Apple Safari vulnerabilities
1,654 known vulnerabilities affecting apple/safari.
Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1
Vulnerabilities
Page 82 of 83
CVE-2012-0678P4MEDIUMCVSS 4.3≤ 5.1.7v1.0+75 more2012-07-25
CVE-2012-0678 [MEDIUM] CWE-79 CVE-2012-0678: Cross-site scripting (XSS) vulnerability in Apple Safari before 6.0 allows remote attackers to injec
Cross-site scripting (XSS) vulnerability in Apple Safari before 6.0 allows remote attackers to inject arbitrary web script or HTML via a feed:// URL.
nvd
CVE-2010-1940P4MEDIUMCVSS 4.3v4.0.52010-05-14
CVE-2010-1940 [MEDIUM] CWE-255 CVE-2010-1940: Apple Safari 4.0.5 on Windows sends the "Authorization: Basic" header appropriate for one web site t
Apple Safari 4.0.5 on Windows sends the "Authorization: Basic" header appropriate for one web site to a different web site named in a Location header received from the first site, which allows remote web servers to obtain sensitive information by logging HTTP requests. NOTE: the provenance of this information is unknown; the details are obtained solel
nvd
CVE-2016-4751P4LOWCVSS 3.5≤ 9.1.32016-09-25
CVE-2016-4751 [LOW] CWE-254 CVE-2016-4751: The Safari Tabs component in Apple Safari before 10 allows remote attackers to spoof the address bar
The Safari Tabs component in Apple Safari before 10 allows remote attackers to spoof the address bar of a tab via a crafted web site.
nvdapple
CVE-2006-1988P4MEDIUMCVSS 5.0v2.0v2.0.1+2 more2006-04-21
CVE-2006-1988 [MEDIUM] CVE-2006-1988: The WebTextRenderer(WebInternal) _CG_drawRun:style:geometry: function in Apple Safari 2.0.3 allows r
The WebTextRenderer(WebInternal) _CG_drawRun:style:geometry: function in Apple Safari 2.0.3 allows remote attackers to cause a denial of service (application crash) via an HTML LI tag with a large VALUE attribute (list item number), which triggers a null dereference in QPainter::drawText, probably due to a failed memory allocation that uses the VALUE.
nvd
CVE-2005-0341P4MEDIUMCVSS 4.3v1.2.42005-05-02
CVE-2005-0341 [MEDIUM] CVE-2005-0341: Apple Safari 1.2.4 does not obey the Content-type field in the HTTP header and renders text as HTML,
Apple Safari 1.2.4 does not obey the Content-type field in the HTTP header and renders text as HTML, which allows remote attackers to inject arbitrary web script or HTML and perform cross-site scripting (XSS) attacks.
nvd
CVE-2012-3694P4MEDIUMCVSS 4.3≤ 5.1.7v1.0+75 more2012-07-25
CVE-2012-3694 [MEDIUM] CWE-200 CVE-2012-3694: WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-a
WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-assisted remote attackers to obtain sensitive information about full pathnames via a crafted web site.
nvd
CVE-2007-6592P4MEDIUMCVSS 4.3v22007-12-28
CVE-2007-6592 [MEDIUM] CVE-2007-6592: Apple Safari 2, when a user accepts an SSL server certificate on the basis of the CN domain name in
Apple Safari 2, when a user accepts an SSL server certificate on the basis of the CN domain name in the DN field, regards the certificate as also accepted for all domain names in subjectAltName:dNSName fields, which makes it easier for remote attackers to trick a user into accepting an invalid certificate for a spoofed web site.
nvd
CVE-2016-4583P4LOWCVSS 3.1v9.1.22016-07-18
CVE-2016-4583 [LOW] CVE-2016-4583: Safari 9.1.2
Apple Security Update: About the security content of Safari 9.1.2
Product: Safari
Version: 9.1.2
CVE: CVE-2016-4583
Component: WebKit
Impact: Visiting a malicious website may disclose image data from another website
Description: A timing issue existed in the processing of SVG. This issue was addressed through improved validation.
apple
CVE-2006-3224P4MEDIUMCVSS 5.4v2.0.3_417.9.32006-06-26
CVE-2006-3224 [MEDIUM] CVE-2006-3224: Apple Safari 2.0.3 (417.9.3) on Mac OS X 10.4.6 allows remote attackers to cause a denial of service
Apple Safari 2.0.3 (417.9.3) on Mac OS X 10.4.6 allows remote attackers to cause a denial of service (CPU consumption) via Javascript with an infinite for loop. NOTE: it could be argued that this is not a vulnerability, unless it interferes with the operation of the system outside of the scope of Safari itself.
