Iphone

Vendor:

First CVE: Aug 3, 2007 · Active for 18 years

23
Total CVEs
More Total CVEs than 95% of tracked products
4.6
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
5.6
Avg CVSS
Higher Avg CVSS than 16% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Iphone over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 3, 2007
18 years ago
Most Recent CVE
Mar 18, 2022
1,589 days ago

CVE Severity & Scoring

Iphone23 CVEs
All CVEs352,231 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network1 (4.3%)
Unknown22 (95.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (4.3%)
High0 (0.0%)
Unknown22 (95.7%)
User Interaction
None0 (0.0%)
Unknown22 (95.7%)
Required1 (4.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (4.3%)
Unknown22 (95.7%)

Top CVEs

Signals from CVEs in this product scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Integer signedness error in Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to execute arbitrary code or cause a denial of service (application
Jul 14, 200810.041NOYES
Mobile Safari on Apple iPhone 1.1.2 and 1.1.3 allows remote attackers to cause a denial of service (memory exhaustion and device crash) via certain JavaScript code that constructs
Feb 12, 20087.134NOYES
Use-after-free vulnerability in WebKit in Apple iPod touch 1.1 through 2.0.2, and iPhone 1.0 through 2.0.2, allows remote attackers to execute arbitrary code or cause a denial of s
Sep 11, 20089.327NONO
WebCore in Apple Safari does not properly perform garbage collection of JavaScript document elements, which allows remote attackers to execute arbitrary code or cause a denial of s
Jul 14, 20089.326NONO
The HTTP client functionality in Apple iPhone OS 3.1 on the iPhone 2G and 3.1.3 on the iPhone 3GS allows remote attackers to cause a denial of service (Safari, Mail, or Springboard
Apr 1, 20105.025NOYES
Off-by-one error in the _web_drawInRect:withFont:ellipsis:alignment:measureOnly function in WebKit in Safari in Apple iPhone 1.1.4 and 2.0 and iPod touch 1.1.4 and 2.0 allows remot
Sep 16, 20085.025NOYES
Use-after-free vulnerability in WebKit, as used in Apple Safari before 5.0.5; iOS before 4.3.2 for iPhone, iPod, and iPad; iOS before 4.2.7 for iPhone 4 (CDMA); and possibly other
Mar 10, 20116.824NONO
A logic issue was addressed with improved state management. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing ma
Mar 18, 20226.523NONO
Unspecified vulnerability in Foundation, as used in Apple iPhone 1.0 through 1.1.2, iPod touch 1.1 through 1.1.2, and Mac OS X 10.5 through 10.5.1, allows remote attackers to cause
Jan 16, 20086.821NONO
Apple iPhone 1.1.1, with Bluetooth enabled, allows physically proximate attackers to cause a denial of service (application termination) and execute arbitrary code via crafted Serv
Sep 27, 20077.520NONO

Exploit Exposure

Signals from CVEs in this product scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
17.4% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (23 CVEs).

Media Mentions

Signals from CVEs in this product scope (23 CVEs).

Top CNAs Publishing CVEs For Iphone

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.111.20.3%00
2.0.225.63.2%00
2.0.119.35.9%00
2.027.26.5%01
1.1.427.26.5%01
1.1.319.35.9%00
1.119.35.9%00
1.0214.60.4%00
1.045.21.8%00