VulnerabilityModified
CVE-2012-3742
Safari in Apple iOS before 6 does not properly restrict use of an unspecified Unicode character that looks similar to the https lock indicator, which allows remote attackers to spoof https connections by placing this character in the TITLE element of a…
MEDIUM 5.0EPSS 1.92%
Does this matter?
Lower severity and a low EPSS score (1.92%). Track it; it rarely justifies an emergency change on its own.
Description
Safari in Apple iOS before 6 does not properly restrict use of an unspecified Unicode character that looks similar to the https lock indicator, which allows remote attackers to spoof https connections by placing this character in the TITLE element of a web page.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.92% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- apple/iphone os
- Source
- product-security@apple.com
References
- http://lists.apple.com/archives/security-announce/2012/Sep/msg00003.htmlVendor Advisory
- http://osvdb.org/85632
- http://support.apple.com/kb/HT5503Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78708
- http://lists.apple.com/archives/security-announce/2012/Sep/msg00003.htmlVendor Advisory
- http://osvdb.org/85632
- http://support.apple.com/kb/HT5503Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78708
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.