Cross-site scripting (XSS) vulnerability in the PDF functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL in embedded PDF content.
http://lists.apple.com/archives/security-announce/2015/Jun/msg00004.html
http://lists.opensuse.org/opensuse-updates/2016-03/msg00054.html
http://support.apple.com/kb/HT204950
OR
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* versions up to 6.2.6 (inclusive)
cpe:2.3:a:apple:safari:7.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:7.0.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:7.0.4:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:7.0.5:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:7.0.6:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:7.1.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:7.1.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:7.1.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:7.1.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:7.1.4:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:7.1.5:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:7.1.6:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:8.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:8.0.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:8.0.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:8.0.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:8.0.4:*:*:*:*:*:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
89950 | openSUSE Security Update : webkit2gtk3 (openSUSE-2016-340) | Nessus | SuSE Local Security Checks | medium |
8950 | Safari < 6.2.7 / 7.1.7 / 8.0.7 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | high |
84491 | Mac OS X : Apple Safari < 6.2.7 / 7.1.7 / 8.0.7 Multiple Vulnerabilities | Nessus | MacOS X Local Security Checks | medium |