cbcvebase.

Apple tvOS vulnerabilities

2,371 known vulnerabilities affecting apple/tvos.

Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL174HIGH1277MEDIUM858LOW59UNKNOWN3

Vulnerabilities

Page 36 of 119
CVE-2016-1857P3HIGHCVSS 8.8fixed in 9.2.12016-05-20
CVE-2016-1857 [HIGH] CVE-2016-1857: WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1854, CVE-2016-1855, and CVE-2016-1856.
nvdapple
CVE-2016-4737P3HIGHCVSS 8.8≤ 10.02016-09-25
CVE-2016-4737 [HIGH] CWE-119 CVE-2016-4737: WebKit in Apple iOS before 10, Safari before 10, tvOS before 10, and watchOS before 3 allows remote WebKit in Apple iOS before 10, Safari before 10, tvOS before 10, and watchOS before 3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
nvdapple
CVE-2026-43810P3CRITICALCVSS 9.8fixed in 26.62026-07-27
CVE-2026-43810 [CRITICAL] CWE-119 CVE-2026-43810: The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26 The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2026-43807P3CRITICALCVSS 9.8fixed in 26.62026-07-27
CVE-2026-43807 [CRITICAL] CWE-120 CVE-2026-43807: A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.5.2 and A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious accessory may be able to cause unexpected app termination.
nvd
CVE-2016-4730P3HIGHCVSS 8.8≤ 10.02016-09-25
CVE-2016-4730 [HIGH] CVE-2016-4730: WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execu WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4611, CVE-2016-4733, CVE-2016-4734, and CVE-2016-4735.
nvdapple
CVE-2016-4735P3HIGHCVSS 8.8fixed in 10.02016-09-25
CVE-2016-4735 [HIGH] CVE-2016-4735: WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execu WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4611, CVE-2016-4730, CVE-2016-4733, and CVE-2016-4734.
nvdapple
CVE-2026-64751P3CRITICALCVSS 9.8fixed in 26.62026-07-27
CVE-2026-64751 [CRITICAL] CWE-416 CVE-2026-64751: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26. A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2016-4624P3HIGHCVSS 8.8fixed in 9.2.22016-07-22
CVE-2016-4624 [HIGH] CVE-2016-4624: WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4589, CVE-2016-4622, and CVE-2016-4623.
nvdapple
CVE-2016-4623P3HIGHCVSS 8.8fixed in 9.2.22016-07-22
CVE-2016-4623 [HIGH] CVE-2016-4623: WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4589, CVE-2016-4622, and CVE-2016-4624.
nvdapple
CVE-2016-4589P3HIGHCVSS 8.8v9.2.22016-07-18
CVE-2016-4589 [HIGH] CVE-2016-4589: tvOS 9.2.2 Apple Security Update: About the security content of tvOS 9.2.2 Product: tvOS Version: 9.2.2 CVE: CVE-2016-4589 Component: WebKit Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: Multiple memory corruption issues were addressed through improved memory handling.
apple
CVE-2016-1856P3HIGHCVSS 8.8fixed in 9.2.12016-05-20
CVE-2016-1856 [HIGH] CVE-2016-1856: WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1854, CVE-2016-1855, and CVE-2016-1857.
nvdapple
CVE-2016-1854P3HIGHCVSS 8.8fixed in 9.2.12016-05-20
CVE-2016-1854 [HIGH] CWE-119 CVE-2016-1854: WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1855, CVE-2016-1856, and CVE-2016-1857.
nvdapple
CVE-2016-7595P3HIGHCVSS 8.8v10.12016-12-12
CVE-2016-7595 [HIGH] CVE-2016-7595: tvOS 10.1 Apple Security Update: About the security content of tvOS 10.1 Product: tvOS Version: 10.1 CVE: CVE-2016-7595 Component: CoreText Impact: Processing a maliciously crafted font file may lead to arbitrary code execution Description: Multiple memory corruption issues existed in the handling of font files. These issues were addressed through improved bounds checking.
apple
CVE-2016-7658P3HIGHCVSS 8.8v10.12016-12-12
CVE-2016-7658 [HIGH] CVE-2016-7658: tvOS 10.1 Apple Security Update: About the security content of tvOS 10.1 Product: tvOS Version: 10.1 CVE: CVE-2016-7658 Component: Audio Impact: Processing a maliciously crafted file may lead to arbitrary code execution Description: A memory corruption issue was addressed through improved input validation.
apple
CVE-2016-7588P3HIGHCVSS 8.8v10.12016-12-12
CVE-2016-7588 [HIGH] CVE-2016-7588: tvOS 10.1 Apple Security Update: About the security content of tvOS 10.1 Product: tvOS Version: 10.1 CVE: CVE-2016-7588 Component: CoreMedia Playback Impact: Processing a maliciously crafted .mp4 file may lead to arbitrary code execution Description: A memory corruption issue was addressed through improved memory handling.
apple
CVE-2016-7659P3HIGHCVSS 8.8v10.12016-12-12
CVE-2016-7659 [HIGH] CVE-2016-7659: tvOS 10.1 Apple Security Update: About the security content of tvOS 10.1 Product: tvOS Version: 10.1 CVE: CVE-2016-7659 Component: Audio Impact: Processing a maliciously crafted file may lead to arbitrary code execution Description: A memory corruption issue was addressed through improved input validation.
apple
CVE-2016-4691P3HIGHCVSS 8.8v10.12016-12-12
CVE-2016-4691 [HIGH] CVE-2016-4691: tvOS 10.1 Apple Security Update: About the security content of tvOS 10.1 Product: tvOS Version: 10.1 CVE: CVE-2016-4691 Component: FontParser Impact: Processing a maliciously crafted font file may lead to arbitrary code execution Description: Multiple memory corruption issues existed in the handling of font files. These issues were addressed through improved bounds checking.
apple
CVE-2016-4586P3HIGHCVSS 8.8fixed in 9.2.22016-07-22
CVE-2016-4586 [HIGH] CWE-119 CVE-2016-4586: WebKit in Apple Safari before 9.1.2 and tvOS before 9.2.2 allows remote attackers to execute arbitra WebKit in Apple Safari before 9.1.2 and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
nvdapple
CVE-2018-4150P3HIGHCVSS 7.8fixed in 11.32018-04-03
CVE-2018-4150 [HIGH] CWE-119 CVE-2018-4150: An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app
nvdapple
CVE-2018-4360P3HIGHCVSS 8.8fixed in 122019-04-03
CVE-2018-4360 [HIGH] CWE-119 CVE-2018-4360: Multiple memory corruption issues were addressed with improved memory handling. This issue affected Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
nvdapple
Apple tvOS vulnerabilities | cvebase