CVE-2011-0163

MEDIUM

Description

WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle unspecified "cached resources," which allows remote attackers to cause a denial of service (resource unavailability) via a crafted web site that conducts a cache-poisoning attack.

References

http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html

http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html

http://support.apple.com/kb/HT4564

http://support.apple.com/kb/HT4566

http://www.securitytracker.com/id?1025182

https://exchange.xforce.ibmcloud.com/vulnerabilities/66001

Details

Source: MITRE

Published: 2011-03-11

Updated: 2017-08-17

Type: CWE-20

Risk Information

CVSS v2.0

Base Score: 4.3

Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 8.6

Severity: MEDIUM