Vulnerability Name: | CVE-2016-4583 (CCN-115695) | ||||||||||||||||||||
Assigned: | 2016-07-21 | ||||||||||||||||||||
Published: | 2016-07-21 | ||||||||||||||||||||
Updated: | 2019-03-20 | ||||||||||||||||||||
Summary: | WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to bypass the Same Origin Policy and obtain image date from an unintended web site via a timing attack involving an SVG document. | ||||||||||||||||||||
CVSS v3 Severity: | 3.1 Low (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N) 2.7 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||
CVSS v2 Severity: | 2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N)
| ||||||||||||||||||||
Vulnerability Type: | CWE-362 | ||||||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-4583 Source: APPLE Type: Mailing List, Vendor Advisory APPLE-SA-2016-07-18-2 Source: APPLE Type: Mailing List, Vendor Advisory APPLE-SA-2016-07-18-4 Source: APPLE Type: Mailing List, Vendor Advisory APPLE-SA-2016-07-18-5 Source: MISC Type: Third Party Advisory, VDB Entry http://packetstormsecurity.com/files/138502/WebKitGTK-SOP-Bypass-Information-Disclosure.html Source: BUGTRAQ Type: Third Party Advisory, VDB Entry 20160825 WebKitGTK+ Security Advisory WSA-2016-0005 Source: BID Type: Third Party Advisory, VDB Entry 91830 Source: CCN Type: BID-91830 Apple iOS/tvOS/Safari Multiple Security Vulnerabilities Source: SECTRACK Type: Third Party Advisory, VDB Entry 1036343 Source: XF Type: UNKNOWN apple-safari-cve20164583-sec-bypass(115695) Source: CCN Type: Apple Web site About the security content of Safari 9.1.2 Source: CONFIRM Type: Vendor Advisory https://support.apple.com/HT206900 Source: CONFIRM Type: Vendor Advisory https://support.apple.com/HT206902 Source: CONFIRM Type: Vendor Advisory https://support.apple.com/HT206905 Source: CCN Type: WhiteSource Vulnerability Database CVE-2016-4583 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |