cbcvebase.

Apple Safari vulnerabilities

1,654 known vulnerabilities affecting apple/safari.

Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1

Vulnerabilities

Page 81 of 83
CVE-2003-0975P4MEDIUMCVSS 5.0v1.0v1.12003-12-15
CVE-2003-0975 [MEDIUM] CVE-2003-0975: Apple Safari 1.0 through 1.1 on Mac OS X 10.3.1 and Mac OS X 10.2.8 allows remote attackers to steal Apple Safari 1.0 through 1.1 on Mac OS X 10.3.1 and Mac OS X 10.2.8 allows remote attackers to steal user cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.
nvd
CVE-2007-3758P4MEDIUMCVSS 4.3≤ 3.0.32007-09-27
CVE-2007-3758 [MEDIUM] CWE-79 CVE-2007-3758: Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and in Mac OS X 10.4 Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and in Mac OS X 10.4 through 10.4.10, allows remote attackers to set Javascript window properties for web pages that are in a different domain, which can be leveraged to conduct cross-site scripting (XSS) attacks.
nvd
CVE-2008-1007P4MEDIUMCVSS 4.3≤ 3.0.4v0.8+14 more2008-03-19
CVE-2008-1007 [MEDIUM] CWE-79 CVE-2008-1007: WebCore, as used in Apple Safari before 3.1, does not enforce the frame navigation policy for Java a WebCore, as used in Apple Safari before 3.1, does not enforce the frame navigation policy for Java applets, which allows remote attackers to conduct cross-site scripting (XSS) attacks.
nvd
CVE-2005-4678P4MEDIUMCVSS 5.0v2.0.22005-12-31
CVE-2005-4678 [MEDIUM] CVE-2005-4678: Apple Safari 2.0.2 (aka 416.12) allows remote attackers to spoof the URL in the status bar via the t Apple Safari 2.0.2 (aka 416.12) allows remote attackers to spoof the URL in the status bar via the title in an image in a link to a trusted site within a form to the malicious site. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
nvd
CVE-2007-3756P4MEDIUMCVSS 4.3≤ 3.0.32007-09-27
CVE-2007-3756 [MEDIUM] CWE-200 CVE-2007-3756: Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 thr Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows remote attackers to obtain sensitive information via a crafted web page that identifies the URL of the parent window, even when the parent window is in a different domain.
nvd
CVE-2008-1009P4MEDIUMCVSS 4.3v0.8v0.9+14 more2008-03-19
CVE-2008-1009 [MEDIUM] CWE-79 CVE-2008-1009: Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remo Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary JavaScript by modifying the history object.
nvd
CVE-2008-1003P4MEDIUMCVSS 4.3v0.8v0.9+14 more2008-03-19
CVE-2008-1003 [MEDIUM] CWE-79 CVE-2008-1003: Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remo Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to sites that set the document.domain property or have the same document.domain.
nvd
CVE-2008-1001P4MEDIUMCVSS 4.3v3.0v3.0.1+3 more2008-03-19
CVE-2008-1001 [MEDIUM] CWE-79 CVE-2008-1001: Cross-site scripting (XSS) vulnerability in Apple Safari before 3.1, when running on Windows XP or V Cross-site scripting (XSS) vulnerability in Apple Safari before 3.1, when running on Windows XP or Vista, allows remote attackers to inject arbitrary web script or HTML via a crafted URL that is not properly handled in the error page.
nvd
CVE-2012-3695P4MEDIUMCVSS 4.3≤ 5.1.7v1.0+75 more2012-07-25
CVE-2012-3695 [MEDIUM] CWE-79 CVE-2012-3695: Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 6.0 allows remote attacker Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 6.0 allows remote attackers to inject arbitrary web script or HTML by leveraging improper URL canonicalization during the handling of the location.href property.
nvd
CVE-2011-0217P4MEDIUMCVSS 4.3≤ 5.0.5v1.0+54 more2011-07-21
CVE-2011-0217 [MEDIUM] CWE-200 CVE-2011-0217: Apple Safari before 5.0.6 provides AutoFill information to scripts that execute before HTML form sub Apple Safari before 5.0.6 provides AutoFill information to scripts that execute before HTML form submission, which allows remote attackers to obtain Address Book information via a crafted form, as demonstrated by a form that includes non-visible fields.
