CVE-2015-5805

MEDIUM

Description

WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.

References

http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html

http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html

http://lists.apple.com/archives/security-announce/2015/Sep/msg00007.html

http://lists.opensuse.org/opensuse-updates/2016-03/msg00054.html

http://www.securityfocus.com/bid/76763

http://www.securitytracker.com/id/1033609

https://support.apple.com/HT205212

https://support.apple.com/HT205221

https://support.apple.com/HT205265

Details

Source: MITRE

Published: 2015-09-18

Updated: 2016-12-22

Type: CWE-119

Risk Information

CVSS v2.0

Base Score: 6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 8.6

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* versions up to 8.0.8 (inclusive)

Configuration 2

OR

cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* versions up to 8.4.1 (inclusive)

Configuration 3

OR

cpe:2.3:a:apple:itunes:*:*:*:*:*:*:*:* versions up to 12.2 (inclusive)

Tenable Plugins

View all (9 total)

IDNameProductFamilySeverity
89950openSUSE Security Update : webkit2gtk3 (openSUSE-2016-340)NessusSuSE Local Security Checks
medium
86601Apple iTunes < 12.3 Multiple Vulnerabilities (uncredentialed check)NessusPeer-To-Peer File Sharing
high
8958iTunes for Windows < 12.3 Multiple Vulnerabilities Nessus Network MonitorWeb Clients
high
8979Apple iOS < 9.0 Multiple VulnerabilitiesNessus Network MonitorMobile Devices
high
8976Safari < 9.0 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
medium
86270Mac OS X < 10.11 Multiple Vulnerabilities (GHOST)NessusMacOS X Local Security Checks
critical
86252Mac OS X : Apple Safari < 9.0 Multiple VulnerabilitiesNessusMacOS X Local Security Checks
critical
86001Apple iTunes < 12.3 Multiple Vulnerabilities (credentialed check)NessusWindows
high
85987Apple iOS < 9.0 Multiple VulnerabilitiesNessusMobile Devices
critical