Vulnerability Name: | CVE-2012-0585 (CCN-73871) |
Assigned: | 2012-03-07 |
Published: | 2012-03-07 |
Updated: | 2018-11-29 |
Summary: | The Private Browsing feature in Safari in Apple iOS before 5.1 allows remote attackers to bypass intended privacy settings and insert history entries via JavaScript code that calls the (1) pushState or (2) replaceState method.
|
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): None Integrity (I): Low Availibility (A): None |
|
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Authentication (Au): None | Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None | 5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N) 3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Athentication (Au): None
| Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None |
|
Vulnerability Type: | CWE-264
|
Vulnerability Consequences: | Bypass Security |
References: | Source: MITRE Type: CNA CVE-2012-0585
Source: APPLE Type: Mailing List, Vendor Advisory APPLE-SA-2012-03-07-2
Source: CCN Type: APPLE-SA-2012-03-07-2 iOS 5.1 Software Update
Source: APPLE Type: Mailing List, Vendor Advisory APPLE-SA-2012-03-12-1
Source: OSVDB Type: Broken Link 79964
Source: CCN Type: SA48288 Apple iOS Multiple Vulnerabilities
Source: SECUNIA Type: Third Party Advisory 48288
Source: SECUNIA Type: Third Party Advisory 48377
Source: CCN Type: OSVDB ID: 79964 Apple iOS Safari Private Browsing Mode Weakness Multiple Method Browsing History Recording
Source: CCN Type: BID-52364 Apple iPhone/iPad/iPod touch Prior to iOS 5.1 Multiple Vulnerabilities
Source: SECTRACK Type: Third Party Advisory, VDB Entry 1026774
Source: XF Type: Third Party Advisory, VDB Entry appleios-browsing-sec-bypass(73871)
Source: XF Type: UNKNOWN appleios-browsing-sec-bypass(73871)
|
Vulnerable Configuration: | Configuration 1: cpe:/o:apple:iphone_os:*:*:*:*:*:*:*:* (Version < 5.1) Configuration CCN 1: cpe:/o:apple:iphone_os:3.1:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.0:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.0.1:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.1:-:ipodtouch:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.2.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.2.2:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.0.1:-:ipodtouch:*:*:*:*:*OR cpe:/o:apple:ios:4.0.2:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.0:-:ipodtouch:*:*:*:*:*OR cpe:/o:apple:ios:4.2.1:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.3.2:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.3.1:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.3.3:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.2.5:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.2.8:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.3.0:*:*:*:*:*:*:*OR cpe:/o:apple:ios:5.0:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.0:-:iphone:*:*:*:*:*OR cpe:/o:apple:ios:4.0.1:-:iphone:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.2:-:ipodtouch:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.2:-:iphone:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.2.1:-:ipad:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.1:-:iphone:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.1.3:-:iphone:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.1.2:-:iphone:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.0:-:iphone:*:*:*:*:*OR cpe:/o:apple:ios:4.3.5:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.3.5:-:ipodtouch:*:*:*:*:*OR cpe:/o:apple:ios:4.3.5:-:ipad:*:*:*:*:*OR cpe:/o:apple:ios:5.0.1:*:*:*:*:*:*:*OR cpe:/o:apple:ios:5.0.1:-:ipad:*:*:*:*:*OR cpe:/o:apple:ios:5.0.1:-:iphone:*:*:*:*:*OR cpe:/o:apple:ios:5.0.1:-:ipodtouch:*:*:*:*:*OR cpe:/o:apple:ios:5.0:-:ipad:*:*:*:*:*OR cpe:/o:apple:ios:5.0:-:iphone:*:*:*:*:*OR cpe:/o:apple:ios:5.0:-:ipodtouch:*:*:*:*:*
Denotes that component is vulnerable |
BACK |