Vulnerability Name: | CVE-2016-1785 (CCN-111638) | ||||||||||||||||||||
Assigned: | 2016-03-21 | ||||||||||||||||||||
Published: | 2016-03-21 | ||||||||||||||||||||
Updated: | 2018-10-09 | ||||||||||||||||||||
Summary: | The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles character encoding during access to cached data, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site. | ||||||||||||||||||||
CVSS v3 Severity: | 6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N) 5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
| ||||||||||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-1785 Source: APPLE Type: Vendor Advisory APPLE-SA-2016-03-21-1 Source: APPLE Type: Vendor Advisory APPLE-SA-2016-03-21-6 Source: BUGTRAQ Type: UNKNOWN 20160331 WebKitGTK+ Security Advisory WSA-2016-0003 Source: SECTRACK Type: UNKNOWN 1035353 Source: XF Type: UNKNOWN apple-safari-cve20161785-info-disc(111638) Source: CCN Type: Apple Web site About the security content of Safari 9.1 Source: CONFIRM Type: Vendor Advisory https://support.apple.com/HT206166 Source: CONFIRM Type: Vendor Advisory https://support.apple.com/HT206171 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |