VYPR

Safari

by Apple Inc.

CVEs (1,740)

  • CVE-2022-32868MedSep 20, 2022
    risk 0.28cvss 4.3epss 0.01

    A logic issue was addressed with improved state management. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. A website may be able to track users through Safari web extensions.

  • CVE-2022-22654MedMar 18, 2022
    risk 0.28cvss 4.3epss 0.01

    A user interface issue was addressed. This issue is fixed in watchOS 8.5, Safari 15.4. Visiting a malicious website may lead to address bar spoofing.

  • CVE-2020-9993MedDec 8, 2020
    risk 0.28cvss 4.3epss 0.01

    The issue was addressed with improved UI handling. This issue is fixed in watchOS 7.0, Safari 14.0, iOS 14.0 and iPadOS 14.0. Visiting a malicious website may lead to address bar spoofing.

  • CVE-2020-9987MedDec 8, 2020
    risk 0.28cvss 4.3epss 0.01

    An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 14.0. Visiting a malicious website may lead to address bar spoofing.

  • CVE-2020-9945MedDec 8, 2020
    risk 0.28cvss 4.3epss 0.01

    A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, Safari 14.0.1. Visiting a malicious website may lead to address bar spoofing.

  • CVE-2020-9942MedDec 8, 2020
    risk 0.28cvss 4.3epss 0.01

    An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, Safari 13.1.2. Visiting a malicious website may lead to address bar spoofing.

  • CVE-2020-9857MedOct 27, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.5, Security Update 2020-003 Mojave, Security Update 2020-003 High Sierra. A malicious website may be able to exfiltrate autofilled data…

  • CVE-2019-8898MedOct 27, 2020
    risk 0.28cvss 4.3epss 0.01

    An information disclosure issue existed in the handling of the Storage Access API. This issue was addressed with improved logic. This issue is fixed in iOS 13.3 and iPadOS 13.3, tvOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows. Visiting a maliciously crafted website may…

  • CVE-2019-8827MedOct 27, 2020
    risk 0.28cvss 4.3epss 0.01

    The HTTP referrer header may be used to leak browsing history. The issue was resolved by downgrading all third party referrers to their origin. This issue is fixed in Safari 13.0.3, iTunes 12.10.2 for Windows, iCloud for Windows 10.9.2, tvOS 13.2, iOS 13.2 and iPadOS 13.2,…

  • CVE-2020-9894MedOct 16, 2020
    risk 0.28cvss 4.3epss 0.03

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A remote attacker may be able to cause…

  • CVE-2020-9784MedApr 1, 2020
    risk 0.28cvss 4.3epss 0.01

    A logic issue was addressed with improved restrictions. This issue is fixed in Safari 13.1. A malicious iframe may use another website’s download settings.

  • CVE-2020-3887MedApr 1, 2020
    risk 0.28cvss 4.3epss 0.01

    A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. A download's origin may be incorrectly associated.

  • CVE-2020-3885MedApr 1, 2020
    risk 0.28cvss 4.3epss 0.02

    A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. A file URL may be incorrectly processed.

  • CVE-2020-3833MedFeb 27, 2020
    risk 0.28cvss 4.3epss 0.01

    An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 13.0.5. Visiting a malicious website may lead to address bar spoofing.

  • CVE-2019-8670MedDec 18, 2019
    risk 0.28cvss 4.3epss 0.01

    An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.6, Safari 12.1.2. Visiting a malicious website may lead to address bar spoofing.

  • CVE-2018-4445MedApr 3, 2019
    risk 0.28cvss 4.3epss 0.01

    "Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This issue affected versions prior to iOS 12.1.1, Safari 12.0.2.

  • CVE-2018-4440MedApr 3, 2019
    risk 0.28cvss 4.3epss 0.02

    A logic issue was addressed with improved state management. This issue affected versions prior to iOS 12.1.1, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.

  • CVE-2018-4307MedApr 3, 2019
    risk 0.28cvss 4.3epss 0.01

    A logic issue was addressed with improved state management. This issue affected versions prior to iOS 12, Safari 12.

  • CVE-2018-4278MedJan 11, 2019
    risk 0.28cvss 4.3epss 0.02

    In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, sound fetched through audio elements may be exfiltrated cross-origin. This issue was addressed with improved audio taint tracking.

  • CVE-2018-4232MedJun 8, 2018
    risk 0.28cvss 4.3epss 0.02

    An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. The issue involves the "WebKit" component. It…

Page 46 of 87