Vulnerability Name: | CVE-2015-1084 (CCN-101655) | ||||||||
Assigned: | 2015-03-17 | ||||||||
Published: | 2015-03-17 | ||||||||
Updated: | 2015-09-30 | ||||||||
Summary: | The user interface in WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, does not display URLs consistently, which makes it easier for remote attackers to conduct phishing attacks via a crafted URL. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-17 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2015-1084 Source: APPLE Type: Vendor Advisory APPLE-SA-2015-04-08-3 Source: APPLE Type: Vendor Advisory APPLE-SA-2015-03-17-1 Source: SECTRACK Type: UNKNOWN 1031936 Source: XF Type: UNKNOWN apple-safari-cve20151084-phishing(101655) Source: CCN Type: Apple Web site About the security content of Safari 8.0.4, Safari 7.1.4, and Safari 6.2.4 Source: CONFIRM Type: Vendor Advisory https://support.apple.com/HT204560 Source: CONFIRM Type: Vendor Advisory https://support.apple.com/HT204661 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |