CVE-2016-4591 on Ubuntu 14.04 LTS (trusty) - medium.
Description:
WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 mishandles the location variable, which allows remote attackers to access the local filesystem via unspecified vectors.