Apple Safari vulnerabilities
1,592 known vulnerabilities affecting apple/safari.
Total CVEs
1,592
CISA KEV
31
actively exploited
Public exploits
157
Exploited in wild
25
Severity breakdown
CRITICAL211HIGH603MEDIUM757LOW20UNKNOWN1
Vulnerabilities
Page 77 of 80
CVE-2008-1024MEDIUMCVSS 6.8v3v3.12008-04-17
CVE-2008-1024 [MEDIUM] CWE-399 CVE-2008-1024: Apple Safari before 3.1.1, when running on Windows XP or Vista, allows remote attackers to cause a d
Apple Safari before 3.1.1, when running on Windows XP or Vista, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a file download with a crafted file name, which triggers memory corruption.
nvd
CVE-2008-1001MEDIUMCVSS 4.3v3.0v3.0.1+3 more2008-03-19
CVE-2008-1001 [MEDIUM] CWE-79 CVE-2008-1001: Cross-site scripting (XSS) vulnerability in Apple Safari before 3.1, when running on Windows XP or V
Cross-site scripting (XSS) vulnerability in Apple Safari before 3.1, when running on Windows XP or Vista, allows remote attackers to inject arbitrary web script or HTML via a crafted URL that is not properly handled in the error page.
nvd
CVE-2008-1010MEDIUMCVSS 6.8v0.8v0.9+14 more2008-03-19
CVE-2008-1010 [MEDIUM] CWE-119 CVE-2008-1010: Buffer overflow in WebKit, as used in Apple Safari before 3.1, allows remote attackers to execute ar
Buffer overflow in WebKit, as used in Apple Safari before 3.1, allows remote attackers to execute arbitrary code via crafted regular expressions in JavaScript.
nvd
CVE-2008-1009MEDIUMCVSS 4.3v0.8v0.9+14 more2008-03-19
CVE-2008-1009 [MEDIUM] CWE-79 CVE-2008-1009: Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remo
Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary JavaScript by modifying the history object.
nvd
CVE-2008-1004MEDIUMCVSS 4.3v0.8v0.9+14 more2008-03-19
CVE-2008-1004 [MEDIUM] CWE-79 CVE-2008-1004: Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remo
Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to the Web Inspector.
nvd
CVE-2008-1011MEDIUMCVSS 4.3v0.8v0.9+14 more2008-03-19
CVE-2008-1011 [MEDIUM] CWE-79 CVE-2008-1011: Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple Safari before 3.1, allows remot
Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML via a frame that calls a method instance in another frame.
nvd
CVE-2008-1006MEDIUMCVSS 4.3v0.8v0.9+14 more2008-03-19
CVE-2008-1006 [MEDIUM] CWE-79 CVE-2008-1006: Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remo
Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML by using the window.open function to change the security context of a web page.
nvd
CVE-2008-1007MEDIUMCVSS 4.3≤ 3.0.4v0.8+14 more2008-03-19
CVE-2008-1007 [MEDIUM] CWE-79 CVE-2008-1007: WebCore, as used in Apple Safari before 3.1, does not enforce the frame navigation policy for Java a
WebCore, as used in Apple Safari before 3.1, does not enforce the frame navigation policy for Java applets, which allows remote attackers to conduct cross-site scripting (XSS) attacks.
nvd
CVE-2008-1002MEDIUMCVSS 4.3v0.8v0.9+14 more2008-03-19
CVE-2008-1002 [MEDIUM] CWE-79 CVE-2008-1002: Cross-site scripting (XSS) vulnerability in Apple Safari before 3.1 allows remote attackers to injec
Cross-site scripting (XSS) vulnerability in Apple Safari before 3.1 allows remote attackers to inject arbitrary web script or HTML via a crafted javascript: URL.
nvd
CVE-2008-1008MEDIUMCVSS 4.3v0.8v0.9+14 more2008-03-19
CVE-2008-1008 [MEDIUM] CWE-79 CVE-2008-1008: Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remo
Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML via the document.domain property.
nvd
CVE-2008-1003MEDIUMCVSS 4.3v0.8v0.9+14 more2008-03-19
CVE-2008-1003 [MEDIUM] CWE-79 CVE-2008-1003: Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remo
Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to sites that set the document.domain property or have the same document.domain.
