cbcvebase.

Apple Safari vulnerabilities

1,654 known vulnerabilities affecting apple/safari.

Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH622MEDIUM790LOW20UNKNOWN11

Vulnerabilities

Page 8 of 83
CVE-2011-0222P3CRITICALCVSS 9.3PoC≤ 5.0.5v1.0+54 more2011-07-21
CVE-2011-0222 [CRITICAL] CWE-119 CVE-2011-0222: WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or c WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.
nvd
CVE-2009-2195P3CRITICALCVSS 9.3PoC≤ 4.0.2v0.8+58 more2009-08-12
CVE-2009-2195 [CRITICAL] CWE-119 CVE-2009-2195: Buffer overflow in WebKit in Apple Safari before 4.0.3 allows remote attackers to execute arbitrary Buffer overflow in WebKit in Apple Safari before 4.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted floating-point numbers.
nvd
CVE-2010-0050P3HIGHCVSS 8.8PoCfixed in 4.0.52010-03-15
CVE-2010-0050 [HIGH] CWE-416 CVE-2010-0050: Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execu Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an HTML document with improperly nested tags.
nvd
CVE-2010-1759P3CRITICALCVSS 9.3PoC≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1759 [CRITICAL] CWE-399 CVE-2010-1759: Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the Node.normalize method.
nvd
CVE-2017-2447P3HIGHCVSS 8.1PoC≤ 10.0.32017-04-02
CVE-2017-2447 [HIGH] CWE-119 CVE-2017-2447: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted web site.
nvdapple
CVE-2007-3186P3CRITICALCVSS 9.3PoCv2.0v2.0.1+5 more2007-06-12
CVE-2007-3186 [CRITICAL] CWE-264 CVE-2007-3186: Apple Safari Beta 3.0.1 for Windows allows remote attackers to execute arbitrary commands via shell Apple Safari Beta 3.0.1 for Windows allows remote attackers to execute arbitrary commands via shell metacharacters in a URI in the SRC of an IFRAME, as demonstrated using a gopher URI.
nvd
CVE-2022-42867P2HIGHCVSS 8.8fixed in 16.22022-12-15
CVE-2022-42867 [HIGH] CWE-416 CVE-2022-42867: A use after free issue was addressed with improved memory management. This issue is fixed in Safari A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2010-1939P3HIGHCVSS 7.6PoCv4.0.52010-05-13
CVE-2010-1939 [HIGH] CWE-399 CVE-2010-1939: Use-after-free vulnerability in Apple Safari 4.0.5 on Windows allows remote attackers to execute arb Use-after-free vulnerability in Apple Safari 4.0.5 on Windows allows remote attackers to execute arbitrary code by using window.open to create a popup window for a crafted HTML document, and then calling the parent window's close method, which triggers improper handling of a deleted window object.
nvd
CVE-2017-2365P3MEDIUMCVSS 6.5PoCfixed in 10.0.32017-02-20
CVE-2017-2365 [MEDIUM] CWE-200 CVE-2017-2365: An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0 An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
nvdapple
CVE-2017-2363P3MEDIUMCVSS 6.5PoCfixed in 10.0.32017-02-20
CVE-2017-2363 [MEDIUM] CWE-200 CVE-2017-2363: An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0 An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
nvdapple
CVE-2010-0049P3CRITICALCVSS 9.3PoC≤ 4.0.4v4.0+4 more2010-03-15
CVE-2010-0049 [CRITICAL] CWE-399 CVE-2010-0049: Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execu Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via HTML elements with right-to-left (RTL) text directionality.
nvd
CVE-2010-0046P3CRITICALCVSS 9.3PoC≤ 4.0.4v4.0+4 more2010-03-15
CVE-2010-0046 [CRITICAL] CWE-94 CVE-2010-0046: The Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 4.0.5 allows remote The Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted format arguments.
nvd
CVE-2017-2364P3MEDIUMCVSS 6.5PoC≤ 10.0.22017-02-20
CVE-2017-2364 [MEDIUM] CWE-200 CVE-2017-2364: An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0 An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
nvdapple
CVE-2017-2367P3MEDIUMCVSS 6.5PoC≤ 10.0.32017-04-02
CVE-2017-2367 [MEDIUM] CVE-2017-2367: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
nvdapple
CVE-2017-2479P3MEDIUMCVSS 6.5PoCfixed in 10.12017-04-02
CVE-2017-2479 [MEDIUM] CWE-20 CVE-2017-2479: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affected. iTunes before 12.6 on Windows is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive inf
nvdapple
CVE-2017-7089P3MEDIUMCVSS 6.1PoC≤ 10.1.22017-10-23
CVE-2017-7089 [MEDIUM] CWE-79 CVE-2017-7089: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that is mishandled during parent-tab processing.
nvdapple
CVE-2017-2442P3MEDIUMCVSS 6.5PoC≤ 10.0.32017-04-02
CVE-2017-2442 [MEDIUM] CWE-20 CVE-2017-2442: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit JavaScript Bindings" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
nvdapple
CVE-2017-2480P3MEDIUMCVSS 6.5PoC≤ 10.0.32017-04-02
CVE-2017-2480 [MEDIUM] CWE-200 CVE-2017-2480: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affected. iTunes before 12.6 on Windows is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive in
nvdapple
CVE-2019-8649P3MEDIUMCVSS 6.1PoCfixed in 12.1.2≥ unspecified, < Safari 12.1.22019-12-18
CVE-2019-8649 [MEDIUM] CWE-79 CVE-2019-8649: A logic issue existed in the handling of synchronous page loads. This issue was addressed with impro A logic issue existed in the handling of synchronous page loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to universal cross sit
nvdapple
CVE-2019-8690P3MEDIUMCVSS 6.1PoCfixed in 12.1.2≥ unspecified, < Safari 12.1.22019-12-18
CVE-2019-8690 [MEDIUM] CWE-79 CVE-2019-8690: A logic issue existed in the handling of document loads. This issue was addressed with improved stat A logic issue existed in the handling of document loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to universal cross site script
nvdapple
Apple Safari vulnerabilities | cvebase