cbcvebase.

Apple Safari vulnerabilities

1,677 known vulnerabilities affecting apple/safari.

Total CVEs
1,677
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
52
Severity breakdown
CRITICAL211HIGH628MEDIUM815LOW22UNKNOWN1

Vulnerabilities

Page 83 of 84
CVE-2012-0678P4MEDIUMCVSS 4.3≤ 5.1.7v1.0+75 more2012-07-25
CVE-2012-0678 [MEDIUM] CWE-79 CVE-2012-0678: Cross-site scripting (XSS) vulnerability in Apple Safari before 6.0 allows remote attackers to injec Cross-site scripting (XSS) vulnerability in Apple Safari before 6.0 allows remote attackers to inject arbitrary web script or HTML via a feed:// URL.
nvd
CVE-2010-1940P4MEDIUMCVSS 4.3v4.0.52010-05-14
CVE-2010-1940 [MEDIUM] CWE-255 CVE-2010-1940: Apple Safari 4.0.5 on Windows sends the "Authorization: Basic" header appropriate for one web site t Apple Safari 4.0.5 on Windows sends the "Authorization: Basic" header appropriate for one web site to a different web site named in a Location header received from the first site, which allows remote web servers to obtain sensitive information by logging HTTP requests. NOTE: the provenance of this information is unknown; the details are obtained solel
nvd
CVE-2016-4751P4LOWCVSS 3.5≤ 9.1.32016-09-25
CVE-2016-4751 [LOW] CWE-254 CVE-2016-4751: The Safari Tabs component in Apple Safari before 10 allows remote attackers to spoof the address bar The Safari Tabs component in Apple Safari before 10 allows remote attackers to spoof the address bar of a tab via a crafted web site.
nvdapple
CVE-2006-1988P4MEDIUMCVSS 5.0v2.0v2.0.1+2 more2006-04-21
CVE-2006-1988 [MEDIUM] CVE-2006-1988: The WebTextRenderer(WebInternal) _CG_drawRun:style:geometry: function in Apple Safari 2.0.3 allows r The WebTextRenderer(WebInternal) _CG_drawRun:style:geometry: function in Apple Safari 2.0.3 allows remote attackers to cause a denial of service (application crash) via an HTML LI tag with a large VALUE attribute (list item number), which triggers a null dereference in QPainter::drawText, probably due to a failed memory allocation that uses the VALUE.
nvd
CVE-2010-4008P4MEDIUMCVSS 4.3fixed in 5.0.42010-11-17
CVE-2010-4008 [MEDIUM] CWE-119 CVE-2010-4008: libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, an libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.
nvd
CVE-2012-3694P4MEDIUMCVSS 4.3≤ 5.1.7v1.0+75 more2012-07-25
CVE-2012-3694 [MEDIUM] CWE-200 CVE-2012-3694: WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-a WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-assisted remote attackers to obtain sensitive information about full pathnames via a crafted web site.
nvd
CVE-2007-6592P4MEDIUMCVSS 4.3v22007-12-28
CVE-2007-6592 [MEDIUM] CVE-2007-6592: Apple Safari 2, when a user accepts an SSL server certificate on the basis of the CN domain name in Apple Safari 2, when a user accepts an SSL server certificate on the basis of the CN domain name in the DN field, regards the certificate as also accepted for all domain names in subjectAltName:dNSName fields, which makes it easier for remote attackers to trick a user into accepting an invalid certificate for a spoofed web site.
nvd
CVE-2016-4583P4LOWCVSS 3.1v9.1.22016-07-18
CVE-2016-4583 [LOW] CVE-2016-4583: Safari 9.1.2 Apple Security Update: About the security content of Safari 9.1.2 Product: Safari Version: 9.1.2 CVE: CVE-2016-4583 Component: WebKit Impact: Visiting a malicious website may disclose image data from another website Description: A timing issue existed in the processing of SVG. This issue was addressed through improved validation.
apple
CVE-2006-3224P4MEDIUMCVSS 5.4v2.0.3_417.9.32006-06-26
CVE-2006-3224 [MEDIUM] CVE-2006-3224: Apple Safari 2.0.3 (417.9.3) on Mac OS X 10.4.6 allows remote attackers to cause a denial of service Apple Safari 2.0.3 (417.9.3) on Mac OS X 10.4.6 allows remote attackers to cause a denial of service (CPU consumption) via Javascript with an infinite for loop. NOTE: it could be argued that this is not a vulnerability, unless it interferes with the operation of the system outside of the scope of Safari itself.
