Логотип exploitDog
bind:CVE-2015-3750
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2015-3750

Количество 5

Количество 5

ubuntu логотип

CVE-2015-3750

больше 10 лет назад

WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not enforce the HTTP Strict Transport Security (HSTS) protection mechanism for Content Security Policy (CSP) report requests, which allows man-in-the-middle attackers to obtain sensitive information by sniffing the network or spoof a report by modifying the client-server data stream.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2015-3750

больше 10 лет назад

WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not enforce the HTTP Strict Transport Security (HSTS) protection mechanism for Content Security Policy (CSP) report requests, which allows man-in-the-middle attackers to obtain sensitive information by sniffing the network or spoof a report by modifying the client-server data stream.

CVSS2: 6.4
EPSS: Низкий
github логотип

GHSA-544q-w4rg-fjc5

больше 3 лет назад

WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not enforce the HTTP Strict Transport Security (HSTS) protection mechanism for Content Security Policy (CSP) report requests, which allows man-in-the-middle attackers to obtain sensitive information by sniffing the network or spoof a report by modifying the client-server data stream.

EPSS: Низкий
fstec логотип

BDU:2015-11216

больше 10 лет назад

Уязвимость браузера Safari и операционной системы iOS, позволяющая нарушителю получить доступ к защищаемой информации

CVSS2: 6.4
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2016:0761-1

почти 10 лет назад

Security update for webkit2gtk3

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2015-3750

WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not enforce the HTTP Strict Transport Security (HSTS) protection mechanism for Content Security Policy (CSP) report requests, which allows man-in-the-middle attackers to obtain sensitive information by sniffing the network or spoof a report by modifying the client-server data stream.

CVSS2: 6.4
1%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-3750

WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not enforce the HTTP Strict Transport Security (HSTS) protection mechanism for Content Security Policy (CSP) report requests, which allows man-in-the-middle attackers to obtain sensitive information by sniffing the network or spoof a report by modifying the client-server data stream.

CVSS2: 6.4
1%
Низкий
больше 10 лет назад
github логотип
GHSA-544q-w4rg-fjc5

WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not enforce the HTTP Strict Transport Security (HSTS) protection mechanism for Content Security Policy (CSP) report requests, which allows man-in-the-middle attackers to obtain sensitive information by sniffing the network or spoof a report by modifying the client-server data stream.

1%
Низкий
больше 3 лет назад
fstec логотип
BDU:2015-11216

Уязвимость браузера Safari и операционной системы iOS, позволяющая нарушителю получить доступ к защищаемой информации

CVSS2: 6.4
1%
Низкий
больше 10 лет назад
suse-cvrf логотип
openSUSE-SU-2016:0761-1

Security update for webkit2gtk3

почти 10 лет назад

Уязвимостей на страницу