| Vulnerability Name: | CVE-2015-3755 (CCN-105636) | ||||||||||||||||||||||||
| Assigned: | 2015-08-11 | ||||||||||||||||||||||||
| Published: | 2015-08-11 | ||||||||||||||||||||||||
| Updated: | 2019-02-07 | ||||||||||||||||||||||||
| Summary: | WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, allows remote attackers to spoof the user interface via a malformed URL. | ||||||||||||||||||||||||
| CVSS v3 Severity: | 4.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N) 3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||
| CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
| ||||||||||||||||||||||||
| Vulnerability Type: | CWE-254 | ||||||||||||||||||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2015-3755 Source: APPLE Type: Mailing List, Vendor Advisory APPLE-SA-2015-08-13-1 Source: APPLE Type: Mailing List, Vendor Advisory APPLE-SA-2015-08-13-3 Source: SUSE Type: Mailing List, Third Party Advisory openSUSE-SU-2016:0761 Source: BID Type: Third Party Advisory, VDB Entry 76344 Source: CCN Type: BID-76344 Apple Safari CVE-2015-3755 Muliple Security Bypass Vulnerabilities Source: SECTRACK Type: Third Party Advisory, VDB Entry 1033274 Source: XF Type: UNKNOWN apple-safari-cve20153755-info-disc(105636) Source: CCN Type: Apple Web site About the security content of Safari 8.0.8, Safari 7.1.8, and Safari 6.2.8 Source: CONFIRM Type: Vendor Advisory https://support.apple.com/kb/HT205030 Source: CONFIRM Type: Vendor Advisory https://support.apple.com/kb/HT205033 | ||||||||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
| BACK | |||||||||||||||||||||||||