Vulnerability Name: | CVE-2016-4613 (CCN-118470) | ||||||||||||||||||||
Assigned: | 2016-10-24 | ||||||||||||||||||||
Published: | 2016-10-24 | ||||||||||||||||||||
Updated: | 2017-07-29 | ||||||||||||||||||||
Summary: | An issue was discovered in certain Apple products. Safari before 10.0.1 is affected. iCloud before 6.0.1 is affected. iTunes before 12.5.2 is affected. tvOS before 10.0.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive information via a crafted web site. | ||||||||||||||||||||
CVSS v3 Severity: | 6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N) 5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
| ||||||||||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-4613 Source: BID Type: UNKNOWN 93949 Source: CCN Type: BID-93949 WebKit Memory Corruption and Information Disclosure Vulnerabilities Source: SECTRACK Type: UNKNOWN 1037139 Source: XF Type: UNKNOWN apple-safari-cve20164613-info-disc(118470) Source: CCN Type: Apple security document HT207270 About the security content of tvOS 10.0.1 Source: CCN Type: Apple Web site About the security content of Safari 10.0.1 Source: CCN Type: Apple security document HT207273 About the security content of iCloud for Windows 6.0.1 Source: CCN Type: Apple security document HT207274 About the security content of iTunes 12.5.2 for Windows Source: CONFIRM Type: UNKNOWN https://support.apple.com/HT207270 Source: CONFIRM Type: UNKNOWN https://support.apple.com/HT207272 Source: CONFIRM Type: UNKNOWN https://support.apple.com/HT207273 Source: CONFIRM Type: UNKNOWN https://support.apple.com/HT207274 Source: CCN Type: WhiteSource Vulnerability Database CVE-2016-4613 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration 4: Configuration CCN 1: ![]() | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |