Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
iOS Number Of NVD 3610 CRITICAL 137 HIGH 1663 MEDIUM 1468 LOW 246
URL https://www.apple.com/jp/ios/
Explanation This is the operating system installed on the iPhone provided by Apple.
Tag
  • Mobile
  • Apple

Add Information URL
No Type Name URL
1 https://support.apple.com/en-us/HT201222
2 https://developer.apple.com/documentation/ios-ipados-release-notes
3 https://en.wikipedia.org/wiki/IOS_version_history

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
2541 iOS17 17.6.1 Aug. 27, 2024 Sept. 18, 2023 8 111 166 22
2542 iOS16 16.4.1 April 7, 2023 Sept. 12, 2022 24 241 291 56
2543 iOS 15 15.7 Sept. 12, 2022 Sept. 20, 2021 38 392 376 72
2544 iOS 14 14.8 Sept. 13, 2021 July 9, 2020 52 563 483 79
2545 iOS 13 13.7 Sept. 1, 2020 Sept. 19, 2019 64 743 567 96
2546 iOS 12 12.5.1 Jan. 11, 2021 Sept. 17, 2018 83 900 647 108
2547 iOS 11 11.4.1 July 9, 2018 Sept. 19, 2017 93 1065 716 116
2548 iOS 10 10.3.4 July 22, 2019 Sept. 13, 2016 119 1286 816 133
2549 iOS 9 9.3.6 July 22, 2019 Sept. 16, 2015 133 1412 943 149
2550 iOS 8 8.4.1 Aug. 13, 2015 Sept. 17, 2014 131 1467 1156 181
2551 iOS 7 7.0.6 Feb. 21, 2014 Sept. 18, 2013 131 1488 1219 204
2552 iOS 6 6.0.2 Dec. 18, 2012 Sept. 19, 2012 131 1514 1282 216
2553 iOS 5 5.0.1 Nov. 10, 2011 Oct. 12, 2011 131 1583 1356 228
2554 iOS 4 4.0.2 Aug. 11, 2010 June 21, 2010 132 1610 1411 235
2555 iPhone OS 3 3.0.1 July 31, 2009 June 17, 2009 132 1617 1426 238
2556 iPhone OS 2 1.1.5 July 15, 2008 July 11, 2008 133 1629 1421 236
2557 iPhone OS 1 1.0.2 Aug. 21, 2007 June 29, 2007 132 1634 1422 237
2558 iOS7.1 7.1.2 131 1481 1195 198
2559 iOS6.1 6.1.6 131 1505 1263 212
2560 iOS6.0 6.0.2 131 1514 1281 216
2561 iOS5.1 5.1.1 131 1524 1334 226
2562 iOS4.3 4.3.5 131 1602 1384 234
2563 iOS4.2 4.2.9 131 1604 1389 234
2564 iOS4.1 4.1 132 1607 1401 234
2565 iOS3.2 3.2.2 132 1611 1416 236
2566 iOS3.1 3.1.3 132 1614 1424 236
2567 iOS2.2 2.2.1 132 1625 1420 232
2568 iOS2.1 2.1.1 132 1629 1421 236
2569 iOS2.0 2.0.2 133 1629 1420 236
2570 iOS16.2 16.2 18 206 258 55
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
2541 7.8
9.3
HIGH
Local
AppleMobileFileIntegrity in Apple iOS before 10 and OS X before 10.12 mishandles process entitlement and Team ID values in the task port inheritance policy, which allows attackers to execute arbitrar… CWE-20
 Improper Input Validation 
CVE-2016-4698 cpe:2.3:o:apple:iphone_os:*:* 9.3.5 2024-11-21 11:52
2016-09-25
Show GitHub Exploit DB Packet Storm
2542 9.8
10.0
CRITICAL
Network
xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, wh… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-4658 cpe:2.3:o:apple:iphone_os:*:* 10.0 2024-11-21 11:52
2016-09-25
Show GitHub Exploit DB Packet Storm
2543 6.1
4.3
MEDIUM
Network
Cross-site scripting (XSS) vulnerability in Safari Reader in Apple iOS before 10 and Safari before 10 allows remote attackers to inject arbitrary web script or HTML via a crafted web site, aka "Unive… CWE-79
Cross-site Scripting
CVE-2016-4618 cpe:2.3:o:apple:iphone_os:*:* 9.3.5 2024-11-21 11:52
2016-09-25
Show GitHub Exploit DB Packet Storm
2544 8.8
6.8
HIGH
Network
WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a differ… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-4611 cpe:2.3:o:apple:iphone_os:*:* 10.0 2024-11-21 11:52
2016-09-25
Show GitHub Exploit DB Packet Storm
2545 3.3
2.1
LOW
Local
Printing UIKit in Apple iOS before 10 mishandles environment variables, which allows local users to discover cleartext AirPrint preview content by reading a temporary file. CWE-200
Information Exposure
CVE-2016-4749 cpe:2.3:o:apple:iphone_os:*:* 9.3.5 2024-11-21 11:52
2016-09-19
Show GitHub Exploit DB Packet Storm
2546 3.7
4.3
LOW
Network
Mail in Apple iOS before 10 mishandles certificates, which makes it easier for man-in-the-middle attackers to discover mail credentials via unspecified vectors. CWE-200
Information Exposure
CVE-2016-4747 cpe:2.3:o:apple:iphone_os:*:* 9.3.5 2024-11-21 11:52
2016-09-19
Show GitHub Exploit DB Packet Storm
2547 5.3
5.0
MEDIUM
Network
The Keyboards component in Apple iOS before 10 does not properly use a cache for auto-correct suggestions, which allows remote attackers to obtain sensitive information in opportunistic circumstances… CWE-200
Information Exposure
CVE-2016-4746 cpe:2.3:o:apple:iphone_os:*:* 9.3.5 2024-11-21 11:52
2016-09-19
Show GitHub Exploit DB Packet Storm
2548 5.9
4.3
MEDIUM
Network
The Assets component in Apple iOS before 10 allows man-in-the-middle attackers to block software updates via vectors related to lack of an HTTPS session for retrieving updates. CWE-254
 7PK - Security Features
CVE-2016-4741 cpe:2.3:o:apple:iphone_os:*:* 9.3.5 2024-11-21 11:52
2016-09-19
Show GitHub Exploit DB Packet Storm
2549 2.9
1.9
LOW
Local
Apple iOS before 10, when Handoff for Messages is used, does not ensure that a Messages signin has occurred before displaying messages, which might allow attackers to obtain sensitive information via… CWE-200
Information Exposure
CVE-2016-4740 cpe:2.3:o:apple:iphone_os:*:* 9.3.5 2024-11-21 11:52
2016-09-19
Show GitHub Exploit DB Packet Storm
2550 5.5
4.3
MEDIUM
Local
The GeoServices component in Apple iOS before 10 and watchOS before 3 does not properly restrict access to PlaceData information, which allows attackers to discover physical locations via a crafted a… CWE-200
Information Exposure
CVE-2016-4719 cpe:2.3:o:apple:iphone_os:*:* 9.3.5 2024-11-21 11:52
2016-09-19
Show GitHub Exploit DB Packet Storm