Apple Safari vulnerabilities
1,654 known vulnerabilities affecting apple/safari.
Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH622MEDIUM790LOW20UNKNOWN11
Vulnerabilities
Page 9 of 83
CVE-2017-2445P3MEDIUMCVSS 6.1PoC≤ 10.0.32017-04-02
CVE-2017-2445 [MEDIUM] CWE-79 CVE-2017-2445: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via crafted frame objects.
nvdapple
CVE-2017-2510P3MEDIUMCVSS 6.1PoC≤ 10.12017-05-22
CVE-2017-2510 [MEDIUM] CWE-79 CVE-2017-2510: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with pageshow events.
nvdapple
CVE-2017-2504P3MEDIUMCVSS 6.1PoCfixed in 10.1.12017-05-22
CVE-2017-2504 [MEDIUM] CWE-79 CVE-2017-2504: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with WebKit Editor commands.
nvdapple
CVE-2017-2508P3MEDIUMCVSS 6.1PoC≤ 10.12017-05-22
CVE-2017-2508 [MEDIUM] CWE-79 CVE-2017-2508: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with container nodes.
nvdapple
CVE-2009-4186P3CRITICALCVSS 9.3PoCv4.0.32009-12-03
CVE-2009-4186 [CRITICAL] CWE-119 CVE-2009-4186: Stack consumption vulnerability in Apple Safari 4.0.3 on Windows allows remote attackers to cause a
Stack consumption vulnerability in Apple Safari 4.0.3 on Windows allows remote attackers to cause a denial of service (application crash) via a long URI value (aka url) in the Cascading Style Sheets (CSS) background property.
nvd
CVE-2012-3748P3MEDIUMCVSS 5.1PoC≤ 6.0.1v1.0+65 more2012-11-03
CVE-2012-3748 [MEDIUM] CWE-362 CVE-2012-3748: Race condition in WebKit in Apple iOS before 6.0.1 and Safari before 6.0.2 allows remote attackers t
Race condition in WebKit in Apple iOS before 6.0.1 and Safari before 6.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving JavaScript arrays.
nvd
CVE-2017-2528P3MEDIUMCVSS 6.1PoC≤ 10.12017-05-22
CVE-2017-2528 [MEDIUM] CWE-79 CVE-2017-2528: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with cached frames.
nvdapple
CVE-2007-2843P3CRITICALCVSS 10.0PoCv2.0.42007-05-24
CVE-2007-2843 [CRITICAL] CVE-2007-2843: Cross-domain vulnerability in Apple Safari 2.0.4 allows remote attackers to access restricted inform
Cross-domain vulnerability in Apple Safari 2.0.4 allows remote attackers to access restricted information from other domains via Javascript, as demonstrated by a js script that accesses the location information of cross-domain web pages, probably involving setTimeout and timed events.
nvd
CVE-2015-1155P3MEDIUMCVSS 4.3PoC≤ 6.2.5v7.0+18 more2015-05-08
CVE-2015-1155 [MEDIUM] CWE-264 CVE-2015-1155: The history implementation in WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.
The history implementation in WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote attackers to bypass the Same Origin Policy and read arbitrary files via a crafted web site.
nvd
CVE-2016-4622P3HIGHCVSS 8.8fixed in 9.1.22016-07-22
CVE-2016-4622 [HIGH] CVE-2016-4622: WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers
WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4589, CVE-2016-4623, and CVE-2016-4624.
nvdapple
CVE-2015-1126P3MEDIUMCVSS 4.3PoC≤ 6.2.4v7.0+16 more2015-04-10
CVE-2015-1126 [MEDIUM] CWE-20 CVE-2015-1126: WebKit, as used in Apple iOS before 8.3 and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x bef
WebKit, as used in Apple iOS before 8.3 and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, does not properly handle the userinfo field in FTP URLs, which allows remote attackers to trigger incorrect resource access via unspecified vectors.
nvd
CVE-2020-9895P3CRITICALCVSS 9.8fixed in 13.1.2≥ unspecified, < Safari 13.1.22020-10-16
CVE-2020-9895 [CRITICAL] CWE-416 CVE-2020-9895: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
nvdapple
CVE-2022-22629P3HIGHCVSS 8.8fixed in 15.4≥ unspecified, < 15.42022-09-23
CVE-2022-22629 [HIGH] CWE-787 CVE-2022-22629: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Mo
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iTunes 12.12.3 for Windows, iOS 15.4 and iPadOS 15.4, tvOS 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2014-1300P3CRITICALCVSS 10.0v7.0.22014-03-26
CVE-2014-1300 [CRITICAL] CVE-2014-1300: Unspecified vulnerability in Apple Safari 7.0.2 on OS X allows remote attackers to execute arbitrary
Unspecified vulnerability in Apple Safari 7.0.2 on OS X allows remote attackers to execute arbitrary code with root privileges via unknown vectors, as demonstrated by Google during a Pwn4Fun competition at CanSecWest 2014.
nvd
CVE-2022-32792P3HIGHCVSS 8.8v15.62022-07-20
CVE-2022-32792 [HIGH] CVE-2022-32792: Safari 15.6
Apple Security Update: About the security content of Safari 15.6
Product: Safari
Version: 15.6
CVE: CVE-2022-32792
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: An out-of-bounds write issue was addressed with improved input validation.
apple
CVE-2023-42852P3HIGHCVSS 8.8fixed in 17.1≥ unspecified, < 17.12023-10-25
CVE-2023-42852 [HIGH] CVE-2023-42852: A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, w
A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, macOS Sonoma 14.1, Safari 17.1, tvOS 17.1. Processing web content may lead to arbitrary code execution.
nvdapple
CVE-2023-40447P3HIGHCVSS 8.8fixed in 17.1≥ unspecified, < 17.12023-10-25
CVE-2023-40447 [HIGH] CWE-119 CVE-2023-40447: The issue was addressed with improved memory handling. This issue is fixed in iOS 17.1 and iPadOS 17
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.1 and iPadOS 17.1, watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, macOS Sonoma 14.1, Safari 17.1, tvOS 17.1. Processing web content may lead to arbitrary code execution.
nvdapple
CVE-2024-23213P3HIGHCVSS 8.8fixed in 17.32024-01-23
CVE-2024-23213 [HIGH] CWE-119 CVE-2024-23213: The issue was addressed with improved memory handling. This issue is fixed in Safari 17.3, iOS 16.7.
The issue was addressed with improved memory handling. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. Processing web content may lead to arbitrary code execution.
nvdapple
CVE-2010-3804P3MEDIUMCVSS 5.0PoC≤ 5.0.2v5.0+51 more2010-11-22
CVE-2010-3804 [MEDIUM] CVE-2010-3804: The JavaScript implementation in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 a
The JavaScript implementation in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, uses a weak algorithm for generating values of random numbers, which makes it easier for remote attackers to track a user by predicting a value, a related issue to CVE-2008-5913 and CVE-2010-3171.
nvd
CVE-2023-41074P3HIGHCVSS 8.8fixed in 17.0≥ unspecified, < 172023-09-27
CVE-2023-41074 [HIGH] CVE-2023-41074: The issue was addressed with improved checks. This issue is fixed in tvOS 17, Safari 17, watchOS 10,
The issue was addressed with improved checks. This issue is fixed in tvOS 17, Safari 17, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may lead to arbitrary code execution.
nvdapple