VulnerabilityModified
CVE-2015-1126
WebKit, as used in Apple iOS before 8.3 and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, does not properly handle the userinfo field in FTP URLs, which allows remote attackers to trigger incorrect resource access via unspecified…
MEDIUM 4.3EPSS 9.89%
Does this matter?
Lower severity and a low EPSS score (9.89%). Track it; it rarely justifies an emergency change on its own.
Description
WebKit, as used in Apple iOS before 8.3 and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, does not properly handle the userinfo field in FTP URLs, which allows remote attackers to trigger incorrect resource access via unspecified vectors.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 9.89% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- apple/iphone os · apple/safari
- Source
- product-security@apple.com
References
- http://lists.apple.com/archives/security-announce/2015/Apr/msg00000.htmlVendor Advisory
- http://lists.apple.com/archives/security-announce/2015/Apr/msg00002.htmlVendor Advisory
- http://www.securitytracker.com/id/1032047
- https://support.apple.com/HT204658Vendor Advisory
- https://support.apple.com/HT204661Vendor Advisory
- http://lists.apple.com/archives/security-announce/2015/Apr/msg00000.htmlVendor Advisory
- http://lists.apple.com/archives/security-announce/2015/Apr/msg00002.htmlVendor Advisory
- http://www.securitytracker.com/id/1032047
- https://support.apple.com/HT204658Vendor Advisory
- https://support.apple.com/HT204661Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.