Apple Safari vulnerabilities
1,654 known vulnerabilities affecting apple/safari.
Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1
Vulnerabilities
Page 83 of 83
CVE-2005-1385P4LOWCVSS 2.6v1.32005-05-03
CVE-2005-1385 [LOW] CVE-2005-1385: Safari 1.3 allows remote attackers to cause a denial of service (application crash) via a long https
Safari 1.3 allows remote attackers to cause a denial of service (application crash) via a long https URL that triggers a NULL pointer dereference.
nvd
CVE-2026-20656P4LOWCVSS 3.3fixed in 26.32026-02-11
CVE-2026-20656 [LOW] CWE-285 CVE-2026-20656: A logic issue was addressed with improved validation. This issue is fixed in Safari 26.3, iOS 18.7.5
A logic issue was addressed with improved validation. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, macOS Tahoe 26.3. An app may be able to access a user's Safari history.
nvdapple
CVE-2020-9912P4LOWCVSS 3.3fixed in 13.1.2≥ unspecified, < Safari 13.1.22020-10-16
CVE-2020-9912 [LOW] CVE-2020-9912: A logic issue was addressed with improved restrictions. This issue is fixed in Safari 13.1.2. A mali
A logic issue was addressed with improved restrictions. This issue is fixed in Safari 13.1.2. A malicious attacker may be able to change the origin of a frame for a download in Safari Reader mode.
nvdapple
CVE-2015-5748P4LOWCVSS 2.1≤ 8.0.82015-08-17
CVE-2015-5748 [LOW] CWE-17 CVE-2015-5748: The kernel in Apple OS X before 10.10.5 does not properly mount HFS volumes, which allows local user
The kernel in Apple OS X before 10.10.5 does not properly mount HFS volumes, which allows local users to cause a denial of service via a crafted volume.
nvd
CVE-2016-1849P4LOWCVSS 3.3≤ 9.12016-05-20
CVE-2016-1849 [LOW] CWE-200 CVE-2016-1849: The "Clear History and Website Data" feature in Apple Safari before 9.1.1, as used in iOS before 9.3
The "Clear History and Website Data" feature in Apple Safari before 9.1.1, as used in iOS before 9.3.2 and other products, mishandles the deletion of browsing history, which might allow local users to obtain sensitive information by leveraging read access to a Safari directory.
nvdapple
CVE-2005-2272P4LOWCVSS 2.6v2.02005-07-13
CVE-2005-2272 [LOW] CVE-2005-2272: Safari version 2.0 (412) does not clearly associate a Javascript dialog box with the web page that g
Safari version 2.0 (412) does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."
nvd
CVE-2011-0169P4LOWCVSS 2.6≤ 5.0.3v1.0+52 more2011-03-11
CVE-2011-0169 [LOW] CWE-79 CVE-2011-0169: WebKit in Apple Safari before 5.0.4, when the Web Inspector is used, does not properly handle the wi
WebKit in Apple Safari before 5.0.4, when the Web Inspector is used, does not properly handle the window.console._inspectorCommandLineAPI property, which allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted web site.
nvd
CVE-2007-3274P4MEDIUMCVSS 4.3v3.0v3.0.12007-06-19
CVE-2007-3274 [MEDIUM] CWE-399 CVE-2007-3274: Apple Safari 3.0 and 3.0.1 on Windows XP SP2 allows attackers to cause a denial of service (applicat
Apple Safari 3.0 and 3.0.1 on Windows XP SP2 allows attackers to cause a denial of service (application crash) via JavaScript that sets the document.location variable, as demonstrated by an empty value of document.location.
nvd
CVE-2013-7127P4LOWCVSS 2.1v6.0.52013-12-17
CVE-2013-7127 [LOW] CWE-310 CVE-2013-7127: Apple Safari 6.0.5 on Mac OS X 10.7.5 and 10.8.5 stores cleartext credentials in LastSession.plist,
Apple Safari 6.0.5 on Mac OS X 10.7.5 and 10.8.5 stores cleartext credentials in LastSession.plist, which allows local users to obtain sensitive information by reading this file.
nvd
CVE-2009-1707P4LOWCVSS 1.2≤ 3.2.3v3.0+10 more2009-06-10
CVE-2009-1707 [LOW] CWE-362 CVE-2009-1707: Race condition in the Reset Safari implementation in Apple Safari before 4.0 on Windows might allow
Race condition in the Reset Safari implementation in Apple Safari before 4.0 on Windows might allow local users to read stored web-site passwords via unspecified vectors.
nvd
CVE-2015-1127P4LOWCVSS 2.1≤ 6.2.4v7.0+16 more2015-04-10
CVE-2015-1127 [LOW] CWE-200 CVE-2015-1127: The private-browsing implementation in WebKit in Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.
The private-browsing implementation in WebKit in Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 places browsing history into an index, which might allow local users to obtain sensitive information by reading index entries.
nvd
CVE-2008-3644P4LOWCVSS 1.9≤ 3.1.2v0.8+32 more2008-11-17
CVE-2008-3644 [LOW] CWE-200 CVE-2008-3644: Apple Safari before 3.2 does not properly prevent caching of form data for form fields that have aut
Apple Safari before 3.2 does not properly prevent caching of form data for form fields that have autocomplete disabled, which allows local users to obtain sensitive information by reading the browser's page cache.
nvd
CVE-2009-1716P4LOWCVSS 2.1≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1716 [LOW] CWE-264 CVE-2009-1716: CFNetwork in Apple Safari before 4.0 on Windows does not properly protect the temporary files create
CFNetwork in Apple Safari before 4.0 on Windows does not properly protect the temporary files created for downloads, which allows local users to obtain sensitive information by reading these files.
nvd
CVE-2016-4695UNKNOWNv10.0.22016-12-13
CVE-2016-4695 CVE-2016-4695: Safari 10.0.2
Apple Security Update: About the security content of Safari 10.0.2
Product: Safari
Version: 10.0.2
CVE: CVE-2016-4695
Component: JavaScriptCore
Impact: A script executing in a JavaScript sandbox may be able to access state outside that sandbox
Description: A validation issue existed in processing JavaScript. This issue was addressed through improved validation.
apple
← Previous83 / 83