Sheets (CSS) implementation in Apple iOS before 9.2.1 and Safari before 9.0.3 mishandles the "a:visited button" selector during height processing, which makes it easier for remote attackers to obtain sensitive browser-history information via a crafted web site.
nvdapple
CVE-2018-4440P4MEDIUMCVSS 4.3fixed in 12.0.22019-04-03
CVE-2018-4440 [MEDIUM] CWE-20 CVE-2018-4440: A logic issue was addressed with improved state management. This issue affected versions prior to iO A logic issue was addressed with improved state management. This issue affected versions prior to iOS 12.1.1, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.
nvdapple
CVE-2020-9942P4MEDIUMCVSS 4.3fixed in 13.1.2≥ unspecified, < 13.12020-12-08
CVE-2020-9942 [MEDIUM] CWE-1021 CVE-2020-9942: An inconsistent user interface issue was addressed with improved state management. This issue is fix An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, Safari 13.1.2. Visiting a malicious website may lead to address bar spoofing.
nvdapple
CVE-2019-8827P4MEDIUMCVSS 4.3fixed in 13.0.3≥ unspecified, < 13.02020-10-27
CVE-2019-8827 [MEDIUM] CVE-2019-8827: The HTTP referrer header may be used to leak browsing history. The issue was resolved by downgrading The HTTP referrer header may be used to leak browsing history. The issue was resolved by downgrading all third party referrers to their origin. This issue is fixed in Safari 13.0.3, iTunes 12.10.2 for Windows, iCloud for Windows 10.9.2, tvOS 13.2, iOS 13.2 and iPadOS 13.2, iCloud for Windows 7.15. Visiting a maliciously crafted website may reveal the sites a
nvdapple
CVE-2025-43228P4MEDIUMCVSS 4.3fixed in 18.62025-07-30
CVE-2025-43228 [MEDIUM] CWE-451 CVE-2025-43228: The issue was addressed with improved UI. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18 The issue was addressed with improved UI. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6. Visiting a malicious website may lead to address bar spoofing.
nvdapple
Apple Safari vulnerabilities | cvebase