Vulnerabilities > Apple > Safari

DATE CVE VULNERABILITY TITLE RISK
2017-05-22 CVE-2017-2505 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple Iphone OS
An issue was discovered in certain Apple products.
network
low complexity
apple CWE-119
8.8
2017-05-22 CVE-2017-2504 Cross-site Scripting vulnerability in Apple Iphone OS
An issue was discovered in certain Apple products.
network
low complexity
apple CWE-79
6.1
2017-05-22 CVE-2017-2500 Improper Input Validation vulnerability in Apple Safari
An issue was discovered in certain Apple products.
network
low complexity
apple CWE-20
4.7
2017-05-22 CVE-2017-2499 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple Iphone OS
An issue was discovered in certain Apple products.
local
low complexity
apple CWE-119
7.8
2017-05-22 CVE-2017-2496 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple Iphone OS
An issue was discovered in certain Apple products.
network
low complexity
apple CWE-119
8.8
2017-05-22 CVE-2017-2495 Improper Input Validation vulnerability in Apple Iphone OS
An issue was discovered in certain Apple products.
network
low complexity
apple CWE-20
6.5
2017-04-24 CVE-2011-3438 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple Safari 5.0.6
WebKit, as used in Safari 5.0.6, allows remote attackers to cause a denial of service (process crash) or arbitrary code execution.
network
low complexity
apple CWE-119
8.8
2017-04-03 CVE-2017-5949 Out-of-bounds Write vulnerability in Apple Safari 22
JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 22, allows remote attackers to cause a denial of service (heap-based out-of-bounds write and application crash) or possibly have unspecified other impact via crafted JavaScript code that triggers access to red-zone memory locations, related to jit/ThunkGenerators.cpp, llint/LowLevelInterpreter32_64.asm, and llint/LowLevelInterpreter64.asm.
network
low complexity
apple CWE-787
critical
9.8
2017-04-03 CVE-2016-10226 Out-of-bounds Read vulnerability in Apple Safari 18
JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 18, allows remote attackers to cause a denial of service (bitfield out-of-bounds read and application crash) via crafted JavaScript code that is mishandled in the operatorString function, related to assembler/MacroAssemblerARM64.h, assembler/MacroAssemblerX86Common.h, and wasm/WasmB3IRGenerator.cpp.
network
low complexity
apple CWE-125
7.5
2017-04-03 CVE-2016-10222 Improper Input Validation vulnerability in Apple Safari 18
runtime/JSONObject.cpp in JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 18, allows remote attackers to cause a denial of service (segmentation violation and application crash) via crafted JavaScript code that triggers a "type confusion" in the JSON.stringify function.
network
low complexity
apple CWE-20
7.5