nvd
CVE-2012-3650P4MEDIUMCVSS 4.3≤ 5.1.7v1.0+75 more2012-07-25
CVE-2012-3650 [MEDIUM] CWE-200 CVE-2012-3650: WebKit in Apple Safari before 6.0 accesses uninitialized memory locations during the rendering of SV WebKit in Apple Safari before 6.0 accesses uninitialized memory locations during the rendering of SVG images, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.
nvd
CVE-2011-3844P4MEDIUMCVSS 4.3v5.0.52012-03-08
CVE-2011-3844 [MEDIUM] CWE-20 CVE-2011-3844: Apple Safari 5.0.5 does not properly implement the setInterval function, which allows remote attacke Apple Safari 5.0.5 does not properly implement the setInterval function, which allows remote attackers to spoof the address bar via a crafted web page.
nvd
CVE-2010-4008P4MEDIUMCVSS 4.3fixed in 5.0.42010-11-17
CVE-2010-4008 [MEDIUM] CWE-119 CVE-2010-4008: libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, an libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.
nvd
CVE-2010-0925P4MEDIUMCVSS 5.0v4.0.42010-03-03
CVE-2010-0925 [MEDIUM] CVE-2010-0925: cfnetwork.dll 1.450.5.0 in CFNetwork, as used by safari.exe 531.21.10 in Apple Safari 4.0.4 on Windo cfnetwork.dll 1.450.5.0 in CFNetwork, as used by safari.exe 531.21.10 in Apple Safari 4.0.4 on Windows, allows remote attackers to cause a denial of service (application crash) via a long string in the SRC attribute of a (1) IMG or (2) IFRAME element.
nvd
CVE-2010-0924P4MEDIUMCVSS 5.0v4.0.3v4.0.42010-03-03
CVE-2010-0924 [MEDIUM] CVE-2010-0924: cfnetwork.dll 1.450.5.0 in CFNetwork, as used by safari.exe 531.21.10 in Apple Safari 4.0.3 and 4.0. cfnetwork.dll 1.450.5.0 in CFNetwork, as used by safari.exe 531.21.10 in Apple Safari 4.0.3 and 4.0.4 on Windows, allows remote attackers to cause a denial of service (application crash) via a long string in the BACKGROUND attribute of a BODY element.
nvd
CVE-2007-2400P4MEDIUMCVSS 4.3v3.0v3.0.12007-06-25
CVE-2007-2400 [MEDIUM] CWE-79 CVE-2007-2400: Race condition in Apple Safari 3 Beta before 3.0.2 on Mac OS X, Windows XP, Windows Vista, and iPhon Race condition in Apple Safari 3 Beta before 3.0.2 on Mac OS X, Windows XP, Windows Vista, and iPhone before 1.0.1, allows remote attackers to bypass the JavaScript security model and modify pages outside of the security domain and conduct cross-site scripting (XSS) attacks via vectors related to page updating and HTTP redirects.
nvd
CVE-2007-4698P4MEDIUMCVSS 4.3≤ 3.0.32007-11-15
CVE-2007-4698 [MEDIUM] CWE-79 CVE-2007-4698: Apple Safari 3 before Beta Update 3.0.4 on Windows, and Mac OS X 10.4 through 10.4.10, allows remote Apple Safari 3 before Beta Update 3.0.4 on Windows, and Mac OS X 10.4 through 10.4.10, allows remote attackers to conduct cross-site scripting (XSS) attacks by causing JavaScript events to be associated with the wrong frame.
nvd
CVE-2011-3027P4MEDIUMCVSS 4.3fixed in 6.02012-02-16
CVE-2011-3027 [MEDIUM] CWE-704 CVE-2011-3027: Google Chrome before 17.0.963.56 does not properly perform a cast of an unspecified variable during Google Chrome before 17.0.963.56 does not properly perform a cast of an unspecified variable during handling of columns, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.
nvd
CVE-2011-2800P4MEDIUMCVSS 4.3fixed in 5.1.12011-08-03
CVE-2011-2800 [MEDIUM] CWE-200 CVE-2011-2800: Google Chrome before 13.0.782.107 allows remote attackers to obtain potentially sensitive informatio Google Chrome before 13.0.782.107 allows remote attackers to obtain potentially sensitive information about client-side redirect targets via a crafted web site.
nvd
CVE-2007-2391P4MEDIUMCVSS 4.3v3.0.12007-06-14
CVE-2007-2391 [MEDIUM] CWE-79 CVE-2007-2391: Cross-site scripting (XSS) vulnerability in Apple Safari Beta 3.0.1 for Windows allows remote attack Cross-site scripting (XSS) vulnerability in Apple Safari Beta 3.0.1 for Windows allows remote attackers to inject arbitrary web script or HTML via a web page that includes a windows.setTimeout function that is activated after the user has moved from the current page.
nvd
Apple Safari vulnerabilities | cvebase