cbcvebase.

Apple Safari vulnerabilities

1,654 known vulnerabilities affecting apple/safari.

Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1

Vulnerabilities

Page 79 of 83
CVE-2013-1012P4MEDIUMCVSS 4.3≤ 6.0.4v6.0+3 more2013-06-05
CVE-2013-1012 [MEDIUM] CWE-79 CVE-2013-1012: Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 6.0.5 allows remote attack Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 6.0.5 allows remote attackers to inject arbitrary web script or HTML via vectors involving IFRAME elements.
nvd
CVE-2015-3660P4MEDIUMCVSS 4.3≤ 6.2.6v7.0+20 more2015-07-03
CVE-2015-3660 [MEDIUM] CWE-79 CVE-2015-3660: Cross-site scripting (XSS) vulnerability in the PDF functionality in WebKit in Apple Safari before 6 Cross-site scripting (XSS) vulnerability in the PDF functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL in embedded PDF content.
nvd
CVE-2010-3259P4MEDIUMCVSS 4.3fixed in 4.1.3≥ 5.0, < 5.0.32010-09-07
CVE-2010-3259 [MEDIUM] CWE-200 CVE-2010-3259: WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53 WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53, and webkitgtk before 1.2.6, does not properly restrict read access to images derived from CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive image data via a crafted web site.
nvd
CVE-2011-0163P4MEDIUMCVSS 4.3≤ 5.0.3v1.0+52 more2011-03-11
CVE-2011-0163 [MEDIUM] CWE-20 CVE-2011-0163: WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle unspecifie WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle unspecified "cached resources," which allows remote attackers to cause a denial of service (resource unavailability) via a crafted web site that conducts a cache-poisoning attack.
nvd
CVE-2011-3968P4MEDIUMCVSS 4.3fixed in 6.02012-02-09
CVE-2011-3968 [MEDIUM] CWE-416 CVE-2011-3968: Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving Cascading Style Sheets (CSS) token sequences.
nvd
CVE-2016-1781P4MEDIUMCVSS 4.3≤ 9.0.32016-03-24
CVE-2016-1781 [MEDIUM] CWE-19 CVE-2016-1781: WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles attachment URLs, which makes it easi WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles attachment URLs, which makes it easier for remote web servers to track users via unspecified vectors.
nvdapple
CVE-2020-9993P4MEDIUMCVSS 4.3v14.0≥ unspecified, < 14.02020-12-08
CVE-2020-9993 [MEDIUM] CWE-1021 CVE-2020-9993: The issue was addressed with improved UI handling. This issue is fixed in watchOS 7.0, Safari 14.0, The issue was addressed with improved UI handling. This issue is fixed in watchOS 7.0, Safari 14.0, iOS 14.0 and iPadOS 14.0. Visiting a malicious website may lead to address bar spoofing.
nvd
CVE-2007-4424P4MEDIUMCVSS 4.3≤ 3.0.32007-08-18
CVE-2007-4424 [MEDIUM] CVE-2007-4424: Apple Safari for Windows 3.0.3 and earlier does not prompt the user before downloading a file, which Apple Safari for Windows 3.0.3 and earlier does not prompt the user before downloading a file, which allows remote attackers to download arbitrary files to the desktop of a client system via certain HTML, as demonstrated by a filename in the DATA attribute of an OBJECT element. NOTE: it could be argued that this is not a vulnerability because a dangerous file
nvd
CVE-2018-4307P4MEDIUMCVSS 4.3fixed in 122019-04-03
CVE-2018-4307 [MEDIUM] CWE-20 CVE-2018-4307: A logic issue was addressed with improved state management. This issue affected versions prior to iO A logic issue was addressed with improved state management. This issue affected versions prior to iOS 12, Safari 12.
nvdapple
CVE-2015-1129P4MEDIUMCVSS 4.3≤ 6.2.4v7.0+16 more2015-04-10
CVE-2015-1129 [MEDIUM] CWE-310 CVE-2015-1129: Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 does not properly select X.509 cli Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 does not properly select X.509 client certificates, which makes it easier for remote attackers to track users via a crafted web site.
