WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-1153 and CVE-2015-1154.
http://lists.apple.com/archives/security-announce/2015/Jun/msg00001.html
http://lists.apple.com/archives/security-announce/2015/Jun/msg00006.html
http://lists.apple.com/archives/security-announce/2015/May/msg00000.html
http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html
http://lists.opensuse.org/opensuse-updates/2016-03/msg00054.html
http://support.apple.com/kb/HT204941
http://www.securityfocus.com/bid/74525
http://www.securitytracker.com/id/1032270
https://support.apple.com/HT204826
Source: MITRE
Published: 2015-05-08
Updated: 2016-12-03
Type: NVD-CWE-noinfo
Base Score: 6.8
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
Impact Score: 6.4
Exploitability Score: 8.6
Severity: MEDIUM
OR
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* versions up to 8.3 (inclusive)
OR
cpe:2.3:a:apple:itunes:*:*:*:*:*:*:*:* versions up to 12.2 (inclusive)
OR
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* versions up to 6.2.5 (inclusive)
cpe:2.3:a:apple:safari:7.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:7.0.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:7.0.4:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:7.0.5:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:7.0.6:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:7.1.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:7.1.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:7.1.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:7.1.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:7.1.4:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:7.1.5:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:8.0.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:8.0.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:8.0.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:8.0.3:*:*:*:*:*:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
89950 | openSUSE Security Update : webkit2gtk3 (openSUSE-2016-340) | Nessus | SuSE Local Security Checks | medium |
86601 | Apple iTunes < 12.3 Multiple Vulnerabilities (uncredentialed check) | Nessus | Peer-To-Peer File Sharing | high |
86600 | Apple iTunes < 12.2 Multiple Vulnerabilities (uncredentialed check) | Nessus | Peer-To-Peer File Sharing | high |
8958 | iTunes for Windows < 12.3 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | high |
8977 | Apple iOS < 8.4 Multiple Vulnerabilities | Nessus Network Monitor | Mobile Devices | high |
86001 | Apple iTunes < 12.3 Multiple Vulnerabilities (credentialed check) | Nessus | Windows | high |
8870 | Safari < 6.2.6 / 7.1.6 / 8.0.6 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | high |
84504 | Apple iTunes < 12.2 Multiple Vulnerabilities (credentialed check) | Nessus | Windows | high |
84490 | Apple iOS < 8.4 Multiple Vulnerabilities (Logjam) | Nessus | Mobile Devices | high |
83291 | Mac OS X : Apple Safari < 6.2.6 / 7.1.6 / 8.0.6 Multiple Vulnerabilities | Nessus | MacOS X Local Security Checks | medium |