cbcvebase.

Apple Safari vulnerabilities

1,677 known vulnerabilities affecting apple/safari.

Total CVEs
1,677
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
52
Severity breakdown
CRITICAL211HIGH628MEDIUM815LOW22UNKNOWN1

Vulnerabilities

Page 78 of 84
CVE-2013-5130P4MEDIUMCVSS 5.0≤ 6.0.5v6.0+4 more2013-10-24
CVE-2013-5130 [MEDIUM] CWE-200 CVE-2013-5130: WebKit in Apple Safari before 6.1 disables the Private Browsing feature upon a launch of the Web Ins WebKit in Apple Safari before 6.1 disables the Private Browsing feature upon a launch of the Web Inspector, which makes it easier for context-dependent attackers to obtain browsing information by leveraging LocalStorage/ files.
nvd
CVE-2009-1691P4MEDIUMCVSS 4.3≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1691 [MEDIUM] CWE-79 CVE-2009-1691: Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to insufficient access control for standard JavaScript prototypes in other domains.
nvd
CVE-2009-1685P4MEDIUMCVSS 4.3≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1685 [MEDIUM] CWE-79 CVE-2009-1685: Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML by overwriting the document.implementation property of (1) an embedded document or (2) a parent document.
nvd
CVE-2009-1688P4MEDIUMCVSS 4.3≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1688 [MEDIUM] CWE-79 CVE-2009-1688: Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to determining a security context through an approach that is not the "HTML 5 standard method."
nvd
CVE-2010-2264P4MEDIUMCVSS 4.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-2264 [MEDIUM] CWE-200 CVE-2010-2264: The Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 5.0 on Mac OS X 10. The Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document.
nvd
CVE-2010-0042P4MEDIUMCVSS 4.3≤ 4.0.4v4.0+4 more2010-03-15
CVE-2010-0042 [MEDIUM] CWE-200 CVE-2010-0042: ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory ac ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted TIFF image.
nvd
CVE-2010-0041P4MEDIUMCVSS 4.3≤ 4.0.4v4.0+4 more2010-03-15
CVE-2010-0041 [MEDIUM] CWE-200 CVE-2010-0041: ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory ac ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted BMP image.
nvd
CVE-2007-3742P4MEDIUMCVSS 4.3≤ 3.0.22007-08-03
CVE-2007-3742 [MEDIUM] CWE-16 CVE-2007-3742: WebKit in Apple Safari 3 Beta before Update 3.0.3, and iPhone before 1.0.1, does not properly handle WebKit in Apple Safari 3 Beta before Update 3.0.3, and iPhone before 1.0.1, does not properly handle the interaction between International Domain Name (IDN) support and Unicode fonts, which allows remote attackers to create a URL containing "look-alike characters" (homographs) and possibly perform phishing attacks.
nvd
CVE-2018-4278P4MEDIUMCVSS 4.3fixed in 11.1.22019-01-11
CVE-2018-4278 [MEDIUM] CVE-2018-4278: In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iClo In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, sound fetched through audio elements may be exfiltrated cross-origin. This issue was addressed with improved audio taint tracking.
nvdapple
CVE-2009-2842P4MEDIUMCVSS 4.3≤ 4.0.3v1.0+48 more2009-11-13
CVE-2009-2842 [MEDIUM] CVE-2009-2842: Apple Safari before 4.0.4 does not properly implement certain (1) Open Image and (2) Open Link menu Apple Safari before 4.0.4 does not properly implement certain (1) Open Image and (2) Open Link menu options, which allows remote attackers to read local HTML files via a crafted web site.
nvd
CVE-2011-3040P4MEDIUMCVSS 4.3fixed in 6.02012-03-05
CVE-2011-3040 [MEDIUM] CWE-125 CVE-2011-3040: Google Chrome before 17.0.963.65 does not properly handle text, which allows remote attackers to cau Google Chrome before 17.0.963.65 does not properly handle text, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted document.
nvd
CVE-2011-0161P4MEDIUMCVSS 4.3≤ 5.0.3v1.0+52 more2011-03-11
CVE-2011-0161 [MEDIUM] CWE-20 CVE-2011-0161: WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle the Attr.s WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle the Attr.style accessor, which allows remote attackers to bypass the Same Origin Policy and inject Cascading Style Sheets (CSS) token sequences via a crafted web site.
nvd
CVE-2010-3259P4MEDIUMCVSS 4.3fixed in 4.1.3≥ 5.0, < 5.0.32010-09-07
CVE-2010-3259 [MEDIUM] CWE-200 CVE-2010-3259: WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53 WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53, and webkitgtk before 1.2.6, does not properly restrict read access to images derived from CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive image data via a crafted web site.
nvd
CVE-2009-2197P4MEDIUMCVSS 4.3≤ 9.0.32016-03-24
CVE-2009-2197 [MEDIUM] CWE-19 CVE-2009-2197: Apple Safari before 9.1 allows remote attackers to spoof the user interface via a web page that plac Apple Safari before 9.1 allows remote attackers to spoof the user interface via a web page that places text in a crafted context, leading to unintended use of that text within a Safari dialog.
nvdapple
CVE-2015-7093P4MEDIUMCVSS 4.3≤ 9.0.12015-12-11
CVE-2015-7093 [MEDIUM] CWE-20 CVE-2015-7093: Safari in Apple iOS before 9.2 allows remote attackers to spoof a URL in the user interface via a cr Safari in Apple iOS before 9.2 allows remote attackers to spoof a URL in the user interface via a crafted web site.
nvd
CVE-2013-1013P4MEDIUMCVSS 4.3≤ 6.0.4v6.0+3 more2013-06-05
CVE-2013-1013 [MEDIUM] CWE-20 CVE-2013-1013: XSS Auditor in WebKit in Apple Safari before 6.0.5 does not properly rewrite URLs, which allows remo XSS Auditor in WebKit in Apple Safari before 6.0.5 does not properly rewrite URLs, which allows remote attackers to trigger unintended form submissions via unspecified vectors.
nvd
CVE-2017-7144P4MEDIUMCVSS 4.3≤ 10.1.22017-10-23
CVE-2017-7144 [MEDIUM] CWE-275 CVE-2017-7144: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to track Safari Private Browsing users by leveraging cookie mishandling.
nvdapple
CVE-2020-9945P4MEDIUMCVSS 4.3fixed in 14.0.12020-12-08
CVE-2020-9945 [MEDIUM] CWE-1021 CVE-2020-9945: A spoofing issue existed in the handling of URLs. This issue was addressed with improved input valid A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, Safari 14.0.1. Visiting a malicious website may lead to address bar spoofing.
nvd
CVE-2022-32868P4MEDIUMCVSS 4.3fixed in 16.0≥ unspecified, < 162022-09-20
CVE-2022-32868 [MEDIUM] CVE-2022-32868: A logic issue was addressed with improved state management. This issue is fixed in Safari 16, iOS 16 A logic issue was addressed with improved state management. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. A website may be able to track users through Safari web extensions.
nvdapple
CVE-2025-43228P4MEDIUMCVSS 4.3fixed in 18.62025-07-30
CVE-2025-43228 [MEDIUM] CWE-451 CVE-2025-43228: The issue was addressed with improved UI. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18 The issue was addressed with improved UI. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6. Visiting a malicious website may lead to address bar spoofing.
nvdapple
Apple Safari vulnerabilities | cvebase