Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-1786

Опубликовано: 24 мар. 2016
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5.8
CVSS3: 5.4

Описание

The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles HTTP responses with a 3xx (aka redirection) status code, which allows remote attackers to spoof the displayed URL, bypass the Same Origin Policy, and obtain sensitive cached information via a crafted web site.

РелизСтатусПримечание
devel

ignored

no update available
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was ignored [no update available]]
esm-infra/xenial

ignored

no update available
precise

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

trusty was ignored [no update available]
upstream

needs-triage

vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

wily

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

ignored

no update available
esm-apps/xenial

ignored

no update available
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was ignored [no update available]]
precise

ignored

end of life
trusty

ignored

end of standard support
trusty/esm

DNE

trusty was ignored [no update available]
upstream

needs-triage

vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

wily

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

precise

ignored

end of life
trusty

DNE

trusty/esm

DNE

upstream

needs-triage

vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

wily

DNE

xenial

DNE

Показывать по

РелизСтатусПримечание
devel

not-affected

2.12.5-1
esm-infra-legacy/trusty

DNE

esm-infra/xenial

not-affected

2.10.9-1ubuntu1
precise

DNE

trusty

DNE

trusty/esm

DNE

upstream

released

2.10.5
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

wily

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

ignored

no update available
esm-apps/xenial

ignored

no update available
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was ignored [no update available]]
precise

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

trusty was ignored [no update available]
upstream

needs-triage

vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

wily

ignored

end of life

Показывать по

EPSS

Процентиль: 63%
0.00441
Низкий

5.8 Medium

CVSS2

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
почти 10 лет назад

The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles HTTP responses with a 3xx (aka redirection) status code, which allows remote attackers to spoof the displayed URL, bypass the Same Origin Policy, and obtain sensitive cached information via a crafted web site.

CVSS3: 5.4
github
больше 3 лет назад

The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles HTTP responses with a 3xx (aka redirection) status code, which allows remote attackers to spoof the displayed URL, bypass the Same Origin Policy, and obtain sensitive cached information via a crafted web site.

fstec
почти 10 лет назад

Уязвимость операционной системы iOS и браузера Safari, позволяющая нарушителю подменить отображаемый URL-адрес, обойти существующую политику ограничения доступа и получить конфиденциальную информацию

EPSS

Процентиль: 63%
0.00441
Низкий

5.8 Medium

CVSS2

5.4 Medium

CVSS3