VulnerabilityModified
CVE-2011-0159
The Safari Settings feature in Safari in Apple iOS 4.x before 4.3 does not properly implement the clearing of cookies during execution of the Safari application, which might make it easier for remote web servers to track users by setting a cookie.
MEDIUM 5.0EPSS 1.72%
Does this matter?
Lower severity and a low EPSS score (1.72%). Track it; it rarely justifies an emergency change on its own.
Description
The Safari Settings feature in Safari in Apple iOS 4.x before 4.3 does not properly implement the clearing of cookies during execution of the Safari application, which might make it easier for remote web servers to track users by setting a cookie.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.72% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- apple/iphone os
- Source
- product-security@apple.com
References
- http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.htmlVendor Advisory
- http://support.apple.com/kb/HT4564Vendor Advisory
- http://www.securityfocus.com/bid/46810
- http://www.securitytracker.com/id?1025182
- http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.htmlVendor Advisory
- http://support.apple.com/kb/HT4564Vendor Advisory
- http://www.securityfocus.com/bid/46810
- http://www.securitytracker.com/id?1025182
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.