Vulnerability Name:

CVE-2018-0560

Assigned:2017-11-27
Published:2018-04-10
Updated:2018-04-16
Summary:Hatena Bookmark App for iOS Version 3.0 to 3.70 allows remote attackers to spoof the address bar via vectors related to URL display.
CVSS v3 Severity:3.1 Low (CCN CVSS v3 Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N)
2.7 Low (CCN Temporal CVSS v3 Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:2.1 Low (CCN CVSS v2 Vector: AV:N/AC:H/Au:S/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
References:Source: CONFIRM
Type: UNKNOWN
http://bookmark.hatenastaff.com/entry/2018/04/09/170000

Source: JVN
Type: UNKNOWN
JVN#77753476

Source: XF
Type: UNKNOWN
hatena-cve20180560-spoofing(141460)

BACK