nvd
CVE-2008-1005LOWCVSS 2.1v0.8v0.9+14 more2008-03-19
CVE-2008-1005 [LOW] CWE-200 CVE-2008-1005: WebCore, as used in Apple Safari before 3.1, does not properly mask the password field when reverse
WebCore, as used in Apple Safari before 3.1, does not properly mask the password field when reverse conversion is used with the Kotoeri input method, which allows physically proximate attackers to read the password.
nvd
CVE-2008-0298MEDIUMCVSS 4.3PoCv2.0v2.0.1+3 more2008-01-16
CVE-2008-0298 [MEDIUM] CWE-20 CVE-2008-0298: KHTML WebKit as used in Apple Safari 2.x allows remote attackers to cause a denial of service (brows
KHTML WebKit as used in Apple Safari 2.x allows remote attackers to cause a denial of service (browser crash) via a crafted web page, possibly involving a STYLE attribute of a DIV element.
nvd
CVE-2007-6592MEDIUMCVSS 4.3v22007-12-28
CVE-2007-6592 [MEDIUM] CVE-2007-6592: Apple Safari 2, when a user accepts an SSL server certificate on the basis of the CN domain name in
Apple Safari 2, when a user accepts an SSL server certificate on the basis of the CN domain name in the DN field, regards the certificate as also accepted for all domain names in subjectAltName:dNSName fields, which makes it easier for remote attackers to trick a user into accepting an invalid certificate for a spoofed web site.
nvd
CVE-2007-4698MEDIUMCVSS 4.3≤ 3.0.32007-11-15
CVE-2007-4698 [MEDIUM] CWE-79 CVE-2007-4698: Apple Safari 3 before Beta Update 3.0.4 on Windows, and Mac OS X 10.4 through 10.4.10, allows remote
Apple Safari 3 before Beta Update 3.0.4 on Windows, and Mac OS X 10.4 through 10.4.10, allows remote attackers to conduct cross-site scripting (XSS) attacks by causing JavaScript events to be associated with the wrong frame.
nvd
CVE-2007-4692MEDIUMCVSS 4.3≤ 3.0.3v3.0+1 more2007-11-15
CVE-2007-4692 [MEDIUM] CWE-287 CVE-2007-4692: The tabbed browsing feature in Apple Safari 3 before Beta Update 3.0.4 on Windows, and Mac OS X 10.4
The tabbed browsing feature in Apple Safari 3 before Beta Update 3.0.4 on Windows, and Mac OS X 10.4 through 10.4.10, allows remote attackers to spoof HTTP authentication for other sites and possibly conduct phishing attacks by causing an authentication sheet to be displayed for a tab that is not active, which makes it appear as if it is associated wi
nvd
CVE-2007-3758MEDIUMCVSS 4.3≤ 3.0.32007-09-27
CVE-2007-3758 [MEDIUM] CWE-79 CVE-2007-3758: Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and in Mac OS X 10.4
Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and in Mac OS X 10.4 through 10.4.10, allows remote attackers to set Javascript window properties for web pages that are in a different domain, which can be leveraged to conduct cross-site scripting (XSS) attacks.
nvd
CVE-2007-3756MEDIUMCVSS 4.3≤ 3.0.32007-09-27
CVE-2007-3756 [MEDIUM] CWE-200 CVE-2007-3756: Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 thr
Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows remote attackers to obtain sensitive information via a crafted web page that identifies the URL of the parent window, even when the parent window is in a different domain.
nvd
CVE-2007-3760MEDIUMCVSS 4.3≤ 3.0.32007-09-27
CVE-2007-3760 [MEDIUM] CWE-79 CVE-2007-3760: Cross-site scripting (XSS) vulnerability in Safari in Apple iPhone 1.1.1, and Safari 3 before Beta U
Cross-site scripting (XSS) vulnerability in Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows remote attackers to inject arbitrary web script or HTML via frame tags.
nvd
CVE-2007-4671MEDIUMCVSS 6.8≤ 3.0.32007-09-27
CVE-2007-4671 [MEDIUM] CWE-20 CVE-2007-4671: Unspecified vulnerability in Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on
Unspecified vulnerability in Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows remote attackers to "alter or access" HTTPS content via an HTTP session with a crafted web page that causes Javascript to be applied to HTTPS pages from the same domain.
nvd