nvd
CVE-2004-1199P4MEDIUMCVSS 5.0v1.0v1.1+5 more2005-01-10
CVE-2004-1199 [MEDIUM] CVE-2004-1199: Safari 1.2.4 on Mac OS X 10.3.6 allows remote attackers to cause a denial of service (application cr
Safari 1.2.4 on Mac OS X 10.3.6 allows remote attackers to cause a denial of service (application crash from memory exhaustion), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.
nvd
CVE-2009-3016P4MEDIUMCVSS 4.3v4.0.32009-08-31
CVE-2009-3016 [MEDIUM] CWE-79 CVE-2009-3016: Apple Safari 4.0.3 does not properly block javascript: and data: URIs in Refresh headers in HTTP res
Apple Safari 4.0.3 does not properly block javascript: and data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains a javascript: URI, (2) entering a javascript: URI when specifying the content of a Refresh header, (3)
nvd
CVE-2003-0355P4MEDIUMCVSS 5.0v1.02003-06-09
CVE-2003-0355 [MEDIUM] CVE-2003-0355: Safari 1.0 Beta 2 (v73) and earlier does not validate the Common Name (CN) field for X.509 Certifica
Safari 1.0 Beta 2 (v73) and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates.
nvd
CVE-2008-2001P4MEDIUMCVSS 4.3v3.1.12008-04-28
CVE-2008-2001 [MEDIUM] CWE-119 CVE-2008-2001: Apple Safari 3.1.1 allows remote attackers to cause a denial of service (application crash) via a fi
Apple Safari 3.1.1 allows remote attackers to cause a denial of service (application crash) via a file:///%E2 link that triggers an out-of-bounds access, possibly due to a NULL pointer dereference.
nvd
CVE-2009-1710P4LOWCVSS 2.6≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1710 [LOW] CVE-2009-1710: WebKit in Apple Safari before 4.0 allows remote attackers to spoof the browser's display of (1) the
WebKit in Apple Safari before 4.0 allows remote attackers to spoof the browser's display of (1) the host name, (2) security indicators, and unspecified other UI elements via a custom cursor in conjunction with a modified CSS3 hotspot property.
nvd
CVE-2020-3894P4LOWCVSS 3.1fixed in 13.1≥ unspecified, < Safari 13.12020-04-01
CVE-2020-3894 [LOW] CWE-362 CVE-2020-3894: A race condition was addressed with additional validation. This issue is fixed in iOS 13.4 and iPadO
A race condition was addressed with additional validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. An application may be able to read restricted memory.
nvd
CVE-2025-43531P4LOWCVSS 3.1fixed in 26.22025-12-17
CVE-2025-43531 [LOW] CWE-362 CVE-2025-43531: A race condition was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS
A race condition was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2008-2000P4MEDIUMCVSS 4.3v3.1.12008-04-28
CVE-2008-2000 [MEDIUM] CWE-399 CVE-2008-2000: Unspecified vulnerability in Apple Safari 3.1.1 allows remote attackers to cause a denial of service
Unspecified vulnerability in Apple Safari 3.1.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls document.write in an infinite loop.
nvd
CVE-2024-23211P4LOWCVSS 3.3fixed in 17.32024-01-23
CVE-2024-23211 [LOW] CWE-359 CVE-2024-23211: A privacy issue was addressed with improved handling of user preferences. This issue is fixed in Saf
A privacy issue was addressed with improved handling of user preferences. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, watchOS 10.3. A user's private browsing activity may be visible in Settings.
nvdapple
CVE-2010-1796P4LOWCVSS 2.6≤ 5.0v4.0+7 more2010-07-30
CVE-2010-1796 [LOW] CWE-200 CVE-2010-1796: The AutoFill feature in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and bef
The AutoFill feature in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4, allows remote attackers to obtain sensitive Address Book Card information via JavaScript code that forces keystroke events for input fields.
nvd
CVE-2008-1005P4LOWCVSS 2.1v0.8v0.9+14 more2008-03-19
CVE-2008-1005 [LOW] CWE-200 CVE-2008-1005: WebCore, as used in Apple Safari before 3.1, does not properly mask the password field when reverse
WebCore, as used in Apple Safari before 3.1, does not properly mask the password field when reverse conversion is used with the Kotoeri input method, which allows physically proximate attackers to read the password.
nvd