Описание
The International Domain Name (IDN) support in Safari 1.2.5 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.
Ссылки
- Vendor Advisory
- ExploitVendor Advisory
- Exploit
- Vendor Advisory
- Vendor Advisory
- ExploitVendor Advisory
- Exploit
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:apple:safari:1.2.5:*:*:*:*:*:*:*
EPSS
Процентиль: 65%
0.00495
Низкий
5 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
The International Domain Name (IDN) support in Safari 1.2.5 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.
EPSS
Процентиль: 65%
0.00495
Низкий
5 Medium
CVSS2
Дефекты
NVD-CWE-Other