nvd
CVE-2012-3714P4MEDIUMCVSS 4.3≤ 6.0v1.0+76 more2012-09-20
CVE-2012-3714 [MEDIUM] CWE-200 CVE-2012-3714: The Form Autofill feature in Apple Safari before 6.0.1 does not restrict the filled fields to the se The Form Autofill feature in Apple Safari before 6.0.1 does not restrict the filled fields to the set of fields contained in an Autofill popover, which allows remote attackers to obtain the Me card from an Address Book via a crafted web site.
nvd
CVE-2019-8670P4MEDIUMCVSS 4.3fixed in 12.1.2≥ unspecified, < Safari 12.1.22019-12-18
CVE-2019-8670 [MEDIUM] CWE-20 CVE-2019-8670: An inconsistent user interface issue was addressed with improved state management. This issue is fix An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.6, Safari 12.1.2. Visiting a malicious website may lead to address bar spoofing.
nvdapple
CVE-2020-9784P4MEDIUMCVSS 4.3fixed in 13.1≥ unspecified, < Safari 13.12020-04-01
CVE-2020-9784 [MEDIUM] CVE-2020-9784: A logic issue was addressed with improved restrictions. This issue is fixed in Safari 13.1. A malici A logic issue was addressed with improved restrictions. This issue is fixed in Safari 13.1. A malicious iframe may use another website’s download settings.
nvd
CVE-2020-9987P4MEDIUMCVSS 4.3fixed in 14.0≥ unspecified, < 14.02020-12-08
CVE-2020-9987 [MEDIUM] CWE-1021 CVE-2020-9987: An inconsistent user interface issue was addressed with improved state management. This issue is fix An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 14.0. Visiting a malicious website may lead to address bar spoofing.
nvd
CVE-2010-1805P4MEDIUMCVSS 6.9v4.0v4.0.0b+8 more2010-09-10
CVE-2010-1805 [MEDIUM] CWE-264 CVE-2010-1805: Untrusted search path vulnerability in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2 on Windows Untrusted search path vulnerability in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2 on Windows allows local users to gain privileges via a Trojan horse explorer.exe (aka Windows Explorer) program in a directory containing a file that had been downloaded by Safari.
nvd
CVE-2020-3833P4MEDIUMCVSS 4.3fixed in 13.0.5≥ unspecified, < Safari 13.0.52020-02-27
CVE-2020-3833 [MEDIUM] CVE-2020-3833: An inconsistent user interface issue was addressed with improved state management. This issue is fix An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 13.0.5. Visiting a malicious website may lead to address bar spoofing.
nvd
CVE-2018-4445P4MEDIUMCVSS 4.3fixed in 12.0.22019-04-03
CVE-2018-4445 [MEDIUM] CWE-200 CVE-2018-4445: "Clear History and Website Data" did not clear the history. The issue was addressed with improved da "Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This issue affected versions prior to iOS 12.1.1, Safari 12.0.2.
nvdapple
CVE-2025-24128P4MEDIUMCVSS 4.3fixed in 18.32025-01-27
CVE-2025-24128 [MEDIUM] CVE-2025-24128: The issue was addressed by adding additional logic. This issue is fixed in Safari 18.3, iOS 18.3 and The issue was addressed by adding additional logic. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. Visiting a malicious website may lead to address bar spoofing.
nvdapple
CVE-2006-1552P4MEDIUMCVSS 5.0v1.0v1.1+10 more2006-03-31
CVE-2006-1552 [MEDIUM] CWE-189 CVE-2006-1552: Integer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to cause a d Integer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to cause a denial of service (crash) via a crafted JPEG image with malformed JPEG metadata, as demonstrated using Safari, aka "Deja-Doom".
nvd
CVE-2025-43265P4MEDIUMCVSS 4.0fixed in 18.62025-07-30
CVE-2025-43265 [MEDIUM] CWE-125 CVE-2025-43265: An out-of-bounds read was addressed with improved input validation. This issue is fixed in Safari 18 An out-of-bounds read was addressed with improved input validation. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may disclose internal states of the app.
nvdapple
Apple Safari vulnerabilities | cvebase