nvd
CVE-2004-1199P4MEDIUMCVSS 5.0v1.0v1.1+5 more2005-01-10
CVE-2004-1199 [MEDIUM] CVE-2004-1199: Safari 1.2.4 on Mac OS X 10.3.6 allows remote attackers to cause a denial of service (application cr Safari 1.2.4 on Mac OS X 10.3.6 allows remote attackers to cause a denial of service (application crash from memory exhaustion), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.
nvd
CVE-2005-0341P4MEDIUMCVSS 4.3v1.2.42005-05-02
CVE-2005-0341 [MEDIUM] CVE-2005-0341: Apple Safari 1.2.4 does not obey the Content-type field in the HTTP header and renders text as HTML, Apple Safari 1.2.4 does not obey the Content-type field in the HTTP header and renders text as HTML, which allows remote attackers to inject arbitrary web script or HTML and perform cross-site scripting (XSS) attacks.
nvd
CVE-2003-0355P4MEDIUMCVSS 5.0v1.02003-06-09
CVE-2003-0355 [MEDIUM] CVE-2003-0355: Safari 1.0 Beta 2 (v73) and earlier does not validate the Common Name (CN) field for X.509 Certifica Safari 1.0 Beta 2 (v73) and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates.
nvd
CVE-2008-2001P4MEDIUMCVSS 4.3v3.1.12008-04-28
CVE-2008-2001 [MEDIUM] CWE-119 CVE-2008-2001: Apple Safari 3.1.1 allows remote attackers to cause a denial of service (application crash) via a fi Apple Safari 3.1.1 allows remote attackers to cause a denial of service (application crash) via a file:///%E2 link that triggers an out-of-bounds access, possibly due to a NULL pointer dereference.
nvd
CVE-2009-3016P4MEDIUMCVSS 4.3v4.0.32009-08-31
CVE-2009-3016 [MEDIUM] CWE-79 CVE-2009-3016: Apple Safari 4.0.3 does not properly block javascript: and data: URIs in Refresh headers in HTTP res Apple Safari 4.0.3 does not properly block javascript: and data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains a javascript: URI, (2) entering a javascript: URI when specifying the content of a Refresh header, (3)
nvd
CVE-2009-1710P4LOWCVSS 2.6≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1710 [LOW] CVE-2009-1710: WebKit in Apple Safari before 4.0 allows remote attackers to spoof the browser's display of (1) the WebKit in Apple Safari before 4.0 allows remote attackers to spoof the browser's display of (1) the host name, (2) security indicators, and unspecified other UI elements via a custom cursor in conjunction with a modified CSS3 hotspot property.
nvd
CVE-2020-3894P4LOWCVSS 3.1fixed in 13.1≥ unspecified, < Safari 13.12020-04-01
CVE-2020-3894 [LOW] CWE-362 CVE-2020-3894: A race condition was addressed with additional validation. This issue is fixed in iOS 13.4 and iPadO A race condition was addressed with additional validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. An application may be able to read restricted memory.
nvd
CVE-2025-43531P4LOWCVSS 3.1fixed in 26.22025-12-17
CVE-2025-43531 [LOW] CWE-362 CVE-2025-43531: A race condition was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS A race condition was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2026-64779P4LOWCVSS 3.1fixed in 26.6.12026-08-17
CVE-2026-64779 [LOW] CWE-362 CVE-2026-64779: A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2026-64782P4LOWCVSS 3.1fixed in 26.6.12026-08-17
CVE-2026-64782 [LOW] CWE-362 CVE-2026-64782: A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2008-2000P4MEDIUMCVSS 4.3v3.1.12008-04-28
CVE-2008-2000 [MEDIUM] CWE-399 CVE-2008-2000: Unspecified vulnerability in Apple Safari 3.1.1 allows remote attackers to cause a denial of service Unspecified vulnerability in Apple Safari 3.1.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls document.write in an infinite loop.
nvd
Apple Safari vulnerabilities | cvebase