CVE-2011-4692
WebKit, as used in Apple Safari 5.1.1 and earlier and Google Chrome 15 and earlier, does not prevent capture of data about the time required for image loading, which makes it easier for remote attackers to determine whether an image exists in the…
Does this matter?
Lower severity and a low EPSS score (1.21%). Track it; it rarely justifies an emergency change on its own.
Description
WebKit, as used in Apple Safari 5.1.1 and earlier and Google Chrome 15 and earlier, does not prevent capture of data about the time required for image loading, which makes it easier for remote attackers to determine whether an image exists in the browser cache via crafted JavaScript code, as demonstrated by visipisi.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.21% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- apple/safari · apple/webkit · google/chrome
- Source
- cve@mitre.org
References
- http://lcamtuf.coredump.cx/cachetime/Exploit
- http://oxplot.github.com/visipisi/visipisi.htmlExploit
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14098
- http://lcamtuf.coredump.cx/cachetime/Exploit
- http://oxplot.github.com/visipisi/visipisi.htmlExploit
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14098
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.