cbcvebase.

Apple Safari vulnerabilities

1,654 known vulnerabilities affecting apple/safari.

Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1

Vulnerabilities

Page 80 of 83
CVE-2005-2524P4MEDIUMCVSS 5.0v2.02005-10-26
CVE-2005-2524 [MEDIUM] CVE-2005-2524: Safari after 2.0 in Apple Mac OS X 10.3.9 allows remote attackers to bypass domain restrictions via Safari after 2.0 in Apple Mac OS X 10.3.9 allows remote attackers to bypass domain restrictions via crafted web archives that cause Safari to render them as if they came from a different site.
nvd
CVE-2010-0051P4MEDIUMCVSS 4.3≤ 4.0.4v4.0+4 more2010-03-15
CVE-2010-0051 [MEDIUM] CWE-20 CVE-2010-0051: WebKit in Apple Safari before 4.0.5 does not properly validate the cross-origin loading of styleshee WebKit in Apple Safari before 4.0.5 does not properly validate the cross-origin loading of stylesheets, which allows remote attackers to obtain sensitive information via a crafted HTML document. NOTE: this might overlap CVE-2010-0651.
nvd
CVE-2009-1714P4MEDIUMCVSS 4.3≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1714 [MEDIUM] CWE-79 CVE-2009-1714: Cross-site scripting (XSS) vulnerability in Web Inspector in WebKit in Apple Safari before 4.0 allow Cross-site scripting (XSS) vulnerability in Web Inspector in WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to inject arbitrary web script or HTML, and read local files, via vectors related to the improper escaping of HTML attributes.
nvd
CVE-2008-1011P4MEDIUMCVSS 4.3v0.8v0.9+14 more2008-03-19
CVE-2008-1011 [MEDIUM] CWE-79 CVE-2008-1011: Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple Safari before 3.1, allows remot Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML via a frame that calls a method instance in another frame.
nvd
CVE-2008-1004P4MEDIUMCVSS 4.3v0.8v0.9+14 more2008-03-19
CVE-2008-1004 [MEDIUM] CWE-79 CVE-2008-1004: Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remo Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to the Web Inspector.
nvd
CVE-2008-1006P4MEDIUMCVSS 4.3v0.8v0.9+14 more2008-03-19
CVE-2008-1006 [MEDIUM] CWE-79 CVE-2008-1006: Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remo Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML by using the window.open function to change the security context of a web page.
nvd
CVE-2008-1008P4MEDIUMCVSS 4.3v0.8v0.9+14 more2008-03-19
CVE-2008-1008 [MEDIUM] CWE-79 CVE-2008-1008: Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remo Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML via the document.domain property.
nvd
CVE-2010-0651P4MEDIUMCVSS 4.3≤ 4.0.42010-02-18
CVE-2010-0651 [MEDIUM] CWE-200 CVE-2010-0651: WebKit before r52784, as used in Google Chrome before 4.0.249.78 and Apple Safari before 4.0.5, perm WebKit before r52784, as used in Google Chrome before 4.0.249.78 and Apple Safari before 4.0.5, permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers to obtain sensitive information via a crafted document.
nvd
CVE-2011-0242P4MEDIUMCVSS 4.3≤ 5.0.5v1.0+54 more2011-07-21
CVE-2011-0242 [MEDIUM] CWE-79 CVE-2011-0242: Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0.6 allows remote attack Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via vectors involving a URL that contains a username.
nvd
CVE-2010-1420P4MEDIUMCVSS 4.3≤ 5.0.5v1.0+54 more2011-07-21
CVE-2010-1420 [MEDIUM] CWE-79 CVE-2010-1420: Cross-site scripting (XSS) vulnerability in CFNetwork in Apple Safari before 5.0.6 allows remote att Cross-site scripting (XSS) vulnerability in CFNetwork in Apple Safari before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via a crafted text/plain file.
nvd
CVE-2010-0044P4MEDIUMCVSS 4.3≤ 4.0.4v4.0+4 more2010-03-15
CVE-2010-0044 [MEDIUM] CWE-16 CVE-2010-0044: PubSub in Apple Safari before 4.0.5 does not properly implement use of the Accept Cookies preference PubSub in Apple Safari before 4.0.5 does not properly implement use of the Accept Cookies preference to block cookies, which makes it easier for remote web servers to track users by setting a cookie in a (1) RSS or (2) Atom feed.
nvd
CVE-2011-1107P4MEDIUMCVSS 4.3fixed in 5.0.62011-03-01
CVE-2011-1107 [MEDIUM] CVE-2011-1107: Unspecified vulnerability in Google Chrome before 9.0.597.107 allows remote attackers to spoof the U Unspecified vulnerability in Google Chrome before 9.0.597.107 allows remote attackers to spoof the URL bar via unknown vectors.
nvd
CVE-2016-1772P4MEDIUMCVSS 4.3≤ 9.0.32016-03-24
CVE-2016-1772 [MEDIUM] CWE-200 CVE-2016-1772: The Top Sites feature in Apple Safari before 9.1 mishandles cookie storage, which makes it easier fo The Top Sites feature in Apple Safari before 9.1 mishandles cookie storage, which makes it easier for remote web servers to track users via unspecified vectors.
nvdapple
CVE-2011-2845P4MEDIUMCVSS 4.3fixed in 6.02011-10-25
CVE-2011-2845 [MEDIUM] CWE-20 CVE-2011-2845: Google Chrome before 15.0.874.102 does not properly handle history data, which allows user-assisted Google Chrome before 15.0.874.102 does not properly handle history data, which allows user-assisted remote attackers to spoof the URL bar via unspecified vectors.
nvd
CVE-2009-1682P4MEDIUMCVSS 4.3≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1682 [MEDIUM] CWE-255 CVE-2009-1682: Apple Safari before 4.0 does not properly check for revoked Extended Validation (EV) certificates, w Apple Safari before 4.0 does not properly check for revoked Extended Validation (EV) certificates, which makes it easier for remote attackers to trick a user into accepting an invalid certificate.
nvd
CVE-2014-1369P4MEDIUMCVSS 4.3≤ 6.1.4v6.0+14 more2014-07-01
CVE-2014-1369 [MEDIUM] CWE-20 CVE-2014-1369: WebKit in Apple Safari before 6.1.5 and 7.x before 7.0.5 allows user-assisted remote attackers to ac WebKit in Apple Safari before 6.1.5 and 7.x before 7.0.5 allows user-assisted remote attackers to access file: URLs by leveraging a URL drag operation that originates at a crafted web site.
nvd
CVE-2022-22654P4MEDIUMCVSS 4.3fixed in 15.4≥ unspecified, < 15.42022-03-18
CVE-2022-22654 [MEDIUM] CVE-2022-22654: A user interface issue was addressed. This issue is fixed in watchOS 8.5, Safari 15.4. Visiting a ma A user interface issue was addressed. This issue is fixed in watchOS 8.5, Safari 15.4. Visiting a malicious website may lead to address bar spoofing.
nvdapple
CVE-2025-31266P4MEDIUMCVSS 4.3fixed in 18.52025-11-21
CVE-2025-31266 [MEDIUM] CWE-451 CVE-2025-31266: A spoofing issue was addressed with improved truncation when displaying the fully qualified domain n A spoofing issue was addressed with improved truncation when displaying the fully qualified domain name. This issue is fixed in Safari 18.5, macOS Sequoia 15.5. A website may be able to spoof the domain name in the title of a pop-up window.
nvdapple
CVE-2016-9642P4MEDIUMCVSS 5.5v10.12017-03-27
CVE-2016-9642 [MEDIUM] CVE-2016-9642: Safari 10.1 Apple Security Update: About the security content of Safari 10.1 Product: Safari Version: 10.1 CVE: CVE-2016-9642 Component: WebKit Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: Multiple memory corruption issues were addressed through improved input validation.
apple
CVE-2005-0234P4MEDIUMCVSS 5.0v1.2.52005-05-02
CVE-2005-0234 [MEDIUM] CVE-2005-0234: The International Domain Name (IDN) support in Safari 1.2.5 allows remote attackers to spoof domain The International Domain Name (IDN) support in Safari 1.2.5 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.
nvd
Apple Safari vulnerabilities | cvebase